Guild icon
|*KoG*| King of Gores
━━━━━ Chat ━━━━━ / general_chatroom
General discussions or talks about KoG servers and KoG community can be made here. English only.
Between 2021-06-07 00:00:00Z and 2021-06-08 00:00:00Z
Avatar
If someone want to ddos it for testing purposes, go ahead, you have permission to do so (if you do not find the server in the list, use the IP address 45.141.57.5:27000 ) (There are all the KoG maps inside) (edited)
issou 4
f3 3
Avatar
GG @Davide, you just advanced to level 3 !
Avatar
@Moderator Hi guys! I need a moderator to register my account
Avatar
.wHat?**/Alex 2021-06-07 06:42:40Z
@cAт in #info you can See where u can register your acc
Avatar
Sorry, should I contact them directly?
Avatar
Nope, you just have to wait a bit
Avatar
Ok, thank you!
Avatar
@Davide why do u want people to attack ur srv lol
Avatar
Avatar
Deleted User
@Davide why do u want people to attack ur srv lol
Testing new filters 🙂
Avatar
gl, teeworlds is so shitty
06:46
at least 0.6
Avatar
Avatar
Deleted User
gl, teeworlds is so shitty
GL?
Avatar
good luck
Avatar
Avatar
Deleted User
good luck
I think that I already patched all the possible attacks
Avatar
oof
06:48
gl
06:48
:p
Avatar
Avatar
Deleted User
oof
I didn't do it alone, I also had the Voxility team helping me
Avatar
voxility sux
06:49
their filter is too hard
06:49
ask them to stop filtering shit
06:49
It is aggressive, but that's what Teeworlds need to don't be downed. (edited)
06:50
😂
Avatar
@Davide well it would surely drop legitimate traffic due to that lol
06:53
that's also why none is hosting at voxility, after tryin
06:53
but good host if they stop that shit
Avatar
It's under attack right now for example
Avatar
lel who's attacking
Avatar
About 5-6 peoples joined to ddos
Avatar
dafq xD
Avatar
In these hours
06:54
Up you can see the logs
Avatar
yeh but your logs won't show anything special
06:54
for teeworlds the content is more importnat
06:55
But I'm in
06:55
And no lags
06:57
Check the Talk1 room
06:57
Look at the screensharing if you want
Avatar
@Davide do u even block attacks without disabling specific functionalities, like joining the game or being able to see the server
06:58
overwise that's cheating, and everyone already knows how to do that
Avatar
You can still join
Avatar
eg, can't see your srv
06:59
that's an issue (edited)
Avatar
It's normal
06:59
But not an issue for KoG
Avatar
it's bad
06:59
KoG have a static list
06:59
As I can remember
Avatar
well imagine someone not having their srv in favorites
06:59
I have to think about that
Avatar
well :p, our server already has everything against vali, only ovh sux
Avatar
Btw that's only during the attack
Avatar
Avatar
Deleted User
well :p, our server already has everything against vali, only ovh sux
All the servers fall, I tried all the servers, and if you play for some days you will see that sometimes it fall due ddos
07:00
Just play and you see it lol
Avatar
Our server falls cuz OVH is blocking legitimate traffic
07:01
ask them to stop their shit and our srv will never fall
Avatar
Idk why but it is a shit
Avatar
yea, it sux, but afterall everything owuld work perfectly even under attack
Avatar
Actully on mine you just don't see it in the list if it is under attack
Avatar
what about TKEN requests
Avatar
can't attack lol
Avatar
I made this test server do test the vulnerabilities
Avatar
just askin xd
Avatar
And fix it
07:02
Btw
07:02
Mitigation stopped
Avatar
I mean, if u block people entering the srv, that's bad too
Avatar
I don't block
07:02
lol
Avatar
Then how do u do for TKEN :p
Avatar
I didn't tried yet
Avatar
ha
Avatar
If you can, try
Avatar
Well if I could I would have tried, but can't
Avatar
If there is a issue, I can fix it or if I can't, I can ask to voxility to check lol
Avatar
Avatar
Deleted User
Well if I could I would have tried, but can't
Okay
07:05
Btw, do you play Gores, or?
