Friend getting packeted by somebody intentionally, can we do anything?

kukyfrope

Senior member
Mar 21, 2005
344
0
0
A friend and teammate of mine in an online multiplayer game has become the victim of intentional and malicous packeting by one or more people. His internet is fine until we start our official league matches, within minutes his ping is lagging out and he will time-out of the server. Within minutes of the match concluding, his ping is back to normal. He's very unliked by a few people that would do something like this.

Is there anything he can do to prevent this from happening? Anything on his router? Could his ISP do anything? Maybe change his IP?
 

skyking

Lifer
Nov 21, 2001
22,220
5,082
146
If it is people he is gaming with, changing the IP will do nothing. they will figure out a way to find out the new IP.
If it is someone who can get a look at one of his emails, the IP is right there too.
 

Woodie

Platinum Member
Mar 27, 2001
2,747
0
0
The ISP is the most likely to be able to help. Willing? Not sure.
Depending on his firewall(router?), he may be able to improve things somewhat. It's a question of how much he can configure the firewall, and how much he can figure out about the type of DOS attack he's undergoing. The ISP may be willing to assist, since it will affect their network to some extent.
 

Atheus

Diamond Member
Jun 7, 2005
7,313
2
0
First you want to run a packet sniffer like Ethereal to check if that is in fact the problem. You would be looking for huge increases in incoming SNMP traffic or something like that.

If he really is being targetted the next step is to identify the sources, Ethereal will tell you this. You want to find out if it's multiple sources or a single one. If it is a single (or very few) address the best move would be to contact the admin of the offending machine(s) and tell them they are being used to launch attacks. It might even turn out the source is a home PC belonging to one of the people on the game server, if so, you will be able to get them cut off by calling thier ISP.

If it's coming from many sources then you are likely the victim of a botnet. There's not a whole lot you personally can do about this unless you want to set up some DoS prevention technology... it's possible to mitigate the effects of a medium sized DoS with an advanced firewall system such as cisco or modified Linux systems, but it's a significant effort. In this case You should probably call the ISP.

 

BSEagle1

Senior member
Oct 28, 2002
619
0
0
You also might consider contacting your gaming league if you have suspicions of who might be doing it
 

blemoine

Senior member
Jul 20, 2005
312
0
0
what i would do is setup a Linux Based firewall like IPCOP or Endian Firewall. you can set the WAN interface to not respond to pings. It also comes with a Intrusion Detection (Snort) System. i beleive you can set snort to run active so that it will block attacks and not just log them. an alternative to this would be to buy a cheap SOHO router that has an Intrusion Prevention System built in.
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
not much you can do really, except report it as abuse from the sending IP addresses and have your buddy report it to his ISP.

otherwise there is literally nothing in the world you can do to stop the inbound packets. no firewall or anything can stop this.

Running ethereal to capture what is going on and identifying the sources is a good idea.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |