DoS protection - /g/ (#105920128) [Archived: 365 hours ago]

Anonymous
7/16/2025, 1:00:46 AM No.105920128
1749142436910921
1749142436910921
md5: bae241b730af1b561276bbc1076f6f02🔍
Okay so tell me if I'm crazy here.

I run some game servers using Hetzner. Dedicated, 2vcpu. Recently some script kiddies have decided to attack my servers, using whatever bootleg lagbots they have.

I set up nftables rules to drop the traffic, but the problem is they're sending so much (~150mbps) traffic with a ridiculous number of packets to the point where even the act of filtering and dropping the packets is too much for the CPU to handle.

Apparently this isn't recognized as a DDoS attack by hetzner. Am I just fucked? The firewall contrils they provide are whitelist only and have basically no complexity. Do the nft rules just need to get moved to closer to the kernel level or something? I'm at a loss
Replies: >>105920226 >>105921361 >>105921402 >>105923596 >>105924900
Anonymous
7/16/2025, 1:11:47 AM No.105920226
>>105920128 (OP)
I'm reading that fucking with XDP would be a lot faster. How true is that? Or is it negligible?
Anonymous
7/16/2025, 1:24:37 AM No.105920354
file
file
md5: dd32afe16f7d27a94d025ed956a2fb6b🔍
>muh bootleg spambots
>meanwhile freetardo can't handle 150 mbps
can't make this shit up
Replies: >>105923480
Anonymous
7/16/2025, 3:38:44 AM No.105921353
lil bros using our home wifi to host a minecrap server with insufficient dedotated wam
Anonymous
7/16/2025, 3:39:40 AM No.105921361
>>105920128 (OP)
>Dedicated
>2vcpu
wat
Replies: >>105923619
Anonymous
7/16/2025, 3:46:31 AM No.105921402
>>105920128 (OP)
Of course Herzner doesn't call it a DoS because they're a shit provider and trying to scam you in meme bandwidth pricing. Enjoy your retard high bill. Now you know why (((Cloudflare))) exists.
Anonymous
7/16/2025, 9:45:55 AM No.105923480
>>105920354
always a (you)
Anonymous
7/16/2025, 9:47:56 AM No.105923495
Freetard discovers why cloudflare grew 1000% in six years
Anonymous
7/16/2025, 10:03:35 AM No.105923596
>>105920128 (OP)
are you sure its your CPU thats throttling? I've never heard of that in a DOS attack. Usually you exhaust your bandwidth long before your CPU. CPUs are giga fast and can process things much faster than we can send through the line.

Maybe Hetzner is lying to you.
Anonymous
7/16/2025, 10:07:26 AM No.105923619
>>105921361
yeah wtf are you talking about OP?
Anonymous
7/16/2025, 1:27:49 PM No.105924900
>>105920128 (OP)