Argonath RPG - A World of its own

GTA:SA => SA:MP - San Andreas Multiplayer => SA:MP General => Topic started by: Wayne on July 23, 2007, 07:09:01 am

Title: SA-MP Server attack
Post by: Wayne on July 23, 2007, 07:09:01 am
these attackers are small smugglers (bots) wich have no P2P and isnt a player. i got info from then
all players if you see a large amount of bots use /report (one bot ID) [reason]
the names starts like strange names example: AxzAPSAPsPSa16DS yes this is a familiar name remember crashbots from SA-MP 0.1b?

Admins should kick/ban these bots.
this cheater is messing with SA-MP main list i got some info
they use -1 ping and are non players
also they are small smugglers
ive banned one of them kicked the rest..
at least i think they got no IP also no P2P wich makes the ban effect more harder than normal one
check this quote from Cam
Quote
The server crashers does not exploit the SA-MP code, but rather the networking API (RakNet). Going through other people's coding looking for possible errors is not easy, nor is it fun, and it doesn't come to our attention until it is exploited.
Yes he is sure.. there is errors wich not allows they really crashes but it causes a SA:MP main server list crash.
here is a general info
How it went in sequence.
1.Starts out 9 legit players playing peaceful on GamerX which has 125 player slots.
2.These bots start to join quite fast...Took 16 seconds exact for the entire group to join.
3.After all bots joined player count was 124/125
4.Bots had ping -1 and IP was 255.255.255.255 from the GetPlayerIP SA-MP function and then sat there and nothing to much going on.
5.On server for 45 seconds exactly and then all of them got kicked/banned by some system it took 12 seconds total to kick/ban them all..
some pics about these smugglers
http://img410.imageshack.us/img410/2159/gtasa200707212155119500vw0.jpg (http://img410.imageshack.us/img410/2159/gtasa200707212155119500vw0.jpg)
http://img526.imageshack.us/img526/281/gtasa200707212155119500nr9.jpg (http://img526.imageshack.us/img526/281/gtasa200707212155119500nr9.jpg)
http://img244.imageshack.us/img244/6294/gtasa200707212155119500la0.jpg (http://img244.imageshack.us/img244/6294/gtasa200707212155119500la0.jpg)
quote from kyeman
Quote
If you are running an SA-MP 0.2.1 server, please note the following:

A join flooding robot that is capable of causing a denial of service attack is circulating on the internet. It is capable of filling the open game slots on your server and disconnecting existing users.

We have made a temporary fix in the form of a filterscript that you can load on your server to prevent these join flooding attacks. It can be found on our forum here:
http://forum.sa-mp.com/index.php?topic=24525.0 (http://forum.sa-mp.com/index.php?topic=24525.0)

If your server is attacked by this tool, and you have system level packet logs with the IP addresses of the attacker, please email them to [team AT sa-mp.com]

If you are a server owner, and are found to be using this tool to artificially inflate your player count, we may ban your server from listing itself on our master list. Please do not do this.
Title: Re: SA-MP Server attack
Post by: Shifter on July 23, 2007, 07:33:27 am
Iv seen this Hack thing b4 on anothe game (Jedi Knight 2) It was extremly annoying because the servers would constently be full untill they were reset.
Title: Re: SA-MP Server attack
Post by: Andre9977 on July 23, 2007, 08:22:37 am
i actually had to kick 30 bots... Well, its pretty easy. Yes their names are very scary. We actually freaked out, when this happent first time.
And here is the best part: One players ping reachec 10000 during kicking bots  :redface:
Title: Re: SA-MP Server attack
Post by: Wayne on July 23, 2007, 08:46:16 am
these cheaters really dont give a fuck .. they got almost SA-MP script IP code
Posted on: July 23, 2007, 07:24:02 AM
it has something familiar with 0.1b crashbot
the names are familiar no?
Title: Re: SA-MP Server attack
Post by: Obi1 on July 23, 2007, 11:22:12 am
any of u heard of MLRS?? he hcaked argonath b4 his name stood for Multiple Launch Rocket System he used infinite ammo hack..
Title: Re: SA-MP Server attack
Post by: Andre9977 on July 23, 2007, 11:59:06 am
Rocket launcher guy...
Title: Re: SA-MP Server attack
Post by: Obi1 on July 23, 2007, 12:20:59 pm
ye he amde me $2000 lol before he got banned
Posted on: July 23, 2007, 11:11:07 AM
no he didnt give me money.... he killed me 4 times giving me $500...lol
Title: Re: SA-MP Server attack
Post by: Luca_Scalise on July 23, 2007, 12:56:03 pm
I don't understand if they are Bots with AI or not  :trust:
Title: Re: SA-MP Server attack
Post by: Tice on July 23, 2007, 01:23:29 pm
Quote from: Wayne
the names are familiar no?

