Raised This Month: $51 Target: $400
 12% 

Update on Rcon Dos Attacks?


Post New Thread Reply   
 
Thread Tools Display Modes
Author Message
medic917
Senior Member
Join Date: Aug 2014
Old 12-13-2015 , 23:18   Update on Rcon Dos Attacks?
Reply With Quote #1

So I got a dos attack today with this error spamming right before server crashed.
Socket ProcessAccept Error: Too many open files
Socket ProcessAccept Error: Too many open files
Socket ProcessAccept Error: Too many open files


I read about it and is iptables method the only way to fix it? Or is smac's rcon plugin enough?
I also read this exploit was fixed by valve a long time ago but I guess there is still ways around it?

It's a shame people have to attack others, I don't know why they do this...
medic917 is offline
pcmaster
AlliedModders Donor
Join Date: Sep 2009
Old 12-14-2015 , 13:40   Re: Update on Rcon Dos Attacks?
Reply With Quote #2

The simplest way is to simply block all TCP traffic to that port except from your own IP, that's at least how I do it.
__________________
Stopped hosting servers as of November 2018, no longer active around here.
pcmaster is offline
Darkness_
Veteran Member
Join Date: Nov 2014
Old 12-14-2015 , 16:12   Re: Update on Rcon Dos Attacks?
Reply With Quote #3

I had this same issue a while back - it turned out a plugin was doing too many file operations ( open, write, close, repeat ) in a short time span rapidly. Upon deleting the culprit plugin this error completely ceased. If I was you I would analyze the plugins you are running that use File I/O before moving onto trying some IP tables methods and or blocking the TCP port as pcmaster suggested.

Good luck.

Last edited by Darkness_; 12-14-2015 at 16:13.
Darkness_ is offline
medic917
Senior Member
Join Date: Aug 2014
Old 12-16-2015 , 21:38   Re: Update on Rcon Dos Attacks?
Reply With Quote #4

darkness any way to investigate and help me find which plugin is causing it?
Or do I have to use trial and error?

----edit----
looks like it was a dos after all, only my most popular servers are getting this issue.
I just used a firewall and hopefully it does the trick.

Last edited by medic917; 12-16-2015 at 22:49.
medic917 is offline
Dr. Greg House
Professional Troll,
Part-Time Asshole
Join Date: Jun 2010
Old 12-16-2015 , 23:46   Re: Update on Rcon Dos Attacks?
Reply With Quote #5

Looks more like syn-flood.
Using non-default ports for everything and properly configuring iptables helps. And just whitelist ips for rcon or block it entirely.
__________________
Santa or Satan?

Watch out when you're paying people for private requests! Most stuff already exists and you can hardly assess the quality of what you'll get, and if it's worth the money.
Dr. Greg House is offline
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 16:53.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode