Servers down?

Status
Thread Closed: Not open for further replies.
:) If it was my game, and that guy did that, I'd brick his router, and all the other ones he had to go on to buy. Fortunately, I'm not FD ;)

As nice as that would be, it doesn't do to stoop to their level. Two illegal actions don't make a legal one. ;P

That being said, the perpetrator was obviously stupid enough to use a self-identifiable source for his attack, so I daresay if they keep it up, they'll have officials knocking on their door soon enough. They put substantial load on immediate networking infrastructure, too, which could have a trickle-down effect on other services.
 
Last edited:
Thanks for your patience everyone, we understand that a number of you experienced intermittent service over the weekend. The outages were caused by an automated attack on our game server which affected a small number of our servers, but the online team worked over the weekend to ensure that our servers remained online. We have also managed to track down the source and the player responsible who has now been banned from the game.

Service should now be restored to normal - thanks to everyone who reported problems to us during this period.

Good job :) Kinda interesting how one person can cause so much bother. hmm
 
Please FD, stop this. Your network ppl should know that a IP is nowadays no indicator for a "crime", you can hijack every ip. if you cant give us real info about what happend this weekend just tell us nothing. poor player. No offense Edward Lewis since you give us the info FD is giving to you.
 
Last edited:
It might not been the intention of the attacker / player to take down the servers. Maybe it was just an "accident" while he was messing around with one of the hacking tools. This would explain why he used his account for the "attack". A normal DOS attack doesn't need any login information.

Amendmend: As we all know, cheating is possible in this game, because the server doesn't validate the data sent from the client. Therefore, it also seems likely that the sanity checks of the server aren't very good.
 
Last edited:
Well, well, well....i wonder if the guys over at "Shroud of the Avatar" would like a word with that fellow, they suffered from the same thing this weekend.
 
Please FD, stop this. Your network ppl should know that a IP is nowadays no indicator for a "crime", you can hijack every ip. if you cant give us real info about what happend this weekend just tell us nothing. poor player. No offense Edward Lewis since you give us the info FD is giving to you.

nice, but ......
 
Please FD, stop this. Your network ppl should know that a IP is nowadays no indicator for a "crime", you can hijack every ip. if you cant give us real info about what happend this weekend just tell us nothing. poor player. No offense Edward Lewis since you give us the info FD is giving to you.

If he was hacked and he can prove it to FD, then he will be restated after serious lecture about PC security. However that kind of chance is astronomically (pun intended) small.

Respect to FD admin team. I guess attacks are kinda regular thing now (there was another one two months ago I think). Well, space also certainly doesn't lack idiots.
 
Last edited:
Thanks for your patience everyone, we understand that a number of you experienced intermittent service over the weekend. The outages were caused by an automated attack on our game server which affected a small number of our servers, but the online team worked over the weekend to ensure that our servers remained online. We have also managed to track down the source and the player responsible who has now been banned from the game.

Service should now be restored to normal - thanks to everyone who reported problems to us during this period.

A player did this? Good riddance. >:-(
 
TIL* : It only takes one player with a "hack attack" to take down all the ED servers.

*Today I Learned

Since Amazon do their hosting, what you actually learned is it takes one player with the right tools to take down Amazon servers.

Its probably at least in part thanks to that hosting and Amazon's support they were able to identify who was responsible for the attacks and take action.

- - - Updated - - -

Please FD, stop this. Your network ppl should know that a IP is nowadays no indicator for a "crime", you can hijack every ip. if you cant give us real info about what happend this weekend just tell us nothing. poor player. No offense Edward Lewis since you give us the info FD is giving to you.

I don't recall Ed saying the only evidence was an IP address.
 
Since Amazon do their hosting, what you actually learned is it takes one player with the right tools to take down Amazon servers.

Its probably at least in part thanks to that hosting and Amazon's support they were able to identify who was responsible for the attacks and take action.

...
I did a search for aws outages, but there hasn't been anything noteworty, at least for the last 24h. I don't think that he managed to take down the aws servers itself, only the payload, the ed server application.
 
That's generally the only evidence you'll get unless the idiot was bragging about it online to his mates.
Or, unless he was using a hacked player account and doing this thing authenticated... There are way too many ways to hide your IP, must be authenticated attack. Or, somebody grabbed an IP from one of the players, hacked their network and did it from there :) Finally, could be just dumb but you have to have some basic intelligence to pull this off.
 
Last edited:
Or, unless he was using a hacked player account and doing this thing authenticated... There are way too many ways to hide your IP, must be authenticated attack.

Mate, DDoS attacks only get so complicated in nature. Nobody said it involved the game client at all, just a matching IP for a player showing up in the logs.
 
Mate, DDoS attacks only get so complicated in nature. Nobody said it involved the game client at all, just a matching IP for a player showing up in the logs.
So, somebody didn't even bother to reboot his router to save $59,99? Seems unlikely. You have to have some basic networking intelligence to do this, there is no LOIC ED edition :)
 
Last edited:
I hate dealing with DDoS attacks, there's no real prevention only reactive mitigation. Even if your dumping all RTP and UDP traffic upstream they just flood TCP SYN packets.

The traffic needs to blocked upstream of the target service, because if it's still reaching your border gateway it's still congesting your links and your dropping legitimate packets.

That means getting hosting back providers involved, if can take a long time to identify block/null route all zombie hosts a get it calmed down.

We gets meatheads our services, and our customer connection on a regular basis. We use wanguard to alert and protect our customers, but there not a lot you can do when your the target except get on the phone with the service providers.

Sounds like a rough weekend for Frontiers infrastructure team, I hope Ed buys them a Beer and a Curry.
 
Status
Thread Closed: Not open for further replies.
Back
Top Bottom