[bf1942] DoS against port 29900

James Gurney james at globalmegacorp.org
Wed Oct 12 01:39:49 EDT 2005

On 10/11/2005 9:31 PM, ScratchMonkey wrote:
> Sounds like a reflection attack. Valve's servers switched to a 
> challenge-response system to shut down this kind of thing. I believe 

Right, that would make sense. That would explain why blocking incoming 
traffic based on the source address didn't help..

> If you spoof your source UDP address to be your victim, and send tiny 
> requests to lots of game servers, they all reply and swamp the victim.

Any idea how to determine the real source address? I still have the 
incoming flood, which is an irritation more than anything else..


