<?xml version="1.0" ?><rss version="2.0">
    <channel>
	<title>ETF2L &#8211; Latest activity in &#8220;Ddos&#8221;</title>
	<link>https://staging.etf2l.org/forum/support/topic-14890/</link>
	<description><![CDATA[The latest posts to this topic.]]></description>
    	<item>
    	    <title>Reply by WabbitsFoot</title>
    	    <link>https://staging.etf2l.org/forum/support/topic-14890/page-6/?recent=307503#post=307503</link>
    	    <description><![CDATA[Bump for best thread ever (until it gets all srsface)]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=support&#038;topic=14890&#038;post=307503</guid>
    	    <pubDate>Sun, 29 May 2011 17:19:58 +0200</pubDate>
    	</item>
    	<item>
    	    <title>Reply by ronny</title>
    	    <link>https://staging.etf2l.org/forum/support/topic-14890/page-6/?recent=307503#post=259775</link>
    	    <description><![CDATA[Just wanted to inform you that the protection works and I can even log the attack now. I'll just monitor it for the next few weeks before making it public to be sure everything works as expected.]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=support&#038;topic=14890&#038;post=259775</guid>
    	    <pubDate>Wed, 22 Dec 2010 12:07:29 +0100</pubDate>
    	</item>
    	<item>
    	    <title>Reply by Arie</title>
    	    <link>https://staging.etf2l.org/forum/support/topic-14890/page-6/?recent=307503#post=259765</link>
    	    <description><![CDATA[<i>Quoted from octochris</i>
		<blockquote>Will be writing a Windows version soon using ipfw (NOT iptables), unless Arie or Ronny is already on it.</blockquote>

Please do.

<i>Quoted from Black_Bob</i>
		<blockquote>Will this work on multiplay servers using clanforge, not a clue if its linux or windows</blockquote>

You need 'root' (Linux) or 'Administrator' (Windows) rights to configure a firewall like this. So you'll have to ask Multiplay to add an option to enable this for your server. 

It's worth the investment for GSPs since all Orangebox engine games (DoD:S, CS:S and TF2) can be exploited.]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=support&#038;topic=14890&#038;post=259765</guid>
    	    <pubDate>Wed, 22 Dec 2010 10:36:01 +0100</pubDate>
    	</item>
    	<item>
    	    <title>Reply by Black_Bob</title>
    	    <link>https://staging.etf2l.org/forum/support/topic-14890/page-6/?recent=307503#post=259666</link>
    	    <description><![CDATA[Will this work on multiplay servers using clanforge, not a clue if its linux or windows]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=support&#038;topic=14890&#038;post=259666</guid>
    	    <pubDate>Tue, 21 Dec 2010 23:22:56 +0100</pubDate>
    	</item>
    	<item>
    	    <title>Reply by Dr. Chris</title>
    	    <link>https://staging.etf2l.org/forum/support/topic-14890/page-6/?recent=307503#post=259402</link>
    	    <description><![CDATA[Will be writing a Windows version soon using ipfw (NOT iptables), unless Arie or Ronny is already on it.]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=support&#038;topic=14890&#038;post=259402</guid>
    	    <pubDate>Tue, 21 Dec 2010 10:46:41 +0100</pubDate>
    	</item>
    	<item>
    	    <title>Reply by byte</title>
    	    <link>https://staging.etf2l.org/forum/support/topic-14890/page-6/?recent=307503#post=259401</link>
    	    <description><![CDATA[Good Job Arie n Ronny, I'm sure the community appreciate all your efforts and I certainly do!

&#60;3

Cheers

Byte]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=support&#038;topic=14890&#038;post=259401</guid>
    	    <pubDate>Tue, 21 Dec 2010 10:43:29 +0100</pubDate>
    	</item>
    	<item>
    	    <title>Reply by ronny</title>
    	    <link>https://staging.etf2l.org/forum/support/topic-14890/page-6/?recent=307503#post=259384</link>
    	    <description><![CDATA[Firewall rules worked fine for our games vs. Epsi, FB and PwR. Let's see whats happening tonight.

@attacker: If you was away the last two days please come back tonight ;)]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=support&#038;topic=14890&#038;post=259384</guid>
    	    <pubDate>Tue, 21 Dec 2010 09:20:12 +0100</pubDate>
    	</item>
    	<item>
    	    <title>Reply by ronny</title>
    	    <link>https://staging.etf2l.org/forum/support/topic-14890/page-6/?recent=307503#post=258783</link>
    	    <description><![CDATA[<strong>short update:</strong>

Arie and me worked hard the last night and today and hopefully we've found another solution than whitelisting IPs.

We'll test it within the next days in some officials.

<strong>How it works</strong>
We are limiting the "A2S"-Packages from Valve which are used for quering server information like who is playing on the server. This can be done with the linux firewall using "iptables" and the information found here http://developer.valvesoftware.com/wiki/Server_queries

When everything works fine I'll write an howto so you can secure your root server, too.

Btw, sorry to all ppl who were playing on the dm server while we tested this "lag exploit". It just made more sense to test it on a server where people are playing ;-)

Cheers,

Ronny
nice-servers.com]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=support&#038;topic=14890&#038;post=258783</guid>
    	    <pubDate>Sun, 19 Dec 2010 16:35:06 +0100</pubDate>
    	</item>
    	<item>
    	    <title>Reply by Arie</title>
    	    <link>https://staging.etf2l.org/forum/support/topic-14890/page-6/?recent=307503#post=258499</link>
    	    <description><![CDATA[<i>Quoted from Ronny</i>
		<blockquote><strong>How can you help?</strong>
Forward every information you might have about this exploit and I will see what I can do. Currently we just can't do much because we do not have the exploit. And all package information (captured with tcpdump - including udp packages) and iptables log files seemed to be "ok".

