I'm using the latest version of dproto and i'm getting connect flood attacked by a huge botnet it looks like.
From my understanding dproto have an option to ban a reconnecting client that's reconnecting on the same IP over and over but what if there are many IPs (hundreds) connecting to a server over and over preventing players from joining? Is there a way to prevent that?
DProto connection flood help
Started by Digital, Nov 21 2011 01:13 AM
2 replies to this topic
#3
Posted 17 May 2012 - 07:25 PM
>many IPs
it seems it's botnet or socks proxy servers.
You need traffic log to solve the problem.
If the fake client connects successfully or it's just flooding server with getchallenge command and does nothing more.
Probably you can restrict clients by IP (country filter).
Also look!!! at source port of client (udp stats). Maybe port of real clients and fakes is different - so you may reject incoming connect requests from some ports.
I had the same problem with 1 IP and various ports (bot program), bad guy from the same provider as me. I just made acall to provider and they made a call to that client
it seems it's botnet or socks proxy servers.
You need traffic log to solve the problem.
If the fake client connects successfully or it's just flooding server with getchallenge command and does nothing more.
Probably you can restrict clients by IP (country filter).
Also look!!! at source port of client (udp stats). Maybe port of real clients and fakes is different - so you may reject incoming connect requests from some ports.
I had the same problem with 1 IP and various ports (bot program), bad guy from the same provider as me. I just made acall to provider and they made a call to that client
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users