Page 3 of 3

Re: More DDoS Information

Posted: Fri Sep 04, 2026 4:22 pm
by Drakokan
Thank you for the update on the situation!

Re: More DDoS Information

Posted: Fri Sep 04, 2026 6:27 pm
by Turasatana
The limitations regarding anonymity are perfectly understood...
Please keep the updates coming. Hang in there and stay strong!

Re: More DDoS Information

Posted: Fri Sep 04, 2026 7:44 pm
by Noone
I will be patiently sticking with Octowow. I support you 100%. I believe anyone joining ravencraft if they are the true col-prates of the DDos attacks will be regretting it in the future.

As well thank you, for providing this game.

Re: More DDoS Information

Posted: Fri Sep 04, 2026 7:47 pm
by Kestrel
Bohatyr7 wrote: Fri Sep 04, 2026 12:24 pm Hey,

do you have any information on the scale of the attack—in terms of throughput (bps/Gbps), packet rate (pps/Mpps), and the number of new connections per second (cps)?

Ty for your work
I think we may have mentioned it in an early DDoS posting thread but happy to share more of that info. The attack shape changes a lot (typically we see 3-6 times a day).

We also have lost visibility into the raw attack shape after we started using a third party provider to assist in our defenses as we don't have access to the L4 traffic they are scrubbing we only can see what makes it through their scrubbing. This third party provider has not been the most responsive, and have not provided us with details of the attack shape at the L4 level, but they are helping us. Any port in a storm I suppose.

From the attacks before we lost visibility, we were seeing peaks of 400,000 inbound pps and 29,000 SYN/s to our auth server. We are unable to see any throughput from the attack that did not make it through and our server previously (no longer) had a 1Gbit uplink and so we were unable to see any throughput greater than 1Gbit, but they were fully saturating that. Flokinet has also been unable to provide us more details on how they were scrubbing traffic during those times, so these numbers are also likely skewed from just what made it through Flokinet's basic/standard DDoS protection.

Re: More DDoS Information

Posted: Fri Sep 04, 2026 7:56 pm
by Taikajim
Thanks for the update. I've been enjoying my time here and I'm gonna stick around no matter what.

Re: More DDoS Information

Posted: Fri Sep 04, 2026 9:59 pm
by Rightintwo
Thanks for the update, take your time getting this fixed, we don't pay a subscription so you don't owe us anything :D . Imagine being so sad you DDOS attack a private server, for why?

Re: More DDoS Information

Posted: Fri Sep 04, 2026 11:00 pm
by Kestrel
Zulahachus wrote: Fri Sep 04, 2026 3:41 pm Hey, another sw engineer here few out of the box suggestions, I bet they abuse syn packets if they target auth server. Maybe a simple throtling like:
Limit the number of connection attempts (SYNs) per IP per minute. Legitimate players only connect once or few times during a login attempt. If they don't abuse SYN packets you can also try setting firewall policy to drop ACK, FIN, RST packets if they dont belong to active tcp session (there must have been syn to establish legitimate connection).

But yeah you need an access to firewall, or possibility to deploy yours if you have the means, you can always portforward to localports over which you could hopefully setup such policies.
We were doing this when we got hit on the first day of the DDoS, however they shifted to a straight port flood causing our IP's to be blacked out upstream. Then we shifted to our current defense system which does not allow us to do IP filtering ourselves and does all of the filtering on the L4 layer that the DDoS is targeting.