PDA

View Full Version : [L4D]CPU Exploit


Reflux
07-19-2016, 11:17
My server is under attack for 2 days now. This guy is using an exploit that overloads the CPU of the server machine. host Servers. i contacted them they cant help me with my problem. All they said was to ban the IP adress with rcon. This was the 1st thing i did , yet hes still able to do it. Maybe because he has dynamic IP , maybe because the rcon IP ban doesnt stop him , i dont know.


is it possible to cut the connection somehow? maybe even with disabling rcon?

Thanks in Advance!

Spirit_12
07-19-2016, 11:30
Why can't NFO just block that IP from accessing your system. Seems dumb that they wouldn't add a system wide filter for that IP, considering it is malicious activity.

Disabling RCON would be the first thing that I'll do. Did NFO give you any information on what does he do with RCON that causes tickrate to drop? As far as I know NFO don't even offer 100 tickrate.

DarkDeviL
07-19-2016, 11:31
NFO said he is doing this via rcon. are there any way to fix this? is it possible to cut the connection somehow? maybe even with disabling rcon?

If what NFO says here is the right thing, then you can just add firewall restrictions in front of the TCP port of your game server, in this case, TCP 27015.

You need to ask NFO for assistance on how to do that with the specific product that you have with them.

Reflux
07-19-2016, 11:47
They didnt give any information at all.. Their support team is really awful. Tickrate is forced to 100 with a plugin. But it drops because the exploit overloads the CPU. How can i disable rcon?



All i can use it for is to capture incoming Traffic.

Potato Uno
07-19-2016, 11:59
I think forcing your tickrate above what your provider allows you to have might be against their ToS...

Also you can try disabling the rcon password in your server.cfg and command line.

Spirit_12
07-19-2016, 12:04
Another beautiful example of how incompetent NFO support is. I'm glad I made the call to go manage my servers on my own.

Coming back to the topic. NFO does not support higher tickrates. What you might be referring to is fps_max and not exactly tickrate. Last I had a conversation with them, they were too afraid to offer high tickrate, since it uses more CPU.

Reflux
07-19-2016, 12:22
[QUOTE=Spirit_12;2437795]Another beautiful example of how incompetent NFO support is. I'm glad I made the call to go manage my servers on my own.


He doesnt have the RCON password for sure. How could this help me? Can u explain a bit please?

Reflux
07-19-2016, 14:37
I got 1 more question! If i can get NFO to block the rcon's protocol ( 27015 ) from all the inc IP'S will it cause any trouble?

Spirit_12
07-19-2016, 14:43
Nope , im talking about Tickrate. i know they do not support it , yet they dont notice it. But why does this matter? if i was running on 30 tick it would also drop down to 5 when the guy uses the exploit


First of all, you are violating the terms of service, which makes you ineligible to get help on this forum from a moral standpoint.

The best I can recommend you would be to use -condebug in your start up line, and see the console output when the tickrate drops. That will give you an idea of how he is doing it.

Sev
07-19-2016, 15:01
L4D/2 is grieferville, especially L4D1 where the playerbase is very minimal, a lot of the players pride themselves on ruining the game for others and they view L4D2 as garbage, which is probably true on some levels. So naturally, a lot of the playerbase is bitter and self entitled to start.

I don't want to play the blame game, but odds are you were a madmin to the wrong person or trolled the wrong person on your server. Some griefers will attack servers sure, but they'll move on eventually if they aren't blocked by the user or company running the servers.

But again, I don't want to play the blame game all that much. Could just be a habitual griefer.

Reflux
07-19-2016, 15:08
First of all, you are violating the terms of service, which makes you ineligible to get help on this forum from a moral standpoint.

The best I can recommend you would be to use -condebug in your start up line, and see the console output when the tickrate drops. That will give you an idea of how he is doing it.

i've removed the tickrate forcer. It's 30 tick now, yet the exploit is still working.


About the last Reply. No. He was the "madmin" ruining the rest of the l4d community's time and game.