DoS Attack Forces EVE Online Offline
Resorting to the out-of-band messaging that is Facebook, CCP Games has announced that "At 02:05 GMT June 2nd, CCP became aware of a significant and sustained distributed denial-of-service attack (DDoS) against the Tranquility cluster (which houses EVE Online and DUST 514) and web servers."
I was just wondering why I couldn't log in! I criticize you guys a lot, gotta give you props this time.
I swear to God...I swear to God! That is NOT how you treat your human!
That is all.
Stories are late all the time because editors play EVE and can't be arsed to edit or publish!
I wonder how worldwide productivity would jump if WoW went offline.
They need to get this sorted ASAP. I have important Internet spaceship business to tend to and it really can't wait any longer.
Will rejoice
What kind of intricate in-game machinations will this turn out to be connected to?
Why would anyone launch a DoS attack on EVE online servers?!" :P
Nerds should not attack other nerds.
Why do the gaming servers respond to requests from non-players?
EVE Offline.
For those hopelessly addicted, there are two solutions:
1) practice on the singularity server (aka test server)
2) play the flash version.
In other news, CCP has announced that the new name of their MMO platform will be:
EVE Offline
Geek-girlfriends everywhere rejoice ...
- Jesper
My security clearance is so high I have to kill myself if I remember I have it...
Presumably they left a gaping whole in it.
It's standard practice to test critical code, make that all new code, in live deployments ... only after a failure do they appear to look at the test server bug reports.
It's not Facebook that they're updating from; It's Twitter. Their Facebook account is linked to Twitter.
Anyway, this isn't the first time the servers have been DDoS'd; This happens about every 4 months or so on average. And unfortunately, they've handled it about as well each time as you're seeing now: They tend not to announce the DDoS until hours after the news is all over the forums that people are experiencing mass disconnects and instability. And once the problem has been identified (late), their response is usually to kill all the servers, remove the BGP routing table entry for their network, and wait it out.
They don't have the capability of weathering DDoS attacks; Though they claim otherwise, history tells another story. It has to do with the fact that their game depends on a cluster architecture that is not adaptable to something like Amazon cloud, or any kind of scalability. I don't really want to get into details here because it gets really technical, but basically it comes down to data syncronization within the cluster requiring very low latency between nodes. And that means you can't locate the nodes off-site, and proxying is only of limited utility.
They tried proxying the front-end for accepting connections and authenticating users, because that's what has been targetted in the past and is one of the few components that can be moved. The current DDoS attack though is generating large numbers of connections that look the same as legitimate connections, so the proxies are allowing them. Rather than just throwing as much bandwidth as they can at the network as in the past, they're now crafting their traffic.
I suspect the reason the attack is being launched now is because in a few days they're releasing a new patch of the game which will change the network protocols used by the client... their hack might not work then, so they probably decided to launch it now before it becomes useless. They are hitting people on the weekend because it's when the most users are on... so it's most likely to be noticed.
#fuckbeta #iamslashdot #dicemustdie
Must be Goonswarm, protesting about the upcoming patch. It's all player generated content.
Where's the HOSTS file guy to post his 10 pages of spam on hosts file
and blame a bad hosts file for the reason eve is offline
har har
Usually I would expect DDoS extortion to come FROM Russia. Now I wonder how all those hardcore Russian EVE players are going to react if this wasn't their idea....
Theory 1 They want to drive down the stock price by sullying them before the big release this week
Theory 2 They are butt sore over their podding by Goonswarm, or Test, or some noob named 5t@rTw33rp
Theory 3 Collect Underpants
Theory 4 ????.
Theory 5 PROFIT
Sorry about the writing. Robot fingers, you know? Cliff Steele in DOOM PATROL #23
"Eve Offline" .. F2P!!
Comment removed based on user account deletion
aka Spreadsheet Simulator 2013?
Some have speculated that this may be related to some russian based player corporations. I find it interesting that as most US players would be getting ready to go to bed and it is prime time (6:30pm ish) in russia, that the DDOS would subside. while it may be a possible coincidence, it is about 2:30am eastern in the US and the servers are about to be restarted.
Goons pissed off someone again?
Contrary to the popular belief, there indeed is no God.
Couldn't have happened to a more wretched hive of scum and villainy in all the virtual worlds!
(obviously, that comment excludes carebears & all non-sociopath gamers :)
I host for a small, indie, open-source, free-to-play multiplayer game project. I get ddos-ed about once or twice a month.
It seems like it has become much easier in the past few months for skids to get ahold of a botnet. Maybe it's time to start pushing for vuln scanning by residential ISPs and simply cutting off infected people totally. Hell, the greedy ISPs could continue to charge the account holder after disconnection and even try to charge for on-site disinfection services.
The days of clever DDOS mitigation through firewalling and inspection are over. It now requires vast and increasing amounts of resources (bandwidth, packets per second capability for the DDOS scrubbing) to combat a level 1 skid's botnet.
There are two ways to fix this. One - force the asshole users to protect their machines and not allow attacks to originate from their nodes. Two - force the asshole providers to be responsible for removing the asshole infected zombie nodes from their networks, or limit the attack ability of the zombie nodes.
I don't have the money to fight off a ddos. If skids keep upgrading their ddos capability, you're going to see the monetization of the internet gain speed. Hobbyist servers and pages will increasingly get ddosed by machines that had some vulnerability exploited. We don't really have the money for ddos mitigation, even if we are vigilant about patching vulernabilities and following best practices to keep our stuff from being rooted.
It doesn't help that those infected hosts now can get 150mbit/sec upload speeds... Verizon only charges an extra $10 a month for 50/25mbit service. It wouldn't take many of them to kill a lot of decent sized sites.
It was the North Koreans. Supreme Leader Kim kept getting boned within a few minutes of logging in and, being the most awesomest gamer in the world, instructed his people to take down the whole nest of conspiring cheaters.
Ironically, I'm reading this story from EVE's In-Game Browser. :)