User
Pass
2FA
 
 

HLDS flood large lag/ping and crash
Go to page 1, 2  Next    
 
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.    Freakz Forum Index -> Trash Bin -> CS 2006-2019 (Archived) -> Fixed issues
Author Message5461
AmaRelle

[Mentally Stable]



Status: Offline
(since 24-08-2009 15:05)
Joined: 05 May 2009
Posts: 11, Topics: 1
Location: Bulgaria,Assenovgrad

Reputation: 88.5
Votes: 4

Post Posted: 03-08-2009, 00:56:08 | Translate post to: ... (Click for more languages)

Hi all,
I have a problem. Flood and send packets my IP address and the server has a large lag / ping. Please help.
Thank you!

0 0
  
Back to top
View user's profile Send private message
Shocker

[Freakz owner]



Status: Offline
(since 08-02-2020 12:17)
Joined: Momentul zero
Posts: 33986, Topics: 1350
Location: localhost

Reputation: 6485.6
Votes: 829

   
Post Posted: 03-08-2009, 00:59:26 | Translate post to: ... (Click for more languages)

How can you tell it's flood? Some firewall tells you that?

FREAKZ COMMUNITY @ Facebook
WOW FREAKZ @ Facebook
0 0
  
Back to top
View user's profile Send private message
AmaRelle

[Mentally Stable]



Status: Offline
(since 24-08-2009 15:05)
Joined: 05 May 2009
Posts: 11, Topics: 1
Location: Bulgaria,Assenovgrad

Reputation: 88.5
Votes: 4

Post Posted: 03-08-2009, 01:05:31 | Translate post to: ... (Click for more languages)

Attacked and stop my internet,and in my server large ping

Windows Firewall log:

Code:
2009-07-31 23:52:37 DROP UDP 91.148.150.111 90.154.249.118 1185 24033 29 - - - - - - - RECEIVE
2009-07-31 23:52:37 DROP UDP 91.148.150.111 90.154.249.118 1185 55530 29 - - - - - - - RECEIVE
2009-07-31 23:52:37 DROP UDP 91.148.150.111 90.154.249.118 1185 60317 29 - - - - - - - RECEIVE
2009-07-31 23:52:37 DROP UDP 91.148.150.111 90.154.249.118 1185 38743 29 - - - - - - - RECEIVE
2009-07-31 23:52:37 DROP UDP 91.148.150.111 90.154.249.118 1185 46937 29 - - - - - - - RECEIVE
2009-07-31 23:52:37 DROP UDP 91.148.150.111 90.154.249.118 1185 64853 29 - - - - - - - RECEIVE
2009-07-31 23:52:37 DROP UDP 91.148.150.111 90.154.249.118 1185 23659 29 - - - - - - - RECEIVE
2009-07-31 23:52:37 DROP UDP 91.148.150.111 90.154.249.118 1185 15404 29 - - - - - - - RECEIVE
2009-07-31 23:52:37 DROP UDP 91.148.150.111 90.154.249.118 1185 54489 29 - - - - - - - RECEIVE
2009-07-31 23:52:37 DROP UDP 91.148.150.111 90.154.249.118 1185 46483 29 - - - - - - - RECEIVE
2009-07-31 23:52:37 DROP UDP 91.148.150.111 90.154.249.118 1185 39403 29 - - - - - - - RECEIVE
2009-07-31 23:52:37 DROP UDP 91.148.150.111 90.154.249.118 1185 17287 29 - - - - - - - RECEIVE
2009-07-31 23:52:37 DROP UDP 91.148.150.111 90.154.249.118 1185 64677 29 - - - - - - - RECEIVE
2009-07-31 23:52:37 DROP UDP 91.148.150.111 90.154.249.118 1185 19948 29 - - - - - - - RECEIVE
2009-07-31 23:52:37 DROP UDP 91.148.150.111 90.154.249.118 1185 62382 29 - - - - - - - RECEIVE
2009-07-31 23:52:37 DROP UDP 91.148.150.111 90.154.249.118 1185 17061 29 - - - - - - - RECEIVE
2009-07-31 23:52:37 DROP UDP 91.148.150.111 90.154.249.118 1185 30302 29 - - - - - - - RECEIVE
2009-07-31 23:52:37 DROP UDP 91.148.150.111 90.154.249.118 1185 7185 29 - - - - - - - RECEIVE
.....

