can anyone help please?

Discussion in 'Spearhead' started by welshwolf, Feb 1, 2012.

  1. LeBabouin Papio anubis

    Contributions:
    419
    Specialties:
    Scripting
    Processing:
    Graphics:
    PREMIUM
    I Donated
    How do you ban those IP's from your box? Do you add routes to nowhere or have you applied some other techbnique ?
  2. loeri loeri.tk

    Contributions:
    45
    Specialties:
    Mapper, Scripting, Programming, Support
    Processing:
    Graphics:
    PREMIUM
    I Donated
    LeBabouin likes this.
  3. LeBabouin Papio anubis

    Contributions:
    419
    Specialties:
    Scripting
    Processing:
    Graphics:
    PREMIUM
    I Donated
  4. zlatko Staff Sergeant

    Contributions:
    146
    Specialties:
    Mapper, Scripting, Pure Gamer
    Processing:
    Graphics:
    PREMIUM
    I Donated
    yes this is great but only for dedicated servers
    servers for rent does not work:(
  5. LeBabouin Papio anubis

    Contributions:
    419
    Specialties:
    Scripting
    Processing:
    Graphics:
    PREMIUM
    I Donated
    for rented servers just use Daven's "sv addip" and "sv writeip" commands, that works 100%.
    I finally found the way to block IP's on 2003 servers without making the route table more heavy. That might be usefull to someone including me when i'll loose the address:

    Configure the IP Security Policy to block your first IP address
    1. Click “Start” and “Run” – type “MMC” and press OK.
    2. In the MMC, click “File” and “Add/Remove Snap In.”
    3. In the “Standalone” tab, click “Add.”
    4. Select “IP Security Policy Management” and click “Add.”
    5. Select “Local Computer” and click “Finish.”
    6. Close the “Add standalone Snap-in” window and click “OK” on the “Add/Remove Snap-in” window.
    7. Now that you are back in the MMC console, right-click on “IP Security Policies on Local Computer” in the left-hand pane and select “Create IP Security Policy.”
    8. Click “Next.”
    9. Enter a name (ex. IP Block List) and description into the boxes and click “Next.”
    10. Leave “Activate the default response rule” checked. Click “Next.”
    11. Leave “Active Directory default (Kerberos)” checked. Click “Next.”
    12. Leave “Edit properties” checked. Click “Finish.”
    13. The Properties box should be open.
    14. To add your first IP address, click “Add.” Make sure “Use Add Wizard” is checked beside the button.
    15. Click “Next” when the “Create IP Security Rule” wizard opens.
    16. Leave “This rule does not specify a tunnel” checked. Click “Next.”
    17. Select “All network connections” under Network Type (unless you want to specify by adapter). Click “Next.”
    18. You are now at the “IP Filter List.” The “All ICMP Traffic” and “All IP Traffic” options will not meet our needs; we will need to add another. Click “Add.”
    19. Name the IP Filter List (ex. Blocked IP List) and enter a description. Click “Add” to enter the first IP address to block.
    20. The “IP Filter Wizard” will pop up. Click “Next.”
    21. This will be the first IP address or IP range we enter to block. Enter a description (I usually enter the IP itself) and make sure “Mirrored” is selected below. This will ensure packets to/from are blocked, allowing you to create one rule instead of two. Click “Next.”
    22. Keep “Source Address” as “My IP Address” and click “Next.”
    23. Under “Destination Address” select “A specific IP Address” or “A specific IP Subnet.” If you select “Any IP address” it will block all IPs!
    24. Enter in the IP address in the fields below and click “Next.”
    25. Under “select protocol type” choose “Any” (means “All”) unless you specifically want to block from RDP (Remote Desktop), TCP or UDP, etc. Click “Next.”
    26. Click “Finish.”
    27. Now that you are back to the “IP Filter List” click “OK.”
    28. You will be back in the “IP Filter List” list in the Security Rule Wizard – make sure you select your new “Blocked IP List” and not “All IP Traffic” or “All ICMP Traffic.” Click “Next.”
    29. You will be taken to “Filter Action.” The lists: Permit, Request Security (Optional), and Require Security will not meet our needs. Click “Add.”
    30. In the “IP Security Filter Action” wizard, click “Next.”
    31. Select a name (ex. Block all Packets) and click “Next.”
    32. Select “Block” for the filter action behavior. Click “Next.”
    33. Click “Finish.”
    34. You are back to the “Filter Action” list. Select your new list (Block All Packets) and click “Next.”
    35. Click “Finish.”
    36. You are back to your IP Security Policy list (Blocked IP List) Properties. Click “OK.”
    37. Back in the “IP Security Policies on Local Computer” snap-in, you’ll need to assign the new policy. In the right-hand pane, right-click on your new list (IP Block List) and select “assign.”
    To make it easier the next time you wish to block an IP address, save the MMC Snap-in configuration as a shortcut. Go to “File” and “Save As” and save it on your Desktop or Start Menu.
    To Block Additional IP Addresses
    1. Enter the IP Block List snap-in you saved.
    2. In the right-hand pane double-click your IP Block List.
    3. Under “IP Filter List” select the newly created “Blocked IP List” and click “Edit.” Make sure “Use Add Wizard” is checked.
    4. Under “IP Filter Lists” select your “Blocked IP List” (not All ICMP or IP Traffic) and click “Edit.”
    5. You are now in the “Add IP wizard” area. You will see the first IP address you blocked in a listing under “IP Filters.” Click “Add.”
    6. Follow all previous steps to add the IP address you wish to block. Once finished, exit all dialog boxes.
    You may need to restart the server for the settings to take effect.
    Spyke and zlatko like this.
  6. zlatko Staff Sergeant

