Re: [hlds_linux] Prevent UDP attacks

2012-10-03 Thread Invalid Protocol
inux-boun...@list.valvesoftware.com [mailto:hlds_linux-boun...@list.valvesoftware.com] On Behalf Of Mico Sent: Wednesday, October 03, 2012 0:17 AM To: Half-Life dedicated Linux server mailing list Subject: [hlds_linux] Prevent UDP attacks In the message log of the operating system (Ubuntu 12.04) I'm

Re: [hlds_linux] Prevent UDP attacks

2012-10-02 Thread Herover
Also, if you know the source address, you can filter them using wireshark to see what they send to you Den 03/10/2012 01.50 skrev "lee bailey" : > Just use iptables to block the packet itself. > You can use a sniffer like tcpdump to find the string of the udp packet. > I used a similar method to b

Re: [hlds_linux] Prevent UDP attacks

2012-10-02 Thread lee bailey
Just use iptables to block the packet itself. You can use a sniffer like tcpdump to find the string of the udp packet. I used a similar method to block these HLBrute thingies and it worked, this time though you need a hex string and a slightly different command is used to block it as it is a hex st

Re: [hlds_linux] Prevent UDP attacks

2012-10-02 Thread Ross Bemrose
SourceMod doesn't run on HLDS games, so SMAC isn't going to either. On 10/2/2012 7:22 PM, Cameron Munroe wrote: The problem is if it is from multiple IPs it becomes harder. If you aren't using sourcemod it is a mute point on SMAC. Though im unsure if its supported as I run mainly tf2. block

Re: [hlds_linux] Prevent UDP attacks

2012-10-02 Thread Cameron Munroe
The problem is if it is from multiple IPs it becomes harder. If you aren't using sourcemod it is a mute point on SMAC. Though im unsure if its supported as I run mainly tf2. block each one? On 10/2/2012 4:16 PM, Mico wrote: Are Servers Counter-Strike 1.6 (HL-BETA) SourceMod supports HLDS?

Re: [hlds_linux] Prevent UDP attacks

2012-10-02 Thread Mico
Are Servers Counter-Strike 1.6 (HL-BETA) SourceMod supports HLDS? I was looking for a solution using iptables. So consult here, as there are skilled people. On Mar 02 Oct 2012 19:24:35 Cameron Munroe escribió: > Did you do a lookup on one or two of the addresses and do you have SMAC > installed?

Re: [hlds_linux] Prevent UDP attacks

2012-10-02 Thread Cameron Munroe
Did you do a lookup on one or two of the addresses and do you have SMAC installed? On 10/2/2012 3:23 PM, Mico wrote: Nop, are different IP range. Many addresses to do a manual lock. On Mar 02 Oct 2012 19:19:17 Cameron Munroe escribió: Is it the same address? On 10/2/2012 3:17 PM, Mico wrote

Re: [hlds_linux] Prevent UDP attacks

2012-10-02 Thread Mico
Nop, are different IP range. Many addresses to do a manual lock. On Mar 02 Oct 2012 19:19:17 Cameron Munroe escribió: > Is it the same address? > > On 10/2/2012 3:17 PM, Mico wrote: > > In the message log of the operating system (Ubuntu 12.04) I'm seeing a > > lot of logs like the following: > >

Re: [hlds_linux] Prevent UDP attacks

2012-10-02 Thread Cameron Munroe
Is it the same address? On 10/2/2012 3:17 PM, Mico wrote: In the message log of the operating system (Ubuntu 12.04) I'm seeing a lot of logs like the following: [848814.998297] UDP: short packet: From 190.xxx.xxx.xxx:308 /33 to 200.xxx.xxx.xxx:27025 [874435.912157] UDP: short packet: From 190.

[hlds_linux] Prevent UDP attacks

2012-10-02 Thread Mico
In the message log of the operating system (Ubuntu 12.04) I'm seeing a lot of logs like the following: [848814.998297] UDP: short packet: From 190.xxx.xxx.xxx:308 /33 to 200.xxx.xxx.xxx:27025 [874435.912157] UDP: short packet: From 190.xxx.xxx.xxx:4805 49320/37 to 200.xxx.xxx.xxx:27024 [88201