<?xml version="1.0" ?><rss version="2.0">
    <channel>
	<title>ETF2L &#8211; Latest activity in &#8220;Any easy ways to avoid the ddos?&#8221;</title>
	<link>https://staging.etf2l.org/forum/general/topic-4865/</link>
	<description><![CDATA[The latest posts to this topic.]]></description>
    	<item>
    	    <title>Reply by gryzor</title>
    	    <link>https://staging.etf2l.org/forum/general/topic-4865/page-3/?recent=81523#post=81523</link>
    	    <description><![CDATA[<blockquote><blockquote>zBlock has nothing to do with a Distributed Denial of Service attack</blockquote>
Uhh yes, new version does block it. Hello, read Cadred maybe sometime?</blockquote>
ViQun, are you trying to be funny or did you just quit reading after that line?

Read: http://etf2l.org/forum/general/topic-4865/page-2/?recent=81523#post-81445
and: http://etf2l.org/forum/general/topic-4865/page-2/?recent=81523#post-81452

Also read the link mentioned in the first post for clarification of what is being discussed here :)]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=general&#038;topic=4865&#038;post=81523</guid>
    	    <pubDate>Wed, 05 Aug 2009 21:28:24 +0200</pubDate>
    	</item>
    	<item>
    	    <title>Reply by ViQun</title>
    	    <link>https://staging.etf2l.org/forum/general/topic-4865/page-3/?recent=81523#post=81519</link>
    	    <description><![CDATA[<blockquote>zBlock has nothing to do with a Distributed Denial of Service attack</blockquote>
Uhh yes, new version does block it. Hello, read Cadred maybe sometime?]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=general&#038;topic=4865&#038;post=81519</guid>
    	    <pubDate>Wed, 05 Aug 2009 21:24:35 +0200</pubDate>
    	</item>
    	<item>
    	    <title>Reply by gryzor</title>
    	    <link>https://staging.etf2l.org/forum/general/topic-4865/page-3/?recent=81523#post=81518</link>
    	    <description><![CDATA[Quickly adding to #1 above, it does not really constitute as "hacking", no. More like "doing things a lot of people can do, but don't since they're sane individuals". Let's keep the hacker-label where it belongs, amongst clever people who can do really cool shit with anything technical :)

It's mostly done by some poor souls injecting "backdoors" into popular files and placing them on torrents/dc/p2p-sites that "common" people use. Making them spew out a bunch of packets is one thing (or, ddosing), most have more nasty "features" -- fairly common in this community and ones like this, is stealing steam-accounts for obvious reasons. Generally, creditcards and other type of monetary fraud are the most popular usage. 

Rule of thumb is to NOT run anything you absolutely know for certain where and who it's from. Do not trust "antivirus" or "antitrojan"-utilities, I've seen a great deal of people whining about lost steamaccounts and what not after using their "private" torrent-trackers and other lame crap, due to the fact the injected portion of the "trojanhorse" is re-linked with different code every time and code-crypted. Low impact clientèle and no reports since they never get discovered in this "small group" of people is the reason. And it's really easy to do. 

Just a warning.

Stay safe :)]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=general&#038;topic=4865&#038;post=81518</guid>
    	    <pubDate>Wed, 05 Aug 2009 21:22:33 +0200</pubDate>
    	</item>
    	<item>
    	    <title>Reply by waebi</title>
    	    <link>https://staging.etf2l.org/forum/general/topic-4865/page-3/?recent=81523#post=81510</link>
    	    <description><![CDATA[<blockquote>I've got two questions.

1. Isn't ddos'ing kinda like hacking? making it illegal to do.
</blockquote>

Another question: Would someone actually CARE about that?

<blockquote>
2. Can you track where the ddos is coming from?</blockquote>

Read the doc Gryzor posted, it's quite nice and explains why you cant track DDoS: It's coming from a lot of pcs at the same time, and these are "remote controlled".
So no, basically you cant track it.

The thing we face here is in most cases <strong>NOT DDoS,</strong> but a simple DoS as it was explained already. Meaning, mostly it's spamming commands to certain ports to make the server lag and/or crash, or abusing server features etc.]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=general&#038;topic=4865&#038;post=81510</guid>
    	    <pubDate>Wed, 05 Aug 2009 21:02:52 +0200</pubDate>
    	</item>
    	<item>
    	    <title>Reply by MasterBlaster</title>
    	    <link>https://staging.etf2l.org/forum/general/topic-4865/page-3/?recent=81523#post=81507</link>
    	    <description><![CDATA[I've got two questions.

