Server flooded with multiple connections
#1

This is an emergency. My server keeps getting attacked these days with a tool that creates multiple connections. I don't know how, but they got past the host firewall and they are forcing the CPU causing major lag. I banned the person who attacked up until now, and just when the things were getting better, they came back after about an hour, and this time they were more than one.

I don't know what tool they use, but like I said, it got past the firewalls and filters and it forces the CPU up to 100 %.
Once the players connect to the server they stay frozen. They never get to choose the class.

Here is what I found on the log (this is the 1st guy caught):
Код:
[19:10:55] Incoming connection: 78.96.188.35:62119
[19:10:56] Incoming connection: 78.96.188.35:62120
[19:10:56] Incoming connection: 78.96.188.35:62121
[19:10:56] Incoming connection: 78.96.188.35:62122
[19:10:57] Incoming connection: 78.96.188.35:62123
[19:10:57] Incoming connection: 78.96.188.35:62124
[19:10:57] Incoming connection: 78.96.188.35:62125
[19:10:58] Incoming connection: 78.96.188.35:62126
[19:10:58] Incoming connection: 78.96.188.35:62127
I banned him on sight but after an hour, big surprise. More came back:
Код:
[22:07:33] Incoming connection: 78.97.16.45:1336
[22:07:52] Incoming connection: 79.118.228.243:1262
[22:08:07] Incoming connection: 94.62.248.206:1875
[22:08:13] Incoming connection: 89.123.128.14:3808
[22:08:14] Incoming connection: 188.173.28.230:2904
[22:08:32] Incoming connection: 82.78.92.191:57533
[22:08:41] Incoming connection: 80.96.113.3:62634
[22:08:54] Incoming connection: 89.123.128.14:3825
[22:08:55] Incoming connection: 95.65.59.38:6412
[22:08:56] Incoming connection: 86.126.176.58:4915
[22:09:01] Incoming connection: 188.27.93.248:61331
[22:09:13] Incoming connection: 188.24.166.41:59809
[22:09:31] Incoming connection: 194.102.249.120:65375
[22:09:40] Incoming connection: 89.39.62.156:59739
[22:09:41] Incoming connection: 2.82.134.16:49451
[22:09:42] Incoming connection: 86.104.54.38:56876
[22:09:43] Incoming connection: 188.25.97.3:65192
[22:09:51] Incoming connection: 80.96.113.3:64615
[22:10:18] Incoming connection: 90.230.195.71:61479
[22:10:20] Incoming connection: 92.83.253.223:9771
[22:10:59] Incoming connection: 80.96.113.3:64616
[22:11:11] Incoming connection: 86.122.106.25:4321
[22:11:31] Incoming connection: 2.82.134.16:49455
[22:12:28] Incoming connection: 78.97.221.141:61257
[22:12:43] Incoming connection: 86.122.102.51:4398
[22:12:52] Incoming connection: 78.97.57.92:61629
[22:13:04] Incoming connection: 2.82.134.16:49484
They seem to connect partially to the server, because we can't seem to see them coming and going.
And to be honest, I don't know what to think on the second wave. I can't know if they are actually players or bots, because there are to many IP's.

Is there any script what so ever that can stop these connections? I really need some help here, please!! I know people somehow make connection limits per time to prevent flood. How can I do that?
Reply
#2

What host are you using?
Reply
#3

http://forum.sa-mp.com/showthread.ph...32#post1668332
Reply
#4

Quote:
Originally Posted by Alex Valdez
Посмотреть сообщение
What host are you using?
I don't really know what type of host it is. All I know is that so far it served us very well.

Quote:
Originally Posted by Porsche911
Посмотреть сообщение
That seems to me my problem. Thank you for the link, I'll try those codes.
Reply
#5

No code will work for this problem because the bots never connect.
You can't detect them with pawn
Reply
#6

that's just great....Any other ideas?
Reply
#7

Firewall all those ips manually...
Reply
#8

If your running on a VPS you can IP.Drop thier tables (another firewall function).
Reply
#9

it's a public hosting service. I already contacted them about this and they told me that they will do something...meanwhile, the server is still down. I don't want to wait for them...
Reply
#10

He has several routers...
Reply


Forum Jump:


Users browsing this thread: 2 Guest(s)