Ongoing Service Impact

News & Announcements Started Last reply 16 posts
Hello all,

We wanted to let you know that we are aware of and monitoring direct denial of service (https://en.wikipedia.org/wiki/Denial-of-service_attack) attacks directed at our games. If you’ve been experiencing connection drops, or sporadic high latency, please know that we’re closely watching the situation and working to mitigate them as quickly as possible. We'll be posting updates on the @L2andAionOps (https://twitter.com/L2andAionOps)account on this and any other service impacting issues.


If you’re experiencing connection or latency issues which you believe to be outside of these attacks, we ask that you please submit a support ticket so we can collect additional information.

We appreciate your understanding and patience.
Guess why xD
ty at least for finally a response....
Guess why xD


why ???
Patience we will have, because we know that you are working to correct these problems, but somehow we need a reward to pay the damages, something that is better than Angel Cat, because it is really impossible to play. ;);););)
DDOS attacks / piracy of computer networks is a federal offence once u found out who is responsible and mitigated the issue you should inform the FBI.

you could have traffic go through amazon web service they supposed to have algorithm to detect and deter these kind of attacks for their customers

a little hint if u banned some nova characters you should probably look that way sounds like the same issue you had a year or so ago when nova leaders and/or Martelx got banned. Have you banned a character named m87 recently aka martelx. his name is William if that can help you send the authorities.
DDOS attacks / piracy of computer networks is a federal offence once u found out who is responsible and mitigated the issue you should inform the FBI.

you could have traffic go through amazon web service they supposed to have algorithm to detect and deter these kind of attacks for their customers

a little hint if u banned some nova characters you should probably look that way sounds like the same issue you had a year or so ago when nova leaders and/or Martelx got banned. Have you banned a character named m87 recently aka martelx. his name is William if that can help you send the authorities.

Did you actually believe the hero/world chats about M87 being MartelX? lol.
Well few weeks +50% to base exp would fix the hassle :)
... a little hint if u banned some nova characters you should probably look that way sounds like the same issue you had a year or so ago when nova leaders and/or Martelx got banned. Have you banned a character named m87 recently aka martelx. his name is William if that can help you send the authorities.

Hime spoke of "our games (http://boards.lineage2.com/showthread.php?t=293265#1)" (plural). These attacks might as well be related to MxM - Juji going on a rampage. Or maybe it's the anti-low-level protocol of which Magnakai (http://boards.lineage2.com/showthread.php?t=293238#1) became an innocent victim. The new anti-bot works for all NCsoft games, and you can see the big RMT companies also on screenshots from all games. They seem to be severely hurt, which means that the people in Austin are actually doing their job :)
Hime spoke of "our games (http://boards.lineage2.com/showthread.php?t=293265#1)" (plural). These attacks might as well be related to MxM - Juji going on a rampage. Or maybe it's the anti-low-level protocol of which Magnakai (http://boards.lineage2.com/showthread.php?t=293238#1) became an innocent victim. The new anti-bot works for all NCsoft games, and you can see the big RMT companies also on screenshots from all games. They seem to be severely hurt, which means that the people in Austin are actually doing their job :)

well that's good smash them rmters slackers go to work! :D
I submitted a ticket because one of my desktops is having an issue with lineage 2 clients disconnecting on it. All three clients will d/c at the same time. Even with just one client running it'll dc after a couple minutes. All other online games on that machine stays connected fine. I think the problem is that I pinged the server for a few hours yesterday on accident. I fell asleep on accident thus leaving that machine pinging away for hours.

It's not my network and I have installed no updates. Not even the AV has been updated.

THe other 2 desktops and the 2 laptops I have all stay connected fine so it's not on my end.

So my belief is that the machine was flagged via the DDOS protection being used.
DDOS attacks / piracy of computer networks is a federal offence once u found out who is responsible and mitigated the issue you should inform the FBI.

Welcome to the internet. I can tell you are new here. The denial part of the attack is executed by a large amount of general purpose computing devices, including personally and privately owned as well as belonging to the public sector (governmental institutions). Let's just name all these devices, regardless of who factually owns them "sleeper agents".

The model of activating these sleeper agents has been devised, implemented and tested a long time ago, with the most notable successful execution example being Torpig/Sinowal distributed via Mebroot (primarily over Win XP). An article with a brief design overview can be found here (https://css.csail.mit.edu/6.858/2009/readings/torpig.pdf).

The idea is that a full software installation, configuration and distribution platform is developed for enterprise customers, then a special variation (rootkit) is created and published to the world using both social engineering (fake emails/websites) as well as both reported/fixed and unreported 0-day exploits. Access to pre-deployed rootkit instances is then sold to anyone willing to do business.
It's those who purchase the access to aforementioned instances that actually deploy malware/backdoors that steal passwords or direct the computers to offload valid traffic onto a specific service.

As with Torpig/Sinowal, there is never anything that would link some actual person(s) with the stolen data and/or carried out denial of service attacks.

And no court of law would ever dare to sentence any person/private entity/government institution for "negligence to protect their computing devices from misuse".
Welcome to the internet. I can tell you are new here. The denial part of the attack is executed by a large amount of general purpose computing devices, including personally and privately owned as well as belonging to the public sector (governmental institutions). Let's just name all these devices, regardless of who factually owns them "sleeper agents".

The model of activating these sleeper agents has been devised, implemented and tested a long time ago, with the most notable successful execution example being Torpig/Sinowal distributed via Mebroot (primarily over Win XP). An article with a brief design overview can be found here (https://css.csail.mit.edu/6.858/2009/readings/torpig.pdf).

The idea is that a full software installation, configuration and distribution platform is developed for enterprise customers, then a special variation (rootkit) is created and published to the world using both social engineering (fake emails/websites) as well as both reported/fixed and unreported 0-day exploits. Access to pre-deployed rootkit instances is then sold to anyone willing to do business.
It's those who purchase the access to aforementioned instances that actually deploy malware/backdoors that steal passwords or direct the computers to offload valid traffic onto a specific service.

As with Torpig/Sinowal, there is never anything that would link some actual person(s) with the stolen data and/or carried out denial of service attacks.

And no court of law would ever dare to sentence any person/private entity/government institution for "negligence to protect their computing devices from misuse".

EDIT : So I figured out today what was happening with my secondary machine. The secondary machine has a static IP as I use it to host teamspeak/mumble/ftp/etc. For some reason one of the phones is demanding to have that IP on the wifi. So whenever that phone had wifi turned on it would interfere with the secondary machine. So I changed the static IP and adjusted the firewall to perma fix the problem. It's really weird that the phone kept getting that IP as DHCP is setup for wifi connections.


Like you said most if not all the machines doing the actual work of the DDOS are zombies. That's why the internet of things is a potentially terrible idea as keeping all that secure is a nightmare. When you discover your fridge has been spamming people's emails you'll understand.. OR the children's toys that were hacked... etc etc


My secondary machine is no longer having issues staying connected and NCsoft's support responded to my ticket exactly 1 hour and 20 minutes after I posted it. I'm quite surprised as I've had some less than stellar interactions in the past with ncsupport. So kudos for getting on the ball there.
Hello all,

We wanted to let you know that we are aware of and monitoring direct denial of service (https://en.wikipedia.org/wiki/Denial-of-service_attack) attacks directed at our games. If you’ve been experiencing connection drops, or sporadic high latency, please know that we’re closely watching the situation and working to mitigate them as quickly as possible. We'll be posting updates on the @L2andAionOps (https://twitter.com/L2andAionOps)account on this and any other service impacting issues.


If you’re experiencing connection or latency issues which you believe to be outside of these attacks, we ask that you please submit a support ticket so we can collect additional information.

We appreciate your understanding and patience.

any new ?

still lost packets lineage2
Hello all,

We wanted to let you know that we are aware of and monitoring direct denial of service (https://en.wikipedia.org/wiki/Denial-of-service_attack) attacks directed at our games. If you’ve been experiencing connection drops, or sporadic high latency, please know that we’re closely watching the situation and working to mitigate them as quickly as possible. We'll be posting updates on the @L2andAionOps (https://twitter.com/L2andAionOps)account on this and any other service impacting issues.


If you’re experiencing connection or latency issues which you believe to be outside of these attacks, we ask that you please submit a support ticket so we can collect additional information.

We appreciate your understanding and patience.

Finally you admit it.

You ban the whole CIS, but still aware of DDoS? qq