<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[DDoS and now something new again?]]></title><description><![CDATA[<p dir="auto">The game begins. A few minutes later, the connection to all players is lost and my own internet connection stops working for about 5 minutes.</p>
<p dir="auto">This has happened several times now. At first, I thought it was my own internet connection, as it was completely down for all devices. But no, it's FAF's fault.</p>
<p dir="auto">What is being attacked here again, what security vulnerability is being exploited?</p>
<p dir="auto">The behavior has also been documented by others on Discord, but I have not yet read any official statement from a faf team member.</p>
<p dir="auto"><img src="/assets/uploads/files/1755963480947-67867868.jpg" alt="67867868.jpg" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.faforever.com/topic/9440/ddos-and-now-something-new-again</link><generator>RSS for Node</generator><lastBuildDate>Thu, 04 Jun 2026 12:07:20 GMT</lastBuildDate><atom:link href="https://forum.faforever.com/topic/9440.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 23 Aug 2025 15:07:56 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to DDoS and now something new again? on Wed, 01 Oct 2025 13:02:01 GMT]]></title><description><![CDATA[<p dir="auto"><img src="/assets/uploads/files/1759322920723-attack-vectors-dnsfragment.jpg" alt="Attack vectors DNSFRAGMENT.jpg" class=" img-fluid img-markdown" /></p>
<p dir="auto">Since I play via my own vpn, i can see what is attacking me when I play faf.</p>
<p dir="auto">Attack type: UDP DNS Fragment Flood<br />
Source ports: Variable high ports (commonly around 40000)<br />
Destination port: UDP 53 (DNS)<br />
Always relatively short (but enough to ruin a match).</p>
<p dir="auto">And no, nothing else runs on this server, and I only ever use it when I play faf.</p>
]]></description><link>https://forum.faforever.com/post/69557</link><guid isPermaLink="true">https://forum.faforever.com/post/69557</guid><dc:creator><![CDATA[Sturmgewehr]]></dc:creator><pubDate>Wed, 01 Oct 2025 13:02:01 GMT</pubDate></item><item><title><![CDATA[Reply to DDoS and now something new again? on Sun, 07 Sep 2025 04:35:57 GMT]]></title><description><![CDATA[<p dir="auto">So it seems... I can connect to other Australia or NZ players, or I can connect to US players with a US VPN... but it definitely seems AUS/NZ has been isolated.</p>
]]></description><link>https://forum.faforever.com/post/69199</link><guid isPermaLink="true">https://forum.faforever.com/post/69199</guid><dc:creator><![CDATA[Gibsaw]]></dc:creator><pubDate>Sun, 07 Sep 2025 04:35:57 GMT</pubDate></item><item><title><![CDATA[Reply to DDoS and now something new again? on Sat, 06 Sep 2025 22:09:07 GMT]]></title><description><![CDATA[<p dir="auto">Well, whatever has been done. I can no longer connect <em>AT ALL</em>.  Goes straight from "checking" to "disconnected" for all players.</p>
<p dir="auto">So how do I help? Logs? If so, where do I upload them?</p>
]]></description><link>https://forum.faforever.com/post/69196</link><guid isPermaLink="true">https://forum.faforever.com/post/69196</guid><dc:creator><![CDATA[Gibsaw]]></dc:creator><pubDate>Sat, 06 Sep 2025 22:09:07 GMT</pubDate></item><item><title><![CDATA[Reply to DDoS and now something new again? on Sat, 06 Sep 2025 19:35:28 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/sturmgewehr" aria-label="Profile: Sturmgewehr">@<bdi>Sturmgewehr</bdi></a> said in <a href="/post/69170">DDoS and now something new again?</a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/brutus5000" aria-label="Profile: Brutus5000">@<bdi>Brutus5000</bdi></a> Is it possible to have a client update for the weekend where all connections go through relay only, to see what happens?<br />
