WeepCraft spam?

Discussion in 'Server & Community Management' started by HiddenCloud, Mar 17, 2013.

  1. Hi guys, just yesterday I noticed heaps and heaps of 'lost connection' reports in my console. First I thought it was DDoS, but if it was it shouldn't show up on the mc console. Then some kids started mentioning weepcraft. Turns out someone's been using weepcraft to try to crash my server for 2 days in a row. (he didnt manage, but it causes some lag)

    Is there any way this can be blocked? I have a premium server and the crasher pings the server over and over with proxys. I already have an anti-proxy plugin, but it doesn't block ping spam.

    Regards, HiddenCloud
     
  2. This is very strange. Im getting people on my server saying "WeepCraft will shut you down" and now parts of my world have currupted chunks -_-

    Also getting this in console, never seen anything like this before.

    [​IMG]

    9.161:59354]: Outdated client!
    18:30:07
    CONSOLE:
    [INFO] Disconnecting Td0gHs40 [/185.2.12.77:4757]: Outdated client!
    18:30:09
    CONSOLE:
    [INFO] CrucialBlade issued server command: /warp spawn
    18:30:09
    CONSOLE:
    [INFO] BryanRadecki issued server command: /msg cole yay no more lag
    18:30:11
    INFO:
    Old player furby121 is logging in.
    18:30:11
    CONSOLE:
    furby121 has logged in.
    18:30:11
    CONSOLE:
    [INFO] furby121[/69.159.57.104:52555] logged in with entity id 15511 at ([world] -9624.472104373752, 7.0, -420.5221704667436)
    18:30:11
    CONSOLE:
    [INFO] Disconnecting qnTWR8mV [/1.214.208.114:58849]: Outdated client!
    18:30:11
    CONSOLE:
    [INFO] Disconnecting qnTWR8mV [/212.49.70.48:4033]: Outdated client!
    18:30:11
    CONSOLE:
    [INFO] Disconnecting JCgAuHmu [/178.150.156.219:3461]: Outdated client!
    18:30:11
    CONSOLE:
    [INFO] Disconnecting L53RYxjd [/209.190.33.13:3668]: Outdated client!
    18:30:11
    CONSOLE:
    [INFO] /109.195.23.55:3771 lost connection
    18:30:11
    CONSOLE:
    [INFO] 6Hunter: deathwatch57r8 8was 48 by 6Hunter: coconutcream227r8.
    18:30:11
    CONSOLE:
    [INFO] Disconnecting ZNJrNjXb [/46.37.209.49:50485]: Outdated client!
    18:30:11
    CONSOLE:
    [INFO] Disconnecting RtJwS6ON [/46.37.209.49:50492]: Outdated client!
    18:30:11
    CONSOLE:
    [INFO] Disconnecting ch3qF1zC [/90.207.69.161:59419]: Outdated client!
    18:30:11
    CONSOLE:
    [INFO] Disconnecting RtJwS6ON [/216.83.60.76:9224]: Outdated client!
    18:30:13
    CONSOLE:
    [INFO] PvPGoDs Hunter: Marc724: lev
    18:30:13
    CONSOLE:
    [INFO] Disconnecting ch3qF1zC [/202.101.209.219:3705]: Outdated client!
    18:30:13
    CONSOLE:
    [INFO] Disconnecting o6A34z1t [/185.2.12.77:3210]: Outdated client!
    18:30:13
    PLAYER_COMMAND:
    _DeadCurent_: /f who criminal
    18:30:13
    CONSOLE:
    [INFO] Hickstar issued server command: /r and u could reward me
    18:30:13
    CONSOLE:
    [INFO] Disconnecting brsLy7jP [/202.113.65.229:4852]: Outdated client!
    18:30:15
    CONSOLE:
    [INFO] Disconnecting TlRRAYcT [/202.113.65.229:3164]: Outdated client!
    18:30:15
    CONSOLE:
    [INFO] PvPGoDs Hunter: Marc724: 1v1
    18:30:15
    CONSOLE:
    [INFO] Disconnecting TlRRAYcT [/202.101.209.219:4046]: Outdated client!
    18:30:15
    CONSOLE:
    [INFO] Disconnecting JOTN7ktE [/178.150.156.219:2335]: Outdated client!
    18:30:17
    CONSOLE:
    [INFO] tubbychicco issued server command: /spawn
    18:30:17
    CONSOLE:
    [INFO] Disconnecting 5Hnr4GXy [/1.214.208.114:58930]: Outdated client!
    18:30:17
    PLAYER_COMMAND:
    Leninavenger12: /f show unstopablezing
    18:30:17
    CONSOLE:
    [INFO] 7[6c67] c[Tickets] bSupport: FusionRush-MC.com/support.html 9Ban Appeal: FusionRush-MC.com/banappeal.html3 Report Player: FusionRush-MC.com/reportplayer.html
    18:30:17
    CONSOLE:
    [INFO] Disconnecting Z08f7BPM [/212.49.70.48:1521]: Outdated client!
    18:30:17
    CONSOLE:
    [INFO] Disconnecting fMiXlkSt [/90.207.69.161:59489]: Outdated client!
    18:30:17
    PLAYER_COMMAND:
    _DeadCurent_: /f who lenina
    18:30:17
    CONSOLE:
    [INFO] mncscom issued server command: /home
    18:30:19
    CONSOLE:
    [INFO] Disconnecting DcQfjXAQ [/212.49.70.48:1229]: Outdated client!
    18:30:19
    CONSOLE:
    [INFO] Disconnecting 2dybQqyN [/59.11.237.151:1352]: Outdated client!
    18:30:19
    PLAYER_COMMAND:
    furby121: /f who
    18:30:19
    CONSOLE:
    [INFO] Disconnecting Dd4BoFb7 [/185.2.12.77:1697]: Outdated client!
    18:30:19
    CONSOLE:
    [INFO] Disconnecting Dd4BoFb7 [/90.207.69.161:59504]: Outdated client!
    18:30:19
    CONSOLE:
    [INFO] Disconnecting Dd4BoFb7 [/216.83.60.76:10893]: Outdated client!
    18:30:19
    NoCheatPlus:
    Pixelsboy failed FastBreak: tried to break blocks (4) faster than possible. VL 5.
    18:30:21
    CONSOLE:
    [INFO] Disconnecting kTNpZjeR [/178.150.156.219:4234]: Outdated client!
    18:30:21
    CONSOLE:
    [INFO] 2001inferno issued server command: /warp spawnfront
    18:30:21
    CONSOLE:
    [INFO] Disconnecting kTNpZjeR [/202.101.209.219:1264]: Outdated client!
    18:30:21
    CONSOLE:
    [INFO] Disconnecting uZOnYrRt [/1.214.208.114:59000]: Outdated client!
    18:30:21
    CONSOLE:
    [INFO] Disconnecting O4bYownP [/202.113.65.229:1325]: Outdated client!
    18:30:23
    INFO:
    Old player lolcop12 is logging in.
    18:30:23
    CONSOLE:
    lolcop12 has logged in.
    18:30:23
    CONSOLE:
    [INFO] lolcop12[/88.90.86.171:26175] logged in with entity id 17959 at ([world] 2812.2272994816303, 10.0, -2643.699999988079)
    18:30:23
    CONSOLE:
    [INFO] Disconnecting Uo6YLNL1 [/90.207.69.161:59578]: Outdated client!
    18:30:23
    PLAYER_COMMAND:
    Leninavenger12: /f show unstopable
    18:30:25
    NoCheatPlus:
    Pixelsboy failed FastBreak: tried to break blocks (4) faster than possible. VL 24.
    18:30:25
    CONSOLE:
    [INFO] PvPGoDs Hunter: Marc724: lenin
    18:30:25
    INFO:
    Old player MCcreeper10 is logging in.
    18:30:25
    CONSOLE:
    MCcreeper10 has logged in.
    18:30:25
    CONSOLE:
    [INFO] MCcreeper10[/2.216.252.164:49190] logged in with entity id 18086 at ([world] 2950.109671550685, 64.0, -2760.952482143454)
    18:30:27
    PLAYER_COMMAND:
    titch12: /f pow 2001in
    18:30:27
    INFO:
    Old player piggyman225 is logging in.
    18:30:27
    CONSOLE:
    piggyman225 has logged in.
    18:30:27
    CONSOLE:
    [INFO] piggyman225[/68.12.240.163:56264] logged in with entity id 18171 at ([world] 160.62203690638987, 69.0, 540.5097178450907)
    18:30:27
    CONSOLE:
    [INFO] xx28aylin28xx issued server command: /r no u tryed to fucking kill me
    18:30:27
    CONSOLE:
    [INFO] Disconnecting FnUn2YAl [/209.190.33.13:4013]: Outdated client!
    18:30:27
    CONSOLE:
    [INFO] Disconnecting xhnewYNh [/216.83.60.76:12540]: Outdated client!
    18:30:27
    CONSOLE:
    [INFO] Disconnecting 80NlMWAe [/59.11.237.151:1664]: Outdated client!
    18:30:27
    INFO:
    Old player agentcreeper23 is logging in.
    18:30:27
    CONSOLE:
    agentcreeper23 has logged in.
    18:30:27
    CONSOLE:
    [INFO] agentcreeper23[/65.27.186.175:49483] logged in with entity id 18185 at ([world] 322.4847185783337, 61.0, 549.5011636627005)
    18:30:29
    CONSOLE:
    [INFO] Disconnecting MRcNguFs [/178.150.156.219:3300]: Outdated client!
    18:30:29
    CONSOLE:
    [INFO] Disconnecting u6d6oYUu [/202.101.209.219:2963]: Outdated client!