Link to the things which I already tried: http://www.nice-servers.com/en/blog/84-ddos-und-dos-exploits-gegenmassnahmen.html

Cheers,

Ronny
nice-servers.com</blockquote>

I have the necessary tools to launch an attack. Verified it takes less than 1MB/s upstream to kill a busy server (my own, achievement_idle, don't worry ;) ). Ronny, contact me on friends or IRC.

Also, how can you help:
Keep playing games, get videocasts instead of relay-casts. Get the casters whitelisted and on the server until the situation is resolved.]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=support&#038;topic=14890&#038;post=258499</guid>
    	    <pubDate>Sat, 18 Dec 2010 23:19:34 +0100</pubDate>
    	</item>
    	<item>
    	    <title>Reply by adam-skyride</title>
    	    <link>https://staging.etf2l.org/forum/support/topic-14890/page-6/?recent=307503#post=258430</link>
    	    <description><![CDATA[sounds great ronny, give me a shout if there's anything i can help with.

I didn't realise it was actually such an issue if I'm honest.]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=support&#038;topic=14890&#038;post=258430</guid>
    	    <pubDate>Sat, 18 Dec 2010 20:53:36 +0100</pubDate>
    	</item>
    	<item>
    	    <title>Reply by ronny</title>
    	    <link>https://staging.etf2l.org/forum/support/topic-14890/page-5/?recent=307503#post=258424</link>
    	    <description><![CDATA[Hi,

short update from my side. Nearly every game of the top5 teams were attacked in the past few weeks so we started to find solutions to fix it (Thx to Arie and Shox!).

<strong>How did see that the server was attacked?</strong>
All people were warping around and it was unplayable.

<strong>Did it affect all gameservers on the physical machine?</strong>
No! Just the gameserver where the top teams were playing were affected. Therefore it was no general DDOS attack to the server. It even isn't a normal DOS attack. It seems to be a simple exploit / bug in the source engine of Valve.

<strong>Do Anti-(D)DOS Plugins help?</strong>
There are a lot of plugins out there to avoid (D)DOS attacks. Plugins as a gameserver addon (DAF), sourcemod, metamod addons and the query cache application in my blog entry. And NO. They don't help because it is not a D(DOS) attack! We were able to play one game after the first attack and it seemed to help so I posted this blog entry. But the next day the attack was back.

<strong>What are the next steps?</strong>
Don't know yet. Shox is working on an application to simulate this behavior and we will then try to fix it with e.g. iptables (Firewall). So far, the only chance when someone is using this exploit is 

1) Go offline in steam friends
2) Play on a private server not listed in steams masterlist
3) Whitelist the players ip adress for iptables

Yes, I know that this is complicated. But these things are currently be done by all top teams for every game!

<strong>How can you help?</strong>
Forward every information you might have about this exploit and I will see what I can do. Currently we just can't do much because we do not have the exploit. And all package information (captured with tcpdump - including udp packages) and iptables log files seemed to be "ok".

Link to the things which I already tried: http://www.nice-servers.com/en/blog/84-ddos-und-dos-exploits-gegenmassnahmen.html

Cheers,

Ronny
nice-servers.com]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=support&#038;topic=14890&#038;post=258424</guid>
    	    <pubDate>Sat, 18 Dec 2010 20:32:33 +0100</pubDate>
    	</item>
    	<item>
    	    <title>Reply by Spike Himself</title>
    	    <link>https://staging.etf2l.org/forum/support/topic-14890/page-5/?recent=307503#post=258222</link>
    	    <description><![CDATA[This is my favourite thread. Thank you, Monkeyman :D]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=support&#038;topic=14890&#038;post=258222</guid>
    	    <pubDate>Sat, 18 Dec 2010 12:50:03 +0100</pubDate>
    	</item>
    	<item>
    	    <title>Reply by WARHURYEAH</title>
    	    <link>https://staging.etf2l.org/forum/support/topic-14890/page-5/?recent=307503#post=258084</link>
    	    <description><![CDATA[This thread was the best thing ever until just after the start of page 4, then it got shit :(

But srsface guise This was Funneh lol =]]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=support&#038;topic=14890&#038;post=258084</guid>
    	    <pubDate>Sat, 18 Dec 2010 01:43:38 +0100</pubDate>
    	</item>
    	<item>
    	    <title>Reply by xInuy</title>
    	    <link>https://staging.etf2l.org/forum/support/topic-14890/page-5/?recent=307503#post=258074</link>
    	    <description><![CDATA[http://i203.photobucket.com/albums/aa168/ThisIsNotDan91/GTFO.gif]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=support&#038;topic=14890&#038;post=258074</guid>
    	    <pubDate>Sat, 18 Dec 2010 00:53:57 +0100</pubDate>
    	</item>
    	<item>
    	    <title>Reply by Hildreth</title>
    	    <link>https://staging.etf2l.org/forum/support/topic-14890/page-5/?recent=307503#post=258073</link>
    	    <description><![CDATA[Dumb petty argument threads should be reserved for GotFra....oh wait this is the right place.]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=support&#038;topic=14890&#038;post=258073</guid>
    	    <pubDate>Sat, 18 Dec 2010 00:50:42 +0100</pubDate>
    	</item>
    </channel>
</rss>