stop the ddos somehow
- Super Aggro Crag
- In Game PermaBanned
- Joined: Sat Mar 21, 2015 9:47 pm
- Byond Username: Super Aggro Crag
- oranges
- Code Maintainer
- Joined: Tue Apr 15, 2014 9:16 pm
- Byond Username: Optimumtact
- Github Username: optimumtact
- Location: #CHATSHITGETBANGED
- D&B
- Joined: Mon Jun 13, 2016 2:23 am
- Byond Username: Repukan
- Location: *teleports behind you*
- Yakumo_Chen
- Joined: Fri Dec 11, 2015 10:08 pm
- Byond Username: Yakumo Chen
- oranges
- Code Maintainer
- Joined: Tue Apr 15, 2014 9:16 pm
- Byond Username: Optimumtact
- Github Username: optimumtact
- Location: #CHATSHITGETBANGED
Re: stop the ddos somehow
the free tier we are using is being swamped by the DDOSYakumo_Chen wrote:Pick the free one?
- terranaut
- Joined: Fri Jul 18, 2014 11:43 pm
- Byond Username: Terranaut
Re: stop the ddos somehow
just pick it 5 times and stack it loloranges wrote:the free tier we are using is being swamped by the DDOSYakumo_Chen wrote:Pick the free one?
- Cobby
- Code Maintainer
- Joined: Sat Apr 19, 2014 7:19 pm
- Byond Username: ExcessiveUseOfCobby
- Github Username: ExcessiveUseOfCobblestone
-
- Joined: Sat Dec 15, 2018 10:33 am
- Byond Username: Darkness12344
Re: stop the ddos somehow
hjkghjkghjkghjkghjk
Last edited by Retardedgrayshit on Mon Feb 07, 2022 8:39 pm, edited 1 time in total.
- oranges
- Code Maintainer
- Joined: Tue Apr 15, 2014 9:16 pm
- Byond Username: Optimumtact
- Github Username: optimumtact
- Location: #CHATSHITGETBANGED
Re: stop the ddos somehow
this, this is salt
- Super Aggro Crag
- In Game PermaBanned
- Joined: Sat Mar 21, 2015 9:47 pm
- Byond Username: Super Aggro Crag
Re: stop the ddos somehow
More like dan gayRetardedgrayshit wrote:Hey Dan Gar here just wanted to say i hope your shitty server gets ddosed until the end of time
- peoplearestrange
- Joined: Tue Apr 22, 2014 12:02 pm
- Byond Username: Peoplearestrange
- Location: old
Re: stop the ddos somehow
Is this more salt than the time someone printed out a pic of anon and literally shit on it? It's certainly on a par. Either way they both need you to handle your own poop to clean up.Retardedgrayshit wrote:Hey Dan Gar here just wanted to say i hope your shitty server gets ddosed until the end of time
Whatever
Spoiler:
- PKPenguin321
- Site Admin
- Joined: Tue Jul 01, 2014 7:02 pm
- Byond Username: PKPenguin321
- Github Username: PKPenguin321
- Location: U S A, U S A, U S A
Re: stop the ddos somehow
It's baitpeoplearestrange wrote:Is this more salt than the time someone printed out a pic of anon and literally shit on it? It's certainly on a par. Either way they both need you to handle your own poop to clean up.Retardedgrayshit wrote:Hey Dan Gar here just wanted to say i hope your shitty server gets ddosed until the end of time
i play Lauser McMauligan. clown name is Cold-Ass Honkey
i have three other top secret characters as well.
tell the best admin how good he is
i have three other top secret characters as well.
tell the best admin how good he is
Spoiler:
- MisterPerson
- Board Moderator
- Joined: Tue Apr 15, 2014 4:26 pm
- Byond Username: MisterPerson
Re: stop the ddos somehow
Woah calm down there Crag, your cunning wit's gonna kill someone.Super Aggro Crag wrote:More like dan gayRetardedgrayshit wrote:Hey Dan Gar here just wanted to say i hope your shitty server gets ddosed until the end of time
I code for the code project and moderate the code sections of the forums.
Feedback is dumb and it doesn't matter
Feedback is dumb and it doesn't matter
-
- Joined: Sat Aug 26, 2017 4:57 am
- Byond Username: Carshalash
Re: stop the ddos somehow
Aren't you that guy that would hound admins every round for free antag?Retardedgrayshit wrote:Hey Dan Gar here just wanted to say i hope your shitty server gets ddosed until the end of time
- Plapatin
- In-Game Game Master
- Joined: Wed Sep 06, 2017 11:26 am
- Byond Username: Plapatin
- Location: Location: Location: Location: Location: Location: Location: Location: Location:
Re: stop the ddos somehow
holy shit its been a while i thought you diedpeoplearestrange wrote:Is this more salt than the time someone printed out a pic of anon and literally shit on it? It's certainly on a par. Either way they both need you to handle your own poop to clean up.Retardedgrayshit wrote:snip
wesoda25 wrote:i had a dream that me and some friends were like in this tribal village and we were all doing cocaine around this massive bonfire and I kept seeing all these foreshadowing elements that we were gonna die but i just did more cocaine
OrdoM wrote:Argent, a swan argent over a saltire vert - the vert representing the vomit cast upon the floor by the vomitgoose
- Electronics
- Github User
- Joined: Fri Sep 19, 2014 4:49 pm
- Byond Username: Electronics111
- Github Username: Electronics
Re: stop the ddos somehow
Can we not get whatever ISP we have to block the sources of the ddos?