Avatar
Avatar
Deleted User
Well if I could I would have tried, but can't
(Ask to someone that can try, so)
Avatar
go ask vali
07:07
this idiot
Avatar
Who's vali? lol
Avatar
GG @Davide, you just advanced to level 4 !
Avatar
Avatar
Davide
KoG have a static list
No, we dont have a "static list"
Avatar
the one who does all the attacks against most of servers recently
Avatar
Avatar
Avolicious
No, we dont have a "static list"
Why I still see some "dead" servers?
07:08
Look at the screen sharing @Avolicious
Avatar
if you use latest ddnet version there's a cache I think
Avatar
Because they're not online
Avatar
they seem to test https masters
Avatar
DDNet 15.5 adds HTTP(s) master, yes
Avatar
Avatar
Avolicious
Because they're not online
But still in list, right?
Avatar
You can download the list on your own 🙂
Avatar
That's not a static list? lol
07:09
If the server is offline, but you still see it
Avatar
They're added to ddnet's tab
Avatar
Avatar
Deleted User
the one who does all the attacks against most of servers recently
And it is in this discord? lol
Avatar
no I think he would have been banned just after joining it lmao
Avatar
GG @Deleted User, you just advanced to level 7 !
Avatar
Avatar
Deleted User
no I think he would have been banned just after joining it lmao
Oh ok
Avatar
this retard
Avatar
Avatar
Deleted User
no I think he would have been banned just after joining it lmao
As I said, if some dead servers still in the list, it is not full dynamic
Avatar
only some caching shit
Avatar
Avatar
Deleted User
this retard
xD
Avatar
but if you take the fact that https masters are only in testing state rn
Avatar
Avatar
Deleted User
only some caching shit
I see that there is 4-5 dead servers in the list since about weeks
Avatar
old https masters doesn't rly have static list
Avatar
That's not cache o.o
Avatar
Checkout the link I've posted
Avatar
the list is being sent to you by masters
Avatar
"servers-kog": [
Avatar
Avatar
Avolicious
Checkout the link I've posted
Already done
Avatar
Avatar
Deleted User
the list is being sent to you by masters
Yes i know
Avatar
This is just the verification
07:11
To get the checkmark on ddnet clients
07:12
Btw, if you want ask him in private @Deleted User
07:12
And we can see him fails xD
07:13
(or if he can fall it, then I can patch it, lol )
Avatar
I won't talk to him lol, go ask him by yourself
07:13
won't talk to a noob
Avatar
I don't know him LOL
07:13
xDD
07:13
Btw I already tried all the types of attacks
07:13
And nothing happens
07:14
Ok I listen you now @Avolicious
07:14
Another attack
07:15
about
07:15
There is a TS inside and a webserver, not only TW
07:15
?
07:16
I reiceved more than 1.2 Tbps about a week ago
07:16
I have a company, it's not a " vps that I purchased from someone "
07:16
Repeat
07:16
Yes Voxility mainly
07:18
lol
07:18
probably ddnet-server don't have so good the packets (edited)
07:18
😄
07:18
the abnormal packets
07:18
what?xD
07:19
I don't understand you ;'(
Avatar
fstd -> 64p based inforeq gie3 -> vanilla inforeq TKEN -> joining server
07:19
I seen it yes
07:20
LOL
07:21
yes?
