Ivan Ivanov | 18 May 2012 16:49
Picon

HLDS ddos attacks [spoofed IPs]

Hello,

For the last few days I've been attacked by a big(huge) number of international IPs [Russia, USA, Korea, China, Italy etc..]. It's obviously a ddos attacks, so at first I tried different protections (iptables rules, apf, csf firewalls, ddos deflate and none of them helped). I also asked my ISP to stop all the international traffic, but that didn't help either because the IPs are spoofed. Is there any protection from these kinds of attacks and if yes, what is it?
<div>
Hello,<br><br>For the last few days I've been attacked by a big(huge) number of international IPs [Russia, USA, Korea, China, Italy etc..]. It's obviously a ddos attacks, so at first I tried different protections (iptables rules, apf, csf firewalls, ddos deflate and none of them helped). I also asked my ISP to stop all the international traffic, but that didn't help either because the IPs are spoofed. Is there any protection from these kinds of attacks and if yes, what is it?<br>
</div>
Ronny Schedel | 18 May 2012 16:57
Picon
Favicon

Re: HLDS ddos attacks [spoofed IPs]

What kind of ddos did you got? If it is a syn flood, just limit the syn ack answers with your firewall. A game server normally don’t need much TCP traffic, so you can limit it to 10/sec.
 
 
 
Sent: Friday, May 18, 2012 4:49 PM
Subject: [hlds] HLDS ddos attacks [spoofed IPs]
 
Hello,

For the last few days I've been attacked by a big(huge) number of international IPs [Russia, USA, Korea, China, Italy etc..]. It's obviously a ddos attacks, so at first I tried different protections (iptables rules, apf, csf firewalls, ddos deflate and none of them helped). I also asked my ISP to stop all the international traffic, but that didn't help either because the IPs are spoofed. Is there any protection from these kinds of attacks and if yes, what is it?

_______________________________________________
To unsubscribe, edit your list preferences, or view the list archives, please visit:
https://list.valvesoftware.com/cgi-bin/mailman/listinfo/hlds
<div>
<div dir="ltr">
<div>
<div>What kind of ddos did you got? If it is a syn flood, just limit the syn ack 
answers with your firewall. A game server normally don&rsquo;t need much TCP traffic, 
so you can limit it to 10/sec. </div>
<div>&nbsp;</div>
<div>&nbsp;</div>
<div>
<div>
<div>&nbsp;</div>
<div>
<div>From: <a title="harryp123 <at> abv.bg" href="mailto:harryp123 <at> abv.bg">Ivan Ivanov</a> </div>
<div>Sent: Friday, May 18, 2012 4:49 PM</div>
<div>To: <a title="hlds <at> list.valvesoftware.com" href="mailto:hlds <at> list.valvesoftware.com">hlds <at> list.valvesoftware.com</a> </div>
<div>Subject: [hlds] HLDS ddos attacks [spoofed IPs]</div>
</div>
</div>
<div>&nbsp;</div>
</div>
<div>Hello,<br><br>For 
the last few days I've been attacked by a big(huge) number of international IPs 
[Russia, USA, Korea, China, Italy etc..]. It's obviously a ddos attacks, so at 
first I tried different protections (iptables rules, apf, csf firewalls, ddos 
deflate and none of them helped). I also asked my ISP to stop all the 
international traffic, but that didn't help either because the IPs are spoofed. 
Is there any protection from these kinds of attacks and if yes, what is it?<br><p>
</p>
_______________________________________________<br>To unsubscribe, edit your 
list preferences, or view the list archives, please 
visit:<br>https://list.valvesoftware.com/cgi-bin/mailman/listinfo/hlds<br>
</div>
</div>
</div>
</div>
Picon
Gravatar

Re: HLDS ddos attacks [spoofed IPs]

I have my problem, recommend programs to prevent these attacks.