    18:30:29
    CONSOLE:
    [INFO] PvPGoDs Hunter: Marc724: 1v1
    18:30:29
    CONSOLE:
    [INFO] Disconnecting UOVTcr6j [/202.101.209.219:3015]: Outdated client!
    18:30:29
    CONSOLE:
    [INFO] Disconnecting pMB6FhcC [/202.113.65.229:3261]: Outdated client!
    18:30:29
    CONSOLE:
    [INFO] ryanmcvey1888 issued server command: /msg aylin can i tp to you?
    18:30:29
    CONSOLE:
    [INFO] Disconnecting zPBnbPdw [/90.207.69.161:59654]: Outdated client!
    18:30:29
    NoCheatPlus:
    Pixelsboy failed FastBreak: tried to break blocks (4) faster than possible. VL 32.
    18:30:29
    CONSOLE:
    [INFO] Disconnecting xkbvD7gn [/216.83.60.76:13027]: Outdated client!
    18:30:29
    CONSOLE:
    [INFO] Disconnecting 6zDQkhkl [/202.113.65.229:4812]: Outdated client!
    18:30:31
    CONSOLE:
    [INFO] Disconnecting GPbAbm3Z [/212.49.70.48:4927]: Outdated client!
    18:30:31
    CONSOLE:
    [INFO] Disconnecting MQ8jEG4d [/46.37.209.49:51673]: Outdated client!
    18:30:31
    CONSOLE:
    [INFO] Disconnecting Ib7IaVym [/90.207.69.161:59670]: Outdated client!
    18:30:31
    CONSOLE:
    [INFO] 6Hunter: BryanRadecki7r8 8was 48 by a 6Hunter: ICON_ELEMENTZ7r8.
    18:30:31
    CONSOLE:
    [INFO] **UnStopAble Champion: UnStopAbleZING: dude
    18:30:31
    CONSOLE:
    [INFO] _DeadCurent_ issued server command: /warp ipvp
    18:30:33
    PLAYER_COMMAND:
    GentleNathan: /f map
    18:30:33
    PLAYER_COMMAND:
    furby121: /f who lenin
    18:30:33
    PLAYER_COMMAND:
    _DeadCurent_: /f who
    18:30:33
    CONSOLE:
    [INFO] FactionChat RedLegion: *slimshady7046: lois
    18:30:35
    PLAYER_COMMAND:
    xx28aylin28xx: /f map
    18:30:35
    CONSOLE:
    [INFO] /109.195.23.55:3553 lost connection
    18:30:35
    CONSOLE:
    [INFO] Disconnecting oNsN23R3 [/90.207.69.161:59712]: Outdated client!
    18:30:35
    CONSOLE:
    [INFO] Disconnecting MOS7kW3S [/185.2.12.77:3825]: Outdated client!
    18:30:37
    CONSOLE:
    [INFO] /109.195.23.55:4934 lost connection
    18:30:37
    CONSOLE:
    [INFO] Disconnecting usZjvfRK [/202.101.209.219:1147]: Outdated client!
    18:30:39
    PLAYER_COMMAND:
    xx28aylin28xx: /f wo beast
    18:30:39
    CONSOLE:
    [INFO] BryanRadecki issued server command: /msg cole yay no more lag
    18:30:39
    CONSOLE:
    [INFO] mncscom issued server command: /pv 2
    18:30:39
    CONSOLE:
    [INFO] Disconnecting ovpMUNoK [/202.113.65.229:3569]: Outdated client!
    18:30:39
    CONSOLE:
    [INFO] /109.195.23.55:2485 lost connection
    18:30:41
    CONSOLE:
    [INFO] Disconnecting ovpMUNoK [/1.214.208.114:59256]: Outdated client!
    18:30:41
    Minestats:
    Updated online stats. Took: 174 Milliseconds.
    18:30:41
    CONSOLE:
    bjte has left.
    18:30:41
    CONSOLE:
    [INFO] bjte lost connection: disconnect.quitting
    18:30:41
    CONSOLE:
    [INFO] Disconnecting IneN321V [/209.190.33.13:2639]: Outdated client!
    18:30:41
    CONSOLE:
    [INFO] Disconnecting zOSCRdJa [/90.207.69.161:59792]: Outdated client!
    18:30:41
    CONSOLE:
    [INFO] FactionChat RedLegion: *slimshady7046: give my stufff back
    18:30:41
    CONSOLE:
    [INFO] Disconnecting dJuPk8KW [/212.49.70.48:4941]: Outdated client!
    18:30:43
    CONSOLE:
    [INFO] BryanRadecki issued server command: /warp pvp
    18:30:43
    CONSOLE:
    [INFO] Disconnecting bWvFLSsI [/185.2.12.77:2224]: Outdated client!
    18:30:43
    CONSOLE:
    [INFO] /2.216.252.164:49189 lost connection
    18:30:43
    CONSOLE:
    [INFO] Disconnecting M7qmwIWO [/178.150.156.219:4121]: Outdated client!
    18:30:43
    CONSOLE:
    [INFO] Disconnecting lKMWlr1W [/90.207.69.161:59841]: Outdated client!
    18:30:43

