47
« on: Thursday, February 27, 2014, 13:24:57 PM »
These attacks are botnet attacks directly targeting the AA gameport and the queryport (+1). They are using an exploit in the Unreal 2.5 engine that causes high (100%) cpu utilization of the server (thus crashing AA and lagging any other server program like httpd, teamspeak, ect) when sending malformed packets to the game and query ports. So, if you are NOT running the default ports (1716), an attacker still has to find your IP and Ports. To do this, I suspect they're grabbing a list of IPs and ports off of Battletracker. If not, they're simply clicking through the Assist client server list and gathering the information, or worse they're getting this information from Assist by other means. My point is, if you take your server off of Battletracker, and if Assist did not give ip/port information (which it doesn't need to) and you DO NOT RUN THE STANDARD PORT then the attacker would have to connect to every server to get that information. A determined attacker can do what they want. You can just restart your server with the -Port= option with a random port and the ongoing DDOS doesn't affect AA server anymore. The attacker's information becomes old quickly. Somebody doing it for the fun and lulz might not bother doing this with a bunch of servers if the information was harder to get to.