free

News

collapse

User Info

 
 
Welcome, Guest. Please login or register.
Did you miss your activation email?

* Recent Posts

Re: ordinary day in VCMP by Denlow
[Yesterday at 04:58:56 pm]


Re: The Soprano Family | Royal Loyalty by .Mario.
[July 26, 2025, 03:05:43 pm]


Re: [SA:MP]House of Sforza | The Elite Power | Estd. 2006 | LS - LV by FrankCivello
[July 17, 2025, 12:50:43 am]


NOTICE OF PARKING ENFORCEMENT CHANGES by Huntsman
[June 19, 2025, 05:22:50 pm]


Re: Stopping by by Sinister
[June 08, 2025, 01:58:04 pm]


Re: Stopping by by Ehks
[June 04, 2025, 12:25:17 am]


Re: Rest in peace by Stefanrsb
[June 02, 2025, 03:38:02 am]


Re: [SA:MP]House of Sforza | The Elite Power | Estd. 2006 | LS - LV by Stefanrsb
[June 02, 2025, 03:09:22 am]


Re: The Soprano Family | Royal Loyalty by Stefanrsb
[June 02, 2025, 03:00:31 am]


Re: The Gvardia Family || San Fierro's Main Power || Best criminal group of 09/10/11 by Stefanrsb
[June 02, 2025, 02:47:01 am]


Re: BALLAS | In memory of INFERNO 9 and NBA by Stefanrsb
[June 02, 2025, 02:31:29 am]


Re: Count to 1,000,000. by Stefanrsb
[June 02, 2025, 02:15:04 am]

* Who's Online

  • Dot Guests: 351
  • Dot Hidden: 0
  • Dot Users: 0

There aren't any users online.

* Birthday Calender

July 2025
Sun Mon Tue Wed Thu Fri Sat
1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 [29] 30 31

What is a DDOS and why is it so hard to stop?

Teddy · 2081

0 Members and 1 Guest are viewing this topic.

Offline TeddyTopic starter

  • Orc
  • *****
    • Posts: 9161
  • "I'm on top of the world because of you."
  • With us since: 05/02/2011
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
on: January 11, 2015, 08:41:49 am
A number of people have complained about DDOS attacks bringing down the servers over the last couple of weeks, and well, pretty much throughout the entirety of Argonath's history. Some have asked why we can't do anything about it. So this is basic introduction to what exactly a DDOS attack is and as a result why it's so hard to stop.

First off there is a difference between DOS and DDOS. DOS by itself stands for Denial of Service attack, which indicates a single machine attacking a target. In DDOS it stands for Distributed Denial of Service. Meaning the attack is coming from an arbitrary amount of sources. Since a DOS attack is from a single user on a single network connection, these attacks are generally a lot easier to detect and resolve.

How exactly is this preformed?
Quite simply a denial of service attack is flooding the server with so many requests it unable to handle legitimate traffic. Imagine this: Your friend wants to come over and hangout, however, once he nears your house the entire front lawn and street is flooded with hundred of people standing in between him and your front door. This is a similar concept to denial of service.

Why is it so hard to stop?
Denial service attacks by concept seem so simple and rudimentary, right? So why are they so hard to stop... well by the simple nature of networking. Denial of Service attacks are simply flooding of requests and it's not yet possible to effectively distinguish between legitimate traffic and attack traffic. As a result of this simple factor, preventing denial of service attacks becomes a challenge. There is methods to do so however they create latency issues and other efficiency problems which most professional denounce. The next available step is to detect and mitigate the service disruption attempts.

How is it stopped by hosts like OVH?
Any service that offers anti-ddos protection does not actually prevent denial of service attacks. They use specialized network monitoring software and hardware which can detect an influx or irregular amount of traffic. Essentially they detect that there is a shit load of traffic coming in and it's not usual traffic. This then triggers a series of protocols (both hardware and software) which aim to remedy the issue. Each data center has their own methods of conducting this protection. OVH specifically uses a method called vacuuming, and no, it's not a bunch of French people standing at a server with a vacuum and a baguette, as interesting as an image as that may be to picture. It is some really complicated network stuff that nearly surpasses my understanding of computer networks, and happens to be the most state-of-the-art and industry leading method.

