The DDOS on SoUlFaThEr and screams about "atL"
I got "attacked" today in the weekly cup. My connection to TS and my connection to the server were attacked but nothing else. It was NOT a DDOS and it seems to me none of the attacks on those cups were a proper DDOS where I was involved due to the behavior of the "lag" the player or streamer was getting. If you want more info on what a DDOS really is and how to tell what it does eitehr ask me or search for it....im sure theres plenty on it out there becuiase these attacks are growing. But thats not the CASE here......and it's also not atL either.
The attack was a SYN flood attack. Its a partial DOS. It came from 2 addreses sitting behind the chinese network and both from about the same area. The tracert readouts on the 2 addresses were 1 hop away from each other.
The attack is basically a port80 (HHTP) and port 443 (HTTPS) flood of 3way handshakes that never finish. They start the handshake process and then drop out of the network before it can be completed, which leaves broken connections open. The end of the story is that your network is trying to send packets to an address that no longer exists or didnt exist in the first place because the attacker (if he was smart...) put a ghost IP in the TCP Header when it sent the SYN.
At then end of this statement, I found out where atL lives, he seemed rather surprised about this and also i knew his ISP...and it was not him. I even had a direct talk with him today because I wanted to hear his story and check out his technical knowledge and see if he might slip up in lying to me about what he knows and what he doesnt. It didn't seem to me he was lying.....he was in fact very nice and open minded. Kinda surprised me actually.
As I said before to many around here, a DDoS (Distrubuted Denial of Service) attack costs a lot of frickin money generally because its a battle of capacity and because it is illegal. It costs a shitload of money to control a botnet too. So they sell their services and thats how modern hackers are making their case, by allowing YOU to use their stuff to attack anything. These things are not done on any small organization that would make said person no money. Like XJ.
Next time we do any cups and streams, you guys need to turn off your steam friends and shut down anything you dont need on. It seems to me that Steam Friends has a hole in it. Aoki tells me that all CS GO tournaments are run with steam friends off. They must know something we don't.
No one can attack you if they dont know your IP. So even getting it changed just before an event can already help.....I mean your WAN ip.
So if anyone was wondering why I jumped out of the server and TS......it was to monitor my traffic. My attacker was actually not strong enough to completely down me. He just made it kinda ugly for 3 minutes in an irregular way but yeah....i got some info to go on so if they should decide to do it again...I wil have a lot more info because since i am now a victim, I wil run my "special" software while we do tomorrows cup.
One last time: It wasn't atL......and it was not a DDOS.
TIL! Thank you!
I didn't know that you've been attacked :O
There were several people that got attacked on the previous weekly cups, but somehow Soulfather had it worst.
I really don't see how "we" can stop this ...
I had it worst
Valve is trying to kill 1.6! The patch that broke everything and now this! It all makes sense!
This was a month ago.
makes me smile every time i read this thread
Makes me smile too. Oh, Not
makes me smile every time i read kayne in all threads :-)
well he knows something that we don't :(
Originally posted by ShoCkwell he knows something that we don't :(
yeah well im not here to start anything but the reason is that he cant accept the fact that he's wrong about pretty much everything in that first post. already had talk about it in the admin thread, but theres no idea to keep on about it =)
Kayne the only REAL way for you to know what happened on my computer that day (because you are4 SOOOO sure I am wrong), is if you were the one doing it so be careful how much you think you might know.
Even if you called the artillery on me from the Ukraine like atL did with Sitka, you still do not 100% know what they actually did,
so have a seat and go read the Admin Rules one more time for old times sake. It seems you missed or have forgotten a few things that you shouldn't be doing.
SYN flood:
A SYN flood occurs when a host sends a flood of TCP/SYN packets, often with a forged sender address. Each of these packets is handled like a connection request, causing the server to spawn a half-open connection, by sending back a TCP/SYN-ACK packet (Acknowledge), and waiting for a packet in response from the sender address (response to the ACK Packet). However, because the sender address is forged, the response never comes. These half-open connections saturate the number of available connections the server is able to make, keeping it from responding to legitimate requests until after the attack ends.
Seems legit to me.
Originally posted by SoUlFaThErKayne the only REAL way for you to know what happened on my computer that day (because you are4 SOOOO sure I am wrong), is if you were the one doing it so be careful how much you think you might know.
Even if you called the artillery on me from the Ukraine like atL did with Sitka, you still do not 100% know what they actually did,
so have a seat and go read the Admin Rules one more time for old times sake. It seems you missed or have forgotten a few things that you shouldn't be doing.
as i said, i didnt want to start anything but.. why would i read the "admin rules"? what did i miss or what am i doing that i shouldnt be doing? uhh
Nice1 WeMeRA :D
See those don't kill your internet connection. a DDOS does and acts completely different...it gradually grows until it finally cuts you off.
I never got my internet connection cut off :D And was easily reading tons of packets recorded by Wireshark that showed me exactly what I said. It was a syn flood and nothing else. I was even seeing it as a synflood in cmd.exe's "netstats -a" with a bunch of incompleted 3 way handshakes.
In case you guys ever get attacked there's a few things you might be able to do against them. You can get the address and quickly write an ACL on your router that blocks incoming traffic from that entire network.
Redirect trafffic headed for port 80 or port 443 into an unused VLAN where all the packets will simply get dropped. The famous VLAN666 :D
The other way is to simply get more capacity in your network than your attacker which can get expensive.
We found out 2 interesting things however and since then have been taking precaustions. These 2 things apparently are avoiding an attack. It seems no coincidence to me that after this the attacks suddenly stopped.
The reason the attacks stopped is, that a certain somebody maybe just got bored of raping you. But who knows, sometimes people (you) write cheques with their mouth that their asses can't cash if you know what i mean ;)
This is quite simple SF.
Let's point some things out:
1) You don't know jackshit
2) If you keep talking shit, a certain somebody might feel the urge to prove you wrong, i.e. making you cry again, asking "WHY MEE??? GOD DAMN WHY MEEE?? PLES GOD MAKE IT STAAAHP".
So, you have the choice. Stfu for once and all or get rekt again.
EDIT:
I changed my mind to be fair. This Community needs a massive shakeup, things are so boring. Prepare your anuses, here we go again ;)
Originally posted by SoUlFaThErKayne the only REAL way for you to know what happened on my computer that day (because you are4 SOOOO sure I am wrong), is if you were the one doing it so be careful how much you think you might know.
Even if you called the artillery on me from the Ukraine like atL did with Sitka, you still do not 100% know what they actually did,
so have a seat and go read the Admin Rules one more time for old times sake. It seems you missed or have forgotten a few things that you shouldn't be doing.
lol'd at the Ukraine part.
Truth is, ATL is a former KGB-Agent and best buddy to Putin obviously. Once he can't suceed, he just calls for Putins backup, clearly.
kz is dead. confirmed in this thread.