<html>
    <head>
      <base href="https://bugzilla.icculus.org/" />
    </head>
    <body><table border="1" cellspacing="0" cellpadding="8">
        <tr>
          <th>Bug ID</th>
          <td><a class="bz_bug_link 
          bz_status_NEW "
   title="NEW --- - DDOS with getchallenge"
   href="https://bugzilla.icculus.org/show_bug.cgi?id=5954">5954</a>
          </td>
        </tr>

        <tr>
          <th>Summary</th>
          <td>DDOS with getchallenge
          </td>
        </tr>

        <tr>
          <th>Classification</th>
          <td>Unclassified
          </td>
        </tr>

        <tr>
          <th>Product</th>
          <td>ioquake3
          </td>
        </tr>

        <tr>
          <th>Version</th>
          <td>unspecified
          </td>
        </tr>

        <tr>
          <th>Hardware</th>
          <td>All
          </td>
        </tr>

        <tr>
          <th>OS</th>
          <td>All
          </td>
        </tr>

        <tr>
          <th>Status</th>
          <td>NEW
          </td>
        </tr>

        <tr>
          <th>Severity</th>
          <td>blocker
          </td>
        </tr>

        <tr>
          <th>Priority</th>
          <td>P3
          </td>
        </tr>

        <tr>
          <th>Component</th>
          <td>Misc
          </td>
        </tr>

        <tr>
          <th>Assignee</th>
          <td>zachary@ioquake.org
          </td>
        </tr>

        <tr>
          <th>Reporter</th>
          <td>jawfin@gmail.com
          </td>
        </tr>

        <tr>
          <th>QA Contact</th>
          <td>quake3-bugzilla@icculus.org
          </td>
        </tr></table>
      <p>
        <div>
        <pre>I hope I'm posting in the correct forum, apologies if not.
I was directed here from: -
<a href="https://github.com/Razish/OpenJK/issues/281">https://github.com/Razish/OpenJK/issues/281</a>

This related to Jedi Knight:Jedi Academy, specifically the work done by the
guys in the OpenJK project.

Although there is flood protection on getstatus and getinfo, its not aggressive
enough to stop our server from lagging out with what's allowed through.

But my principle issue is protection for getchallenge.  A DDOS attack sending
getchallenge packets completely lags the server and prevents legitimate
connections from happening.  After a period of time the server crashes.

I can get more information if required, my server is hosted by EscapedTurkey
and I can ask them for whatever is needed to solve this.

Thanks for your help
Cheers
Jonathan</pre>
        </div>
      </p>
      <hr>
      <span>You are receiving this mail because:</span>
      
      <ul>
          <li>You are the QA Contact for the bug.</li>
      </ul>
    </body>
</html>