    [INFO] Disconnecting PG7p65rZ [/202.101.209.219:2975]: Outdated client!
    18:30:43
    CONSOLE:
    [INFO] Disconnecting lKMWlr1W [/202.113.65.229:1527]: Outdated client!
    18:30:43
    CONSOLE:
    [INFO] Disconnecting V3b0nq0F [/216.83.60.76:15477]: Outdated client!
    18:30:43
    CONSOLE:
    [INFO] Disconnecting V3b0nq0F [/212.49.70.48:1936]: Outdated client!
    18:30:43
    PLAYER_COMMAND:
    xx28aylin28xx: /f who beast
     
  3. Well, Best case scenario - he will stop after a few days
    Worst case scenario - you will have to use BungeeCord with at least 2 servers BungeeCorded together, one lobby and one main.
     
  4. YoFuzzy3

    Supporter

    SexyMime
    Pretty sure that's the result of someone using a program that spams fake clients (bots) onto your server using proxies. Normally they would join, sometimes spam, and quit very quickly over and over with dozens of the bots, which can cause major lag. The program they're using is out-dated so the bots can't join your server so it has less of an effect.
     
  5. why do people do this?
    maybe it's a rival server that you overtook in a server list or something
     
  6. Fun, feeling stronger if doing it, loving to see other suffer, feeling cool because they have a "hack" that actually works and some other reasons.
     
    • Like Like x 1
  7. jeff142

    Benefactor

    Had the same thing for weeks even back in 1.4.6 i had this stuff
     
  8. Made this thread earlier. http://www.spigotmc.org/threads/bots.1122/
    Now I know what people are using to cause this, thanks.
     
  9. SexyMime i recommend: pastebin.com :p
     
  10. FINALLY! I've been looking on the net for other people with the same problem that I have.

    For me, this started a couple days ago when the player BROcrafter12 joined.

    While he was connected, the spambot started hitting my server from the SAME ip as BROcrafter12 came from.
    It sucks to be him for using his own IP address to test the spambot :)

    Code (Text):