Avatar
Avatar
Davide
yes
iptables -A INPUT -p udp -m u32 --u32 "38=0x67696533" -j serverinfo iptables -A INPUT -p udp -m u32 --u32 "38=0x66737464" -j serverinfo
Avatar
Why there are a /24 blocked at the "ddnet-setup.sh" WTF HAHAHA
Avatar
Did someone try to ask vali if he would stop ? kek
upp 1
oele 2
Avatar
I don't do this shit, because it can flood the conntrack
Avatar
Avatar
Davide
I reiceved more than 1.2 Tbps about a week ago
how lol
Avatar
Avatar
bony
how lol
UDP RAW
Avatar
Maybe we can make him happy. Send weed and cake
f3 1
f4 1
cheater 1
Avatar
from what source(s)
Avatar
Avatar
Avolicious
iptables -A INPUT -p udp -m u32 --u32 "38=0x67696533" -j serverinfo iptables -A INPUT -p udp -m u32 --u32 "38=0x66737464" -j serverinfo
Don't do this thing on the servers, this enable conntrack and with a small TCP with high pps someone can fuck up your server
07:23
lol
07:23
Saturating the conntrack 😄
Avatar
conntrack is enabled by default lol
Avatar
Yes but not used
07:24
If you use it, it is easy to saturate it and then the server goes down (edited)
Avatar
it is, that's why you can flag your packets and ask conntrack to not track them
07:24
with -j NOTRACK
Avatar
By default conntrack do not track it.
07:24
😛
07:24
If you put that rules ' iptables -A INPUT -p udp -m u32 --u32 "38=0x67696533" -j serverinfo iptables -A INPUT -p udp -m u32 --u32 "38=0x66737464" -j serverinfo iptables -A serverinfo -m hashlimit --hashlimit-above 1000/s --hashlimit-burst 2500 --hashlimit-mode dstport --hashlimit-name si_dstport -j DROP iptables -A serverinfo -m hashlimit --hashlimit-above 20/s --hashlimit-burst 100 --hashlimit-mode srcip --hashlimit-name si_srcip -j DROP ' (edited)
07:25
Conntrack will be saturated very easy
07:25
And then your server go down because of conntrack
07:25
That's why isn't a nice idea
Avatar
iptables -t raw -A PREROUTING -p udp -j NOTRACK iptables -t raw -A OUTPUT -p udp -j NOTRACK iptables -N serverinfo iptables -A INPUT -p udp -m u32 --u32 "38=0x67696533" -j serverinfo iptables -A INPUT -p udp -m u32 --u32 "38=0x66737464" -j serverinfo iptables -A serverinfo -s 37.187.108.123 -j ACCEPT iptables -A serverinfo -m hashlimit --hashlimit-above 1000/s --hashlimit-burst 2500 --hashlimit-mode dstport --hashlimit-name si_dstport -j DROP iptables -A serverinfo -m hashlimit --hashlimit-above 20/s --hashlimit-burst 100 --hashlimit-mode srcip --hashlimit-name si_srcip -j DROP iptables -I INPUT -s 185.82.223.0/24 -j DROP iptables-save > /etc/iptables.up.rules
Avatar
never had problems with conntrack, just increase the table
Avatar
Better do it in a real firewall
07:25
Not just on iptables
Avatar
Avatar
Deleted User
never had problems with conntrack, just increase the table
If you do it, cpu is fucking loaded in that case
Avatar
netfilter is old and lel go ask ovh to put a free firewall for us lmao
Avatar
Avatar
Deleted User
netfilter is old and lel go ask ovh to put a free firewall for us lmao
I'm not OVH
Avatar
never had problems with my case :p
Avatar
So I can do it
07:26
xD
Avatar
what kind of infrastructure do u have that can even handle tbps
07:26
massive link or what
Avatar
We use cloudflare oele
Avatar
Avatar
bony
what kind of infrastructure do u have that can even handle tbps
Avatar
But unfortunately not for gameserver 😦
Avatar
Avatar
Avolicious
But unfortunately not for gameserver 😦
You can use it too, but you need Magic Transit 🙂
07:27
(Spoiler: isn't free)
07:28
You can probably ask to Francisco#0068 if you need a Cloudflare protection (edited)
07:28
He sell servers with CF Magic Transit
07:28
But I don't think CF is really nice at UDP
07:28
lol
07:29
Dns is easy to protect
07:30
Better to put a server for testing purposes only
07:30
It's not for production, for now
07:30
production I said
07:30
he filter isn't ready
07:31
Not a problem
07:32
Yes I want
07:32
Hahahaha
07:32
Under attack, another time
07:32
Nah
07:32
It don't
Avatar
I didn't listen @Deleted User , but I see your mic activating
Avatar
GG @Davide, you just advanced to level 5 !