Better / worse / the same.</p>
<p dir="auto">Currently completely unplayable.<br />
Unless you are already working on a good solution, I don't see any other plan that can be implemented quickly to possibly improve the situation.</p>
<p dir="auto">At the very least, further steps could then be planned based on the knowledge gained.</p>
</blockquote>
<p dir="auto">Yes, this is what we did for now. If this solves it, we'll work on more cost-effective solutions to keep it like that.</p>
]]></description><link>https://forum.faforever.com/post/69195</link><guid isPermaLink="true">https://forum.faforever.com/post/69195</guid><dc:creator><![CDATA[Brutus5000]]></dc:creator><pubDate>Sat, 06 Sep 2025 19:35:28 GMT</pubDate></item><item><title><![CDATA[Reply to DDoS and now something new again? on Sat, 06 Sep 2025 18:27:27 GMT]]></title><description><![CDATA[<p dir="auto"><a href="https://discord.com/channels/197033481883222026/197078254681587712/1413952423827079249" rel="nofollow ugc">https://discord.com/channels/197033481883222026/197078254681587712/1413952423827079249</a></p>
]]></description><link>https://forum.faforever.com/post/69192</link><guid isPermaLink="true">https://forum.faforever.com/post/69192</guid><dc:creator><![CDATA[Giebmasse]]></dc:creator><pubDate>Sat, 06 Sep 2025 18:27:27 GMT</pubDate></item><item><title><![CDATA[Reply to DDoS and now something new again? on Sat, 06 Sep 2025 01:42:33 GMT]]></title><description><![CDATA[<p dir="auto">@Lenkin is GAF getting DDossed too? i</p>
]]></description><link>https://forum.faforever.com/post/69177</link><guid isPermaLink="true">https://forum.faforever.com/post/69177</guid><dc:creator><![CDATA[Prophet-]]></dc:creator><pubDate>Sat, 06 Sep 2025 01:42:33 GMT</pubDate></item><item><title><![CDATA[Reply to DDoS and now something new again? on Fri, 05 Sep 2025 17:44:43 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/brutus5000" aria-label="Profile: Brutus5000">@<bdi>Brutus5000</bdi></a> Is it possible to have a client update for the weekend where all connections go through relay only, to see what happens?<br />
Better / worse / the same.</p>
<p dir="auto">Currently completely unplayable.<br />
Unless you are already working on a good solution, I don't see any other plan that can be implemented quickly to possibly improve the situation.</p>
<p dir="auto">At the very least, further steps could then be planned based on the knowledge gained.</p>
]]></description><link>https://forum.faforever.com/post/69170</link><guid isPermaLink="true">https://forum.faforever.com/post/69170</guid><dc:creator><![CDATA[Sturmgewehr]]></dc:creator><pubDate>Fri, 05 Sep 2025 17:44:43 GMT</pubDate></item><item><title><![CDATA[Reply to DDoS and now something new again? on Fri, 05 Sep 2025 17:42:35 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/limez3_" aria-label="Profile: LimeZ3_">@<bdi>LimeZ3_</bdi></a> said in <a href="/post/69167">DDoS and now something new again?</a>:</p>
<blockquote>
<p dir="auto">@Lenkin<br />
Just a "what if"<br />
What if GAF has all the same vulnerabilities, but just doesn't get ddosed?<br />
I can only guess the reasons why.</p>
</blockquote>
<p dir="auto">My understanding is GAF does get DDOSed, but it routes all its connections through a central server so it's much less of a problem. It can do that because it has MUCH fewer players than FAF does</p>
]]></description><link>https://forum.faforever.com/post/69169</link><guid isPermaLink="true">https://forum.faforever.com/post/69169</guid><dc:creator><![CDATA[Deribus]]></dc:creator><pubDate>Fri, 05 Sep 2025 17:42:35 GMT</pubDate></item><item><title><![CDATA[Reply to DDoS and now something new again? on Fri, 05 Sep 2025 17:04:22 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/defiant" aria-label="Profile: Defiant">@<bdi>Defiant</bdi></a> university degree, dutch version</p>