    2013-03-14 21:03:08 [INFO] BROcrafter12[/68.7.101.225:57390] logged in with entity id 539157 at ([world] -185.5, 68.62000000476837, -162.5)
    2013-03-14 21:03:14 [INFO] [G] [Tourist] BROcrafter12: Hello!
    2013-03-14 21:03:25 [INFO] [G] [Tourist] BROcrafter12: is a op online?
    2013-03-14 21:03:33 [INFO] [G] [Tourist] BROcrafter12: I need to talk bussness
    2013-03-14 21:03:42 [INFO] [G] [Tourist] BROcrafter12: Did i ask for that?
    2013-03-14 21:03:47 [INFO] [G] [Tourist] BROcrafter12: nop so stfu
    2013-03-14 21:04:02 [INFO] [G] [Tourist] BROcrafter12: your not a op Fucker
    2013-03-14 21:04:22 [INFO] [G] [Tourist] BROcrafter12: Sorry
    2013-03-14 21:04:40 [INFO] [G] [Tourist] BROcrafter12: Yes sir
    2013-03-14 21:04:42 [INFO] [G] [Tourist] BROcrafter12: Sorry
    2013-03-14 21:04:48 [INFO] [G] [Tourist] BROcrafter12: Could i ask you something>
    2013-03-14 21:04:51 [INFO] [G] [Tourist] BROcrafter12: ?
    2013-03-14 21:04:52 [INFO] [G] [Tourist] BROcrafter12: Owner
    2013-03-14 21:06:01 [INFO] Disconnecting CAMijZZG [/68.7.101.225:57647]: Outdated client!
    2013-03-14 21:06:02 [INFO] Disconnecting 6zUa6kVf [/68.7.101.225:57652]: Outdated client!
    2013-03-14 21:06:06 [INFO] Disconnecting yOSudRfl [/68.7.101.225:57756]: Outdated client!
    2013-03-14 21:06:12 [INFO] Disconnecting jX7EA1O3 [/68.7.101.225:57851]: Outdated client!
    2013-03-14 21:06:13 [INFO] Disconnecting 3H2i75gX [/68.7.101.225:57856]: Outdated client!
    2013-03-14 21:06:15 [INFO] [G] [Tourist] BROcrafter12: I need a server
    2013-03-14 21:06:17 [INFO] Disconnecting OJ5J3ADw [/68.7.101.225:57923]: Outdated client!
    2013-03-14 21:06:20 [INFO] [G] [Tourist] BROcrafter12: :3
    2013-03-14 21:06:22 [INFO] Disconnecting 4HszoH76 [/68.7.101.225:58008]: Outdated client!
    2013-03-14 21:06:25 [INFO] Disconnecting BGLylDg6 [/68.7.101.225:58034]: Outdated client!
    2013-03-14 21:06:28 [INFO] Disconnecting IAV71UqZ [/68.7.101.225:58070]: Outdated client!
    2013-03-14 21:06:33 [INFO] Disconnecting 4xE2jtzu [/68.7.101.225:58113]: Outdated client!
    2013-03-14 21:06:36 [INFO] Disconnecting UkqXH140 [/68.7.101.225:58161]: Outdated client!
    2013-03-14 21:06:38 [INFO] Disconnecting QAeXMFkD [/68.7.101.225:58187]: Outdated client!
    2013-03-14 21:06:44 [INFO] Disconnecting DcYgEHnJ [/68.7.101.225:58305]: Outdated client!
    2013-03-14 21:06:45 [INFO] BROcrafter12's y speed was too high (speed=0.8399999737739563, max=0.5)
    2013-03-14 21:06:47 [INFO] Disconnecting ql1nU1iH [/68.7.101.225:58359]: Outdated client!
    2013-03-14 21:06:49 [INFO] Disconnecting TTKZonkK [/68.7.101.225:58368]: Outdated client!
    2013-03-14 21:06:54 [INFO] Disconnecting LAfCw5lU [/68.7.101.225:58427]: Outdated client!
    2013-03-14 21:06:59 [INFO] Disconnecting rvT85aeP [/68.7.101.225:58532]: Outdated client!
    2013-03-14 21:07:00 [INFO] Disconnecting OAXuIfGH [/68.7.101.225:58535]: Outdated client!
    2013-03-14 21:07:05 [INFO] Disconnecting uiKcVGPQ [/68.7.101.225:58580]: Outdated client!
    2013-03-14 21:07:10 [INFO] Disconnecting ZblP033j [/68.7.101.225:58624]: Outdated client!
    2013-03-14 21:07:10 [INFO] Disconnecting xr6If3vt [/68.7.101.225:58634]: Outdated client!
    2013-03-14 21:07:15 [INFO] Disconnecting 6D68INsS [/68.7.101.225:58725]: Outdated client!
    2013-03-14 21:07:21 [INFO] Disconnecting zwWhCUPK [/68.7.101.225:58815]: Outdated client!
