Re: [hlds_linux] Servers get attacked via DDoS

2013-01-11 Thread Marco Padovan
You need bandwidth, a lot(saw 3gbit+ attacks these days...) Il 11/01/2013 00.47, Martin Pajenkamp ha scritto: It seems, like competitive matches are getting hit by DDoS attacks again, like in 2010. This time, it seems the attacker is using a DNS reflection attack. Does anyone have a tip how to

Re: [hlds_linux] Servers get attacked via DDoS

2013-01-11 Thread Sachin Sud
Hi, I can help you in some ways with ddos attack.! Email me ! I will tell you some things which will help you. Ignoring board because its not required here On Fri, Jan 11, 2013 at 2:22 PM, Marco Padovan e...@evcz.tk wrote: You need bandwidth, a lot(saw 3gbit+ attacks these days...) Il

Re: [hlds_linux] Servers get attacked via DDoS

2013-01-11 Thread Saint K .
Sounds dodgy Why not share on this list? Saint K. From: hlds_linux-boun...@list.valvesoftware.com [hlds_linux-boun...@list.valvesoftware.com] On Behalf Of Sachin Sud [sudsac...@gmail.com] Sent: 11 January 2013 10:43 To: Half-Life dedicated Linux

Re: [hlds_linux] Servers get attacked via DDoS

2013-01-11 Thread Sachin Sud
Hi, My intensions are not to spam this mail list. But if you guys are comfortable , you need to answer few questions by which i can help you better to get saved from ddos attacks. Which country are you from? How many game servers you host? How often the attack happens? Is it specific to any

Re: [hlds_linux] Servers get attacked via DDoS

2013-01-11 Thread Arnim Eijkhoudt
Haha, I hope you're joking. Almost none of your questions are remotely relevant to this type of attack. DNS reflection attacks can only be effectively mitigated upstream. The structural solution, unfortunately, is educating/informing the admins of the broken DNS servers (short of just

Re: [hlds_linux] Servers get attacked via DDoS

2013-01-11 Thread Sachin Sud
LOL :) Jerk! On Fri, Jan 11, 2013 at 3:46 PM, Arnim Eijkhoudt peng...@dhcp.net wrote: Haha, I hope you're joking. Almost none of your questions are remotely relevant to this type of attack. DNS reflection attacks can only be effectively mitigated upstream. The structural solution,

Re: [hlds_linux] Servers get attacked via DDoS

2013-01-11 Thread Michael Johansen
Oh well, atleast Arnim has something useful to say, and besides, your intensions wasn't to spam this mailinglist, however you just did. Congratulations. From: sudsac...@gmail.com Date: Fri, 11 Jan 2013 15:48:29 +0530 To: hlds_linux@list.valvesoftware.com Subject: Re: [hlds_linux] Servers

Re: [hlds_linux] Servers get attacked via DDoS

2013-01-11 Thread Marco Padovan
Are you giving free 10gbit uplinks to everybody? Il 11/01/2013 10.43, Sachin Sud ha scritto: Hi, I can help you in some ways with ddos attack.! Email me ! I will tell you some things which will help you. Ignoring board because its not required here On Fri, Jan 11, 2013 at 2:22 PM, Marco

Re: [hlds_linux] Servers get attacked via DDoS

2013-01-11 Thread Sachin Sud
Too late :( I gave the warning earlier but u never bothered to listen / I will email him personally and take it further! No offence. Because fighting with a Bull makes you one ! On Fri, Jan 11, 2013 at 3:52 PM, Michael Johansen michs...@live.no wrote: Oh well, atleast Arnim has something

Re: [hlds_linux] Servers get attacked via DDoS

2013-01-11 Thread Marco Padovan
yes, the attacks is exactly that... but those are not just broken dns,i even saw some *well known* IT names into the attackers. Il 11/01/2013 11.16, Arnim Eijkhoudt ha scritto: Haha, I hope you're joking. Almost none of your questions are remotely relevant to this type of attack. DNS

Re: [hlds_linux] Servers get attacked via DDoS

2013-01-11 Thread gameadmin
Just because they're well known doesn't make them immune to configuration cockups... one solution might be to get your host to firewall all incoming from port 53 except for stuff coming from your hosts' DNS servers (or google's, or whoever) - that won't help if the bandwidth is going to

