Forum

ASSIST, AMERICA'S ARMY COMMUNITY - RELIVE THE GLORY DAYS OF AMERICA'S ARMY 2.5

Author Topic: DDOS Attacks - Remove addresses  (Read 2879 times)

0 Members and 1 Guest are viewing this topic.

Offline 82nd_DXO_COL=Shad

DDOS Attacks - Remove addresses
« on: Wednesday, February 26, 2014, 12:46:47 PM »
I don't know if these attacks are annoying anyone or not.  Apparently whoever is doing them doesn't much usage of the LOIC and they don't last long.  But, I have some ideas on making it harder for whomever is doing it to work harder doing it.

First thing I'd like people to do is look at the Assist server list and see who may be benefiting - who's left.  Maybe there's a douchebag trying to drive player traffic their way.  The other possibility is that somebody is just being a douchebag and has no interest.

I hate to go to this extreme, but I think I will have to pull server information out of Battletracker to keep IP and port information private.  Same goes for GameTracker and other similar sites as well.  These attacks are targeted towards AA ports using a known problem in the Unreal 2.5 engine.  I would ask that Assist remove both the IP information and Port information from the Assist client.  Individual users do not need them to connect anymore.  The information should stay private within the Assist client.
While some of us may not have the flexibility to change IP addresses, we do have the flexibility to change our ports.  And yes, I know technically a person can still get that information, but would have to go through a hell of a harder time to do so, especially with multiple servers.  I'd rather take the fun out of it for them.

Offline ELiZ

Re: DDOS Attacks - Remove addresses
« Reply #1 on: Wednesday, February 26, 2014, 14:33:56 PM »
Even if you get all sites, including the assist Client to hide IP/port, a "bad" person would just join the server, and that way get all the info needed anyway

Offline 82nd_DXO_COL=Shad

Re: DDOS Attacks - Remove addresses
« Reply #2 on: Wednesday, February 26, 2014, 14:53:41 PM »
What they seem to be doing is going down a list of multiple servers when they do the attacks.  Where they get that list of ips/ports, I am not sure if it's Battletracker (which publishes XML sources of ips), or if they're going into the assist client and writing/copying the addresses down.  If the address information was blocked from the Assist client, to get information on each server they would have to connect to each server and use networking tools to get the ip/port information.  So, they would have to work harder for their effort.  If it was just a matter of one server, I'd agree with you on that.
This may not even be anyone part of the Assist community.  They are spamming specific AA ports I use, but could be working a list off of Battletracker.  I'm seeing ports 8777 and 1716 (I don't use 1716) being spammed as well.  It may not even be an Assist providing the information.  But we do not use or need specific ip address/port information for connecting to servers anymore.  Assist handles that, so I would think it isn't needed anymore.
« Last Edit: Wednesday, February 26, 2014, 15:02:30 PM by 82nd_DXO_COL=Shad »

Offline ELiZ

Re: DDOS Attacks - Remove addresses
« Reply #3 on: Wednesday, February 26, 2014, 14:58:56 PM »
This game is based on the use of gamespy.

All the info needed there is available though a simple gamespy query.

Offline 82nd_DXO_COL=Shad

Re: DDOS Attacks - Remove addresses
« Reply #4 on: Wednesday, February 26, 2014, 15:04:30 PM »
There are two GS queries:  One to the server, and one to GameSpy master server.  Which do you refer to?  I thought GS no longer supported AA2 servers and that armyops wasn't sending to the master server anymore - so the query to GS would be out.  The one to the server requires knowing the ip address and the port  to begin with.
« Last Edit: Wednesday, February 26, 2014, 15:26:06 PM by 82nd_DXO_COL=Shad »

Offline Possessed

  • bWpnRecoil == False;
  • Administrator
  • Epic Poster
  • *
  • Posts: 3,620
  • You suffer, but why?!
    • View Profile
  • AA: Possessed
Re: DDOS Attacks - Remove addresses
« Reply #5 on: Wednesday, February 26, 2014, 17:14:59 PM »
Server IP:port is avaliable pressing F4(?) in-game too :)
These things I have spoken unto you, that in me ye might have peace. In the world ye shall have tribulation: but be of good cheer; I have overcome the world.
John 16:33


Offline [SWISS]Merlin

Re: DDOS Attacks - Remove addresses
« Reply #6 on: Wednesday, February 26, 2014, 18:02:24 PM »
for a ddos attack you only need the ip - and this you can get at the server list :(
or in game

Offline 82nd_DXO_COL=Shad

Re: DDOS Attacks - Remove addresses
« Reply #7 on: Thursday, February 27, 2014, 13:24:57 PM »
These attacks are botnet attacks directly targeting the AA gameport and the queryport (+1).  They are using an exploit in the Unreal 2.5 engine that causes high (100%)  cpu utilization of the server (thus crashing AA and lagging any other server program like httpd, teamspeak, ect) when sending malformed packets to the game and query ports.  So, if you are NOT running the default ports (1716), an attacker still has to find your IP and Ports.  To do this, I suspect they're grabbing a list of IPs and ports off of Battletracker.  If not, they're simply clicking through the Assist client server list and gathering the information, or worse they're getting this information from Assist by other means.  My point is, if you take your server off of Battletracker, and if Assist did not give ip/port information (which it doesn't need to) and you DO NOT RUN THE STANDARD PORT then the attacker would have to connect to every server to get that information.  A determined attacker can do what they want.  You can just restart your server with the -Port= option with a random port and the ongoing DDOS doesn't affect AA server anymore. The attacker's information becomes old quickly. Somebody doing it for the fun and lulz might not bother doing this with a bunch of servers if the information was harder to get to.
« Last Edit: Thursday, February 27, 2014, 14:38:35 PM by 82nd_DXO_COL=Shad »

Offline Possessed

  • bWpnRecoil == False;
  • Administrator
  • Epic Poster
  • *
  • Posts: 3,620
  • You suffer, but why?!
    • View Profile
  • AA: Possessed
Re: DDOS Attacks - Remove addresses
« Reply #8 on: Thursday, February 27, 2014, 14:01:31 PM »
Its easy to find the server IP:port. Servers that aren't on BT list aren't tracked too :)
These things I have spoken unto you, that in me ye might have peace. In the world ye shall have tribulation: but be of good cheer; I have overcome the world.
John 16:33


Offline 82nd_DXO_COL=Shad

Re: DDOS Attacks - Remove addresses
« Reply #9 on: Thursday, February 27, 2014, 14:17:34 PM »
Good point about BT.  Do ya wanna get tracked or DDOS'd today lol
Well, if Assist ever does take over tracking from BT, now they know what not to publicly list...
« Last Edit: Thursday, February 27, 2014, 14:36:58 PM by 82nd_DXO_COL=Shad »

Offline [SWISS]Merlin

Re: DDOS Attacks - Remove addresses
« Reply #10 on: Thursday, February 27, 2014, 16:29:15 PM »
yeah shad, you are right. this would be a solution. but therefor the assist own tracking system has to be running because we would not have that much players on non tracked servers.

 

Download Assist

×

Download Game Client

Important: Battletracker no longer exists. However, old Battletracker accounts may still work. You can create a new 25Assist account here

Download Server Manager