All of what was mentioned here are what are referred to as volume based attacks, which is what Argonath mostly receives. There are also protocol attacks and application layer attacks. Last year there was a Zero-day exploit found in SA:MP which allowed attackers to bring down a server. Similar incidents have occurred before as well in the VC:MP server and other game servers; they are often quickly patched. Since this exploited a bug in the server software, this was an application layer denial of service attack. Protocol attacks aim to disrupt server resources rather than network.



Offline KelviNC

  • Veteran
  • ***
    • Posts: 2391
    • @MohammadAli901
  • With us since: 07/10/2011
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
  • SA:MP: [WS]Freddy_Moralez
Reply #1 on: January 11, 2015, 09:01:11 am
Can't we get a DDOS protector for the server? Like I have no idea from where and how to get it. But still, if we can get one that will be great.



Offline CharlieKasper

  • Retired (SA:MP Admin)
  • Orc
  • *****
    • Posts: 3196
    With us since: 24/04/2010
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
  • SA:MP: Charlie_Corleone
Reply #2 on: January 11, 2015, 09:20:12 am
Informative, helps us all users who don't have much knowledge. Thanks! :)



Offline AryaN

  • To Serve and Protect
  • Regular
  • **
    • Posts: 495
    With us since: 22/04/2011
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
  • SA:MP: [WS]Dexter_Smith
  • Discord: Dexter#4252
Reply #3 on: January 11, 2015, 10:27:18 am
Thanks for this elaboration. This just cleared my many doubts related to DDOS.  ;)



Offline TeddyTopic starter

  • Orc
  • *****
    • Posts: 9161
  • "I'm on top of the world because of you."
  • With us since: 05/02/2011
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
Reply #4 on: January 11, 2015, 10:47:03 am
Can't we get a DDOS protector for the server? Like I have no idea from where and how to get it. But still, if we can get one that will be great.

It is being worked on as far as I am aware.



Offline Axison

  • Angels Of Death MC
  • Orc
  • *****
    • Posts: 1970
    With us since: 14/12/2011
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
  • SA:MP: =AV=Axis
Reply #5 on: January 11, 2015, 11:12:15 am
Thanks Teddy, cleared some of my questions regarding ddos


Angels of Death MC | Argonath Veterans| Music Enthusiast


Offline Ben.

  • Veteran
  • ***
    • Posts: 2958
  • Benjamin J. Blake
  • With us since: 21/07/2009
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
  • SA:MP: =AV=Ben_Blake
Reply #6 on: January 11, 2015, 11:21:04 am
Does the server have the funds for this, or will donations be essential?


Salt and hate won't take us anywhere.
And we do not try to be real life, as why would you ever play real life if you have one ? We play the GTA universe, and our players should try to live in the GTA world, not the real one.


Offline Tovenaarke

  • A Helper
  • Hero
  • ****
    • Posts: 3365
  • Can I help you?
  • With us since: 18/06/2007
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
    • Private Wiki (old)
  • SA:MP: [WS]Tovenaarke
  • IV:MP: Tovenaarke
  • V:MP: [WS]Tovenaarke
Reply #7 on: January 11, 2015, 11:23:46 am
Informative, helps us all users who don't have much knowledge. Thanks! :)
Indeed, now I can 'imagen' what it is...


Do not be afraid of things you do not know (yet)...


Offline TeddyTopic starter

  • Orc
  • *****
    • Posts: 9161
  • "I'm on top of the world because of you."
  • With us since: 05/02/2011
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
Reply #8 on: January 11, 2015, 11:24:35 am
Does the server have the funds for this, or will donations be essential?

That's something for Gandalf to disclose. However, I will say donations are always helpful in expanding and improving.



Offline Kostas

  • Hero
  • ****
    • Posts: 2143
  • With us since: 25/07/2011
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
  • SA:MP: Kostas Evans
  • Minecraft: L2DuelistKing
  • Discord: Kostas#4542
Reply #9 on: January 11, 2015, 12:25:58 pm
From the few articles that I've read in the past. The people doing DDoS attacks usually have a whole army of "zombies"(not sure if I remember well that name) in their possession which they use in order to attack the server at that time. Seeing how many people have access to such attacks, I guess anyones computer could be a "zombie", used when ever they want to attack a server. So first of all, is there any way for someone to find out, if he is being used? And also, is there any way for us, from the server side, durring the attack to somehow record the "attackers" (or atleast as many as we get the time to) and then notify them, that their computers are being used like that, and guide them on how to remove their "virus"?


