DoS Attack Forces EVE Online Offline
Resorting to the out-of-band messaging that is Facebook, CCP Games has announced that "At 02:05 GMT June 2nd, CCP became aware of a significant and sustained distributed denial-of-service attack (DDoS) against the Tranquility cluster (which houses EVE Online and DUST 514) and web servers."
I was just wondering why I couldn't log in! I criticize you guys a lot, gotta give you props this time.
I swear to God...I swear to God! That is NOT how you treat your human!
That is all.
They need to get this sorted ASAP. I have important Internet spaceship business to tend to and it really can't wait any longer.
Will rejoice
What kind of intricate in-game machinations will this turn out to be connected to?
Why would anyone launch a DoS attack on EVE online servers?!" :P
Nerds should not attack other nerds.
Why do the gaming servers respond to requests from non-players?
I assume that there is, at very least, some sort of authentication service that has to evaluate a request to determine whether or not it comes from a player...
For those hopelessly addicted, there are two solutions:
1) practice on the singularity server (aka test server)
2) play the flash version.
Why do the gaming servers respond to requests from non-players?
Ahhh, this question is unanswerable as it is one of the few true mysteries of the universe, like magnets ( wtf, how do they work!), velcro, and the location of the proverbial "other sock".
Why do gaming servers respond to requests from non-players? Well dude, the answer might as well be 42, nobody knows.
*sigh*
You need to log in to the game at some point.
But only once, unless you are the sort of coward who logs out!
Are we sure it was DDoS and wasn't the Goons all trying to log on en masse.
All generalizations are false, including this one. Mark Twain
It's not Facebook that they're updating from; It's Twitter. Their Facebook account is linked to Twitter.
Anyway, this isn't the first time the servers have been DDoS'd; This happens about every 4 months or so on average. And unfortunately, they've handled it about as well each time as you're seeing now: They tend not to announce the DDoS until hours after the news is all over the forums that people are experiencing mass disconnects and instability. And once the problem has been identified (late), their response is usually to kill all the servers, remove the BGP routing table entry for their network, and wait it out.
They don't have the capability of weathering DDoS attacks; Though they claim otherwise, history tells another story. It has to do with the fact that their game depends on a cluster architecture that is not adaptable to something like Amazon cloud, or any kind of scalability. I don't really want to get into details here because it gets really technical, but basically it comes down to data syncronization within the cluster requiring very low latency between nodes. And that means you can't locate the nodes off-site, and proxying is only of limited utility.
They tried proxying the front-end for accepting connections and authenticating users, because that's what has been targetted in the past and is one of the few components that can be moved. The current DDoS attack though is generating large numbers of connections that look the same as legitimate connections, so the proxies are allowing them. Rather than just throwing as much bandwidth as they can at the network as in the past, they're now crafting their traffic.
I suspect the reason the attack is being launched now is because in a few days they're releasing a new patch of the game which will change the network protocols used by the client... their hack might not work then, so they probably decided to launch it now before it becomes useless. They are hitting people on the weekend because it's when the most users are on... so it's most likely to be noticed.
#fuckbeta #iamslashdot #dicemustdie
Because in networking, every new connection comes from a "non-player" until you're authenticated as otherwise.
I swear to God...I swear to God! That is NOT how you treat your human!
Where's the HOSTS file guy to post his 10 pages of spam on hosts file
and blame a bad hosts file for the reason eve is offline
har har
Theory 1 They want to drive down the stock price by sullying them before the big release this week
Theory 2 They are butt sore over their podding by Goonswarm, or Test, or some noob named 5t@rTw33rp
Theory 3 Collect Underpants
Theory 4 ????.
Theory 5 PROFIT
Sorry about the writing. Robot fingers, you know? Cliff Steele in DOOM PATROL #23
Initially it looked to me like an attack on their DNS servers, not the game itself.
A dig would work or not depending on which name server you were randomly allocated.
If you managed to resolve the required names you could get in and play just fine. Was fun having NPC null almost to myself.
They've brought the lot down now of course, but don't just assume that it's a problem with the game code.
Russian DDoS operators take their life in their own hands by this, I have fought with and along side Russians (on Eve) and they take this very serious.
Sorry about the writing. Robot fingers, you know? Cliff Steele in DOOM PATROL #23
You should be in charge of the whole internet. You got it all figured out.
Invaders must die
Player generated content = marketing spiel for "we don't actually put in any content, we just let the anti-social types attack everyone".
Considering they've managed to take down Serenity (the China specific EVE on-line server) also ... I'd say the usual haunts of DDoS operators might not be as safe as they think they are.
Oh, for anyone who wishes to track it:
http://eve-offline.net/ and
http://eve-offline.net/?server=tranquility
This space for rent. All reasonable inquiries will be entertained at proprietors discretion.
aka Spreadsheet Simulator 2013?
unless you are the sort of coward who logs out!
Pfft, I'm the sort of coward who doesn't even log in!
You should probably learn how networking actually works. It will avoid making posts that are this bad.
The way the server knows what IP the packet came from is by the IP layer of the stack processing the packet. Which means the packet triggered work by the server, and the DDoS can do it's job.
Your "solution" requires the server to predict that a non-player IP will be sending a packet and reject it before examining the packet at all. But that's assuming the DDoS is sending random packets.
If the person behind the DDoS doesn't have enough nodes to carry out the attack above, then they can send bad "login" requests. The server will have to process them completely in order to reject the login.
I believe that other servers were taken down by CCP as a precaution measure.
If you post as an AC, don't expect me to spend a mod point on you.
Haha. ^ mod up.
Actually, even if you can distinguish, is no way to prevent any host of the Internet from sending traffic to you. If you gather enough upstream bandwidth, you can clog any pipe you want. Some research works have proposed ways to amend this, for example this.
Couldn't have happened to a more wretched hive of scum and villainy in all the virtual worlds!
(obviously, that comment excludes carebears & all non-sociopath gamers :)
Re your sig: if you think that belief in a monotheistic, infinite, possibly personal, possibly triune, deity is a popular choice these days...then I find your lack of faith stupefying! Just sayin...
Why do the gaming servers respond to requests from non-players?
I doubt they respond.
But the packet coming in as request get routed through the game servers network _until_ one part of the network decides to drop the packet(s) because they are illegit.
DDoS attacks basically always flood your network, consider it like a traffic jam in a city. You delete cars from the road as you recognize them as part of the DDoS but new cars coming into the city all the time cause more jams at the entrances to the city.
Cost free eBook I read (by iBook/Kobo/Amazon/ObookO/Gutenberg etc.): "The Green Odyssey" by Philip Jose Farmer.
Don't you know? Most upstream providers have Layer7 firewalls that can drop non-player EvE logins. The secret is the magic pixie dust.
It doesn't help that those infected hosts now can get 150mbit/sec upload speeds... Verizon only charges an extra $10 a month for 50/25mbit service. It wouldn't take many of them to kill a lot of decent sized sites.
It was the North Koreans. Supreme Leader Kim kept getting boned within a few minutes of logging in and, being the most awesomest gamer in the world, instructed his people to take down the whole nest of conspiring cheaters.
Pfft ...
What nonsense are you talking about?
How should an ISP know wheather a package you snt upstream is legit or ot?
Go smoke something else ...
Cost free eBook I read (by iBook/Kobo/Amazon/ObookO/Gutenberg etc.): "The Green Odyssey" by Philip Jose Farmer.