]]></description><link>https://forum.faforever.com/post/69168</link><guid isPermaLink="true">https://forum.faforever.com/post/69168</guid><dc:creator><![CDATA[LimeZ3_]]></dc:creator><pubDate>Fri, 05 Sep 2025 17:04:22 GMT</pubDate></item><item><title><![CDATA[Reply to DDoS and now something new again? on Fri, 05 Sep 2025 17:01:25 GMT]]></title><description><![CDATA[<p dir="auto">@Lenkin<br />
Just a "what if"<br />
What if GAF has all the same vulnerabilities, but just doesn't get ddosed?<br />
I can only guess the reasons why.</p>
]]></description><link>https://forum.faforever.com/post/69167</link><guid isPermaLink="true">https://forum.faforever.com/post/69167</guid><dc:creator><![CDATA[LimeZ3_]]></dc:creator><pubDate>Fri, 05 Sep 2025 17:01:25 GMT</pubDate></item><item><title><![CDATA[Reply to DDoS and now something new again? on Fri, 05 Sep 2025 16:53:06 GMT]]></title><description><![CDATA[<p dir="auto">I checked with my internet provider<br />
They said "your IP is dynamic and it changes automatically once every 24 h"<br />
There is no way I can change my IP myself, outside of that</p>
]]></description><link>https://forum.faforever.com/post/69164</link><guid isPermaLink="true">https://forum.faforever.com/post/69164</guid><dc:creator><![CDATA[LimeZ3_]]></dc:creator><pubDate>Fri, 05 Sep 2025 16:53:06 GMT</pubDate></item><item><title><![CDATA[Reply to DDoS and now something new again? on Fri, 05 Sep 2025 14:58:35 GMT]]></title><description><![CDATA[<p dir="auto">SO how GAF makes their new Fire adapter? Does they spend so much money for this? Do faf realy cant spend donations to save server? Im sure it shouldnt cost so much money anyway, it cant be superexpensive just to fix this fuckn ip leak. Do this or faf dies, dont u understand?  Let's just wait for it to go away on its own as always.</p>
]]></description><link>https://forum.faforever.com/post/69159</link><guid isPermaLink="true">https://forum.faforever.com/post/69159</guid><dc:creator><![CDATA[xxx_LenKing_xxx]]></dc:creator><pubDate>Fri, 05 Sep 2025 14:58:35 GMT</pubDate></item><item><title><![CDATA[Reply to DDoS and now something new again? on Thu, 04 Sep 2025 18:19:33 GMT]]></title><description><![CDATA[<p dir="auto">Same thing here. Thought my pc was broken. I even timed out connecting to this forum. AFter exiting the game nothing would load until I ran a network test and the Nvidia overlay popped up like id just entered a game again and my internet suddenly works perfectly.</p>
]]></description><link>https://forum.faforever.com/post/69133</link><guid isPermaLink="true">https://forum.faforever.com/post/69133</guid><dc:creator><![CDATA[hulgarth]]></dc:creator><pubDate>Thu, 04 Sep 2025 18:19:33 GMT</pubDate></item><item><title><![CDATA[Reply to DDoS and now something new again? on Tue, 02 Sep 2025 16:30:05 GMT]]></title><description><![CDATA[<p dir="auto">Anecdotally, after mucking around in 2 lobbies that instantly crashed for 40 mins, I went to play Starcraft 2 ladder and got 2 disconnects that forced me to forfeit a few hours apart, which is very rare (2 in one day is unheard of). So yeah I would not play custom lobbies without unplugging your router for 10 mins afterward if you play other competitive games like Starcraft or Counter Strike because until your IP changes it's gonna get hit.</p>
<p dir="auto">Really unfortunate stuff, although I can't say I'm surprised people this manchildtarded lurk among the playerbase.</p>