1. Isn't ddos'ing kinda like hacking? making it illegal to do.

2. Can you track where the ddos is coming from?]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=general&#038;topic=4865&#038;post=81507</guid>
    	    <pubDate>Wed, 05 Aug 2009 20:56:13 +0200</pubDate>
    	</item>
    	<item>
    	    <title>Reply by Wlv</title>
    	    <link>https://staging.etf2l.org/forum/general/topic-4865/page-3/?recent=81523#post=81506</link>
    	    <description><![CDATA[*no more flames in this thread — keep on topic in this one and create your own flame-thread if necessary*]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=general&#038;topic=4865&#038;post=81506</guid>
    	    <pubDate>Wed, 05 Aug 2009 20:53:38 +0200</pubDate>
    	</item>
    	<item>
    	    <title>Reply by GibbZ</title>
    	    <link>https://staging.etf2l.org/forum/general/topic-4865/page-3/?recent=81523#post=81496</link>
    	    <description><![CDATA[Me and my 4chan newfags fucking ion cannon attack servers all the time. Good crack it is.]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=general&#038;topic=4865&#038;post=81496</guid>
    	    <pubDate>Wed, 05 Aug 2009 20:27:39 +0200</pubDate>
    	</item>
    	<item>
    	    <title>Reply by SuperFly-</title>
    	    <link>https://staging.etf2l.org/forum/general/topic-4865/page-2/?recent=81523#post=81491</link>
    	    <description><![CDATA[*no more flames in this thread -- keep on topic*]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=general&#038;topic=4865&#038;post=81491</guid>
    	    <pubDate>Wed, 05 Aug 2009 20:02:29 +0200</pubDate>
    	</item>
    	<item>
    	    <title>Reply by end0</title>
    	    <link>https://staging.etf2l.org/forum/general/topic-4865/page-2/?recent=81523#post=81486</link>
    	    <description><![CDATA[it's not too hard to gather a botnet in a couple of hours, so everyone with minimal knowledge of these technologies can ddos any serv. it's way more easier than some of you think]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=general&#038;topic=4865&#038;post=81486</guid>
    	    <pubDate>Wed, 05 Aug 2009 19:45:35 +0200</pubDate>
    	</item>
    	<item>
    	    <title>Reply by gryzor</title>
    	    <link>https://staging.etf2l.org/forum/general/topic-4865/page-2/?recent=81523#post=81466</link>
    	    <description><![CDATA[<blockquote>you might as well whitelist the IPs of the players actually connecting to the server, including 1 stv relay.
Wouldnt that work?</blockquote>

It would work just as well as zBlock, but in a broader perspective, yes. This requires blocking done via IP-filtering though, not any ordinary "built-in" lists (I do not even know of any such things present in Source). 

What I _do_ know by personal experience, is that adding offenders IP to the "banned IP-list" is not enough for them to "pre-execute" commands, much less crash the server itself by sending bogus data to the port. It has to be done as described above to be effective.

... And after all said and done, the suggestion with "hidden" server(s) would solve all these issues in one go, so it'd be the "best" way of doing things.]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=general&#038;topic=4865&#038;post=81466</guid>
    	    <pubDate>Wed, 05 Aug 2009 19:16:09 +0200</pubDate>
    	</item>
    	<item>
    	    <title>Reply by Xzar</title>
    	    <link>https://staging.etf2l.org/forum/general/topic-4865/page-2/?recent=81523#post=81465</link>
    	    <description><![CDATA[the packets coming to the "firewall" block the connection anyway. whitelisting doesn't help

you guys need to understand the mechanics of ddos :p]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=general&#038;topic=4865&#038;post=81465</guid>
    	    <pubDate>Wed, 05 Aug 2009 19:14:37 +0200</pubDate>
    	</item>
    	<item>
    	    <title>Reply by waebi</title>
    	    <link>https://staging.etf2l.org/forum/general/topic-4865/page-2/?recent=81523#post=81461</link>
    	    <description><![CDATA[you might as well whitelist the IPs of the players actually connecting to the server, including 1 stv relay.
Wouldnt that work?]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=general&#038;topic=4865&#038;post=81461</guid>
    	    <pubDate>Wed, 05 Aug 2009 19:05:34 +0200</pubDate>
    	</item>
    	<item>
    	    <title>Reply by Xzar</title>
    	    <link>https://staging.etf2l.org/forum/general/topic-4865/page-2/?recent=81523#post=81459</link>
    	    <description><![CDATA[also just figure out from the server logs if it actually was some source engine abusing or a real ddos. Abusing can be patched and whatever but DDOS can only be "stopped" with completely hiding the server where the game is played.]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=general&#038;topic=4865&#038;post=81459</guid>
    	    <pubDate>Wed, 05 Aug 2009 19:04:16 +0200</pubDate>
    	</item>
    	<item>
    	    <title>Reply by Xzar</title>
    	    <link>https://staging.etf2l.org/forum/general/topic-4865/page-2/?recent=81523#post=81454</link>
    	    <description><![CDATA[<blockquote>
Nobody likes you</blockquote>

coming from nvc, I kinda lold :[]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=general&#038;topic=4865&#038;post=81454</guid>
    	    <pubDate>Wed, 05 Aug 2009 19:00:45 +0200</pubDate>
    	</item>
    	<item>
    	    <title>Reply by gryzor</title>
    	    <link>https://staging.etf2l.org/forum/general/topic-4865/page-2/?recent=81523#post=81452</link>
    	    <description><![CDATA[Why do I even bother... Fine, just because I'm such a nice and FRIENDLY guy! :D

The ACTUAL concept of DDOS is and has been a real "threat" to games, by packeting the gameservers themselves.

If you'd like to call crashing a server by executing a bunch of... say... common Q-Engine flaw, a bunch of (thousands) 'ý's on its port via some UDP packet(s) a DDOS-attack, that's just plain wrong. 

If you'd say it was a Denial Of Service attack, sure -- but both issues are a huge problem for any high-profile service and are dealt with differently.]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=general&#038;topic=4865&#038;post=81452</guid>
    	    <pubDate>Wed, 05 Aug 2009 18:59:55 +0200</pubDate>
    	</item>
    </channel>
</rss>