    2013-03-14 21:07:21 [INFO] Disconnecting y0M6cil6 [/68.7.101.225:58819]: Outdated client!
    2013-03-14 21:07:22 [INFO] [G] [Tourist] BROcrafter12: I cant do anyting
    2013-03-14 21:07:26 [INFO] Disconnecting QEIcHBUO [/68.7.101.225:58893]: Outdated client!
    2013-03-14 21:07:31 [INFO] Disconnecting BqxBwa12 [/68.7.101.225:58937]: Outdated client!
    2013-03-14 21:07:33 [INFO] Disconnecting tZ1hCt3W [/68.7.101.225:58957]: Outdated client!
    2013-03-14 21:07:37 [INFO] Disconnecting LabZksK0 [/68.7.101.225:59046]: Outdated client!
    2013-03-14 21:07:42 [INFO] Disconnecting lXcryiP7 [/68.7.101.225:59112]: Outdated client!
    2013-03-14 21:07:44 [INFO] Disconnecting tuaYz5l6 [/68.7.101.225:59137]: Outdated client!
    2013-03-14 21:07:47 [INFO] Disconnecting ilcSmMAG [/68.7.101.225:59172]: Outdated client!
    2013-03-14 21:07:52 [INFO] Disconnecting ypZNfPYH [/68.7.101.225:59250]: Outdated client!
    2013-03-14 21:07:55 [INFO] Disconnecting GPEGRHcp [/68.7.101.225:59295]: Outdated client!
    2013-03-14 21:07:58 [INFO] Disconnecting Jgs6hgUF [/68.7.101.225:59334]: Outdated client!
    2013-03-14 21:07:59 [INFO] [G] [Tourist] BROcrafter12: fuck! this server
    2013-03-14 21:08:03 [INFO] Disconnecting Jd4bCV1i [/68.7.101.225:59402]: Outdated client!
    2013-03-14 21:08:05 [INFO] GriefPrevention: Muted spam from BROcrafter12: fuck! this server
    2013-03-14 21:08:05 [INFO] GriefPrevention: Muted spam from BROcrafter12: fuck! this server
    2013-03-14 21:08:05 [INFO] GriefPrevention: Muted spam from BROcrafter12: fuck! this server
    2013-03-14 21:08:05 [INFO] GriefPrevention: Warned BROcrafter12 about spam penalties.
    2013-03-14 21:08:05 [INFO] GriefPrevention: Muted spam from BROcrafter12: fuck! this server
    2013-03-14 21:08:05 [INFO] GriefPrevention: Muted spam from BROcrafter12: fuck! this server
    2013-03-14 21:08:05 [INFO] GriefPrevention: Muted spam from BROcrafter12: fuck! this server
    2013-03-14 21:08:05 [INFO] GriefPrevention: Muted spam from BROcrafter12: fuck! this server
    2013-03-14 21:08:05 [INFO] GriefPrevention: Muted spam from BROcrafter12: fuck! this server
    2013-03-14 21:08:05 [INFO] GriefPrevention: Banning BROcrafter12 for spam.
    2013-03-14 21:08:07 [INFO] Disconnecting 07n1uCGL [/68.7.101.225:59434]: Outdated client!
    2013-03-14 21:08:09 [INFO] Disconnecting r4sXBnCr [/68.7.101.225:59445]: Outdated client!
    2013-03-14 21:08:10 [INFO] Disconnecting BROcrafter12 [/68.7.101.225:59447]: The Ban Hammer has spoken!
    2013-03-14 21:08:16 [INFO] Disconnecting BROcrafter12 [/68.7.101.225:59529]: The Ban Hammer has spoken!
    2013-03-14 21:08:18 [INFO] Disconnecting NBbvm1r7 [/68.7.101.225:59541]: Outdated client!
    2013-03-14 21:09:20 [INFO] /68.7.101.225:59550 lost connection
    2013-03-14 21:10:40 [INFO] /68.7.101.225:59664 lost connection
    2013-03-14 21:23:16 [INFO] /68.7.101.225:61140 lost connection
    2013-03-14 21:28:14 [INFO] /68.7.101.225:62223 lost connection
    2013-03-14 21:28:48 [INFO] /68.7.101.225:62437 lost connection
    2013-03-14 21:29:19 [INFO] /68.7.101.225:62626 lost connection
    2013-03-14 21:29:54 [INFO] /68.7.101.225:62823 lost connection
    2013-03-14 21:30:16 [INFO] /68.7.101.225:63016 lost connection
    2013-03-14 21:30:40 [INFO] /68.7.101.225:63214 lost connection
     
