That is my understanding.Finhagain wrote: Thu Sep 03, 2026 8:34 pm The DDOS mitigations we have seen so far are initial efforts and stop gaps correct? They haven't implemented the Flockinet solution yet?
I read that the Ravencraft team has heard about the attack. They said that many of these are fixed in their 1.18.1 code base. Further they claim that they are able to quickly able to find and stop those exploits.Kestrel wrote: Thu Sep 03, 2026 7:43 pm For some more details on todays attack, read below.
The first wave of the attack started at 15:52:31 today targeting our authentication server once again (also flooding our PvE realm, and at the very end of the attack hitting the HC realm). This first attack caused some latency and looting issues on the server, along with a 3% drop in player during a time when our population usually is growing to its daily peek.
The second wave was active from 16:39 until 16:46 and was significantly stronger, and disconnecting 46% of the population, while those who remained still experienced extreme lag/latency.
A developer on the team pushed a change to all realms with a restart at 17:37 attempting to get some mitigations in place.
Wave three went from 17:51-17:54, this time including the PvP realm in the attack but still primarily focusing the flood on the auth server. Mid wave they also changed the shape of their attack going from a full junk traffic flood to a mix of junk traffic and a large number of connection requests to induce connection churn.
A small precursor wave targeted just our radio ports from 13:35-13:42.
Wave four hit from 18:39 until 18:49 the hardest yet nearly instantly bringing our population down 94%. More updates will likely be given once the attack stop.
This to me reads as nothing more than extortion. We DDoS your server, and then if you let us "consult" you it will magically stop. I wouldn't be surprised if their help would entail signing over assets or significant sums of money.Thaodan wrote: Thu Sep 03, 2026 9:54 pm I read that the Ravencraft team has heard about the attack. They said that many of these are fixed in their 1.18.1 code base. Further they claim that they are able to quickly able to find and stop those exploits.
They offer help to any project using the 2024 leaked sources (Funny to say that about GPL software..) in diagnosing and patching the exploits which bring these servers down.
Did your hear about this message, would you contact/accept their help?
I think if these DDoS attacks are based or include possible exploits it could be worth to contact them. In general a good relationship with them sounds only beneficial to me.
(Assuming a good faith intend in their post, please don't start any argument beyond the offer to help regarding the DDoS attack)
Users browsing this forum: No registered users and 1 guest