Jump to content

Dizaka

Balancing Advisors
  • Posts

    482
  • Joined

  • Last visited

  • Days Won

    5

Posts posted by Dizaka

  1. On 10/5/2020 between 9:00 pm and 11:00 pm eastern time the lobby users are being hit hard by who ever is the DDOS child.  I'm being ignored for some reason.  Mgically, a number of users who rarely, if ever, log in logged in.  The first topic on these user's mind was DDOS.  Peculiar but just speculation.

     

    Below is a WAN chart of traffic since 9/11.  Most peaks, if not all, except between 9/15 and 9/16, are when I disconnected from 0ad due to, what I believe, were ddos attacks.

    image.thumb.png.c314f8d8627ada5d6c66159ec4666232.png

     

    Below is the corresponding LAN chart.  Notice how traffic between 9/15 and 9/16 can be seen on LAN?  That's because it goes past the router and isn't blocked/discarded like a DDOS attack.  The 9/15-9/16 traffic is a 4 tb download.

    image.thumb.png.48bf9836f5ee91dcb496de37182faa17.png

     

    • Thanks 1
  2. Specing game.  Phyzik mentioned something about screenshots and Issh luled about them (ph4r em!).  Wasn't involved in game (was spec).

    This happened around 6:46 pm easter us time.

    First ddos during this game around 6:46.  This one disconnected me from game and sent me to lobby.

    image.png.811c2abdfc0f78d0097a220e821bed8e.png

     

    image.png.a5e7a4dcf758134e8d79115d2bac1b03.png

     

    Received a 2nd ddos around 6:55 or so:

    image.png.37668c1f627b9de888a162d68effd76a.png

    image.png.0751d7f982820dc5b4b88af8a94d6077.png

     

    Banned from game for connectivity issues.  Host is Bonesnscars. (He did the right thing)

     

    Phyzik explicitly asked for ban.  He directly stated his ph3ar of screenshots beforehand (before game started).

     

    image.png.1ffda89c61987f2f6cbe256da7158e24.png

     

    Double checked who else asked for my ban, out of curiosity:

     

    image.thumb.png.eb1b29e8d860ef28a35008a282ace489.png

     

    • Thanks 1
  3. 9:50 pm easter time (NY).  DDOS again.  Can't setup the monitoring yet ...

    image.png.1e6a997389ae33a7bf666005b3c6e6a3.png

     

    Honestly, anytime a player disconnects from a game I'd probably blame DDOS.  It seems like few network connections these days are unstable ...

     

    Note:  I've offered to pay for counseling and therapy services for whoever is doing this.  Please PM me.  

    • Thanks 1
  4. 2 hours ago, smiley said:

    Your ISP will never call, because they have no clue this is even happening. Their threshold will be set a lot higher.

    Accordingly, it's safe to assume that me calling them for this small fish is pointless as there likely won't be a good enough response.

    Dear small fish, you reading this?  Go big or go home.

     

    2 hours ago, smiley said:

    The game logs doesn't really help.

    Conclusory statement.  All of yesterday no attacks on me.  Those one or two attacks could or couldn't have been something.  Looking at my logs I couldn't figure it out as I was testing something else out that rendered the charts unusable.  However, overall yesterday my 0ad experience was fairly stable, minus the one or two weird disconnects I had. 

     

    2 hours ago, smiley said:

    You can either run wireshark and find out what traffic is, where it's coming from, and null route it on your router or you can request a new public IP and never host a game on the lobby. The former will fix it regardless of whether it's a DoS attack or not. And I think your router is an EdgeRouter. Maybe enable logging, but given that its already dying, that might not be the best idea.

    I mean it could be a SYN flood, an ICMP flood, a UDP flood (this might be the case because of how much traffic is going through), illegal TCP flood, etc. Or even unroutable IPs. Impossible to determine with the information available.

    For a distributed denial of service attack running wireshark is likely to be a pointless exercise.  If it's distributed it's coming from multiple devices under the attacker's purview that likely excludes the attacker's device(s).  However, that is an assumption worth checking out.

     

    2 hours ago, smiley said:

    Regardless, nothing much anyone else can do here.

