Page 4 of 7

Re: DDoS Round 7

Posted: Thu Sep 03, 2026 7:49 pm
by Alhazred1691
Villainofrhyme wrote: Thu Sep 03, 2026 7:18 pm you can block me from playing when I'm at my school campus.
This is a skill issue.

Re: DDoS Round 7

Posted: Thu Sep 03, 2026 7:50 pm
by Ocdonotsteal
Kestrel wrote: Thu Sep 03, 2026 7:46 pm We are talking about ways to compensate players beyond the D'Dossy pet, but likely will not hear more on that until we have our full DDoS protections in place and this entire saga has come to an end.
Honestly, having the game playable again is more than enough reward, coming from an old turtler. Yeah, maybe reimburse those who actually lost something due to disconnects, but keep on keeping on. Us shitposters have other things to do in the meanwhile.

Re: DDoS Round 7

Posted: Thu Sep 03, 2026 7:52 pm
by Kjirath
Kestrel wrote: Thu Sep 03, 2026 7:46 pm We are talking about ways to compensate players beyond the D'Dossy pet, but likely will not hear more on that until we have our full DDoS protections in place and this entire saga has come to an end.
I really think you should consider doing it during this time on the contrary, players might help you more than you realise with donations. I mean, everything than can max out retention and purchase rates must be tried right now !

They WILL run out of money at some time, we just got to last longer

Re: DDoS Round 7

Posted: Thu Sep 03, 2026 7:55 pm
by Hennybr
Hennybr wrote: Thu Sep 03, 2026 7:22 pm Even though its not ideal, as a temporary solution couldnt some sort of whitelist be employed until a more complete solution is in place?
Yes, it would make it tedious for new players to get in, but perhaps it could facilitate a stable server for existing players for the time being.
To elaborate on the whitelist idea: put a challenge layer in front of the auth server. Require a CAPTCHA or small proof-of-work and issue a short-lived signed token. The edge/proxy could then cheaply drop or heavily rate-limit connections without a valid token before they create state/load on auth.

That would make reconnecting cheap for verified players while putting a deliberate per-connection cost on the connection-churn attack.

Re: DDoS Round 7

Posted: Thu Sep 03, 2026 7:56 pm
by Edem
Thedruindy wrote: Thu Sep 03, 2026 6:47 pm Sounds like a free repair bot for all :D
A Goblin Brainwashing Device would be nicer.

Re: DDoS Round 7

Posted: Thu Sep 03, 2026 8:01 pm
by Galundra
Kestrel wrote: Thu Sep 03, 2026 7:45 pm
Steamroller wrote: Thu Sep 03, 2026 6:59 pm
2nd week in a row where our raid has gone through this, multiple expensive consumables are gone down the drain, I want to ask if we can request our lost resources through a GM ticket ?
Make an in game ticket, and mention that Kestrel told you to. It will get escalated to me and I will investigate and mail you back consumes lost during any raids that are interrupted due to DDoSes going forward.
I don't think this is a good idea, everyone lost either time/consumables in the server. The situation is what it is, this seems like panicking and not a good look.

Just increase protection we don't need more pets. People who like the server will stay and understand the situation, i was here when only 150pop.

Re: DDoS Round 7

Posted: Thu Sep 03, 2026 8:14 pm
by Tsokay
Hello

I came here from ascenssion, just wanna thanks the team for their hard work :D i'll wait patiently and I'm going to enjoy the game despite the circumstances. Let's see who's the most stubborn. :mrgreen:

Re: DDoS Round 7

Posted: Thu Sep 03, 2026 8:20 pm
by Nhoo
The server was great, but it's been impossible to play for two weeks now.
Every night it's the same thing, it's such a shame.
I hope they can solve the attack problem someday, but for now I'm not playing, it's pure hell.

Re: DDoS Round 7

Posted: Thu Sep 03, 2026 8:26 pm
by Eraanthe
Bigmike001 wrote: Thu Sep 03, 2026 7:10 pm I told my thoughts to my AI, and he wrote this:
-----------------------------------------------------------------------------------------------------------------------------------------
Fellow players and server admins,
I’d like to share a logical breakdown of the ongoing DDoS attacks we’re facing. To understand the situation, let’s follow the chain of causality and apply some basic crisis management principles.

First, the attacks are sustained and costly. For over a week, EU servers have been hammered by DDoS traffic originating from Asia. Launching and maintaining such an assault is not free—it requires financing, botnets, and resources. This clearly indicates a financial motive, not random vandalism. Someone’s livelihood is at stake.

Second, follow the money. Persistent attacks almost always point to vested interests. The most likely scenarios are malicious business competition (a rival server losing players to us) or extortion demanding protection money. In either case, the EU server’s actions—such as poaching players from other communities—triggered this retaliation. The root cause lies with us; we provoked the response by encroaching on someone else’s turf.

Third, desperation breeds extreme measures. The attackers are not mindless trolls; they are acting like a cornered animal fighting for survival. When you push a competitor to the brink, they will lash out with everything they have. This is not an unprovoked act of aggression—it is a desperate counterattack born of necessity.

Now, here’s the critical part: how should we respond? Right now, we have a fire problem. The EU server is burning, and the attackers are pouring gasoline. But a smart firefighter doesn’t fight the fire by running into the inferno and trying to extinguish every flame—that would be an endless war, a futile attempt to battle the root cause directly. Instead, firefighters contain the fire. They cut off the fuel, isolate the blaze, and stop it from spreading further. That’s exactly what blocking Asian IPs would do.

Blocking Asian IPs can be a containment measure, not a solution to the underlying conflict. It’s about reaching peace by stopping the bleeding. By containing the issue—cutting off the source of the attack traffic—we can restore stability for the majority of players. Trying to fight the attackers head-on is an endless war we cannot win; containment is the only rational path to peace.

In summary: the EU server started this conflict by threatening someone’s livelihood, and now we are reaping what we sowed. But we can choose to contain the damage rather than escalate. Block Asian IPs, contain the fire, and let’s have peace.
block chinese IPs

Re: DDoS Round 7

Posted: Thu Sep 03, 2026 8:33 pm
by Praylorswift
Kestrel wrote: Thu Sep 03, 2026 7:43 pm For some more details on todays attack, read below.

The first wave of the attack started at 15:52:31 today targeting our authentication server once again (also flooding our PvE realm, and at the very end of the attack hitting the HC realm). This first attack caused some latency and looting issues on the server, along with a 3% drop in player during a time when our population usually is growing to its daily peek.

The second wave was active from 16:39 until 16:46 and was significantly stronger, and disconnecting 46% of the population, while those who remained still experienced extreme lag/latency.

A developer on the team pushed a change to all realms with a restart at 17:37 attempting to get some mitigations in place.

Wave three went from 17:51-17:54, this time including the PvP realm in the attack but still primarily focusing the flood on the auth server. Mid wave they also changed the shape of their attack going from a full junk traffic flood to a mix of junk traffic and a large number of connection requests to induce connection churn.

A small precursor wave targeted just our radio ports from 13:35-13:42.

Wave four hit from 18:39 until 18:49 the hardest yet nearly instantly bringing our population down 94%. More updates will likely be given once the attack stop.
how are non authenticated requests hitting the game server?