"Server is full, retrying..."

Moderators: Lead Developers, Senior Lead Admins

Locked
User avatar
Puppet.
Mafia
Mafia
Posts: 639
Joined: Fri May 09, 2014 2:06 pm

Re: "Server is full, retrying..."

Post by Puppet. » Thu Dec 04, 2014 10:47 am

With the assistance of iBooze and I, we have found something in the system of this.
iBooze wrote:Hey everyone. I'm currently forum banned, so I had my friend to post this, when I heard about this issue.
The attack is small, but, very complex and effective.

The attack works as follows:
1) It's a spoofed attack with low PPS rate using TTL ~110-118.
2) Have UDP Checksum.
3) Have random SRCPORTs and random IPs.
4) TOS, Sequence and ID of packet it's correct, including the IP header.

I can tell you one thing, though. There's already a solution that I am testing with several of others, and it will not last long before it will be shared with the rest of the SA:MP community (Big probs to ErickOwnZ from the SA:MP community). However, we possibly have to wait for SA:MP to come out with an update, as you can't solve the exploit fully on your own. For now, I've got a single suggestion for the developers here on LS:RP.
Block IPs, packets, and TTLs, and anything suspicious.

In the end, only Kalcor can solve this issue.

User avatar
Maca
Retired Administrator
Retired Administrator
Posts: 5918
Joined: Mon Mar 07, 2011 6:28 pm
Contact:

Re: "Server is full, retrying..."

Post by Maca » Thu Dec 04, 2014 11:03 am

It's a shame that someone dedicates time to making SA-MP a bad experience, but that's just how it is. People asking for an ETA sadly cannot be provided with one as many have already stated that it is completely out of LS-RP's hands. We just have to stick together and ride it out.
Then I heard the voice of the Lord, saying, "Whom shall I send, and who will go for Us?" Then I said, "Here am I. Send me!"

User avatar
JK.777
Wannabe Don
Wannabe Don
Posts: 1073
Joined: Fri Jun 06, 2014 11:55 am

Re: "Server is full, retrying..."

Post by JK.777 » Thu Dec 04, 2014 11:19 am

Sed wrote:For anyone curious, I was taking a look at log excerpts from other servers. This is a version of a slowloris attack, just modified for SAMP. (Speculation)

For example, SAMP forums have this person discussing the attack and they included this log
Spoiler: show