El 18/05/2012 10:49, "Ivan Ivanov" <harryp123 <at> abv.bg> escribió:
Hello,

For the last few days I've been attacked by a big(huge) number of international IPs [Russia, USA, Korea, China, Italy etc..]. It's obviously a ddos attacks, so at first I tried different protections (iptables rules, apf, csf firewalls, ddos deflate and none of them helped). I also asked my ISP to stop all the international traffic, but that didn't help either because the IPs are spoofed. Is there any protection from these kinds of attacks and if yes, what is it?

_______________________________________________
To unsubscribe, edit your list preferences, or view the list archives, please visit:
https://list.valvesoftware.com/cgi-bin/mailman/listinfo/hlds

<div>
<p>I have my problem, recommend programs to prevent these attacks.</p>
<div class="gmail_quote">El 18/05/2012 10:49, "Ivan Ivanov" &lt;<a href="mailto:harryp123 <at> abv.bg">harryp123 <at> abv.bg</a>&gt; escribi&oacute;:<br type="attribution"><blockquote class="gmail_quote">
<div>
Hello,<br><br>For the last few days I've been attacked by a big(huge) number of international IPs [Russia, USA, Korea, China, Italy etc..]. It's obviously a ddos attacks, so at first I tried different protections (iptables rules, apf, csf firewalls, ddos deflate and none of them helped). I also asked my ISP to stop all the international traffic, but that didn't help either because the IPs are spoofed. Is there any protection from these kinds of attacks and if yes, what is it?<br>
</div>
<br>_______________________________________________<br>
To unsubscribe, edit your list preferences, or view the list archives, please visit:<br><a href="https://list.valvesoftware.com/cgi-bin/mailman/listinfo/hlds" target="_blank">https://list.valvesoftware.com/cgi-bin/mailman/listinfo/hlds</a><br><br>
</blockquote>
</div>
</div>
Ivan Ivanov | 18 May 2012 18:27
Picon

Re: HLDS ddos attacks [spoofed IPs]


Ops. I'm on linux and I sent this email to the wrong mailing list :)
And its UDP flood, not SYN/TCP.


-------- Оригинално писмо --------
От: "Ronny Schedel" info <at> ronny-schedel.de
Относно: Re: [hlds] HLDS ddos attacks [spoofed IPs]
До: "Half-Life dedicated Win32 server mailing list"
Изпратено на: Петък, 2012, Май 18 17:57:47 EEST

What kind of ddos did you got? If it is a syn flood, just limit the syn ack answers with your firewall. A game server normally don’t need much TCP traffic, so you can limit it to 10/sec.
 
 
 
Sent: Friday, May 18, 2012 4:49 PM
Subject: [hlds] HLDS ddos attacks [spoofed IPs]
 
Hello,

For the last few days I've been attacked by a big(huge) number of international IPs [Russia, USA, Korea, China, Italy etc..]. It's obviously a ddos attacks, so at first I tried different protections (iptables rules, apf, csf firewalls, ddos deflate and none of them helped). I also asked my ISP to stop all the international traffic, but that didn't help either because the IPs are spoofed. Is there any protection from these kinds of attacks and if yes, what is it?

_______________________________________________
To unsubscribe, edit your list preferences, or view the list archives, please visit:
https://list.valvesoftware.com/cgi-bin/mailman/listinfo/hlds
<at> list.valvesoftware.com>
<div>
<br>Ops. I'm on linux and I sent this email to the wrong mailing list :)<br>And its UDP flood, not SYN/TCP.<br><br><br>

