WTF is being spammed in my server logs?

60 Replies
Cubicake
CubicakeOP2y ago
The ip is from a datacentre is this some sort of very slow ddos attack?
ProGamingDk
ProGamingDk2y ago
could also just be a badly made/updated server scanner
Cubicake
CubicakeOP2y ago
its sent like 100 pings with 1/minute Ones from a datacentre in london, the other a datacentre in germany I banned the ips Update Update: Banning the ips didnt work how do i stop this?
jaegyu
jaegyu2y ago
Did you ban it from your server? banning it from your server instance wont change much, but if you're using something like iptables you can drop the packets coming in.
ProGamingDk
ProGamingDk2y ago
ip banning wont ^^
jaegyu
jaegyu2y ago
something like this is probably what you're looking for, but itll only work on a linux box with iptables. sudo iptables -A INPUT -s <IPADDRESS> -j DROP
Cubicake
CubicakeOP2y ago
yea no im using a host so, is this a ddos attack
jaegyu
jaegyu2y ago
i wouldn't say so. like the GamingDk said previously, probably just a scanner
Cubicake
CubicakeOP2y ago
but why is it scanning every minute?
jaegyu
jaegyu2y ago
not too sure, honestly. I havent had that issue before, but I go through AWS, and not a host provider
ProGamingDk
ProGamingDk2y ago
logging player counts and whos on ask ur host to block em if possible
Cubicake
CubicakeOP2y ago
howd they find my server tho?
ProGamingDk
ProGamingDk2y ago
ipv4's arent private they scan 25565/many other ports on every ip
jaegyu
jaegyu2y ago
idk about every ip, they probably know their host's ip ranges, or has associated the ip's as being from a host service but maybe im just ignorant here
ProGamingDk
ProGamingDk2y ago
every ip. and i mean every ip
jaegyu
jaegyu2y ago
ill take your word for it 🤷‍♂️
ProGamingDk
ProGamingDk2y ago
considering i know many of them @mat
jaegyu
jaegyu2y ago
.
ProGamingDk
ProGamingDk2y ago
ye np
Cubicake
CubicakeOP2y ago
well no mc server list has my server
jaegyu
jaegyu2y ago
still, ip's arent private
ProGamingDk
ProGamingDk2y ago
^^ theres a very limited amount of ipv4's
jaegyu
jaegyu2y ago
like, the numbers themselves. theres only a few billion of them
Cubicake
CubicakeOP2y ago
but whyd they scan mine? What are they using the data for?
ProGamingDk
ProGamingDk2y ago
its every ip they are scanning your server isnt "special" private lists, tracking people etc
Cubicake
CubicakeOP2y ago
yea but its annoying and only just started and I want it to stop
ProGamingDk
ProGamingDk2y ago
you cant just tell it to stop ask ur host thats all u can do
Cubicake
CubicakeOP2y ago
also why is it producing an error? shouldnt it be a player joined the game player left the game sort of thing?
ProGamingDk
ProGamingDk2y ago
either for more spam or for this not entirely
Cubicake
CubicakeOP2y ago
also how r they joining as ip:port? and not a player
ProGamingDk
ProGamingDk2y ago
well it just doesnt get to that stage of the login
Shrecknt
Shrecknt2y ago
:trolley:
LanderYT
LanderYT2y ago
Omg I'm getting the same problem So from what I've seen, there's not much I can do to stop this? Which host are you using?
Cubicake
CubicakeOP2y ago
witherhost
LanderYT
LanderYT2y ago
I'm using EnviroMC, but I'm also getting a similar problem, what did you decide to do about this situation?
jaegyu
jaegyu2y ago
. just contact your host's support about blocking the ips.
Bruhdows
Bruhdows2y ago
just get some plugin to block asns
ProGamingDk
ProGamingDk2y ago
"some plugin" not many of those exist and it would have to do it at the netty level
Cubicake
CubicakeOP2y ago
Now its doing this?
