Hello.
I am currently helping a friends who’s Garry’s Mod server is getting DOS’ed every few days, it seems that source dedicated server is susceptible to a DOS exploit that evolves sending a flood of the “ÿÿÿÿTSource Engine Query” packets to the server I verified this with Wireshark on the server. But the very scary part is the amount of packets needed to take down a server, I tested it on my server that is hosted on a 50/50M line with a small program I wrote that sends 10,000 queries to the server, my uploads from the sending computer is 25KB so not a lot but I was able to take down the server, It looked as if it crashed to the users but it hasn’t, the CPU usage and network usage on the server stayed the same. I had 3 other people on the server at the time to make sure it was not only me as well as soon as the flood stopped the server can back after about one minute.
Now my question is, is there any plug-ins that can help with preventing this exploit I have tried both DAF and qcache both do not work, the attackers also can very easily change their IP address because UDP is stateless and can be spoofed very easily.
Box is windows so I can’t do anything with IP tables.
I am currently helping a friends who’s Garry’s Mod server is getting DOS’ed every few days, it seems that source dedicated server is susceptible to a DOS exploit that evolves sending a flood of the “ÿÿÿÿTSource Engine Query” packets to the server I verified this with Wireshark on the server. But the very scary part is the amount of packets needed to take down a server, I tested it on my server that is hosted on a 50/50M line with a small program I wrote that sends 10,000 queries to the server, my uploads from the sending computer is 25KB so not a lot but I was able to take down the server, It looked as if it crashed to the users but it hasn’t, the CPU usage and network usage on the server stayed the same. I had 3 other people on the server at the time to make sure it was not only me as well as soon as the flood stopped the server can back after about one minute.
Now my question is, is there any plug-ins that can help with preventing this exploit I have tried both DAF and qcache both do not work, the attackers also can very easily change their IP address because UDP is stateless and can be spoofed very easily.
Box is windows so I can’t do anything with IP tables.