Code: Select all

[02:28:52] Incoming connection: 39.137.59.27:33986
[02:28:53] Warning: Minimum time between new connections (600) exceeded for 212.25.72.10:50372. Ignoring the request.
[02:28:53] Warning: client exceeded 'messageholelimit' (1) 71.214.228.24:52499 (902) Limit: 900
[02:28:53] Incoming connection: 71.214.228.24:52499
[02:28:53] Warning: Minimum time between new connections (600) exceeded for 108.178.74.91:26054. Ignoring the request.
[02:28:53] Warning: client exceeded 'messageholelimit' (1) 96.15.183.187:29056 (3000) Limit: 900
[02:28:53] Incoming connection: 96.15.183.187:29056
[02:28:54] Warning: Minimum time between new connections (600) exceeded for 190.75.141.40:29299. Ignoring the request.
[02:28:54] Warning: client exceeded 'messageholelimit' (1) 85.65.241.187:30037 (3000) Limit: 900
[02:28:54] Incoming connection: 85.65.241.187:30037
[02:28:55] Warning: Minimum time between new connections (600) exceeded for 43.233.150.34:26790. Ignoring the request.
[02:28:55] Warning: client exceeded 'messageholelimit' (1) 108.218.33.16:5733 (975) Limit: 900
[02:28:55] Incoming connection: 108.218.33.16:5733
[02:28:55] Warning: Minimum time between new connections (600) exceeded for 109.186.41.135:38769. Ignoring the request.
[02:28:55] Warning: client exceeded 'messageholelimit' (1) 79.18.238.160:8710 (3000) Limit: 900
[02:28:55] Incoming connection: 79.18.238.160:8710
[02:28:56] Warning: Minimum time between new connections (600) exceeded for 109.65.253.187:14503. Ignoring the request.
[02:28:56] Incoming connection: 162.63.55.108:47245
[02:28:56] Warning: client exceeded 'messageholelimit' (1) 162.63.55.108:47245 (3000) Limit: 900
[02:28:56] Warning: Minimum time between new connections (600) exceeded for 92.63.199.234:22084. Ignoring the request.
[02:28:57] Warning: client exceeded 'messageholelimit' (1) 78.53.153.75:10526 (2000) Limit: 900
[02:28:57] Incoming connection: 78.53.153.75:10526
[02:28:57] Warning: Minimum time between new connections (600) exceeded for 109.66.127.230:40005. Ignoring the request.
[02:28:57] Incoming connection: 200.3.173.188:55491
[02:28:57] Warning: client exceeded 'messageholelimit' (1) 200.3.173.188:55491 (2000) Limit: 900
[02:28:58] Warning: Minimum time between new connections (600) exceeded for 186.254.81.189:24510. Ignoring the request.
[02:28:58] Warning: client exceeded 'messageholelimit' (1) 113.36.222.97:45780 (910) Limit: 900
[02:28:58] Incoming connection: 113.36.222.97:45780
[02:28:58] Warning: Minimum time between new connections (600) exceeded for 9.84.48.226:39151. Ignoring the request.
[02:28:58] Incoming connection: 102.131.203.32:49464
[02:28:58] Warning: client exceeded 'messageholelimit' (1) 102.131.203.32:49464 (3000) Limit: 900
[02:28:59] Warning: Minimum time between new connections (600) exceeded for 112.143.158.246:41088. Ignoring the request.
[02:28:59] Incoming connection: 37.214.209.242:63403
[02:28:59] Warning: Minimum time between new connections (600) exceeded for 24.81.96.63:44501. Ignoring the request.
[02:28:59] [join] SAMSUNG has joined the server (26:37.214.209.242)
[02:29:00] Warning: client exceeded 'messageholelimit' (1) 95.73.226.98:17219 (928) Limit: 900
[02:29:00] Incoming connection: 95.73.226.98:17219
[02:29:00] Warning: Minimum time between new connections (600) exceeded for 109.66.182.230:19508. Ignoring the request.
[02:29:01] Incoming connection: 109.121.160.165:56137
[02:29:01] Warning: Minimum time between new connections (600) exceeded for 78.36.155.163:56425. Ignoring the request.
[02:29:02] [join] TAMIK_COP has joined the server (4:109.121.160.165)
[02:29:02] Incoming connection: 78.36.155.163:56425
[02:29:03] [join] Anastasia has joined the server (14:78.36.155.163)
[02:29:03] --- Server Shutting Down. 
So, my speculation is it is sending some sort of packet that requires some sort of proper response, and the server dedicates CPU and network to maintain this connection, while the attacker just closes the connection on his side (preventing these packets to be responded to) eventually causing the server to time out.

Reference:
http://en.wikipedia.org/wiki/Slowloris_%28software%29
http://forum.sa-mp.com/showthread.php?t=545530
After taking a look at this and samp forum, I think this is a serious. I don't think it will get fixed any time soon, but I hope it does.

keinanW
deadmau5 wannabe
deadmau5 wannabe
Posts: 1408
Joined: Sun Mar 31, 2013 2:37 pm
Ingame name: Keinan_Walker
Location: bed

Re: "Server is full, retrying..."

Post by keinanW » Thu Dec 04, 2014 12:10 pm

If there's someone here who somehow was able to connect, TELL HOW

Scarter
Gangster
Gangster
Posts: 114
Joined: Fri Oct 17, 2014 1:37 pm
Ingame name: Aiden Martinix

Re: "Server is full, retrying..."

Post by Scarter » Thu Dec 04, 2014 12:12 pm

Keep admins on the server please...some people are abusing the fact of no admins online to jacjacking with no rp becouse of the problems with login.thanks.

