Hi,
For the past couple of days my server is being attacked with the tsource engine query ddos.
I have a VPS rented with debian on it.
I have bought the module by Fire/Asmodai and applied the iptables rules, but the attacks are still successful.
tcpdump shows the following:
Код
129.138.114.195.19232 > x.x.x.x.27016: [udp sum ok] UDP, length 25
0x0000: d4be d9b6 efa2 0027 0dfd b540 0800 45e0 .......'...@..E.
0x0010: 0035 7003 0000 7011 75e5 818a 72c3 5d7b .5p...p.u...r.]{
0x0020: 1227 4b20 6989 0021 2859 ffff ffff 5453 .'K.i..!(Y....TS
0x0030: 6f75 7263 6520 456e 6769 6e65 2051 7565 ource.Engine.Que^C
0x0040: 7279 00 ry.
Код
89.40.233.58.27015 > x.x.x.x.27016: [udp sum ok] UDP, length 116
0x0000: d4be d9b6 efa2 0027 0dfd b540 0800 45e0 .......'...@..E.
0x0010: 0090 4fba 0000 f611 c1bd 5928 e93a 5d7b ..O.......Y(.:]{
0x0020: 1227 6987 6989 007c b4ae ffff ffff 4930 .'i.i..|......I0
0x0030: 4d69 7831 2e4c 614c 6561 6761 6e65 2e52 Mix1.LaLeagane.R
0x0040: 6f20 2320 5473 2e4c 616c 6561 6761 6e65 o.#.Ts.Laleagane
0x0050: 2e52 6f00 6465 5f64 7573 7432 0063 7374 .Ro.de_dust2.cst
0x0060: 7269 6b65 0043 6f75 6e74 6572 2d53 7472 rike.Counter-Str^C
0x0070: 696b 6500 0a00 000e 0064 6c00 0131 2e31 ike......dl..1.1
0x0080: 2e32 2e37 2f53 7464 696f 0091 8769 08fc .2.7/Stdio...i..
0x0090: 33fa 9d2e 4001 0a00 0000 0000 0000 3...@.........
iptables hits:
Код
36492 2120910 ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpts:27015:27016cs 1.6 packet
965376 40239110 DROP udp -- 0.0.0.0/0 0.0.0.0/0 udp dpts:27015:27016
Other iptables rules:
Код
145 7685 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0 udp dpt:27016 STRING match "TSource" ALGO name bm TO 65535 limit: avg 5/sec burst 25
34130 1808890 DROP udp -- * * 0.0.0.0/0 0.0.0.0 udp dpt:27016 STRING match "TSource" ALGO name bm TO 65535
Код
iptables -I INPUT -p udp -m u32 --u32 "26&0xFFFF=0xfeff" -j DROP
iptables -I INPUT -p udp -m u32 --u32 "24&0xffff=0x0000" -j DROP
When query limiter enabled in reunion:
Код
[REUNION]: Blocking query flood from a lot of spoofed addresses: 26836 pps
[REUNION]: Blocking query flood from a lot of spoofed addresses: 27087 pps
[REUNION]: Blocking query flood from a lot of spoofed addresses: 26961 pps
[REUNION]: Blocking query flood from a lot of spoofed addresses: 26728 pps
[REUNION]: Blocking query flood from a lot of spoofed addresses: 26989 pps
[REUNION]: Blocking query flood from a lot of spoofed addresses: 26784 pps
[REUNION]: Blocking query flood from a lot of spoofed addresses: 27073 pps
[REUNION]: Blocking query flood from a lot of spoofed addresses: 26954 pps
Server is shown as offline in favorites/HLSW/Gametracker.
Latest: rehlds, reunion, regamedll & amxx 1.10.