Project 1999

Go Back   Project 1999 > Blue Community > Blue Server Chat

Closed Thread
 
Thread Tools Display Modes
  #1  
Old 07-27-2013, 03:22 PM
Gaffin Deeppockets Gaffin Deeppockets is offline
Banned


Join Date: Apr 2013
Posts: 285
Default

The more you morans talk about it the more its gonna happen.
  #2  
Old 07-27-2013, 04:10 PM
Glorindale Glorindale is offline
Sarnak


Join Date: May 2010
Posts: 209
Default

Quote:
Originally Posted by Gaffin Deeppockets [You must be logged in to view images. Log in or Register.]
The more you morans talk about it the more its gonna happen.
What the hell are morans and do they have anything to do with IP rangers? ;-)

So it will just go away if we stop talking about it? Wow..why didn't think of that?
  #3  
Old 07-27-2013, 04:17 PM
kingsBlend kingsBlend is offline
Sarnak

kingsBlend's Avatar

Join Date: Sep 2010
Posts: 238
Send a message via AIM to kingsBlend
Default

What I don't understand is.. Rogean, you are the man. You know your shit when it comes to servers and networking, you proved it to us. How do you not know just a little bit on Network Security?
  #4  
Old 07-27-2013, 04:26 PM
Rogean Rogean is offline
¯\_(ツ)_/¯

Rogean's Avatar

Join Date: Oct 2009
Location: Massachusetts
Posts: 5,390
Default

Quote:
Originally Posted by kingsBlend [You must be logged in to view images. Log in or Register.]
How do you not know just a little bit on Network Security?
It's not a lack of knowledge. It's a lack of time and resources.

I have a full time job that gets increasingly busy in the summer. I have commitments all this weekend. I have a trip coming up that I leave for very soon that will put me away for a week. The timing of all of this shit happening is the worst it could possibly be.

Look up DNS Amplification attack, and you guys will see just how little there is that I can do about it myself. No amount of equipment I put on my side of our data center drop will help line saturation. It's up to our data center. I'm seeing what they are willing to do, as well as their upstream providers (Level3).

We used to have DDoS protection. It's one of the reasons that we moved to the data center we're at now. But then they decomissioned the device and decided to not replace it, so now we're stuck in the data center without mitigation. If there's nothing they can do to stop this then we're looking at literally a month or two for us to find and move to a data center that can.
__________________
Sean "Rogean" Norton
Project 1999 Co-Manager

Project 1999 Setup Guide
  #5  
Old 07-27-2013, 04:34 PM
captincrust captincrust is offline
Aviak


Join Date: Sep 2012
Posts: 74
Default

As far as I am know, this is the most common and effective response to combating DDoS attacks. Often your internet service provider will do this sort of stuff as well since it clogs up their network to a degree. I think this is the best option.

There may be something to be done with the login server - EQEmu has been getting pummeled simultaneously and I suspect there is some bug being exploited with the login server. Various eqemu cheat sites (ie: RedGuides) have alluded to this very recently.
  #6  
Old 07-27-2013, 04:46 PM
Glorindale Glorindale is offline
Sarnak


Join Date: May 2010
Posts: 209
Default

Quote:
Originally Posted by Rogean [You must be logged in to view images. Log in or Register.]
It's not a lack of knowledge. It's a lack of time and resources.

I have a full time job that gets increasingly busy in the summer. I have commitments all this weekend. I have a trip coming up that I leave for very soon that will put me away for a week. The timing of all of this shit happening is the worst it could possibly be.

Look up DNS Amplification attack, and you guys will see just how little there is that I can do about it myself. No amount of equipment I put on my side of our data center drop will help line saturation. It's up to our data center. I'm seeing what they are willing to do, as well as their upstream providers (Level3).

