search -  faq -  rulez -  staff

forums






map cycle
irc              pwnalizer
voice         dswp bar




Register

Login


It is currently 05.22.12

 

All times are UTC + 1 hour




Post new topic Reply to topic  [ 9 posts ] 
Author Message
PostPosted: 09.19.11 
Offline
Ingame Mod
User avatar

Joined: 12.28.09
Posts: 130
-----tdm:  
nick: Mad
skill: 1684.29
kills: 165635
deaths: 114622
ratio: 1.44
-----bomb:  
nick: InBulletsWeTrust
skill: 1462.65
kills: 577
deaths: 608
ratio: 0.94
-----ts:  
nick: MadaFakir
skill: 1498.28
kills: 67
deaths: 60
ratio: 1.11
i was playing on tdm when spect attack began
check it if u can



 


Top
 Profile  
 
PostPosted: 09.19.11 
Offline
Ingame Mod
User avatar

Joined: 05.08.09
Posts: 437
Location: Germany
-----tdm:  
nick: fubar
skill: 1621.86
kills: 66219
deaths: 50256
ratio: 1.31
-----bomb:  
nick: |S.Kracht|
skill: 1492.6
kills: 58
deaths: 62
ratio: 0.93
-----ts:  
nick: |S.Kracht|
skill: 1379.73
kills: 357
deaths: 368
ratio: 0.97
yea i c it someones flooding with fake clients.


Attack started 11:42 with client ID 339356 (Nick: 1CI4vbIAK) and lasted until 12:01 with client ID 339501 (Nick: IVuhosI1OTT), so 146 bots were connected.
http://www.dswp.de/echelon/clients.php? ... 30.178.187

http://whois.domaintools.com/99.130.178.187
-> http://whois.arin.net/rest/net/NET-99-128-0-0-1
http://www.robtex.com/ip/99.130.178.187.html

i banned one client but that doesnt help, all different GUID, but always one IP (lol?), and looks like AT&T dialup from Indianapolis

how does no iptable rule prevent so many connections from one src?

edit:
so i had nothin better to do than trolling around abit. that machine wasnt running ssh, win service, socks etc. but... 80.

so lets have a look at this, i guess most likely compromised, machine:


You do not have the required permissions to view the files attached to this post.



 


Last edited by SKracht on 09.19.11, edited 1 time in total.

Top
 Profile  
 
PostPosted: 09.19.11 
Offline
Ingame Mod
User avatar

Joined: 12.05.10
Posts: 939
Location: Estonia, the genuine Earthrealm
-----tdm:  
nick: Adnub
skill: 1682.8
kills: 46788
deaths: 50258
ratio: 0.93
-----bomb:  
nick: AngryFruitSalad
skill: 1148.11
kills: 16
deaths: 33
ratio: 0.48
-----ts:  
nick: Tsundere
skill: 1000.35
kills: 2
deaths: 8
ratio: 0.25
Ain’t it just lovely (UrT forum):

Server COnnection Flooder
Admins: a new tool spotted

_________________
We have adopted affirmative action: for every warning/kick there must be an equivalent punishment for a player in your team.
We’re still evaluating its feasibility for bans; the most likely policy will be moving the cheater to the opposite team if needed.



 


Top
 Profile  
 
PostPosted: 09.19.11 
Offline
Ingame Mod
User avatar

Joined: 05.08.09
Posts: 437
Location: Germany
-----tdm:  
nick: fubar
skill: 1621.86
kills: 66219
deaths: 50256
ratio: 1.31
-----bomb:  
nick: |S.Kracht|
skill: 1492.6
kills: 58
deaths: 62
ratio: 0.93
-----ts:  
nick: |S.Kracht|
skill: 1379.73
kills: 357
deaths: 368
ratio: 0.97
Hm yea I think it doesn't make much traffic but it occupies all slots and i had to join server bye console.

as seen on screenshot...

i googled for something like that, flood tools for urt or q3 server, but found nothing usefull, thx for those links.
this can be easily fixed *imho* but whats the sense of that floodin? why should someone take that effort just to -fill- servers?
Or does it make more traffic than i can imagine?
i dont get the point of this -_-

i didnt do complete scan of that machine just checked a handfull ports, maybe someone gets an deeper nmap inspection on it. i'm pretty sure its a zombie.


You do not have the required permissions to view the files attached to this post.



 


Top
 Profile  
 
PostPosted: 09.20.11 
Offline
Ingame Mod
User avatar

Joined: 05.08.09
Posts: 437
Location: Germany
-----tdm:  
nick: fubar
skill: 1621.86
kills: 66219
deaths: 50256
ratio: 1.31
-----bomb:  
nick: |S.Kracht|
skill: 1492.6
kills: 58
deaths: 62
ratio: 0.93
-----ts:  
nick: |S.Kracht|
skill: 1379.73
kills: 357
deaths: 368
ratio: 0.97
Seems like he is going on, started @ 3:02 tonight and continues since, he is not connecting masses but only a few bots.
new ip ranges:

99.66.79.19
99.70.42.87
99.62.107.38
99.130.207.77
99.130.205.129

looks like he found some realy bad managed piece off hardware overthere.

alphahusky maybe was able to get the real guy, connecting from 84.109.92.101



 