    Contributions:
    146
    Specialties:
    Mapper, Scripting, Pure Gamer
    Processing:
    Graphics:
    PREMIUM
    I Donated
    merci mon ami!!!C'est merveilleux!!!
    I already use it
    daven before the time it gave me also said how toset it up
  7. LeBabouin Papio anubis

    Contributions:
    419
    Specialties:
    Scripting
    Processing:
    Graphics:
    PREMIUM
    I Donated
    3 to add:

    88.198.47.216
    64.85.162.149
    64.85.162.150
  8. Toaster Private First Class

    Contributions:
    1
    Processing:
    Graphics:
    Well I guess I am not alone. I use Davens patch but it the getstatus still floods in. All the Ip's come from other servers and a google search has them all using gametracker
  9. loeri loeri.tk

    Contributions:
    45
    Specialties:
    Mapper, Scripting, Programming, Support
    Processing:
    Graphics:
    PREMIUM
    I Donated
    Get status can also be because off xfire.. just to say!
  10. Toaster Private First Class

    Contributions:
    1
    Processing:
    Graphics:
    I blocked the ip's in server 2008 firewall and it worked. I wonder why Davens patches did not work for me.
  11. LeBabouin Papio anubis

    Contributions:
    419
    Specialties:
    Scripting
    Processing:
    Graphics:
    PREMIUM
    I Donated
    yes and all other server browsers too, including downloadable overflowers :rolleyes: like those we posted above. That would be beneficial to all if anyone getting overflowed post the IP's asap so other people can block those before getting attacked.
  12. Toaster Private First Class

    Contributions:
    1
    Processing:
    Graphics:
    88.198.47.216
    64.85.162.148 to 150
    LeBabouin likes this.
  13. LeBabouin Papio anubis

    Contributions:
    419
    Specialties:
    Scripting
    Processing:
    Graphics:
    PREMIUM
    I Donated
    tya m8!
    66.150.121.181
  14. Toaster Private First Class

    Contributions:
    1
    Processing:
    Graphics:
    For some reason the 66.150.121.181 is getting around windows 2008 firewall even though its blocked. I also see an occasional 108.61.78.148 : -15046
  15. Silent*Angel Corporal

    Contributions:
    6
    Specialties:
    Scripting, Programming
    Processing:
    Graphics:
    SV packet 94.23.153.11:22003 : getstatus

    ...damn everytime I start the server it crush cause of this! o_O one more to add
    LeBabouin likes this.
  16. modder Corporal

    Contributions:
    19
    Specialties:
    Scripting, Programming, Pure Gamer
    Processing:
    Graphics:
    Silent Angel what type of server do you run? I got attacked by
    this IP too.
  17. Silent*Angel Corporal

    Contributions:
    6
    Specialties:
    Scripting, Programming
    Processing:
    Graphics:
    Rented SH server! Damn tonight it crashed my server again..2 times! This brings me to madness. Also I'm trying to add these IPs in listip.cfg via sv addip command but after some time the listip.cfg delete it's content! :(
  18. loeri loeri.tk

    Contributions:
    45
    Specialties:
    Mapper, Scripting, Programming, Support
    Processing:
    Graphics:
    PREMIUM
    I Donated
    Why do you people have this? I run like 9 servers and not even one crashed because off the get status.

    Edit: I just searched for port 22003, it looks like its an (FTP) Remote System Access Exploit not for moh but something called Farmers WIFE 4.4 SP1, don't ask me what that is :D

    Port 27017: Port used by Valve Steam Friends, an instant messaging protocol that is built into Steam, Counter-Strike, Xpire, MBL TF2 Tango. - Remote Buffer Overflow Exploit -

    Port 27015: Port used by Steam servers for online gaming, Half-Life and its mods, such as Counter-Strike.
    Empire: Total War, developer: The Creative Assembly
    Left 4 Dead, developer: Valve Corporation
    Team Fortress 2, developer: Valve
    - Remote Buffer Overflow Exploit -
    zlatko likes this.
  19. Silent*Angel Corporal

    Contributions:
    6
    Specialties:
    Scripting, Programming
    Processing:
    Graphics:
    luky admin lol
  20. Silent*Angel Corporal

    Contributions:
    6
    Specialties:
    Scripting, Programming
    Processing:
    Graphics:
    80.143.76.68
    LeBabouin likes this.

Share This Page