    Another conclusory statement that isn't necessarily true.

  5. 8:48 -- Borg disconnected. 

     

    Players IG:

    image.png.001a20bd92237917330da563fc49673e.png

     

    8:52 -- Was lagging.  Host kicked me.

     

    8:59 -- Lapacientos lagged and was kicked.

    9:00 -- Lapacientos rejoined.  Game continues.

    9:03 -- Borg kicked due to timeout.

    9:09 -- Borg rejoins lobby.  Must have been a somewhat strong ddos.

    image.png.3676a0ebc4bb91dc6943904656916c16.png

    9:24 -- Something new.  Game at a standstill.  Noone showing as lagging.  Eventually borg disconnects/times out.

    9:24 -- Phyzik leaves the game.

     

    Conclusion:  Way too many disconnects and reconnects this game.  Typical game has maybe a person disconnect and then come back fairly fast.  This game was all over the place for whatever reason.

  6. image.thumb.png.be120038172e52e3f8200df5ad5effae.png

     

    6:24 -- Go2die and Acero left spec.

     

    6:27 -- Chetnik kicked for flimsy connection  (Possibly on same IP as previously)

    image.png.31863391fe4cfbd948374fdbbaf9c5c5.png

     

    6:47 -- Ricsand joined game.

    image.png.e8c39a65f765781f5149d25fc3d34dbe.png

    Join failed.  Looks normal though.

    image.png.01f6e1e5315952a73b175b2cedee08a1.png

    6:59 -- FrankStallone left game

    7:01 -- game ended.  

     

    Honestly, this was a normal 0ad game.  No multiple critical-player disconnects, etc.  It's possible that Chetnik did a whole net disco from DDOS as his IP was previously compromised.  Either way, uneventful game and done.  Ricsand probably had issues reconnecting midgame to a max 200 4v4 game with movement on all units.

     

  7. image.png.184dd6e73d296b180a06343311b2e979.png

     

    1)  Kristian solo disconnect.

    image.png.b9e2e2cbda317ceba8f39eeecc57490c.png

    image.png.692a6a01da71b3e464e74c5e0e27fbaa.png

    image.png.b3774c8fadff61cec7d4a73eaca30373.png

     

     

    Either a potatoe for a PC or ...  .  Previously, and in general, his potatoe PC doesn't have issues with his games.

     

    2)  Kristian/Cesar duo disconnect.

    image.png.e6dca4176a7beda43389b5d3e4fd1267.png

    image.png.46447db21f2501c5f6db477f69bd9c00.png

    image.png.d4f510722cc60bafc6c29febed839248.png

     

    Game ended afterwards.  No sure if Cesar/Kristian or other team was winning or whether it was close to end of game.  Was banned by Phyzik for being a silent spec.  Don't have replay on what happened.

    image.png

    • Thanks 1
  8. 6:10 pm Eastern Time.  Net down.  Private no specs game with Nani.

    Update: 6:24 net still down.  Maybe a new record?

    Update: 6:32 net still down.

    Update: 6:34 ... :)

    Update: 6:46 ... :) Watching Netflix through a diff network ...

    Update: 6:49 back online

    Pic below is the start of the DDOS.  There's no middle b/c it was another big one.

    image.png.2ba1e53688033d508efbffbdeb545a3b.png

    • Confused 1
  9. Actually waiting for them to call me.  I know if I call them it's not a problem really and won't take it seriously.  If they call me then they'll take it seriously and at least have a record of this in their system. 

    If whoever is doing this lives in the USA they have the CFAA to worry about.

    Currently still needs offline.

    Back online 5:40 pm eastern time.

    • Like 1
  10. Lagged out around 4:55 Eastern Time.  Logs again show a spike in traffic.

     

    Honestly, no idea who it is.  This was from a game lobby as randomid started hosting.  However, the spikes don't appear to be random/unintentional and are related to 0ad.  

    Game chat provided below to list players inside the lobby.  Note, I haven't reset my public IP so I can be bombed even if the person is not in 0ad.

     

    image.png.79e486b59c0b6137c17fbe19e6fb2a15.png

     

     

    image.png

    • Thanks 2
×
×
  • Create New...