]]></description><link>https://forum.faforever.com/post/69083</link><guid isPermaLink="true">https://forum.faforever.com/post/69083</guid><dc:creator><![CDATA[Zeldafanboy]]></dc:creator><pubDate>Tue, 02 Sep 2025 16:30:05 GMT</pubDate></item><item><title><![CDATA[Reply to DDoS and now something new again? on Tue, 02 Sep 2025 12:53:45 GMT]]></title><description><![CDATA[<p dir="auto">Time to take out my "The end is near" sign. This shit is legit scary. I am not logging in until this is over.</p>
]]></description><link>https://forum.faforever.com/post/69081</link><guid isPermaLink="true">https://forum.faforever.com/post/69081</guid><dc:creator><![CDATA[Kilatamoro]]></dc:creator><pubDate>Tue, 02 Sep 2025 12:53:45 GMT</pubDate></item><item><title><![CDATA[Reply to DDoS and now something new again? on Tue, 02 Sep 2025 12:22:35 GMT]]></title><description><![CDATA[<p dir="auto">I didnt formulate myself correctly. I was aware that you see ips of others while ingame with them. However, these attacks happened by people outside of these games without ever having connected to the lobby</p>
]]></description><link>https://forum.faforever.com/post/69080</link><guid isPermaLink="true">https://forum.faforever.com/post/69080</guid><dc:creator><![CDATA[Nuggets]]></dc:creator><pubDate>Tue, 02 Sep 2025 12:22:35 GMT</pubDate></item><item><title><![CDATA[Reply to DDoS and now something new again? on Tue, 02 Sep 2025 11:35:55 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nuggets" aria-label="Profile: Nuggets">@<bdi>Nuggets</bdi></a> As far as I am aware, all games that use peer to peer will in general expose your IP. Supreme Commander is not any different here. There's an interesting support ticket about the topic from Steam Support:</p>
<ul>
<li><a href="https://help.steampowered.com/en/faqs/view/1433-AD20-F11D-B71E" rel="nofollow ugc">https://help.steampowered.com/en/faqs/view/1433-AD20-F11D-B71E</a></li>
</ul>
<p dir="auto">The solution is to work via relays. Which is what Brutus describes here:</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/brutus5000" aria-label="Profile: Brutus5000">@<bdi>Brutus5000</bdi></a> said in <a href="/post/69034">DDoS and now something new again?</a>:</p>
<blockquote>
<p dir="auto">The ice adapter can do that in theory. This is called using a relay server. We used to run our own but they get killed by DDoS too. Now we are running the relay servers at a 3rd party provider but they are very expensive. so we cannot allow everybody to use it just to hide their ips.</p>
<p dir="auto">We tried a cheaper provider but it doesn't work with the current ice adapter. So we're trying to rewrite it, but it doesn't work reliably beyond 1v1</p>
</blockquote>
<p dir="auto">We're not there yet though. And we could really use the help of people with the right expertise to investigate it further.</p>
]]></description><link>https://forum.faforever.com/post/69079</link><guid isPermaLink="true">https://forum.faforever.com/post/69079</guid><dc:creator><![CDATA[Jip]]></dc:creator><pubDate>Tue, 02 Sep 2025 11:35:55 GMT</pubDate></item><item><title><![CDATA[Reply to DDoS and now something new again? on Tue, 02 Sep 2025 11:19:21 GMT]]></title><description><![CDATA[<p dir="auto">I was not aware that public ips can be seen in any game. Since i now know this i will never play faf without vpn again because this is an absolute disaster for someone like me who hosts his own stuff</p>
]]></description><link>https://forum.faforever.com/post/69078</link><guid isPermaLink="true">https://forum.faforever.com/post/69078</guid><dc:creator><![CDATA[Nuggets]]></dc:creator><pubDate>Tue, 02 Sep 2025 11:19:21 GMT</pubDate></item><item><title><![CDATA[Reply to DDoS and now something new again? on Tue, 02 Sep 2025 02:55:52 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/limez3_" aria-label="Profile: LimeZ3_">@<bdi>LimeZ3_</bdi></a> said in <a href="/post/68989">DDoS and now something new again?</a>:</p>