Top
 Profile  
 
PostPosted: 09.20.11 
Offline
Humppaimitat
User avatar

Joined: 07.15.08
Posts: 3773
Location: Behind U
-----tdm:  
nick: cp_-r_miez.plz
skill: 1718.46
kills: 119204
deaths: 79658
ratio: 1.49
-----bomb:  
nick: miez.plz
skill: 1485.74
kills: 9854
deaths: 9081
ratio: 1.08
-----ts:  
nick: miez.plz
skill: 1429.43
kills: 1055
deaths: 778
ratio: 1.35
Hm AFAIK theres no fix for this DOS Attack in the Q3 engine.
The exploit was found (as so often) by Luigi Auriemma, see here:
http://aluigi.altervista.org/poc.htm
He dont release prooves of concept for software wheres no fix.
if someone (who knows C) wanna have it for testing:
send me PM or ask Luigi for help, hes a friendly guy.
BTW. before u go fixing day+night, maybe check the IoQ3 Dev to find friends...

whats left atm: 99.130.192.0/20 as a new firewall rule, his subnet seem to change from time to time.

Whats possible from my POV:
Auto- Firewall these connections. We have always
- multiple clients
- connecting rapidly
- from the same IP
- ping is 999
- theres no GUID (sure)
Its the smaller solution then install this additional bot, plus it should work better...

####EDIT####
just read krachts IP list.
--> corrected to 99.0.0.0/8
we europeans are pinky pussies, thats teh fucking problem. right? good bye texas. say hello to mister bush.
:D

_________________
Image



 


Top
 Profile  
 
PostPosted: 09.20.11 
Offline
Ingame Mod
User avatar

Joined: 05.08.09
Posts: 437
Location: Germany
-----tdm:  
nick: fubar
skill: 1621.86
kills: 66219
deaths: 50256
ratio: 1.31
-----bomb:  
nick: |S.Kracht|
skill: 1492.6
kills: 58
deaths: 62
ratio: 0.93
-----ts:  
nick: |S.Kracht|
skill: 1379.73
kills: 357
deaths: 368
ratio: 0.97
yep, x connections in x time from 1 ip -> drop. should do it

thx for Luigi link



 


Top
 Profile  
 
PostPosted: 09.20.11 
Offline
fear the MADMIN
User avatar

Joined: 09.01.08
Posts: 1482
-----tdm:  
nick: Hateyouall
skill: 1601.33
kills: 252483
deaths: 151422
ratio: 1.66
-----bomb:  
nick: Thrill.Kill.Cult
skill: 1382.76
kills: 8184
deaths: 7784
ratio: 1.05
-----ts:  
nick: hateyouall
skill: 1424.1
kills: 1422
deaths: 1407
ratio: 1.01
btw. Seen the same spec connecting spam tonight on two other servers.

_________________
Image



 


Top
 Profile  
 
PostPosted: 09.20.11 
Offline
Minister of Defense
User avatar

Joined: 07.21.08
Posts: 851
-----tdm:  
nick: [dswp]Ana
skill: 1754.25
kills: 177628
deaths: 113337
ratio: 1.56
-----bomb:  
nick: [dswp]Ana
skill: 1568.47
kills: 8484
deaths: 8148
ratio: 1.04
-----ts:  
nick: Ana
skill: 1458.91
kills: 2321
deaths: 2163
ratio: 1.07
what i noticed on q3 is that when such floader reconnects all the time its usualy the same slot number. so i once did !kick 7 for like 10 minutes til he gave up, since then i couldnt do ip-ban. but be carefull..

_________________
"Ana is concerned for the future of our world as the best and the brightest of our children are becoming lost in computer games"



 


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 9 posts ] 

All times are UTC + 1 hour


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Imprint

Powered by phpBB © 2000, 2002, 2005, 2007, 2008, 2009, 2010 phpBB Group

Skin by Lucas Kane
we use apache2 mod rewrite with phpBB SEO
map train_beta1-100 © 2009 by SteveMcQueen
Statistics Backend + Database by XLR Stats and B3 Bot
mapvote robot and gameserver monitor © 2009 by BlinKy
mumble viewer Copyright © 2008 Dominik Radner (aka Urmel)
mumble switcher and integration © 2008 by XTJ7, Unclefragger and Wursti
Localisation Plugin © 2009, Team Leads Plugin © 2009 and Knifer Plugin © 2009 by SvaRoX



voice server
tdm » dswp.de:22222
status: online
players: 7/45
map: ut4_turnpike
 
bomb » dswp.de:22223
status: online
players: 0/12
map: ut4_harbortown
 
jump » dswp.de:22224
status: online
players: 0/10
map: ut4_train_dl1
 
team survivor » dswp.de:22225
status: online
players: 0/20
map: ut4_prague
 
siesta » dswp.de:22226
status: offline
btw test the new ajax serwer monitor here!
top 20 players


nameskillkills
RastaSkud1601.41404124
NormaSnockers1782.95356641
Hateyouall1601.33252483
Slevin.Kelevra1714.18189976
Wagner_Moura1562.9188001
Ham&Cheese1923.53181902
z0rn1608.41181016
[dswp]Ana1754.25177628
Goomba1710.31172531
Mad1684.29165635
sleepingsun1662.42162927
Zohan1611.07159737
ubercunt1634.93159240
[VR]Amantius1693.89155438
[dswp]Zottel1738.96151362
TG|Deviant1934.94148148
Graf_ZahlIII1683.66136671
ZEBRA(ESP)1598.25134104
DeletedUser0011537.41132992
marshallLaw1744.68128298