    As you can see, he got banned quickly from our anti spam plugin.
    This listing show only what came from BROcrafter12's IP address but I had thousand more from various IP addresses (proxies I presume)

    I received a lot of "lost connection" request from over 7000 different IP address since then.
    I wrote a shell script that blocks the IP using the firewall when I get more than X lost connection from the same IP in a short time.

    So my firewall has over 7000 ip address blocked.

    Today someone called schoney_11 came on the server and told me my server got added to the weepcraft blacklist. He had a bad attitude and I had to ban him. Very soon after I started getting even more (Outdated client) lines. I presume he added me AGAIN.
    I have not find a way to verify if my server was indeed added or how I could remove it from the blacklist.
    I installed WeepCraft and I saw the blacklist but I could not find my server on the list. The names/IPs of servers are not shown. Maybe I have to be a Weepcraft VIP (cost $5) to see it. I'd hate to have to send $5 to someone who makes hacked clients just to be removed from the blacklist.

    Code (Text):

    2013-03-20 19:09:53 [INFO] schoney_11[/75.186.95.35:42376] logged in with entity id 2226690 at ([world] -190.5, 69.62000000476837, -164.5)
    2013-03-20 19:09:53
     
    I think you might want to consider adding schoney_11 and BROcrafter12.

    And I found this post:
    http://www.planetminecraft.com/blog/a-reason-for-concern-the-weepcraft-blacklist/

    Which says that Weepcraft could be used to DDoS mc servers. With the amount of lost connection received, its not enough to bring down my server but it did have an small impact on bandwidth and maybe it could bring down homemade servers with low power.

    Was anyone able to find out how to confirm when you are on the blacklist?
    Was anyone able to remove their own server from the blacklist?

    My firewall script which uses iptables to block IPs. This script has to be executed by a user who can do sudo.
    Code (Text):

    #!/bin/bash
     
    tail -n0 -f /path/to/server.log |
      /path/to/stripcolors |  # To remove color codes from the logs
      egrep --line-buffered  '\[INFO\] /[0-9\.]*:[0-9]* lost connection$|Disconnecting [a-zA-Z0-9]{8} \[/[0-9\.]*:[0-9]*\]: Outdated client' |
      while read LOGLINE; do
        IP=`echo $LOGLINE | sed 's/.*\[INFO\] \/\([0-9\.]*\):[0-9]* lost.*/\1/' | sed 's/.*\[\/\([0-9\.]*\):[0-9]*\]: Outdated.*/\1/'`
     
        grep -q "$IP" /tmp/good2
        if [ $? -eq 0 ]; then
            CNT=`grep -c "$IP" /path/to/server.log`
            if [ "$CNT" -gt 10 ]; then
                echo "$IP could be the hacker with $CNT"
            fi
            continue
        fi
     
        grep -q "$IP" /tmp/blocked
        if [ $? -eq 0 ]; then
            continue
        fi
     
        CNT=`tail -900 /path/to/server.log | grep -c "$IP"`
        if [ "$CNT" -gt 9 ]; then
            echo "BLOCK $IP with $CNT attempts"
            echo "$IP" >> /tmp/blocked
            sudo iptables -I INPUT -s "$IP" -j DROP
            NEWCNT=`sudo iptables -L -n | grep '^DROP' | sed 's/^DROP *all *\-\- *\([0-9\.]*\) *[0\.\/]* *$/\1/' | sort -u  | wc -l`
            if [ `expr "$NEWCNT" % 10` -eq 0 ]; then
                echo $NEWCNT
            fi
            continue
        fi
        CNT=`grep -c "$IP" /path/to/server.log`
        if [ "$CNT" -gt 9 ]; then
            echo "$IP : $CNT"
            if [ "$CNT" -gt 20 ]; then
                echo "should we BLOCK $IP with $CNT attempts ????"
            fi
        fi
      done
     
     

    The code for stripcolors:

    Code (Text):

    #!/bin/bash
     
    sed -u -r "s/\x1B\[([0-9]{1,2}(;[0-9]{1,2})?)?[m|K]//g"
     
     
    • Like Like x 3
    • Informative Informative x 2
  11. Hi, my kids server is weepcrafted/bot/ddos buy some stupid kids. I have an ide how we could stop this, with pfsense as transparent firewall in front of the router/firewall that uses an updatet list from a URL or something that is updated from a plugin that see when someone is trying to connect more than 2-3 times or something like that. Then we can make a ip list with blacklistes ip's that the pfsense use to block this stupid litle kids. I have 2-4 lost connections every second and if 50-60 trusted servers make a list with this lost connections ip addresses then we would solve this problem with this litle stupid kids.
    To do this i need a way to get this lost connection information, is there some plugin or is it possible to copy the server log to a sql server with help from a plugin?

    pfsense is a open source firewall that is easy to configure and could be run on a old pc, so it should be easy for everyone to setup this transparent firewall and since its transparent there isnt any configuration to de on wan/lan with ip addresses etc, only install it and tell what online ip list to use to block traffic.
     