We used to have DDoS protection. It's one of the reasons that we moved to the data center we're at now. But then they decomissioned the device and decided to not replace it, so now we're stuck in the data center without mitigation. If there's nothing they can do to stop this then we're looking at literally a month or two for us to find and move to a data center that can.
Ah. Now all of you conspiracy theorist can put their "duping" conspiracies to rest. This attack isn't exploiting the game. It is exploiting the TCP/IP stack.

Rogean, it sounds like this attack is affecting other hosted customers at your ISP? If so maybe they will actually do something about it.
  #7  
Old 07-27-2013, 04:55 PM
Rogean Rogean is offline
¯\_(ツ)_/¯

Rogean's Avatar

Join Date: Oct 2009
Location: Massachusetts
Posts: 5,390
Default

Quote:
Originally Posted by Glorindale [You must be logged in to view images. Log in or Register.]
It is exploiting the TCP/IP stack.
DNS is UDP Traffic, not TCP.
__________________
Sean "Rogean" Norton
Project 1999 Co-Manager

Project 1999 Setup Guide
  #8  
Old 07-27-2013, 05:03 PM
Glorindale Glorindale is offline
Sarnak


Join Date: May 2010
Posts: 209
Default

Quote:
Originally Posted by Rogean [You must be logged in to view images. Log in or Register.]
DNS is UDP Traffic, not TCP.
UDP is part of the TCP/IP stack. Sorry to play gotcha but you started it.
  #9  
Old 07-28-2013, 11:42 AM
Pringles Pringles is offline
Planar Protector


Join Date: Nov 2010
Posts: 1,982
Default

Quote:
Originally Posted by Rogean [You must be logged in to view images. Log in or Register.]
It's not a lack of knowledge. It's a lack of time and resources.

I have a full time job that gets increasingly busy in the summer. I have commitments all this weekend. I have a trip coming up that I leave for very soon that will put me away for a week. The timing of all of this shit happening is the worst it could possibly be.

Look up DNS Amplification attack, and you guys will see just how little there is that I can do about it myself. No amount of equipment I put on my side of our data center drop will help line saturation. It's up to our data center. I'm seeing what they are willing to do, as well as their upstream providers (Level3).

We used to have DDoS protection. It's one of the reasons that we moved to the data center we're at now. But then they decomissioned the device and decided to not replace it, so now we're stuck in the data center without mitigation. If there's nothing they can do to stop this then we're looking at literally a month or two for us to find and move to a data center that can.


I am just speculating here since I dont know the scope of the attack, only what you noted about DNS amplification attack, but what about firewalling all DNS related traffic on the p99 boxen, and have us to use our own DNS resolution for the server (windows hosts file). Would that at all help? I wouldnt mind making host entries to resolve p99 DNS so that you can shut it off.
  #10  
Old 07-28-2013, 12:49 PM
Glorindale Glorindale is offline
Sarnak


Join Date: May 2010
Posts: 209
Default

Quote:
Originally Posted by Pringles [You must be logged in to view images. Log in or Register.]
I am just speculating here since I dont know the scope of the attack, only what you noted about DNS amplification attack, but what about firewalling all DNS related traffic on the p99 boxen, and have us to use our own DNS resolution for the server (windows hosts file). Would that at all help? I wouldnt mind making host entries to resolve p99 DNS so that you can shut it off.
I think the only thing that would mitigate the problem is a devices that sits on the ISP's side of Rogean's drop (or somewhere in the path of their connection to the rest of the world). That device would need to be able to track DNS name resolution requests so that when the name resolution responses are returned it could then match them up with the requests and block any responses that don't have matching requests (thus blocking the responses to the spoofed requests). Unfortunately doing that on Rogean's side of the drop wouldn't prevent his drop from being saturated which is what he described was the problem.

I think if his ISP isn't willing to help he has no choice but to move to one that would be willing to help if this happens again.

Boiled down....Rogean really cannot do anything himself to prevent this.
Closed Thread


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 04:59 AM.


Everquest is a registered trademark of Daybreak Game Company LLC.
Project 1999 is not associated or affiliated in any way with Daybreak Game Company LLC.
Powered by vBulletin®
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.