![]() |
|
|
|
#1
|
||||
|
Anycast will not work for P1999 because we cannot replicate our service across multiple data centers (that would result in 10 copies of the server). Turp the problem with your diagram is that somehow your router is magically detecting which traffic is 'bad' and sending it elsewhere, and unfortunately that is not possible.
I think Rogean could actually do a lot more against these attacks then he has, probably because he has a job and such. Some interesting things:
The corollary to all of this is that I'm making the assumption they are sending Everquest packets because they have found some vulnerability in the server code. If they are just flooding the datacenter with DNS packets or whatnot, there is nothing Rogean can do other than pay for more bandwidth.
__________________
Raev | Loraen | Sakuragi <The A-Team> | Solo Artist Challenge | Farmer's Market
Quote:
| |||
|
Last edited by Splorf22; 07-27-2013 at 04:29 PM..
|
|
|||
|
#2
|
|||
|
I'm sure there are plenty of network security specialists here, which given the right information, could easily put a stop to it.
| ||
|
|
|||
|
#3
|
||||
|
Quote:
And no, other customers are not getting affected. The attack would need to be over 10 GBit for that to occur.
__________________
| |||
|
Last edited by Rogean; 07-27-2013 at 04:54 PM..
|
|
|||
|
#4
|
||||
|
Quote:
So hopefully the data center helps or if not maybe we can get the equipment they failed to replace, if not move it! Only 10g, hopefully can fix it. The DDOS culprit is not paying for that weak shit its probably a home setup. Track him down!
__________________
| |||
|
|
||||
|
#5
|
||||
|
Quote:
On the other hand, I am a computer security specialist that has worked in many job sectors, defense and private alike. Get at me Rogain i can help you out. Edit: take an ip address that is sending verified ddos attack, gain root, recover the bot from that computer,debug,see where it connects, join as zombie, see what login commands owner is using, use them to gain control to his net and add it to mine, i mean destroy it. | |||
|
Last edited by Agatha; 07-27-2013 at 04:59 PM..
|
|
|||
|
#6
|
||||
|
Quote:
My experience with problems like this is they are not really worried about it unless you are a large customer or if it affects many customers. However, it sounds like it is only affecting project1999's link to the ISPs network. Even if Rogean installed a tricked out firewall with IPS capabilities it wouldn't matter cause the attacker is sending so much traffic it is saturating his pipe. If Rogean paid for a bigger pipe it would likely get saturated, it would just take that many more DNS responses to do it. | |||
|
Last edited by Glorindale; 07-27-2013 at 05:00 PM..
|
|
|||
|
#7
|
|||
|
Rogean, any chance of throwing up a new temporary red for us to play on. It would be cool to see how well it does. Just a thought, no idea if it would be possible to setup a server in less than an hour or so but it would be pretty fun. Fresh pvp servers are the best.
__________________
Current Games:
Naw | ||
|
|
|||
|
#8
|
||||
|
Rogean, is this actually a bandwidth attack?
Also if you ninja patched in some reset code I will hug you.
__________________
Raev | Loraen | Sakuragi <The A-Team> | Solo Artist Challenge | Farmer's Market
Quote:
| |||
|
|
||||
|
#9
|
|||
|
my method of fixing is probably the only way to go about this in a timely manner. the only other way is to call the FBI, and they take years if you arn't CIA.gov
| ||
|
|
|||
|
#10
|
||||
|
Quote:
| |||
|
|
||||
![]() |
|
|