it's server attack?
#1

i found something from my server_log.txt:
Code:
[12:41:14] [connection] incoming connection: 123.249.81.206:54807 id: 13
[12:41:16] [connection] incoming connection: 123.249.81.206:54808 id: 13
[12:41:18] [connection] incoming connection: 123.249.81.206:54809 id: 13
[12:41:32] [connection] incoming connection: 123.249.81.206:54810 id: 13
[12:41:35] [connection] incoming connection: 123.249.81.206:54811 id: 13
[12:41:37] [connection] incoming connection: 123.249.81.206:54812 id: 13
[12:41:44] [connection] incoming connection: 123.249.81.206:54813 id: 13
[12:41:47] [connection] incoming connection: 123.249.81.206:54814 id: 13
[12:41:48] [connection] incoming connection: 123.249.81.206:54815 id: 13
[12:41:51] [connection] incoming connection: 123.249.81.206:54816 id: 13
[12:41:54] [connection] incoming connection: 123.249.81.206:54817 id: 13
[12:42:08] [connection] incoming connection: 123.249.81.206:54818 id: 13
[12:42:12] [connection] incoming connection: 123.249.81.206:54819 id: 13
[12:42:19] [connection] incoming connection: 123.249.81.206:54820 id: 13
[12:42:23] [connection] incoming connection: 123.249.81.206:54821 id: 13
[12:42:25] [connection] incoming connection: 123.249.81.206:54822 id: 13
[12:42:29] [connection] incoming connection: 123.249.81.206:54823 id: 13
[12:42:42] [connection] incoming connection: 123.249.81.206:54824 id: 13
[12:42:43] [connection] incoming connection: 123.249.81.206:54825 id: 13
[12:42:52] [connection] incoming connection: 123.249.81.206:54826 id: 13
[12:43:04] [connection] incoming connection: 123.249.81.206:54827 id: 13
[12:43:07] [connection] incoming connection: 123.249.81.206:54828 id: 13
[12:43:23] [connection] incoming connection: 123.249.81.206:54829 id: 13
[12:43:26] [connection] incoming connection: 123.249.81.206:54830 id: 13
[12:43:31] [connection] incoming connection: 123.249.81.206:54831 id: 13
[12:43:34] [connection] incoming connection: 123.249.81.206:54832 id: 13
[12:43:48] [connection] incoming connection: 123.249.81.206:54833 id: 13
[12:44:03] [connection] incoming connection: 123.249.81.206:54834 id: 13
[12:44:22] [connection] incoming connection: 123.249.81.206:54835 id: 13
[12:44:25] [connection] incoming connection: 123.249.81.206:54836 id: 13
[12:44:28] [connection] incoming connection: 123.249.81.206:54837 id: 13
[12:44:29] [connection] incoming connection: 123.249.81.206:54838 id: 13
[12:44:41] [connection] incoming connection: 123.249.81.206:54839 id: 13
[12:44:45] [connection] incoming connection: 123.249.81.206:54840 id: 13
[12:44:54] [connection] incoming connection: 123.249.81.206:54841 id: 13
[12:44:59] [connection] incoming connection: 123.249.81.206:54842 id: 13
[12:45:03] [connection] incoming connection: 123.249.81.206:54843 id: 13
[12:45:08] [connection] incoming connection: 123.249.81.206:54844 id: 13
[12:45:08] [connection] incoming connection: 123.249.81.206:54845 id: 13
[12:45:11] [connection] incoming connection: 123.249.81.206:54846 id: 13
[12:45:17] [connection] incoming connection: 123.249.81.206:54847 id: 13
[12:45:22] [connection] incoming connection: 123.249.81.206:54848 id: 13
[12:45:27] [connection] incoming connection: 123.249.81.206:54849 id: 13
[12:45:33] [connection] incoming connection: 123.249.81.206:54850 id: 13
[12:45:42] [connection] incoming connection: 123.249.81.206:54851 id: 13
[12:45:45] [connection] incoming connection: 123.249.81.206:54852 id: 13
[12:45:48] [connection] incoming connection: 123.249.81.206:54853 id: 13
look like someone attack my server...which way he used?
Reply
#2

anyone here?
Reply
#3

Yes, It's attack on your server.

The best way to prevent this is a protection against bots or limit IP per connection and range ban his IP.
Reply
#4

Quote:
Originally Posted by Hunud
View Post
Yes, It's attack on your server.

The best way to prevent this is a protection against bots or limit IP per connection and range ban his IP.
It's not an attack and there is no need to limit IPs in this case.

The IP who is trying to connect is still the same. It looks like it is a bot attack because the IP re-connects every 3/4 seconds.

Maybe the client has not a good connection to connect, so it repeats the connection many times.

Attacks or DDOS attacks are showed with: "[warning] dropping a split packet from client"
Reply
#5

thank for your reply
Reply
#6

Just limit ip connections

PHP Code:
public OnPlayerConnect(playerid)
{
    new 
ip[16], ip2[16], count 0;
    if(
IsPlayerNPC(playerid)) return 1;
    
GetPlayerIp(playeridipsizeof(ip));
    for(new 
0GetPlayerPoolSize(); <= ji++)
    {
        if(!
IsPlayerConnected(i) || IsPlayerNPC(i)) continue;
        
GetPlayerIp(iip2sizeof(ip2));
        if(!
strcmp(ipip2))
        {
            
count ++;
            if(
count 3)
            {
                
Kick(playerid);
                
count --;
            }
        }
    }
    return 
1;

Reply
#7

Just limit the gap between two connections in server.cfg with minconnectiontime
Reply
#8

Quote:
Originally Posted by MAOREM
View Post
Attacks or DDOS attacks are showed with: "[warning] dropping a split packet from client"
Tf no it doesn't?

And i recommend following what @alanhutch said, it's the easiest way, you also got a callback that records these incoming connections Here

It could also be lag on that client's side, this shouldn't even affect your server in any way regardless.
Reply
#9

Raknet Bot member not attack/ddos
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)