  12. Ive had this before aswell, multiple players logging in and saying they will crash the server, then spamming swastikas and then once all of them were taken care of console was being spammed by the un-verified bot connections. Thankfully it stopped after 10 minutes, it didnt really cause any lag, was just annoying.
     
  13. Yesterday from 13:00-23:59 i had 97500 lost connection attakcs (weepcraft) to my server. I installed peerblock and blocked all traffic from any other country than my home country. Today its down to 10 attacks pr minute. I installed peerblock and used a online database that has the location on where a ip is from. I will setup a transparent pfsense firewall in front of my other firewalls to stopp all traffic not from my country.
    Its real easy to setup something that block traffic from countries you dont trust, even windows firewall could use a script to download ip database from online databases.

    After using peerblock there has only been a few attack from my own country, but that was stopped since i did send some abuse mail to there isp's and i got answer back from 4-5 of them that they had taken down the script kids internet :) ha ha ha. No internet in the holiday for this stupid litle kids.

    If someone is god in programming (have time) i think it would have been a great ide to have som plugin or other stuff that log lost connections not connected to a username and have it published to a online database that all could use to block this stupid litle kids that use weepcraft.
     
  14. I talked to the maker and he removed me from the list, you can send him a PM on http://weepforums.com/ or backfire at flycoder.net, cause he's using a php script to spam the server and runs it on his server. (blacklist)

    Here's the list that contains all the servers: http://flycoder.net/Weep/Servers.txt
    Some info about the hacked client's proxy scrape method, the class that adds the server to the list and some php scripts that flycoder.net uses.
    http://pastie.org/pastes/6623251/text
    http://pastie.org/pastes/6623437/text?key=kuygx5elguxfmuy1e1l8ma
    https://www.google.com/search?q=site:pastebin.com+WeepCraft
     
  15. joehot200

    Supporter

    Why dosent Mojang just squah weepcraft? Because, Mojang have a copyright, dont they? i dont understand why people cant just get rid of every single hacked client website.
     
  16. joehot200

    Supporter

    People have many reasons to be mad.
    Let me put it like this: (This happened once to someone else)
    If i payed $100 to a server for a rank, then got demoted and banned, and not refunded, do you think i would not want to DDOS them if i had the tech?

    Just giving an example. he didnt actually DDOS them, but i am just giving an example.
     
  17. Some people who Donate, think they buy immunity and do whatever they want.
    Donating, is not a "get out of jail and get away with murder" card ...
     
  18. Mojang does have copyright on Minecraft but how are they supposed to do this? The MCP team says:
    " - Use MCP to create clients that are used for griefing or exploiting server bugs is not allowed " LINK

    They could sue the WeepCraft author if the copyright allows this but WeepCraft is far not the only client that can do this, there are lots of authors that ignore this rule made by MCP and still use MCP to exploit server bugs and weakness.

    Depends on which way you donate to the server, if you do it over paypal you may get your money back. It also depends on the copyright and rules of that server.

    However only because you get mad on a decision someone made its not allowed for you to damage him/her or his/her product. So no you are not allowed to attack the server just because you don't like something on it.

    I've also had a player that donated to only abuse his powers on other players, so I just demounted him and banned him. My rules said its not allowed to do that and that and that... and he still did that and that and that so yea...
    After the ban he froze his transition on paypal but at the end we still got his donated money because our copyright and rules said that so... Also his dad agreed on them and everything went fine for us.

    Simple: If you sign or agree on something then always read the document first!
     
  19. joehot200

    Supporter

    On donations, my rule is if they abuse a command, it gets removed (e.g. donator abuses /tp and teleports people to him to kill, so remove /tp, and leave him with everything else, and yes it says that in the terms&conditions).


    And also, why dosent mojang/someone just squah them all!??! Nodus, sure, thats fine!, but Clients with the power to crash servers?? That should be destroyed. It disrupts the minecraft community greatly, giving players less access to servers under attack, means certain people with the clients get an unfair advantage in pvp/parkour etc, and basically generally makes things worse for your nice legit members.

    Pretty rubbish that someone dosent do something about them.
     
  20. You cant do much about these clients beacuase when they get caught and dealt with there will be more popping up in its place.