 -------- &#1054;&#1088;&#1080;&#1075;&#1080;&#1085;&#1072;&#1083;&#1085;&#1086; &#1087;&#1080;&#1089;&#1084;&#1086; --------
<br>&#1054;&#1090;: "Ronny Schedel" info <at> ronny-schedel.de
<br>&#1054;&#1090;&#1085;&#1086;&#1089;&#1085;&#1086;: Re: [hlds] HLDS ddos attacks [spoofed IPs]
<br>&#1044;&#1086;: "Half-Life dedicated Win32 server mailing list"
	<br>&#1048;&#1079;&#1087;&#1088;&#1072;&#1090;&#1077;&#1085;&#1086; &#1085;&#1072;: &#1055;&#1077;&#1090;&#1098;&#1082;, 2012, &#1052;&#1072;&#1081; 18 17:57:47 EEST
<br><br><div dir="ltr">
<div>
<div>What kind of ddos did you got? If it is a syn flood, just limit the syn ack 
answers with your firewall. A game server normally don&rsquo;t need much TCP traffic, 
so you can limit it to 10/sec. </div>
<div>&nbsp;</div>
<div>&nbsp;</div>
<div>
<div>
<div>&nbsp;</div>
<div>
<div>From: <a href="javascript:internSendMess('harryp123 <at> abv.bg')" title="harryp123 <at> abv.bg">Ivan Ivanov</a> </div>
<div>Sent: Friday, May 18, 2012 4:49 PM</div>
<div>To: <a href="javascript:internSendMess('hlds <at> list.valvesoftware.com')" title="hlds <at> list.valvesoftware.com">hlds <at> list.valvesoftware.com</a> </div>
<div>Subject: [hlds] HLDS ddos attacks [spoofed IPs]</div>
</div>
</div>
<div>&nbsp;</div>
</div>
<div>Hello,<br><br>For 
the last few days I've been attacked by a big(huge) number of international IPs 
[Russia, USA, Korea, China, Italy etc..]. It's obviously a ddos attacks, so at 
first I tried different protections (iptables rules, apf, csf firewalls, ddos 
deflate and none of them helped). I also asked my ISP to stop all the 
international traffic, but that didn't help either because the IPs are spoofed. 
Is there any protection from these kinds of attacks and if yes, what is it?<br><p>
</p>
_______________________________________________<br>To unsubscribe, edit your 
list preferences, or view the list archives, please 
visit:<br>https://list.valvesoftware.com/cgi-bin/mailman/listinfo/hlds<br>
</div>
</div>
</div> <at> list.valvesoftware.com&gt;</div>
jainil shah | 18 May 2012 19:03
Picon

Re: HLDS ddos attacks [spoofed IPs]

Can somebody post some iptable rules to defend against these basic attacks such as SSH brute force, syn., etc. Also if somebody can recommend decent free/cheap firewalls
On May 18, 2012 12:27 PM, "Ivan Ivanov" <harryp123 <at> abv.bg> wrote:
>
>
> Ops. I'm on linux and I sent this email to the wrong mailing list :)
> And its UDP flood, not SYN/TCP.
>
>
> -------- Оригинално писмо --------
> От: "Ronny Schedel" info <at> ronny-schedel.de
> Относно: Re: [hlds] HLDS ddos attacks [spoofed IPs]
> До: "Half-Life dedicated Win32 server mailing list"
> Изпратено на: Петък, 2012, Май 18 17:57:47 EEST
>
> What kind of ddos did you got? If it is a syn flood, just limit the syn ack answers with your firewall. A game server normally don’t need much TCP traffic, so you can limit it to 10/sec.
>  
>  
>  
> From: Ivan Ivanov
> Sent: Friday, May 18, 2012 4:49 PM
> To: hlds <at> list.valvesoftware.com
> Subject: [hlds] HLDS ddos attacks [spoofed IPs]
>  
> Hello,
>
> For the last few days I've been attacked by a big(huge) number of international IPs [Russia, USA, Korea, China, Italy etc..]. It's obviously a ddos attacks, so at first I tried different protections (iptables rules, apf, csf firewalls, ddos deflate and none of them helped). I also asked my ISP to stop all the international traffic, but that didn't help either because the IPs are spoofed. Is there any protection from these kinds of attacks and if yes, what is it?
>
> ________________________________
> _______________________________________________
> To unsubscribe, edit your list preferences, or view the list archives, please visit:
> https://list.valvesoftware.com/cgi-bin/mailman/listinfo/hlds
>
> _______________________________________________
> To unsubscribe, edit your list preferences, or view the list archives, please visit:
> https://list.valvesoftware.com/cgi-bin/mailman/listinfo/hlds
>