- Qbmax32
- Joined: Sun Feb 19, 2017 4:05 am
- Byond Username: Qbmax32
- Github Username: qbmax32
- Location: in your walls
- Super Aggro Crag
- In Game PermaBanned
- Joined: Sat Mar 21, 2015 9:47 pm
- Byond Username: Super Aggro Crag
- Super Aggro Crag
- In Game PermaBanned
- Joined: Sat Mar 21, 2015 9:47 pm
- Byond Username: Super Aggro Crag
Re: stop the ddos somehow
Well it is weedsmasLaKiller8 wrote:Just flip off the "Allow DDoS" switch smh MSO is so lazy
- ABearInTheWoods
- Joined: Mon Apr 14, 2014 10:56 pm
- Byond Username: MrStonedOne
- Github Username: MrStonedOne
- Contact:
Re: stop the ddos somehow
The source address of an Internet Protocol packet is spoofable. The only protection against this is the fact that establishing a connection requires a 3 way handshake and if you spoof the source address you don't get the 2nd packet so you can't properly respond with the final 3rd packet.
What we are getting is a massive flood of spoofed packets to the tune of 1 to 5 million packets a second, depending on what they can afford at that time.
The source address of these packets is spoofed, during a 10,000 packet sample taken during one of the ddos's, there were 9946 unique source ip addresses.
What we are getting is a massive flood of spoofed packets to the tune of 1 to 5 million packets a second, depending on what they can afford at that time.
The source address of these packets is spoofed, during a 10,000 packet sample taken during one of the ddos's, there were 9946 unique source ip addresses.
Forum/Wiki Administrator, Server host, Database King, Master Coder
MrStonedOne(!vAKvpFcksg) on Reddit(banned), Steam, IRC, Skype Discord. Don't click this

NSFW:
- D&B
- Joined: Mon Jun 13, 2016 2:23 am
- Byond Username: Repukan
- Location: *teleports behind you*
- peoplearestrange
- Joined: Tue Apr 22, 2014 12:02 pm
- Byond Username: Peoplearestrange
- Location: old
Re: stop the ddos somehow
Its kinda amazing (read:sad) that someone is spending their (or their parents) hard earned cash to make a game server suffer for awhile. Because thats all it is, an annoying inconvience. Eventually they will get bored, run out of money, or we'll find away to stop it.MrStonedOne wrote:The source address of an Internet Protocol packet is spoofable. The only protection against this is the fact that establishing a connection requires a 3 way handshake and if you spoof the source address you don't get the 2nd packet so you can't properly respond with the final 3rd packet.
What we are getting is a massive flood of spoofed packets to the tune of 1 to 5 million packets a second, depending on what they can afford at that time.
The source address of these packets is spoofed, during a 10,000 packet sample taken during one of the ddos's, there were 9946 unique source ip addresses.
They think they are self rightous, we think they'll be forgotten.
Na im still alive, just been doing other stuff non SS13, though like us all, we come back eventually.Plapatin wrote:holy shit its been a while i thought you died
Whatever
Spoiler:
-
- Joined: Fri Apr 19, 2019 2:10 pm
- Byond Username: RearAdmiralFuttBucker
Re: stop the ddos somehow
https://en.wikipedia.org/wiki/Hanlon%27s_razorpeoplearestrange wrote:Its kinda amazing (read:sad) that someone is spending their (or their parents) hard earned cash to make a game server suffer for awhile. Because thats all it is, an annoying inconvience. Eventually they will get bored, run out of money, or we'll find away to stop it.MrStonedOne wrote:The source address of an Internet Protocol packet is spoofable. The only protection against this is the fact that establishing a connection requires a 3 way handshake and if you spoof the source address you don't get the 2nd packet so you can't properly respond with the final 3rd packet.
What we are getting is a massive flood of spoofed packets to the tune of 1 to 5 million packets a second, depending on what they can afford at that time.
The source address of these packets is spoofed, during a 10,000 packet sample taken during one of the ddos's, there were 9946 unique source ip addresses.
They think they are self rightous, we think they'll be forgotten.
Na im still alive, just been doing other stuff non SS13, though like us all, we come back eventually.Plapatin wrote:holy shit its been a while i thought you died
"Never attribute to malice that which can be easily explained by human stupidity."