<blockquote>
<p dir="auto">HBO in network security</p>
</blockquote>
<p dir="auto">What is "an HBO in network security"?</p>
]]></description><link>https://forum.faforever.com/post/69075</link><guid isPermaLink="true">https://forum.faforever.com/post/69075</guid><dc:creator><![CDATA[Defiant]]></dc:creator><pubDate>Tue, 02 Sep 2025 02:55:52 GMT</pubDate></item><item><title><![CDATA[Reply to DDoS and now something new again? on Tue, 02 Sep 2025 01:36:42 GMT]]></title><description><![CDATA[<p dir="auto">Had the first time experiencing this like 2-3 weeks ago when somewhere in the first 0-5 min of a game like 5/6 out of 12 ppl's internet completely bricked.</p>
<p dir="auto">Since then i've had my internet crash like 2/3 times (most of the time only for +-2 min), and for comparison i normally have issues like once a year.</p>
<p dir="auto">Dont have any logs sadly didn't think of it, just putting it here as another point on a graph.</p>
]]></description><link>https://forum.faforever.com/post/69073</link><guid isPermaLink="true">https://forum.faforever.com/post/69073</guid><dc:creator><![CDATA[KnownSniper]]></dc:creator><pubDate>Tue, 02 Sep 2025 01:36:42 GMT</pubDate></item><item><title><![CDATA[Reply to DDoS and now something new again? on Mon, 01 Sep 2025 19:49:30 GMT]]></title><description><![CDATA[<p dir="auto">Same. Now, I failed to connect to players in any lobby -- am I being personally attacked, due to my IP being exposed?</p>
]]></description><link>https://forum.faforever.com/post/69072</link><guid isPermaLink="true">https://forum.faforever.com/post/69072</guid><dc:creator><![CDATA[rampeer]]></dc:creator><pubDate>Mon, 01 Sep 2025 19:49:30 GMT</pubDate></item><item><title><![CDATA[Reply to DDoS and now something new again? on Mon, 01 Sep 2025 14:09:12 GMT]]></title><description><![CDATA[<p dir="auto">man this is frustrating. half my games i disconnect within 6 minutes of the game starting. Completely drops my internet. These losers need to get a life and stop trying to ruin FAF</p>
]]></description><link>https://forum.faforever.com/post/69070</link><guid isPermaLink="true">https://forum.faforever.com/post/69070</guid><dc:creator><![CDATA[Prophet-]]></dc:creator><pubDate>Mon, 01 Sep 2025 14:09:12 GMT</pubDate></item><item><title><![CDATA[Reply to DDoS and now something new again? on Mon, 01 Sep 2025 11:53:57 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/sainse" aria-label="Profile: Sainse">@<bdi>Sainse</bdi></a> The logging level should be DEBUG and the box for the ICE log has to be checked. IRC is logged by default.</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/thorkan" aria-label="Profile: Thorkan">@<bdi>Thorkan</bdi></a> PM conversations can not be seen again, when the client was closed. When you have indications or evidence that there is a malicious actor, then contact the moderators through a moderation ticket, please.</p>
]]></description><link>https://forum.faforever.com/post/69068</link><guid isPermaLink="true">https://forum.faforever.com/post/69068</guid><dc:creator><![CDATA[magge]]></dc:creator><pubDate>Mon, 01 Sep 2025 11:53:57 GMT</pubDate></item><item><title><![CDATA[Reply to DDoS and now something new again? on Mon, 01 Sep 2025 11:26:07 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/blackyps" aria-label="Profile: BlackYps">@<bdi>BlackYps</bdi></a> I'ts the landlords router. I don't have access. Does anyone have answers to my 2 questions? That's were we have a clue.</p>
]]></description><link>https://forum.faforever.com/post/69066</link><guid isPermaLink="true">https://forum.faforever.com/post/69066</guid><dc:creator><![CDATA[Thorkan]]></dc:creator><pubDate>Mon, 01 Sep 2025 11:26:07 GMT</pubDate></item></channel></rss>