I'm not sure where I could post this kind of things.
I've read about these kinds of attacks and it's really hard to find a solution. Our shard of 150players average will goes down now until the new version is made (running pol097 ) because of all this shit... You know how it is a lot of work to get a shard working stable and fun to play and how we can be devoted sometimes.... I would strongly have a hint how to stop or prevent Dos Attack. I'm just ... I just feel mad about it.
Oh and by the way.. Internal Web Server is disable...
DOS Attack...
Moderator: POL Developer
I'll try to help if I can. Some questions for you...
How do you know you are being attacked? What type of attack is it? There are lots of different kinds of DOS attacks. Some are trivial to block, some are complex to block. Also, the more systems involved, the harder it will be to block. But that's still relative to how they are attacking.
Any POL logs, IDS/IPS logs, tcpdump output and/or iptables packet logs could help. Don't just post stuff here, but just say what you have, and describe what you see. If there's something that could be analyzed in the types of logs you have, we'll work out what you'll need to send.
How do you know you are being attacked? What type of attack is it? There are lots of different kinds of DOS attacks. Some are trivial to block, some are complex to block. Also, the more systems involved, the harder it will be to block. But that's still relative to how they are attacking.
Any POL logs, IDS/IPS logs, tcpdump output and/or iptables packet logs could help. Don't just post stuff here, but just say what you have, and describe what you see. If there's something that could be analyzed in the types of logs you have, we'll work out what you'll need to send.
-
- Neophyte Poster
- Posts: 31
- Joined: Wed Aug 29, 2007 2:44 pm
- Contact:
You can have some firewalls/packet filters to filter some more specific kinds of DOS attacks (usually using some "bugs" in protocol design). But if attacker is just flooding and has enough of bandtwich, there is NOTHING, you can do. Even if you are discarding such packets, they are blocking your line...