0 0
  
Back to top
View user's profile Send private message
Shocker

[Freakz owner]



Status: Offline
(since 08-02-2020 12:17)
Joined: Momentul zero
Posts: 33986, Topics: 1350
Location: localhost

Reputation: 6485.6
Votes: 829

   
Post Posted: 03-08-2009, 01:16:48 | Translate post to: ... (Click for more languages)

Can you tell me what all those columns mean? Show me the logs header or something

FREAKZ COMMUNITY @ Facebook
WOW FREAKZ @ Facebook
0 0
  
Back to top
View user's profile Send private message
AmaRelle

[Mentally Stable]



Status: Offline
(since 24-08-2009 15:05)
Joined: 05 May 2009
Posts: 11, Topics: 1
Location: Bulgaria,Assenovgrad

Reputation: 88.5
Votes: 4

Post Posted: 03-08-2009, 01:26:04 | Translate post to: ... (Click for more languages)

This?

Code:
#Version: 1.5
#Software: Microsoft Windows Firewall
#Time Format: Local
#Fields: date time action protocol src-ip dst-ip src-port dst-port size tcpflags tcpsyn tcpack tcpwin icmptype icmpcode info path

2009-07-31 23:52:37 DROP UDP 91.148.150.111 90.154.249.118 1185 24033 29 - - - - - - - RECEIVE


0 0
  
Back to top
View user's profile Send private message
Shocker

[Freakz owner]



Status: Offline
(since 08-02-2020 12:17)
Joined: Momentul zero
Posts: 33986, Topics: 1350
Location: localhost

Reputation: 6485.6
Votes: 829

   
Post Posted: 03-08-2009, 01:44:56 | Translate post to: ... (Click for more languages)

So which one is your server? The second IP 90.154.249.118 ? As far as I can see, they're both CS servers, the first one (the attacker?) is a redirect server.

The packet size (29 bytes) is rather small for a flood attack, I don't know what is that, have you tried banning that IP from the firewall?


FREAKZ COMMUNITY @ Facebook
WOW FREAKZ @ Facebook
0 0
  
Back to top
View user's profile Send private message
AmaRelle

[Mentally Stable]



Status: Offline
(since 24-08-2009 15:05)
Joined: 05 May 2009
Posts: 11, Topics: 1
Location: Bulgaria,Assenovgrad

Reputation: 88.5
Votes: 4

Post Posted: 03-08-2009, 02:23:32 | Translate post to: ... (Click for more languages)

My server is 87.120.245.65:27015.
These logs give me a friend, but I think the same man we flood. Tell me something to put the Firewall or otherwise.
Or something to flood after the attacks and to block

0 0
  
Back to top
View user's profile Send private message
Shocker

[Freakz owner]



Status: Offline
(since 08-02-2020 12:17)
Joined: Momentul zero
Posts: 33986, Topics: 1350
Location: localhost

Reputation: 6485.6
Votes: 829

   
Post Posted: 03-08-2009, 09:53:10 | Translate post to: ... (Click for more languages)

As far as I can see, the IP you should ban is 91.148.150.111. Look an option in the firewall, something like BAN or BLOCK IP.

FREAKZ COMMUNITY @ Facebook
WOW FREAKZ @ Facebook
0 0
  
Back to top
View user's profile Send private message
*0ranGe ! extrem

[I ❤ MY POLO!]



Status: Offline
(since 11-12-2017 12:06)
Joined: 01 Jul 2007
Posts: 11419, Topics: 191
Location: Romania

Reputation: 683.4
Votes: 117

   
Post Posted: 03-08-2009, 10:10:52 | Translate post to: ... (Click for more languages)

Use Seagate firewall to ban/block that ip, it's a good firewall.