Well, yes. It seems like the same script for 0.1b adapted for 0.2.1, so it uses the same charhash names.

any of u heard of MLRS?? he hcaked argonath b4 his name stood for Multiple Launch Rocket System he used infinite ammo hack..

MLRS was a s0biet scriptkiddie. These guys are using what look like Python scripts that made multiple connection requests from localhost somehow (-1 ping), until the script is denied connection. The only malicious thing that this script can do is wait for it's bots to be kicked (kicking 124 players all at once = boom) or the server is reset.

Quote from: Luca
I don't understand if they are Bots with AI or not

No, they're a simple script to connect to the server, until they are kicked.
Title: Re: SA-MP Server attack
Post by: lionz on July 23, 2007, 02:20:50 pm
ive seen that on world of warcraft too. they are so annoying
Title: Re: SA-MP Server attack
Post by: Wayne on July 23, 2007, 03:43:32 pm
on the first time when i see those bots i thinked they were crashboters  :rofl:
Title: Re: SA-MP Server attack
Post by: Tice on July 23, 2007, 05:15:28 pm
Quote from: kyeman
If you are running an SA-MP 0.2.1 server, please note the following:

A join flooding robot that is capable of causing a denial of service attack is circulating on the internet. It is capable of filling the open game slots on your server and disconnecting existing users.

We have made a temporary fix in the form of a filterscript that you can load on your server to prevent these join flooding attacks. It can be found on our forum here:
Forum Link (http://forum.sa-mp.com/index.php?topic=24525.0)

If your server is attacked by this tool, and you have system level packet logs with the IP addresses of the attacker, please email them to [team AT sa-mp.com]

If you are a server owner, and are found to be using this tool to artificially inflate your player count, we may ban your server from listing itself on our master list. Please do not do this.
Title: Re: SA-MP Server attack
Post by: Wayne on July 23, 2007, 05:47:47 pm
good quote.. thats quite another info about those
Title: Re: SA-MP Server attack
Post by: Yoshi on July 23, 2007, 06:27:10 pm
Theys till do it on jedi academy.
Title: Re: SA-MP Server attack
Post by: Wayne on July 23, 2007, 08:33:24 pm
we are talking about SA-MP not jedi academy
Posted on: July 23, 2007, 07:30:58 PM
the problem has with curlyboy the crashbot maker to SA-MP 01b so he gave the sources to someone then he just adapted and using localhost
thats helped a lot. :neutral:
Title: Re: SA-MP Server attack
Post by: BlackBird on July 23, 2007, 11:07:53 pm
Every time this happened keep an eye on the list of players. everytime a bot is kicked a players ping will rise to 10k or more. when last bot is kicked it rises up to over 60k then back to 150 or w/e a normal player uses. Find him and ban him. today for example it was a player named Hamster. Normally if you can find him while kicking the bots and you abn him the bots get dced as well.


They dont have an ip. only the person using them has the ip. ban him you ban the bots.


This most recent attack was probally cause the attacker yesterday got banned.


Also this is also most likely a attack by a ahcker who was banned from the server. or sumthin.

This should also be reported to the team AT sa-mp.com as they will find a way to stop this again.

Also on the off chance these bots do have IP you should instate a clone kicker at a maximum number of certian people from 1 ip. like set it at 3-5 as they come in massive swarms. once it reaches over 5 it will kick them and the creator automatically. (Just an idea)
Title: Re: SA-MP Server attack
Post by: [GSF]Niall on July 23, 2007, 11:09:22 pm
that bot came today
Title: Re: SA-MP Server attack
Post by: Obi1 on July 23, 2007, 11:19:50 pm
ye there were loads of bots on today but the admins just kept kicking them :D
Title: Re: SA-MP Server attack
Post by: Wayne on July 24, 2007, 01:31:54 am
the bots was the ip 255.555.555 (localhost)
thats impossible ban then
Title: Re: SA-MP Server attack
Post by: Justin on July 24, 2007, 01:33:20 am
Well, they shut down the internets list to prevent anymore attacks, so we should not get anymore attacks with these things, but i would not be to sure.
Title: Re: SA-MP Server attack
Post by: [Rstar]Razor on July 24, 2007, 03:22:37 am
Yes, i have seen it, i had kicked almost 30 Bots  :neutral:






So, are a admin and you see this, kick or ban



(http://img503.imageshack.us/img503/2662/samp796my4.png)


 :ps: Sorry, but the upload folder is full  :neutral:
Title: Re: SA-MP Server attack
Post by: RiX[LV] on July 24, 2007, 03:29:14 am
Yeah today that bots attack server but we kick them all very fast :D
 :ps: sorry people for flooding screen with kicks
Title: Re: SA-MP Server attack
Post by: Andre9977 on July 24, 2007, 11:14:31 am
http://bust3d.net/index.php/topic,525.0.html
^^ I know that its bust3d behind this
SimplePortal 2.3.7 © 2008-2025, SimplePortal