[06:44:58 INFO]: com.mojang.authlib.GameProfile@6b388136[id=<null>,name=cuute,properties={},legacy=false] (/20.4.48.76:53804) lost connection: Disconnected
[06:48:49 INFO]: com.mojang.authlib.GameProfile@59a445b4[id=<null>,name=cuute,properties={},legacy=false] (/20.4.48.76:42440) lost connection: Disconnected
[06:52:42 INFO]: com.mojang.authlib.GameProfile@2473c20c[id=<null>,name=cuute,properties={},legacy=false] (/20.4.48.76:36670) lost connection: Disconnected
[06:56:35 INFO]: com.mojang.authlib.GameProfile@1991255a[id=<null>,name=cuute,properties={},legacy=false] (/20.4.48.76:56266) lost connection: Disconnected
[06:44:58 INFO]: com.mojang.authlib.GameProfile@6b388136[id=<null>,name=cuute,properties={},legacy=false] (/20.4.48.76:53804) lost connection: Disconnected
[06:48:49 INFO]: com.mojang.authlib.GameProfile@59a445b4[id=<null>,name=cuute,properties={},legacy=false] (/20.4.48.76:42440) lost connection: Disconnected
[06:52:42 INFO]: com.mojang.authlib.GameProfile@2473c20c[id=<null>,name=cuute,properties={},legacy=false] (/20.4.48.76:36670) lost connection: Disconnected
[06:56:35 INFO]: com.mojang.authlib.GameProfile@1991255a[id=<null>,name=cuute,properties={},legacy=false] (/20.4.48.76:56266) lost connection: Disconnected
Wait my servers 1.19.2 is that the broblem?
Cubicake
CubicakeOP2y ago
https://namemc.com/profile/cuute.1 they r north korean???
NameMC
cuute | Minecraft Profile
Check out cuute’s Minecraft skins, name history, UUID, and much more!
Cubicake
CubicakeOP2y ago
They r either north korean or from amsterdam
No description
No description
Cubicake
CubicakeOP2y ago
im so confused
Shrecknt
Shrecknt2y ago
its a vps, they dont live in amsterdam lol
Cubicake
CubicakeOP2y ago
does that mean they r NK lol? i doubt it
Shrecknt
Shrecknt2y ago
no why would it mean that
Cubicake
CubicakeOP2y ago
because the player's namemc account says North Korea?
Shrecknt
Shrecknt2y ago
the owner of the namemc acc can set the location to whatever they want lol
Cubicake
CubicakeOP2y ago
[07:38:37 INFO]: /176.58.106.79:45444 lost connection: Internal Exception: io.netty.handler.codec.DecoderException: java.io.IOException: Packet 2/0 (PacketLoginInStart) was larger than I expected, found 1 bytes extra whilst reading packet 0
[07:38:37 INFO]: /176.58.106.79:45444 lost connection: Internal Exception: io.netty.handler.codec.DecoderException: java.io.IOException: Packet 2/0 (PacketLoginInStart) was larger than I expected, found 1 bytes extra whilst reading packet 0
also these r still appearing
Shrecknt
Shrecknt2y ago
malformed packets
Cubicake
CubicakeOP2y ago
yes but im so confused why has it changed, and why is their scanner so f'd up? if it isnt done why r they testing on a random server
Shrecknt
Shrecknt2y ago
prod is the best testing env :3
Cubicake
CubicakeOP2y ago
but did they just type a random ip and get my server or r they doingthis to everyone???
Shrecknt
Shrecknt2y ago
check other posts on this server, its happening to everyone
Cubicake
CubicakeOP2y ago
wsgbwetgvdsfv ok but its annoying
7H3
7H32y ago
if a single connection per minute is affecting you like a DDoS attack would, consider not using hardware made in 1998 are you using a host or can you block the ip with iptables etc? yeah so there's not much to do aside from that
ProGamingDk
ProGamingDk2y ago
LOL
Cubicake
CubicakeOP2y ago
XD no its just hard to read console Also, ive blocked them with a "firewall rule"
7H3
7H32y ago
nice I've seen reports they appear from multiple IPs so if it ever happens just block that IP as well
rion
rion2y ago
Think there is any risk to them? I've been getting a ton today, and I just noticed them starting up recently.
ProGamingDk
ProGamingDk2y ago
Nah

Did you find this page helpful?