Avatar
@Davide my micsux
07:41
with a mix of nvidia broadcast
07:41
always does that
07:41
dunno why
07:45
@Avolicious btw, I'm doing that because I'm very tired that the kog servers go down while playing on it
07:45
lol
07:45
That's why I'm doing this for free
07:45
lol
07:46
I already asked to qshar
07:46
He said that "We use only official hosters" but I didn't know what it means
07:46
And he didn't replied (edited)
07:46
lol?
07:47
Get IP address location information: country, region/state, city: website monitoring with useful tools, Check IP, Check website
07:47
Please check 😛
07:47
We are open since more that 4 years
Avatar
@Avolicious RU still unavailable?
Avatar
Avatar
QzBoY
@Avolicious RU still unavailable?
y
Avatar
(We're talking in the Talk1 room, I'm not mad, I'm just replying in chat because I can't talk right now) That message is for all the guys that read the chat but is not in the talk room (edited)
07:49
xD
Avatar
Plot twist : Davide = Vali He is spying us out for more effective ddos attacks troll
Avatar
I restarted the server
Avatar
Avatar
Tee-Shirt
Plot twist : Davide = Vali He is spying us out for more effective ddos attacks troll
What lol
07:57
LOL
08:02
Btw this test is making sense now 😄
Avatar
Avatar
Tee-Shirt
Plot twist : Davide = Vali He is spying us out for more effective ddos attacks troll
That would made him the biggest troll over noby and konsti feelsscary
08:12
Most likely no meme before tonight boys it’s surfing day nou
Avatar
Avatar
ahl
That would made him the biggest troll over noby and konsti feelsscary
I'm Davide55 ingame 😛
Avatar
Yea I’m kidding I know you play with a whis skin no color
Avatar
Avatar
ahl
Yea I’m kidding I know you play with a whis skin no color
Mmm I have a custom skin, but yeah you see the whis skin
08:17
Join in the Talk1, I'm streaming the game, so you can see it if you want
Avatar
I’m currently at a COVID center and then I’ll go surf so not today
Avatar
LOL, okay
08:18
xD
Avatar
Avatar
ahl
I’m currently at a COVID center and then I’ll go surf so not today
I've been tested today too xd
Avatar
Avatar
Avolicious
I've been tested today too xd
Didn’t do it for a while I hope my noise will survive feelsscary
Avatar
Avatar
ahl
Didn’t do it for a while I hope my noise will survive feelsscary
08:23
Thats in austria ^^
Avatar
I’m not in Austria anymore, I’m currently in portugal and I’ll go back to France then
08:27
Good memory tho
Avatar
Bruh my noise died for real
Avatar
Avatar
ahl
Bruh my noise died for real
D; (edited)
Avatar
Avatar
Avolicious
iptables -t raw -A PREROUTING -p udp -j NOTRACK iptables -t raw -A OUTPUT -p udp -j NOTRACK iptables -N serverinfo iptables -A INPUT -p udp -m u32 --u32 "38=0x67696533" -j serverinfo iptables -A INPUT -p udp -m u32 --u32 "38=0x66737464" -j serverinfo iptables -A serverinfo -s 37.187.108.123 -j ACCEPT iptables -A serverinfo -m hashlimit --hashlimit-above 1000/s --hashlimit-burst 2500 --hashlimit-mode dstport --hashlimit-name si_dstport -j DROP iptables -A serverinfo -m hashlimit --hashlimit-above 20/s --hashlimit-burst 100 --hashlimit-mode srcip --hashlimit-name si_srcip -j DROP iptables -I INPUT -s 185.82.223.0/24 -j DROP iptables-save > /etc/iptables.up.rules
I checked better and now I understand this rule, it is to limit a possible amplified attack that uses the tw server list masters
08:54
lol
Avatar
No, its to limit request info from each server
08:59
Teeworlds Client -> Teeworlds Master & (https://info2.ddnet.tw/info, only if client is ddnet client) -> Client pings each server from recv. masterlist with SERVERBROWSE_GETINFO/SERVERBROWSE_GETINFO_64_LEGACY -> Server respond to client
08:59
& yes, SERVERBROWSE_GETINFO_64_LEGACY & SERVERBROWSE_GETINFO are amplifiers
09:08
Btw I don't care it, as I can see it is already blocked from my fw this type of attack
09:09
And also from Vox
Avatar
But how do players get info from server if its blocked?