They're not DDoS-ing the hosts in some effort to cause a massive problem for hundreds of people or to somehow gain an upper hand.
They're doing it because "it's funny."
It's like choosing to play an assistant because you want to play Antag, but when you don't get antag you decide to "do dumb fun things" as an assistant which ends up pissing off half the station.
on a related topic, Reverse proxies are an absolutely wonderful way to help mitigate DDoS attacks; has any consideration been given to standing up an nginx reverse proxy for the purposes of DDoS mitigation? or would the BYOND engine have an aneurysm over the concept?
- ABearInTheWoods
- Joined: Mon Apr 14, 2014 10:56 pm
- Byond Username: MrStonedOne
- Github Username: MrStonedOne
- Contact:
Re: stop the ddos somehow
A network of reverse tcp proxies was an idea we discussed to stop the attacks, we can even do validation by just putting a stub byond world that whitelists the ip and redirects to the whitelisted port. The hard part is cost of the other nodes. You can kinda abuse vpses and the fact they all come with some amount of bandwidth at a cheaper cost than buying it directly, subsidised by the fact that most of the clients don't use much of their allotment, but mis-plan the capacity and you're looking at some costly invoices.
Let's say you get 13 amazon lightsail instances at $3.5 a month each $45.5 total, one for each aws region, thats 13tb a month of included bandwidth usage.
This month so far, /tg/ has used 37037.29 GB of bandwidth, most of that from the ddos, and it's only the 23rd.
At 0.09 USD/GB for bandwidth overages, that would be $2,135.28 in overages.
Upgrade the nodes, get the 2TB for $5 a month, and now you have 26TB of capacity for $65 total a month. Thats still not 37TB of capacity.
$937.20 overage fee
It doesn't make sense to scale the nodes up at this point, 10 bucks only gets you 3TB, its cheaper scale them out. 7 more $5 nodes in the 7 popular regions for a total of $100 a month for 40TB of capacity,
This is also the max amount of lightsail nodes you can have in one aws account, before they force you to use ec2 instances that have no included bandwidth. There are other providers with about the same pricing, just not one with nodes in all the same regions as aws, and doesn't tie in as nicely to route 53's latency based domain records to do the actual geoip routing.
Still, thats $100/month to (hopefully) cover the ddos, and given current usage, and the fact the ddos hasn't been happening all month, it would very likely still break past 40TB in one month.
Thats not to say building this system wouldn't have other benefits. Overall ping would drop because the routes would be better than home isp routes.
Even now, pinging my personal ip from the server, and pinging the server from my computer, show two different routes, and a ping drop from 60ms to 45ms, and i'm only two states away from the server. Data Centers generally optimize for better routes. Home isps instead keep the traffic in network for longer, bouncing from connected region to connected region, optimizing for the cheaper route when it finally leaves their network.
Hit 420 on the patreon (or hell, hit 365) and I'll be able to do it. It's not like I can't turn off the nodes if it looks like its about to go over.
Let's say you get 13 amazon lightsail instances at $3.5 a month each $45.5 total, one for each aws region, thats 13tb a month of included bandwidth usage.
This month so far, /tg/ has used 37037.29 GB of bandwidth, most of that from the ddos, and it's only the 23rd.
At 0.09 USD/GB for bandwidth overages, that would be $2,135.28 in overages.
Upgrade the nodes, get the 2TB for $5 a month, and now you have 26TB of capacity for $65 total a month. Thats still not 37TB of capacity.
$937.20 overage fee
It doesn't make sense to scale the nodes up at this point, 10 bucks only gets you 3TB, its cheaper scale them out. 7 more $5 nodes in the 7 popular regions for a total of $100 a month for 40TB of capacity,
This is also the max amount of lightsail nodes you can have in one aws account, before they force you to use ec2 instances that have no included bandwidth. There are other providers with about the same pricing, just not one with nodes in all the same regions as aws, and doesn't tie in as nicely to route 53's latency based domain records to do the actual geoip routing.
Still, thats $100/month to (hopefully) cover the ddos, and given current usage, and the fact the ddos hasn't been happening all month, it would very likely still break past 40TB in one month.
Thats not to say building this system wouldn't have other benefits. Overall ping would drop because the routes would be better than home isp routes.
Even now, pinging my personal ip from the server, and pinging the server from my computer, show two different routes, and a ping drop from 60ms to 45ms, and i'm only two states away from the server. Data Centers generally optimize for better routes. Home isps instead keep the traffic in network for longer, bouncing from connected region to connected region, optimizing for the cheaper route when it finally leaves their network.
Hit 420 on the patreon (or hell, hit 365) and I'll be able to do it. It's not like I can't turn off the nodes if it looks like its about to go over.
Forum/Wiki Administrator, Server host, Database King, Master Coder
MrStonedOne(!vAKvpFcksg) on Reddit(banned), Steam, IRC, Skype Discord. Don't click this

NSFW:
Who is online
Users browsing this forum: No registered users