Re: [hlds_linux] Servers get attacked via DDoS

2013-01-11 Thread Sachin Sud
@127001 ( Some Pin code) .Orrgy Do i really care? Its better you start protecting your servers before its too late! Don't waste your time !:) On Fri, Jan 11, 2013 at 4:06 PM, gamead...@127001.org wrote: Just because they're well known doesn't make them immune to configuration cockups... one

Re: [hlds_linux] Servers get attacked via DDoS

2013-01-11 Thread Saint K .
We've had incoming DNS query reply attacks over several Gbit/sec. Any non-pro gaming community like ours can't defend against such floods of data. All you can do is have your IP's null-routed and wait till the attack dies out. Saint K. From:

Re: [hlds_linux] Servers get attacked via DDoS

2013-01-11 Thread ics
Most of us have experienced ddos attacks like that and yes nullrouting is the only protection so the whole network isn't affected. There is no protection against that without paying huge sums of money. Those are not an option to small communities. -ics - Alkuperäinen viesti - We've

Re: [hlds_linux] Servers get attacked via DDoS

2013-01-11 Thread Marco Padovan
In my opinion the issue is not caused by poorly configured dns server. But due to poorly configured networks that allows spoofed traffic to leave their routers... I'm sure who is used to get ddos already knows who these ISPs allowing spoofing are... If those networks were shutdown there would be

Re: [hlds_linux] Servers get attacked via DDoS

2013-01-11 Thread Saint K .
One would wish every ISP implemented ip source guard, also for the sake of the stability of their own network. From: hlds_linux-boun...@list.valvesoftware.com [hlds_linux-boun...@list.valvesoftware.com] On Behalf Of Marco Padovan [e...@evcz.tk] Sent: 11

Re: [hlds_linux] Servers get attacked via DDoS

2013-01-11 Thread John
The solution that gamead...@127001.org gave was correct. For DNS DRDoS reflection attacks, the best plan is to have your upstream apply an ACL that whitelists the couple of DNS servers that you use and blocks all other traffic from port 53 to your network. Your ISP should be able to do this

Re: [hlds_linux] Large Gaps in the net_graph

2013-01-11 Thread dan
On 10/01/2013 16:52, Essay Tew Phaun wrote: I've narrowed it down. It occurs when turning corners or viewing a new area of a map that has enemies and it's a hard pause, too. There's absolutely nothing normal with these pauses. It's completely unreasonable to expect people to play that way. You

Re: [hlds_linux] Large Gaps in the net_graph

2013-01-11 Thread Essay Tew Phaun
I get it everywhere, on all servers. Like mentioned in my post above, I'm starting to think it's some kind of client problem now. On Fri, Jan 11, 2013 at 2:21 PM, dan needa...@ntlworld.com wrote: On 10/01/2013 16:52, Essay Tew Phaun wrote: I've narrowed it down. It occurs when turning corners

Re: [hlds_linux] Large Gaps in the net_graph

2013-01-11 Thread j m
Again, it's a client issue. The answer is not to be found here. On Jan 11, 2013 12:54 PM, Essay Tew Phaun sc2p...@gmail.com wrote: I get it everywhere, on all servers. Like mentioned in my post above, I'm starting to think it's some kind of client problem now. On Fri, Jan 11, 2013 at 2:21

Re: [hlds_linux] Large Gaps in the net_graph

2013-01-11 Thread Essay Tew Phaun
Okay, and? It wasn't until just a reply or so ago where I suspected that it may be just that. On Fri, Jan 11, 2013 at 4:01 PM, j m zooter...@gmail.com wrote: Again, it's a client issue. The answer is not to be found here. On Jan 11, 2013 12:54 PM, Essay Tew Phaun sc2p...@gmail.com wrote:

Re: [hlds_linux] Servers get attacked via DDoS

2013-01-11 Thread Jake Forrester
I know this is a little late, but here's an iptables rule I use to help against DDoS attacks. You'll probably need to have two--one for UDP and one for TCP if it's a DNS type of attack. # allow only 8 req/sec per IP -A INPUT -p tcp -m state --state NEW -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -m