Jump to content

Recommended Posts

Posted

Right now, there's a server that keeps duplicating itself with the same IP.

All of them are Lakeside with the ip 95.91.202.231

All of the them also have the same tongue and cheek name "Fun Server with Bots" but something else that trails off about DDOSs

Posted

WELLLLL now that explains why my GSP's DDoS protection keeps kicking in for different strange reasons. These are what I have been receiving lately. I was wondering why this IP on my box kept getting attacked. Good thing they were not able to affect our server. ;-)

(D)DoS attack against your service 
Nov 28 2015 12:10:49 PM PT	Our system responded to a (D)DoS against your service with a filter.

Target address: 104.153.104.205
Attack: a specific type of UDP flood/18
Filter duration: about 2 days

What does this mean? 
(D)DoS attack against your service 
Nov 28 2015 09:00:21 AM PT	Our system responded to a (D)DoS against your service with a filter.

Target address: 104.153.104.205
Attack: a flood of UDP traffic from port 111
Filter duration: about 7 days

What does this mean? 
(D)DoS attack against your service 
Nov 28 2015 08:56:52 AM PT	Our system responded to a (D)DoS against your service with a filter.

Target address: 104.153.104.205
Attack: a flood of TCP traffic from specific ports to specific ports
Filter duration: about 60 minutes

What does this mean? 
(D)DoS attack against your service 
Nov 28 2015 08:45:25 AM PT	Our system responded to a (D)DoS against your service with a filter.

Target address: 104.153.104.205
Attack: a UDP-based DRDoS through TeamSpeak servers
Filter duration: about 30 minutes

What does this mean? 
(D)DoS attack against your service 
Nov 27 2015 02:33:48 PM PT	Our system responded to a (D)DoS against your service with a filter.

Target address: 104.153.104.205
Attack: a UDP flood containing the string "statusResponse"
Filter duration: about 7 days

What does this mean? 
(D)DoS attack against your service 
Nov 27 2015 02:20:19 PM PT	Our system responded to a (D)DoS against your service with a filter.

Target address: 104.153.104.205
Attack: a UDP-based DRDoS through TeamSpeak servers
Filter duration: about 30 minutes

What does this mean? 
(D)DoS attack against your service 
Nov 27 2015 02:14:23 PM PT	Our system responded to a (D)DoS against your service with a filter.

Target address: 104.153.104.205
Attack: a flood of TCP traffic from specific ports to specific ports
Filter duration: about 60 minutes

What does this mean? 
(D)DoS attack against your service 
Nov 27 2015 02:14:23 PM PT	Our system responded to a (D)DoS against your service with a filter.

Target address: 104.153.104.205
Attack: a flood of syn-ack TCP traffic from port 80/2
Filter duration: about 8 days

What does this mean? 
(D)DoS attack against your service 
Nov 27 2015 11:04:20 AM PT	Our system responded to a (D)DoS against your service with a filter.

Target address: 104.153.104.205
Attack: a UDP flood of length-28 packets
Filter duration: about 24 hours

What does this mean? 
(D)DoS attack against your service 
Nov 27 2015 10:51:18 AM PT	Our system responded to a (D)DoS against your service with a filter.

Target address: 104.153.104.205
Attack: a specific type of UDP flood related to Source engine queries
Filter duration: about 24 hours

What does this mean? 
(D)DoS attack against your service 
Nov 25 2015 10:23:47 PM PT	Our system responded to a (D)DoS against your service with a filter.

Target address: 104.153.104.205
Attack: a UDP flood of length-29 packets
Filter duration: about 24 hours

Edit: Just sent in a support ticket to my GSP to see if there is anything we can do to catch this person.

Posted

"Catching" them is very unlikely. They are using rented booters to attack. There are multiple providers for these services. At best, you would "catch" whoever is selling the services.

If you really want to discuss prevention methods/info with someone, you should contact DoctorB0NG.

Posted

Most likely some script kiddie paid for a Botnet with this mom's credit card. As a side note, i have added Auto scaling on my server, now Server stays up after a DDoS attack, but people do get dropped from the server when the attack is happening the ping stays at around 900 for a minute or two.

Edit:

This is new, got hit with close to a 3GiB attack for about 5min

3Gibatt.jpg

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...