Offline Mikro

  • SA:MP Bad-Ass
  • Hero
  • ****
    • Posts: 2090
  • [WS]Mikro
  • With us since: 17/08/2009
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
  • SA:MP: [WS]Mikro
Reply #10 on: January 11, 2015, 01:08:08 pm
From the few articles that I've read in the past. The people doing DDoS attacks usually have a whole army of "zombies"(not sure if I remember well that name) in their possession which they use in order to attack the server at that time. Seeing how many people have access to such attacks, I guess anyones computer could be a "zombie", used when ever they want to attack a server. So first of all, is there any way for someone to find out, if he is being used? And also, is there any way for us, from the server side, durring the attack to somehow record the "attackers" (or atleast as many as we get the time to) and then notify them, that their computers are being used like that, and guide them on how to remove their "virus"?

It is not like every attacker got his own army of zombie computers. The thing is that the better hackers/crackers created software to make these attacks easy for people with no understanding of how it actually works. Even worse, they created paid services for bigger DDoS attacks. So every dick with a credit card (from their parents probably) can buy an attack..


Ex. Argonath Weekly Express leader ■  Ex. FBI C. Division Chief (SA:MP) ■  Ex. FBI Director (SA:MP)
Ex. Argonath Government Radio Developer | Tune in! ■  [WS] Member ■  Ex. SA:MP Lead Developer


Offline Ben.

  • Veteran
  • ***
    • Posts: 2958
  • Benjamin J. Blake
  • With us since: 21/07/2009
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
  • SA:MP: =AV=Ben_Blake
Reply #11 on: January 11, 2015, 03:36:40 pm
That's something for Gandalf to disclose. However, I will say donations are always helpful in expanding and improving.
Will kick things off then  :lol:


Salt and hate won't take us anywhere.
And we do not try to be real life, as why would you ever play real life if you have one ? We play the GTA universe, and our players should try to live in the GTA world, not the real one.


Offline TeddyTopic starter

  • Orc
  • *****
    • Posts: 9161
  • "I'm on top of the world because of you."
  • With us since: 05/02/2011
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
Reply #12 on: January 11, 2015, 07:36:41 pm
So first of all, is there any way for someone to find out, if he is being used?

If your PC is being used for an attack you will have a noticeable increase in system resource usage, specifically bandwidth. Typically the software used for zombies is a virus or worm-based. Run virus scans frequently

And also, is there any way for us, from the server side, durring the attack to somehow record the "attackers" (or atleast as many as we get the time to) and then notify them, that their computers are being used like that, and guide them on how to remove their "virus"?

All requests made against a server are logged in some high level log. The problem is distinguishing legitimate attackers (those willing) and illegitimate attacks (those compromised). Since all you get is an IP, the only thing you can contact is their ISP, since from an IP you can't get the user's email address or physical address.



Offline Stivi

  • Hero
  • ****
    • Posts: 4431
  • With us since: 29/03/2012
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
  • Discord: Stiven#6102
Reply #13 on: January 11, 2015, 07:40:02 pm
since from an IP you can't get the user's email address or physical address.
Can't you match the IP with a user's IP ?

Mr Cofiliano how can you deny that we had any relation or intercourse, while you are prosecuting me?


Offline Ben.

  • Veteran
  • ***
    • Posts: 2958
  • Benjamin J. Blake
  • With us since: 21/07/2009
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
  • SA:MP: =AV=Ben_Blake
Reply #14 on: January 11, 2015, 08:13:48 pm
Can't you match the IP with a user's IP ?
I imagine law enforcement would need to be involved for that.


Salt and hate won't take us anywhere.
And we do not try to be real life, as why would you ever play real life if you have one ? We play the GTA universe, and our players should try to live in the GTA world, not the real one.


 


SimplePortal 2.3.7 © 2008-2025, SimplePortal