Project 1999

Go Back   Project 1999 > General Community > Technical Discussion

Reply
 
Thread Tools Display Modes
  #1  
Old 01-03-2015, 07:39 AM
Kemtar Kemtar is offline
Large Bat


Join Date: Dec 2014
Posts: 10
Default Weird UDP Spam from Rogeans IP

so i am getting really weird Firewall Spam on port 6000 from the IP 108.61.129.178

http://i.imgur.com/KWrB4Yr.png

IP Adress seems to be connected to Rogean:

http://myip.ms/view/ip_addresses/181...108.61.129.191

I am currently NOT running P99 and this spam has been going on for a while now trying to connect.

This is kind of worrying me reading about rootkit accusations of the .dll in the past.
Reply With Quote
  #2  
Old 01-03-2015, 07:50 AM
towbes towbes is offline
Aviak

towbes's Avatar

Join Date: Dec 2014
Posts: 96
Default

Check if there is an instance of eqgame.exe running in your process list. I'm not at home so I can't compare that udp request to packet captures with Wireshark while playing, but that is something else you could do in your investigating.
Reply With Quote
  #3  
Old 01-03-2015, 07:54 AM
Kemtar Kemtar is offline
Large Bat


Join Date: Dec 2014
Posts: 10
Default

no eqgame.exe running, i re-connected the DSL and got a new IP adress, Spam has now stopped. I did play on PEQ this morning and payed a visit to the new Alkabor.

I had now logged to char select in p99 to see if port 6000 is getting spammed again, so far not.
Reply With Quote
  #4  
Old 01-03-2015, 08:07 AM
towbes towbes is offline
Aviak

towbes's Avatar

Join Date: Dec 2014
Posts: 96
Default

When playing the game there is a constant stream of UDP packets coming and going, they start the second you attempt to connect from login screen. Download the program wireshark (it's free, find it on google) and you can see the packets in real time. Establish a baseline when playing, then you can determine if what you saw was suspicious. It could just be that the server didn't realize you were disconnected and was still trying to send you information, hard to know without specific knowledge of the situation.
Reply With Quote
  #5  
Old 01-03-2015, 08:13 AM
Kemtar Kemtar is offline
Large Bat


Join Date: Dec 2014
Posts: 10
Default

i PMd Rogean, maybe he can shed some light, thought id also ask here incase its an obvious thing

i have no problem for anti-cheat measures WHILE i play on p99, when i am not, what i do on my PC is my private thing.
Reply With Quote
  #6  
Old 01-03-2015, 08:17 AM
towbes towbes is offline
Aviak

towbes's Avatar

Join Date: Dec 2014
Posts: 96
Default

Do not assume that's what is happening here. First establish a baseline of normal behavior. Then see if you can replicate the issue you had here. Waiting for alerts on your firewall is not the same as monitoring network activity and it is more likely an issue of a false positive on the firewall than an actual security concern.
Reply With Quote
  #7  
Old 01-03-2015, 08:41 AM
Kemtar Kemtar is offline
Large Bat


Join Date: Dec 2014
Posts: 10
Default

no i do not, i just looked through my logs again and this is what my Firewall Summary looks like JUST for today (the most! i did today was logging onto p99 char selection after i saw all those drops)

181307 dropped Packets just today.

i really tend to favor this is a bug on the eqemu server side

[You must be logged in to view images. Log in or Register.]
Reply With Quote
  #8  
Old 01-03-2015, 11:08 AM
Kemtar Kemtar is offline
Large Bat


Join Date: Dec 2014
Posts: 10
Default

i just realized i posted this into the very wrong forum sub-section, i appologize and ask any mod to please move this one to the appropiated one. thank you!
Reply With Quote
  #9  
Old 01-03-2015, 11:23 PM
Rogean Rogean is offline
¯\_(ツ)_/¯

Rogean's Avatar

Join Date: Oct 2009
Location: Massachusetts
Posts: 5,393
Default

178 is an IP Address controlled by Akkadius. That server specifically handles traffic for the Alkabor / EQMac server.
179 is an IP Address controlled by PEQ, and specifically handles their game traffic.
__________________
Sean "Rogean" Norton
Project 1999 Co-Manager

Project 1999 Setup Guide
Last edited by Rogean; 01-03-2015 at 11:28 PM..
Reply With Quote
  #10  
Old 01-04-2015, 12:48 AM
Secrets Secrets is offline
VIP / Contributor

Secrets's Avatar

Join Date: Oct 2009
Posts: 1,354
Default

I just investigated and those are keepalive packets it is sending from the loginserver. Basically connections are not being cleaned up properly and being held indefinitely.

I'm going through the EQMac emu code and will try and fix this up tonight. Apologies if it's bothering you!

Do you see any dropped packets from 9000, 7000-7999 as well?
__________________
Engineer of Things and Stuff, Wearer of Many Hats

“Knowing yourself is the beginning of all wisdom.” — Aristotle
Last edited by Secrets; 01-04-2015 at 12:51 AM..
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 06:17 AM.


Everquest is a registered trademark of Daybreak Game Company LLC.
Project 1999 is not associated or affiliated in any way with Daybreak Game Company LLC.
Powered by vBulletin®
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.