Avatar
I'm working on it 😄
09:10
Btw, it is not a problem, if there is no attack incoming the server can answer to the get info rq (edited)
Avatar
Yeah 🙂
09:11
Bascially you can limit the reqs with an external firewall
Avatar
Yes I know
Avatar
Btw, just to ask, why the ddnet community/kog community have you ever thought of a sort of web "captcha"?
Avatar
???
Avatar
Like a whitelist that you can participate in by solving a captcha on the official site, without it you can't join on the servers
09:52
A whitelist can solve all the issues caused by the ddos
Avatar
You need fallback support for official teeworlds itself
09:52
No it cant
Avatar
Yes it can
Avatar
Because packages are UDP
09:52
What you means.
09:52
Lol
Avatar
You can simply fake the src address
09:52
UDP is connless
Avatar
Yes but it's fixable with ratelimit
09:52
lol
Avatar
External firewall 🙂
09:52
By external fw
Avatar
-> more money
Avatar
I already have that such rules
09:53
On my fw
Avatar
DDNet 15.5 will fix ip leakage, so it might be a bit better
Avatar
Avatar
Avolicious
You need fallback support for official teeworlds itself
Btw, no we can do it without the support of the official tw
Avatar
You have to support official teeworlds
09:55
If there is a solution without fallback, its not worth it
09:59
It support official tw
09:59
But only if you solve a captcha
09:59
For example on the qshar official site
09:59
(That's an example)
10:04
Btw there is very more way to do a nice whitelist, like whitelist the IP after the get info
Avatar
All IP addresses are currently being exposed to all tw servers
10:19
DDNet 15.5 fixes that issue in a nice & handy way imho
Avatar
Avatar
Avolicious
All IP addresses are currently being exposed to all tw servers
What you mean?
11:11
I don't understand xD
11:11
You mean that the server owner can see the players ips? It is normal (edited)
Avatar
qshar knows where we all livefeelspepoman
Avatar
Avatar
Davide
You mean that the server owner can see the players ips? It is normal (edited)
No, player ips are currently being exposed because of server pings
11:23
DDNet 15.5 is facing that issue by using an HTTP(s) master
11:23
So you dont have to ping each server individually
Avatar
OHHHHHHHH
11:23
Shit that's true.
Avatar
Avatar
Avolicious
DDNet 15.5 is facing that issue by using an HTTP(s) master
And the ping function?
11:24
Just .. gone?xD
11:24
I dont know if you checked the PR already, but there is a new function called sv_leak_ip
Avatar
I didn't
Avatar
Avatar
Avolicious
I dont know if you checked the PR already, but there is a new function called sv_leak_ip
yes but
Avatar
GG @Davide, you just advanced to level 6 !
Avatar
if you don't use the 15.5 ddnet server
11:25
you can still steal the ips
11:25
no?
Avatar
You cant
11:25
Because its disabled by default
11:25
AFAIK is that direct pings are only to trusted servers ( checkmarked )
11:30
bool IpLeak = ServerBrowser()->IsFavoritePingAllowed(pSelectedServer->m_NetAddr); if(DoButton_CheckBox(&s_LeakIpButton, Localize("Leak IP"), IpLeak, &ButtonLeakIp)) { ServerBrowser()->FavoriteAllowPing(pSelectedServer->m_NetAddr, !IpLeak); }
11:31
This will avoid ip leakage before accessing the server
11:31
atleast if you dont explicit say that you want a direct ping
Avatar
Avatar
Maze
.
Good point
🎷 8
🐛 9
nobytroll 2
😂 2
Exported 329 message(s)