Page 1 of 2 12 LastLast
Results 1 to 10 of 17

  Click here to go to the first Developer post in this thread.  

Thread: Patch the game to prevent DDOS exploit please!

  1. #1

    Patch the game to prevent DDOS exploit please!

    As it stands, currently ArmA server can be attacked by a DDOS attack using spoofed IP's to make the gameserver in turn send replies to the spoofed IP.
    This has happened to our server lately and I have had to nullroute several subnets and send apologizing emails to host providers after receiving abuse emails from them.

    Make the game handshake by having the client send a request, server replies ok, but please send back this cookie, client replies with cookie and server establishes session..

    / Preed

  2. #2
    Not sure I understand how this will prevent the attacker from spamming initial requests and the server forwarding the spam by replying "OK" to the spoofed IP (with or without "cookie")?

    Don't get me wrong, I look forward to a working generic solution, since this problem is rampaging in many other games as well.

    ~~ He flung himself upon his camel and rode madly off in all directions ~~

  3. #3
    Well, it prevents amplification.. But I guess maybe you could also throw in a time based block on traffic from that IP for a period of time.. Like 30 seconds, if the spoofed IP doesn't reply back like the gameserver expects..
    Another way could be to have a control connection on TCP.. And not respond to any traffic from an ip that doesnt have a corresponding TCP connection.. But this will take a bit more work to implement.

  4. #4
    Hey Preed,

    I too have experienced this. Would be interested in finding a solution.
    Head Admin of Reality Gaming
    Mature Tactical ARMA 2 Community
    www.realitygamer.org


  5. #5
    "organized" attacks aren't the real problem, but simply thousands of people trying to get on DayZ servers by spamming enter which causes servers to die.

    Asus Crosshair IV Formula | Phenom II X6 1090T BE @ 3.8GHz | Sapphire Radeon HD 7870 OC 2GB | 8192MB Kingston 1333MHz DDR3 | WD Caviar Black 1TB 64MB | Creative X-Fi Titanium HD | Seasonic X-750

  6. #6
    Are you guys referring to GameSpy query, or actual game traffic? Because re GameSpy they switched to the protocol revision with handshake some months ago?
    Perhaps good idea to make a private ticket on the Community Issue Tracker with some more details, perhaps logs etc.
    A.C.E. Advanced Combat Environment

    Dev-Heaven.net Free Project Hosting | A2 Community Issue Tracker Help BIS, Help yourself!

  7.   Click here to go to the next Developer post in this thread.   #7

  8. #8
    1. Heavily tune firewall. switch from FW-grimmick lick conntrack stuff to something more serious. like zorp or so. in especially-hostile environment, turn on and tune convener-attacking feats.
    [sometimes]it would be surprising to attacker 2 see message shortly before being offended too. not recommended "in general".
    2. deploy/update/configure full-scale IPS/IDS, such as Snort, Suricata and etc.
    3. purchase hardware IPS/Firewall thingy. partially offload/shrug-off ~40% of stuff.
    4. ENFORCE DEP/NX full-time[Windows users can use something like "bcdedit.exe/set nx AlwaysOn" with administrator privilege/rights, for reference].
    5. put tiny/LW EWS IDS-stuff, alike PSAD on server and heavily tune it on-topic too.
    Last edited by BasileyOne; Jul 29 2012 at 08:43.

  9. #9

    Angry Fort Saint John, BC

    Quote Originally Posted by PreedSwe View Post
    Well, it prevents amplification.. But I guess maybe you could also throw in a time based block on traffic from that IP for a period of time.. Like 30 seconds, if the spoofed IP doesn't reply back like the gameserver expects..
    Another way could be to have a control connection on TCP.. And not respond to any traffic from an ip that doesnt have a corresponding TCP connection.. But this will take a bit more work to implement.
    Hi Preed. The Life Mission servers have always been targets of multi source packet flood attack as you say DDOS exploit (lol)

    Here is what I did:

    Make your server appear down to Novatech0, no matter where he is trying to "see your server" from. He'll think he has won and the attack will cease.

    Also order him a pizza? *nod to da. / AAA*

    For obvious reasons I will not disclose any technical details here. Catch me creeping on these TS3 servers for now 72.20.13.74, ts3.arma2life.com:9988 or ts3.lifeprojectrpg.com if you'd like more infos.

  10. #10
    Master Sergeant SnR's Avatar
    Join Date
    May 17 2007
    Location
    South Australia
    Posts
    676
    Or send your infos to Dwarden. Thanks.

Page 1 of 2 12 LastLast

Similar Threads

  1. Takistan Life Revolution Server under constant DDOS attack.
    By dbx125 in forum ARMA 2 & OA - MULTIPLAYER
    Replies: 6
    Last Post: May 10 2012, 11:58
  2. I can't patch the game using the Beta Patch
    By Jonason in forum ARMA 2 & OA - TROUBLESHOOTING
    Replies: 2
    Last Post: May 30 2009, 02:22
  3. Beta 1.15 Server Admin Exploit?
    By TeeCee in forum ARMA - MULTIPLAYER
    Replies: 10
    Last Post: Feb 27 2009, 19:50
  4. DSO exploit
    By pogingwapo in forum OFFTOPIC
    Replies: 2
    Last Post: Jul 12 2004, 02:21
  5. Face cheating exploit
    By [AIM]Holzy in forum MULTIPLAYER
    Replies: 8
    Last Post: Dec 13 2003, 01:32

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •