Firewall Cookie Flood Connection
#1

Hello friends as promised I'm here!

Protection for the new type of attack described: http://forum.sa-mp.com/showthread.ph...=1#post3919175

The sa:mp authentication system is very simple!

In less than 1 minute any hacker will clone these packages! The hosting companies limited the ability to connect by ip! Now this does not solve the attack is spoofed the attacker uses the ip he wants!

I recommend that kalcor launch an update with an effective authentication system!

I am willing to test the authentication system if there is update!


I was able to Minimize the situation,
The attacker sends only 1 packet of each query [i, r, c]
And 1 cookie request packet!

How about blocking the first bundle of all players with dates [i, r, c and cookie date]?
: This really works without interfering with the rejecting connection to the first packets for all clients!

[EDIT]: the attacker changed his attack script! some improvements had to be made!
when an ip tries to send the packets for 1 second its packets will be blocked, blocking all the first packets of the queries and cookie,
except for query i, in the case of query i I only accept the first package in the interval of 1 second,

this in theory blocks 90% of malicious packages,


after sending the first packets the client ip will be released and no longer blocked by the firewall!


a spoofed attack is not impossible to block!

all attacks are anomalies, although the packets are the same as the client samp.

Unfortunately it is not possible to see the effects of the firewall on the same server node!
ie the firewall must be placed a node earlier than the samp server is.


Example: I own a dedicated, add iptables rules in this dedicated, and create a vps and host my samp server!
in this way it will be possible to see that 90% of the attack is not redirected to the vps server, that is, blocked by iptables!
update your Firewall script!

[EDIT]: samp update
Quote:
Originally Posted by Kalcor
Посмотреть сообщение
I've been working on a temporary fix. Anything better than this would require a client/server update, which would take a lot longer to get out to players. I want to be clear again that nothing added to the SA-MP server code can stop network attacks. There's a point where your host will fold from too many packets, no matter whether you're running a SA-MP server, an IRC server, a MUD, linx, a usenet mirror, color terminal, bitchx etc.

Feedback is requested.

Update 0.3.7 R2-2 (testing):

- Changes the query flood control to deal with different query types independently.
- Connection cookie logging is disabled by default.

Downloads (testing):

SA-MP 0.3.7 R2-2 Linux Server: http://files.sa-mp.com/samp037svr_R2-2.tar.gz
SA-MP 0.3.7 R2-2 Windows Server: http://files.sa-mp.com/samp037_svr_R2-2_win32.zip
UBI has developed a plugin that removes query limits.
can be of great help! use link:http://ubi.livs.pl/samp/samp_prot_ver2.zip


Iptables Firewall Script: https://github.com/Edresson/SAMP-Firewall

[UPDATE ]: problem solved ! The firewall only worked for a specific ip,
Now the firewall works for all servers that use port 7777

Thanks to JernejL Beta Tester for reporting the problem!

Download the Firewall.sh file

Run in linux using: sh Firewall.sh

Sorry about my terrible English .

Original topic: http://forum.sa-mp.com/showthread.ph...37#post3919237
Cordially BlastHoting, http://www.blasthosting.com.br/
Reply


Messages In This Thread
Firewall Protection for Cookie Flood Connection new attack - by RDM - 26.08.2017, 01:59
Re: [CODE] Firewall New Exploit Cookie Flood Connection ! - by Xeon™ - 26.08.2017, 02:05
Re: [CODE] Firewall New Exploit Cookie Flood Connection ! - by RDM - 26.08.2017, 02:19
Re: [CODE] Firewall New Exploit Cookie Flood Connection ! - by Noir - 26.08.2017, 04:24
Re: [CODE] Firewall New Exploit Cookie Flood Connection ! - by Sgt.TheDarkness - 26.08.2017, 07:01
Re: [CODE] Firewall New Exploit Cookie Flood Connection ! - by RDM - 26.08.2017, 09:57
Re: [CODE] Firewall New Exploit Cookie Flood Connection ! - by Sgt.TheDarkness - 26.08.2017, 10:38
Re: [CODE] Firewall New Exploit Cookie Flood Connection ! - by RDM - 26.08.2017, 10:51
Respuesta: Firewall Cookie Flood Connection - by adri1 - 26.08.2017, 20:58
Re: Respuesta: Firewall Cookie Flood Connection - by RDM - 26.08.2017, 21:46
Respuesta: Re: Respuesta: Firewall Cookie Flood Connection - by adri1 - 26.08.2017, 21:56
Re: Respuesta: Re: Respuesta: Firewall Cookie Flood Connection - by RDM - 26.08.2017, 22:04
Re: Firewall Cookie Flood Connection - by Ubi - 26.08.2017, 23:21
Re: Firewall Cookie Flood Connection - by RDM - 27.08.2017, 01:02
Re: Firewall Cookie Flood Connection - by Sgt.TheDarkness - 27.08.2017, 01:19
Re: Firewall Cookie Flood Connection - by Jayse - 27.08.2017, 09:26
Re: Firewall Cookie Flood Connection - by RDM - 27.08.2017, 12:04
Re: Firewall Cookie Flood Connection - by RDM - 27.08.2017, 12:06
Re: Firewall Cookie Flood Connection - by Ubi - 27.08.2017, 22:26
Re: Firewall Cookie Flood Connection - by RDM - 27.08.2017, 23:22
Re: Firewall Cookie Flood Connection - by JernejL - 29.08.2017, 09:14
Re: Firewall Cookie Flood Connection - by RDM - 29.08.2017, 11:04
Re: Respuesta: Firewall Cookie Flood Connection - by RDM - 29.08.2017, 12:19
Respuesta: Firewall Cookie Flood Connection - by adri1 - 29.08.2017, 12:37
Re: Firewall Cookie Flood Connection - by Peek - 29.08.2017, 13:57
Re: Firewall Cookie Flood Connection - by RDM - 29.08.2017, 15:59
Re: Firewall Cookie Flood Connection - by Kaperstone - 29.08.2017, 22:33
Re: Firewall Cookie Flood Connection - by RDM - 29.08.2017, 22:55
Re: Firewall Cookie Flood Connection - by Kaperstone - 29.08.2017, 23:05
Re: Firewall Cookie Flood Connection - by RDM - 29.08.2017, 23:13
Re: Firewall Cookie Flood Connection - by PrettyDiamond - 02.09.2017, 06:06
Re: Firewall Cookie Flood Connection - by Chaprnks - 02.09.2017, 06:31
Re: Firewall Cookie Flood Connection - by PrettyDiamond - 02.09.2017, 16:49
Re: Firewall Cookie Flood Connection - by Astralis - 02.09.2017, 17:01
Re: Firewall Cookie Flood Connection - by Astralis - 02.09.2017, 18:05
Re: Firewall Cookie Flood Connection - by RDM - 02.09.2017, 22:09
Re: Firewall Cookie Flood Connection - by SlowARG - 31.01.2019, 04:45

Forum Jump:


Users browsing this thread: 2 Guest(s)