<div><p>Can somebody post some iptable rules to defend against these basic attacks such as SSH brute force, syn., etc. Also if somebody can recommend decent free/cheap firewalls<br>
On May 18, 2012 12:27 PM, "Ivan Ivanov" &lt;<a href="mailto:harryp123 <at> abv.bg">harryp123 <at> abv.bg</a>&gt; wrote:<br>
&gt;<br>
&gt;<br>
&gt; Ops. I'm on linux and I sent this email to the wrong mailing list :)<br>
&gt; And its UDP flood, not SYN/TCP.<br>
&gt;<br>
&gt;<br>
&gt; -------- &#1054;&#1088;&#1080;&#1075;&#1080;&#1085;&#1072;&#1083;&#1085;&#1086; &#1087;&#1080;&#1089;&#1084;&#1086; -------- <br>
&gt; &#1054;&#1090;: "Ronny Schedel" <a href="mailto:info <at> ronny-schedel.de">info <at> ronny-schedel.de</a> <br>
&gt; &#1054;&#1090;&#1085;&#1086;&#1089;&#1085;&#1086;: Re: [hlds] HLDS ddos attacks [spoofed IPs] <br>
&gt; &#1044;&#1086;: "Half-Life dedicated Win32 server mailing list" <br>
&gt; &#1048;&#1079;&#1087;&#1088;&#1072;&#1090;&#1077;&#1085;&#1086; &#1085;&#1072;: &#1055;&#1077;&#1090;&#1098;&#1082;, 2012, &#1052;&#1072;&#1081; 18 17:57:47 EEST <br>
&gt;<br>
&gt; What kind of ddos did you got? If it is a syn flood, just limit the syn ack answers with your firewall. A game server normally don&rsquo;t need much TCP traffic, so you can limit it to 10/sec.<br>
&gt; &nbsp;<br>
&gt; &nbsp;<br>
&gt; &nbsp;<br>
&gt; From: Ivan Ivanov<br>
&gt; Sent: Friday, May 18, 2012 4:49 PM<br>
&gt; To: <a href="mailto:hlds <at> list.valvesoftware.com">hlds <at> list.valvesoftware.com</a><br>
&gt; Subject: [hlds] HLDS ddos attacks [spoofed IPs]<br>
&gt; &nbsp;<br>
&gt; Hello,<br>
&gt;<br>
&gt; For the last few days I've been attacked by a big(huge) number of international IPs [Russia, USA, Korea, China, Italy etc..]. It's obviously a ddos attacks, so at first I tried different protections (iptables rules, apf, csf firewalls, ddos deflate and none of them helped). I also asked my ISP to stop all the international traffic, but that didn't help either because the IPs are spoofed. Is there any protection from these kinds of attacks and if yes, what is it?<br>

&gt;<br>
&gt; ________________________________<br>
&gt; _______________________________________________<br>
&gt; To unsubscribe, edit your list preferences, or view the list archives, please visit:<br>
&gt; <a href="https://list.valvesoftware.com/cgi-bin/mailman/listinfo/hlds">https://list.valvesoftware.com/cgi-bin/mailman/listinfo/hlds</a><br>
&gt;<br>
&gt; _______________________________________________<br>
&gt; To unsubscribe, edit your list preferences, or view the list archives, please visit:<br>
&gt; <a href="https://list.valvesoftware.com/cgi-bin/mailman/listinfo/hlds">https://list.valvesoftware.com/cgi-bin/mailman/listinfo/hlds</a><br>
&gt;<br></p></div>

Gmane