0 0
  
Back to top
View user's profile Send private message
AmaRelle

[Mentally Stable]



Status: Offline
(since 24-08-2009 15:05)
Joined: 05 May 2009
Posts: 11, Topics: 1
Location: Bulgaria,Assenovgrad

Reputation: 88.5
Votes: 4

Post Posted: 03-08-2009, 10:28:47 | Translate post to: ... (Click for more languages)

Shocker wrote:
As far as I can see, the IP you should ban is 91.148.150.111. Look an option in the firewall, something like BAN or BLOCK IP.


Windows Firewall does not have such an option to block IP -


*0ranGe ! extrem wrote:
Use Seagate firewall to ban/block that ip, it's a good firewall.


Firewall will try this and tell the result .
S[ea]gate firewall -> S[y]gate firewall ?

0 0
  
Back to top
View user's profile Send private message
*0ranGe ! extrem

[I ❤ MY POLO!]



Status: Offline
(since 11-12-2017 12:06)
Joined: 01 Jul 2007
Posts: 11419, Topics: 191
Location: Romania

Reputation: 683.4
Votes: 117

   
Post Posted: 03-08-2009, 14:08:19 | Translate post to: ... (Click for more languages)

Yeah, sorry, sygate i meant.


0 0
  
Back to top
View user's profile Send private message
AmaRelle

[Mentally Stable]



Status: Offline
(since 24-08-2009 15:05)
Joined: 05 May 2009
Posts: 11, Topics: 1
Location: Bulgaria,Assenovgrad

Reputation: 88.5
Votes: 4

Post Posted: 05-08-2009, 11:53:04 | Translate post to: ... (Click for more languages)

Hello,
Firewall helps, but loaded computer.
See CPU Usage:



Is there a way to fix this?
Thank you!

0 0
  
Back to top
View user's profile Send private message
Shocker

[Freakz owner]



Status: Offline
(since 08-02-2020 12:17)
Joined: Momentul zero
Posts: 33986, Topics: 1350
Location: localhost

Reputation: 6485.6
Votes: 829

   
Post Posted: 07-08-2009, 12:21:35 | Translate post to: ... (Click for more languages)

When does it overload your CPU? When you are attacked or all the time?

FREAKZ COMMUNITY @ Facebook
WOW FREAKZ @ Facebook
0 0
  
Back to top
View user's profile Send private message
AmaRelle

[Mentally Stable]



Status: Offline
(since 24-08-2009 15:05)
Joined: 05 May 2009
Posts: 11, Topics: 1
Location: Bulgaria,Assenovgrad

Reputation: 88.5
Votes: 4

Post Posted: 11-08-2009, 00:20:21 | Translate post to: ... (Click for more languages)

Shocker wrote:
When does it overload your CPU? When you are attacked or all the time?


all the time

0 0
  
Back to top
View user's profile Send private message
*0ranGe ! extrem

[I ❤ MY POLO!]



Status: Offline
(since 11-12-2017 12:06)
Joined: 01 Jul 2007
Posts: 11419, Topics: 191
Location: Romania

Reputation: 683.4
Votes: 117

   
Post Posted: 11-08-2009, 09:24:11 | Translate post to: ... (Click for more languages)

I don't recognise that Smc.exe process, do you know what it is ? I know that i had a problem like that with a MuOnline server and it was because of the gameserver that was hardly trying to write logs that i didn't needed so i modified that and after that the CPU was at a maximum of ~10-11%.


0 0
  
Back to top
View user's profile Send private message
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.    Freakz Forum Index -> Trash Bin -> CS 2006-2019 (Archived) -> Fixed issues  
Go to page 1, 2  Next    


The time now is 13-12-2024, 19:31:36
Copyright info

Based on phpBB ro/com
B

 
 
 







I forgot my password


This message appears only once, so
like us now until it's too late ! :D
x