Dior
Asesina
Asesina
Posts: 391
Joined: Tue Sep 03, 2013 9:49 pm
Ingame name: Troubles
Location: Puerto Rico to Miami

Re: "Server is full, retrying..."

Post by Dior » Thu Dec 04, 2014 12:15 pm

keinanW wrote:If there's someone here who somehow was able to connect, TELL HOW
You just have to be patient I guess.. The time you have to wait is different for everyone and random so you never know for sure how long you'll be waiting.

User avatar
NicaHastla
Gold Member
Gold Member
Posts: 1351
Joined: Sat Oct 04, 2014 4:16 pm
Ingame name: [Mask 357867_14]
Location: 32° 6' 33.5988''

Re: "Server is full, retrying..."

Post by NicaHastla » Thu Dec 04, 2014 12:33 pm

Small but hard to fix attack ^^? huh

User avatar
NoGodsNoMasters
Mafia
Mafia
Posts: 396
Joined: Wed Jul 10, 2013 2:02 am
Location: Cell A100

Re: "Server is full, retrying..."

Post by NoGodsNoMasters » Thu Dec 04, 2014 12:55 pm

Glad I read this before reinstalling my GTA, lol. Thanks for the info

User avatar
NicaHastla
Gold Member
Gold Member
Posts: 1351
Joined: Sat Oct 04, 2014 4:16 pm
Ingame name: [Mask 357867_14]
Location: 32° 6' 33.5988''

Re: "Server is full, retrying..."

Post by NicaHastla » Thu Dec 04, 2014 1:06 pm

Why should you re-install ur gta.. this won't help..

User avatar
HalfNakedAndAlmostFamous
Civilian
Civilian
Posts: 26
Joined: Sun Feb 03, 2013 9:25 pm
Ingame name: Danielle_Myers

Re: "Server is full, retrying..."

Post by HalfNakedAndAlmostFamous » Thu Dec 04, 2014 1:22 pm

Why would anybody go for re-installing their game when just by looking at the number of people on the server, it`s obviously not GTA fault but the server have problems..

Scarter
Gangster
Gangster
Posts: 114
Joined: Fri Oct 17, 2014 1:37 pm
Ingame name: Aiden Martinix

Re: "Server is full, retrying..."

Post by Scarter » Thu Dec 04, 2014 1:27 pm

i reinstalled my gta several times not becouse the server but becouse my game gets stupid if i try mod it...dunno why but well...gta normal is better...i love my buccaner xD

Ethan_Gurakuqi
Wannabe Don
Wannabe Don
Posts: 1288
Joined: Sat Nov 22, 2014 1:30 am

Re: "Server is full, retrying..."

Post by Ethan_Gurakuqi » Thu Dec 04, 2014 1:28 pm

Seriously this is a shame that people purposely go out their way to spoil other people's daily hobbies.
Appreciate the update, hopefully it's resolved soon.

User avatar
Leroy
Mafia
Mafia
Posts: 723
Joined: Mon Jul 30, 2012 7:10 pm
Ingame name: Raymond Meadows
Location: The Netherlands
Contact:

Re: "Server is full, retrying..."

Post by Leroy » Thu Dec 04, 2014 1:47 pm

Glad to see it's being worked on.

NCIS
Wannabe Don
Wannabe Don
Posts: 990
Joined: Tue Mar 25, 2014 4:54 pm
Ingame name: Adriano_Gonzales
Location: Podgorica, Montenegro

Re: "Server is full, retrying..."

Post by NCIS » Thu Dec 04, 2014 2:17 pm

Any updates? =)

User avatar
Georgi
I love banitsa
I love banitsa
Posts: 713
Joined: Sun Apr 13, 2014 10:10 pm
Ingame name: Rikki K . Vitaly R

Re: "Server is full, retrying..."

Post by Georgi » Thu Dec 04, 2014 2:45 pm

removed
Last edited by Georgi on Thu Dec 04, 2014 2:49 pm, edited 2 times in total.

Locked

Return to “Announcements Archive”

Who is online

Users browsing this forum: No registered users