Re: [hlds_linux] Incoming DoS attack

2012-11-28 Thread Collin Howard
These days any 12 year old with their mommy's credit card can buy botnets and booters to do attacks. From: Marco Padovan e...@evcz.tk To: hlds_linux@list.valvesoftware.com Sent: Tuesday, November 27, 2012 8:34:28 AM Subject: Re: [hlds_linux] Incoming DoS

Re: [hlds_linux] Incoming DoS attack

2012-11-28 Thread Michael Johansen
The funny thing is, you can actually do so on the IP. Some skid has made a Booter as it's |called in their community| which you can use to take down shit. Send an abuse report to Santrex and block this ip in your software firewall if you are on gigabit, it's only capable of pushing out ~300

Re: [hlds_linux] Incoming DoS attack

2012-11-28 Thread Collin Howard
Yea lol tell me about it! I have been constantly attacked on and off for the past 4 months due to my servers being in the top 20 on gametracker for CS1.6 I must have seen all kinds of ddos attacks out there. For those on linux and getting syn floods, a nice preventative thing you can do is

Re: [hlds_linux] Incoming DoS attack

2012-11-28 Thread Michael Johansen
Syn cookies didn't help for me sadly. Had to tune sysctl a tad more. Bumping up the maximum values for nf_conntrack module and all sorts of things. Now I'm using a couple of iptables rules to block all SYN-packets going over 5 per second. I've blocked ~800k packets the last days since enabling

Re: [hlds_linux] Incoming DoS attack

2012-11-28 Thread Saint K .
Our other server yesterday got hit by the so called DNS response DDoS. So I'm guessing right now the attack wasn't aimed at exploiting SRCDS itself, but simply to put down our services. Not much you can do but wait for the attacks to die out. (If every ISP would just implement ip source guard

Re: [hlds_linux] Incoming DoS attack

2012-11-28 Thread Michael Johansen
If you're with a ISP/provider that actually takes care of their customers they |can| just blackhole the ip's that are attacking, or the signature of the attack in their routers, problem is that it takes time and it takes a lot of CPU, and there may also be like 20k IP's and then you're out of

Re: [hlds_linux] Incoming DoS attack

2012-11-28 Thread Erik-jan Riemers
I am not a promoter, but with Hetzner if an attack is on my server, I just get an email with the list of ip's that where doing the ddos stating they stopped them from coming through. -Original Message- From: hlds_linux-boun...@list.valvesoftware.com

Re: [hlds_linux] Incoming DoS attack

2012-11-28 Thread Michael Johansen
IIRC Hetzner are all automated right? Would be good for them to have a automatic blocking system, so they dont have to spend money on people manning their NOC (if they even have one). From: riem...@binkey.nl Date: Wed, 28 Nov 2012 13:34:22 +0100 To: hlds_linux@list.valvesoftware.com

Re: [hlds_linux] Incoming DoS attack

2012-11-28 Thread Marco Padovan
they use netflow. that specific email is sent for imformative purpose only. if the attack keeps going they nullroute you and disconnect your server from the network Il 28/11/2012 13.36, Michael Johansen ha scritto: IIRC Hetzner are all automated right? Would be good for them to have a

Re: [hlds_linux] Incoming DoS attack

2012-11-28 Thread Collin Howard
  Hi, what rules did you setup to block the syn packets in iptables? After enabling syn cookies it helped for a while but now its not helping. Thanks. From: Michael Johansen michs...@live.no To: hlds_linux@list.valvesoftware.com Sent: Wednesday, November 28,

Re: [hlds_linux] Potential fix for problems on multi-honed servers

2012-11-28 Thread Fletcher Dunn
Hello! If you were using these new binaries during yesterday's Steam prop, let me know how it went. Is the problem resolved? Same problems happened? New problems happened? Thanks, - Fletch From: hlds-boun...@list.valvesoftware.com [mailto:hlds-boun...@list.valvesoftware.com] On Behalf Of

Re: [hlds_linux] Potential fix for problems on multi-honed servers

2012-11-28 Thread Ejziponken -
Does this apply to HLDS 1.6? From: fletch...@valvesoftware.com To: h...@list.valvesoftware.com; hlds_linux@list.valvesoftware.com Date: Wed, 28 Nov 2012 22:33:06 + Subject: Re: [hlds_linux] Potential fix for problems on multi-honed servers Hello! If you were using these new

Re: [hlds_linux] Potential fix for problems on multi-honed servers

2012-11-28 Thread Fletcher Dunn
Yes, those games talk to Steam in the same way, so a multi-honed server could experience the problem. -Original Message- From: hlds_linux-boun...@list.valvesoftware.com [mailto:hlds_linux-boun...@list.valvesoftware.com] On Behalf Of Ejziponken - Sent: Wednesday, November 28, 2012 2:52

Re: [hlds_linux] Potential fix for problems on multi-honed servers

2012-11-28 Thread Ejziponken -
Hm We have one machine with 13 HLDS servers and all of them has one IP each. But I can find my servers in STEAMS serverlist.Could I still have the problem? If I can see the servers, will everybody else see them too? From: fletch...@valvesoftware.com To: hlds_linux@list.valvesoftware.com

Re: [hlds_linux] Potential fix for problems on multi-honed servers

2012-11-28 Thread 1nsane
I was getting something along the lines of could not locate account. Only way for me to get rid of that was to restart the server. On Wed, Nov 28, 2012 at 5:33 PM, Fletcher Dunn fletch...@valvesoftware.comwrote: Hello! If you were using these new binaries during yesterday's Steam prop, let me

[hlds_linux] Replay server going down causes main game server to crash?

2012-11-28 Thread hlds mailing
Apparently if your remote replay server goes offline (due to network or whatever), the entire main TF2 gameserver freezes and you get this error: http://pastebin.com/fxTFjuen This just happened on one of my servers when my replay server became unreachable. This means that if the game server OR

Re: [hlds_linux] Replay server going down causes main game server to crash?

2012-11-28 Thread ics
This has happened to me but the gameserver remains working, only replay shuts itself down. I'm using http method though. -ics - Alkuperäinen viesti - Apparently if your remote replay server goes offline (due to network or whatever), the entire main TF2 gameserver freezes and you get

Re: [hlds_linux] Replay server going down causes main game server to crash?

2012-11-28 Thread Cameron Munroe
Why do you think I disabled replays on my servers? This has been an issue since a year ago and never has and likely never will be fixed. On , hlds mailing wrote: Apparently if your remote replay server goes offline (due to network or whatever), the entire main TF2 gameserver freezes and

Re: [hlds_linux] Replay server going down causes main game server to crash?

2012-11-28 Thread hlds mailing
The local http method? I'm using the FTP method and assuming Cameron was using the same thing. This simple like a simple bug that can be patched... can't believe it's been around for a year. On Wed, Nov 28, 2012 at 10:45 PM, ics i...@ics-base.net wrote: This has happened to me but the

Re: [hlds_linux] Replay server going down causes main game server to crash?

2012-11-28 Thread pilger
This has been around for quite a while. I had to set my server to local HTTP in order to avoid the constant crashes. On 29 November 2012 01:36, hlds mailing h...@mitchellhuang.net wrote: Apparently if your remote replay server goes offline (due to network or whatever), the entire main TF2