View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0000767 | unreal | ircd | public | 2003-03-04 15:39 | 2003-11-20 19:46 |
| Reporter | ora | Assigned To | |||
| Priority | normal | Severity | minor | Reproducibility | always |
| Status | closed | Resolution | fixed | ||
| Product Version | 3.2-beta14 | ||||
| Summary | 0000767: IRCd floods opers with 'Flood from unknown connection' notices | ||||
| Description | (Actually this problem existed in beta14 and I still have it in beta15, Mantis just doesn't offer beta15 in the version box yet :) ) Whenever the IRCd detects a flood from an unknown connection, it sends an appropriate notice to it's opers and Z:Lines the ip. So far so good. But after that, we're receiving the "Flood from unknown connection" notice again, about 50 times which is really annoying, esp. if more than one person is flooding you :) | ||||
| Additional Information | Example: --- *** Notice -- Flood from unknown connection 127.0.0.1 detected --- *** Timed Z:Line added for *@127.0.0.1 on Tue Mar 4 15:08:01 2003 GMT (from matrix.test.net to expire at Tue Mar 4 15:18:01 2003 GMT: Flood from unknown connection) --- *** Notice -- Flood from unknown connection 127.0.0.1 detected --- *** Notice -- Flood from unknown connection 127.0.0.1 detected --- *** Notice -- Flood from unknown connection 127.0.0.1 detected --- *** Notice -- Flood from unknown connection 127.0.0.1 detected --- *** Notice -- Flood from unknown connection 127.0.0.1 detected --- *** Notice -- Flood from unknown connection 127.0.0.1 detected (...) | ||||
| 3rd party modules | |||||
|
|
Hmm did you report this before then? I remember another flood from unknown connection bug, but that one was IPv6 related and has been fixed. |
|
|
even i too face this situation and itz really annoying!!!....i dont use ipv6, running beta 14..hope a fix will be there for it soon |
|
|
IPv6 support was not compiled and we didn't report that bug before. I don't think there is another report like this one (yes, I actually tried to search the db before opening a new report :) ) |
|
|
we have this problem too and we don't use ipv6 as well |
|
|
[/me idle] |
|
|
By the way.. /helpop ?zline (...) *** A time of 0 in the KLINE makes it permanent (Never Expires). (...) KLINE? |
|
|
How about removing sendto_realops("Flood from unknown connection %s detected", cptr->sockhost); in parse.c (line 200)? That seems to solve the problem perfectly :) Besides, that notice is IMHO useless, Unreal adds a Z:line where you can see that someone was flooding... Guess: The 'real problem' could be that Unreal is still accepting (and parsing) data from that connection until it discovers that it actually Z:lined that IP and closes the socket. |
|
|
Altought I don't know what is the perfect way to solve the problem, I don't agree to remove that little piece of information from the code. It's better than nothing, particularly when telling "*** Notice -- Flood from unknown connection 127.0.0.1 detected" first time. |
|
|
Perhaps (since that is related to flooding) it should be sent to snomask +f rather than to all opers? |
|
|
AngryWolf: Your choice, I personally have enough info when I see the Z:line being added, it shows exactly the same stuff as the notice does. codemastr: I think sending that notice to snomask f is a good idea, however I'd appreciate to only see the flood notice once ;p The 'best' solution from my POV (not really able to understand C) would be to immediately close the connection after the Z:Line was set. Not 1 or 2 seconds after that. But I dunno whether that's possible... |
|
|
I agree with both ora and codemastr. ora: Just to tell you, I'm not an Unreal coder, just a person using Unreal for about a year, not more. :) |
|
|
Ok, I think I got this all working correctly now, but, I am not able to reproduce the original problem, so if one of the people here who reported it could see if they are able to reproduce it using the current CVS (.1690) and let me know what happens. Also I've added some config options to give you a little more control over the unknown flood system. set::anti-flood::unknown-flood-bantime (sets the length of time an unknown connection flooder is banned for [default 10 mins]) set::anti-flood::unknown-flood-amount (sets the amount of data in KBs that the flooder must send before he/she is banned [default 4KB]). Additionally, I also moved the "Flood from unknown connection" to snomask +f (since it just seems to be more logical to go there). So when you are testing this, be sure that you have snomask +f set or you won't see anything. Hopefully this will solve all of the problems :) |
|
|
a) You rock! b) The problem seems to be solved. At least I only received the flood notice once when I tested it now. BTW: Cool new options :) Thanks a lot. |
|
|
Great, gonna close the bug then. |
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2003-11-20 19:46 | syzop | Status | resolved => closed |