View Issue Details

IDProjectCategoryView StatusLast Update
0000767unrealircdpublic2003-11-20 19:46
Reporterora Assigned Tocodemastr 
PrioritynormalSeverityminorReproducibilityalways
Status closedResolutionfixed 
Product Version3.2-beta14 
Summary0000767: IRCd floods opers with 'Flood from unknown connection' notices
Description(Actually this problem existed in beta14 and I still have it in beta15, Mantis just doesn't offer beta15 in the version box yet :) )

Whenever the IRCd detects a flood from an unknown connection, it sends an appropriate notice to it's opers and Z:Lines the ip.
So far so good. But after that, we're receiving the "Flood from unknown connection" notice again, about 50 times which is really annoying, esp. if more than one person is flooding you :)
Additional InformationExample:
--- *** Notice -- Flood from unknown connection 127.0.0.1 detected
--- *** Timed Z:Line added for *@127.0.0.1 on Tue Mar 4 15:08:01 2003 GMT (from matrix.test.net to expire at Tue Mar 4 15:18:01 2003 GMT: Flood from unknown connection)
--- *** Notice -- Flood from unknown connection 127.0.0.1 detected
--- *** Notice -- Flood from unknown connection 127.0.0.1 detected
--- *** Notice -- Flood from unknown connection 127.0.0.1 detected
--- *** Notice -- Flood from unknown connection 127.0.0.1 detected
--- *** Notice -- Flood from unknown connection 127.0.0.1 detected
--- *** Notice -- Flood from unknown connection 127.0.0.1 detected
(...)
3rd party modules

Activities

syzop

2003-03-04 15:51

administrator   ~0001747

Hmm did you report this before then? I remember another flood from unknown connection bug, but that one was IPv6 related and has been fixed.

mikron15

2003-03-05 03:44

reporter   ~0001749

even i too face this situation and itz really annoying!!!....i dont use ipv6, running beta 14..hope a fix will be there for it soon

ora

2003-03-05 05:34

reporter   ~0001750

IPv6 support was not compiled and we didn't report that bug before. I don't think there is another report like this one (yes, I actually tried to search the db before opening a new report :) )

_SciFi_

2003-03-05 17:14

reporter   ~0001756

we have this problem too and we don't use ipv6 as well

syzop

2003-03-05 23:12

administrator   ~0001764

[/me idle]

AngryWolf

2003-03-06 09:00

reporter   ~0001773

By the way..

/helpop ?zline
(...)
*** A time of 0 in the KLINE makes it permanent (Never Expires).
(...)

KLINE?

ora

2003-03-06 09:29

reporter   ~0001774

How about removing
   sendto_realops("Flood from unknown connection %s detected", cptr->sockhost);
in parse.c (line 200)?
That seems to solve the problem perfectly :) Besides, that notice is IMHO useless, Unreal adds a Z:line where you can see that someone was flooding...

Guess: The 'real problem' could be that Unreal is still accepting (and parsing) data from that connection until it discovers that it actually Z:lined that IP and closes the socket.

AngryWolf

2003-03-06 16:08

reporter   ~0001779

Altought I don't know what is the perfect way to solve the problem, I don't agree to remove that little piece of information from the code. It's better than nothing, particularly when telling "*** Notice -- Flood from unknown connection 127.0.0.1 detected" first time.

codemastr

2003-03-06 17:47

reporter   ~0001782

Perhaps (since that is related to flooding) it should be sent to snomask +f rather than to all opers?

ora

2003-03-06 18:21

reporter   ~0001783

AngryWolf: Your choice, I personally have enough info when I see the Z:line being added, it shows exactly the same stuff as the notice does.

codemastr: I think sending that notice to snomask f is a good idea, however I'd appreciate to only see the flood notice once ;p
The 'best' solution from my POV (not really able to understand C) would be to immediately close the connection after the Z:Line was set. Not 1 or 2 seconds after that. But I dunno whether that's possible...

AngryWolf

2003-03-06 19:20

reporter   ~0001788

I agree with both ora and codemastr.

ora: Just to tell you, I'm not an Unreal coder, just a person using Unreal for about a year, not more. :)

codemastr

2003-03-18 00:22

reporter   ~0001965

Ok, I think I got this all working correctly now, but, I am not able to reproduce the original problem, so if one of the people here who reported it could see if they are able to reproduce it using the current CVS (.1690) and let me know what happens. Also I've added some config options to give you a little more control over the unknown flood system.

set::anti-flood::unknown-flood-bantime (sets the length of time an unknown connection flooder is banned for [default 10 mins])
set::anti-flood::unknown-flood-amount (sets the amount of data in KBs that the flooder must send before he/she is banned [default 4KB]).

Additionally, I also moved the "Flood from unknown connection" to snomask +f (since it just seems to be more logical to go there). So when you are testing this, be sure that you have snomask +f set or you won't see anything.

Hopefully this will solve all of the problems :)

ora

2003-03-18 01:59

reporter   ~0001966

a) You rock!
b) The problem seems to be solved. At least I only received the flood notice once when I tested it now.

BTW: Cool new options :)

Thanks a lot.

codemastr

2003-03-18 16:34

reporter   ~0001968

Great, gonna close the bug then.

Issue History

Date Modified Username Field Change
2003-11-20 19:46 syzop Status resolved => closed