Jump to content
  • 0

Unknown Packets from IP from Los Angeles California


Question

Posted

Hello guys , i have a question im getting my head around i can't fiind answer .. I was leaving acis gameserver console with debug and logger on for almost 2 days now to check whats going on and looks like i get some weird connection but logins server is clean , on game server console i got this , can someone explain me what is this since server is hosted on my server pc home and no one has the ip how can i get packets from an ip what is this aliens contacting me via gs ? o,O

 

[S] SystemMessage
[S] PartySmallWindowDeleteAll
[S] SystemMessage
[S] SocialAction
[C] Logout
[S] LeaveWorld
FourSepulchersManager: end of the round.
CastleManorManager: Manor mode changed to MAINTENANCE
CastleManorManager: Manor mode changed to MODIFIABLE
Backup to SQL Complete
Done the zip of backup.
backup.sql is deleted!
FourSepulchersManager: end of the round.
[C] ProtocolVersion
Client: [IP: 47.251.92.79] - Failed reading: [C] ProtocolVersion ; java.nio.BufferUnderflowException
null
java.nio.BufferUnderflowException
        at java.base/java.nio.Buffer.nextGetIndex(Unknown Source)
        at java.base/java.nio.HeapByteBuffer.getInt(Unknown Source)
        at net.sf.l2j.commons.mmocore.ReceivablePacket.readD(ReceivablePacket.java:45)
        at net.sf.l2j.gameserver.network.clientpackets.ProtocolVersion.readImpl(ProtocolVersion.java:14)
        at net.sf.l2j.gameserver.network.clientpackets.L2GameClientPacket.read(L2GameClientPacket.java:30)
        at net.sf.l2j.commons.mmocore.SelectorThread.parseClientPacket(SelectorThread.java:445)
        at net.sf.l2j.commons.mmocore.SelectorThread.tryReadPacket(SelectorThread.java:382)
        at net.sf.l2j.commons.mmocore.SelectorThread.readPacket(SelectorThread.java:315)
        at net.sf.l2j.commons.mmocore.SelectorThread.run(SelectorThread.java:190)
Client [IP: 47.251.92.79] - Disconnected, too many buffer underflows in non-authed state.
[S] ServerClose
FourSepulchersManager: end of the round.
Olympiad: Olympiad game ended.

 

 

Untitled.png

 

Untitled.png

5 answers to this question

Recommended Posts

  • 0
Posted

ProtocolVersion packet is one of the first exchanges in the client-server handshake, and if the versions don't match, the server cannot correctly interpret the packet, leading to a buffer underflow.


Since you're the only one trying to log in, the error likely means there's a version mismatch between your game client and the server. Even though it's just you on the server, if the client is not exactly aligned with what the server expects, it can still cause the server to misinterpret the data it receives, leading to that BufferUnderflowException error.

  • 0
Posted (edited)

I've been getting similar for as long as I could remember, usually from random IPs. The one I could track in its entirety led me to a cyber-security firm, who was making random requests to test for vulnerabilities, as per their website.

As such, I came to the conclusion that these random packet requests were just automated scanners looking for unsecured connections and/or vulnerabilities they could exploit.
Could it be a malicious request - I'd say totally!
Is there something to worry about - I wouldn't give 2 fks about it since they couldn't get through.

The server closed the connection, and that's what matters. They'll prolly receive an `attempt failed/connection refused` response in their logs.

Edited by Salty Mike
  • 0
Posted
8 hours ago, Katara512 said:

ProtocolVersion packet is one of the first exchanges in the client-server handshake, and if the versions don't match, the server cannot correctly interpret the packet, leading to a buffer underflow.


Since you're the only one trying to log in, the error likely means there's a version mismatch between your game client and the server. Even though it's just you on the server, if the client is not exactly aligned with what the server expects, it can still cause the server to misinterpret the data it receives, leading to that BufferUnderflowException error.

yo thank you for answer but .. as i said i was outside not home and just leave server log open to check how is going when im away , i was suprised fiinding these connections so it was not me trying to connect from other client or something it was not me at all.

 

1 hour ago, Salty Mike said:

I've been getting similar for as long as I could remember, usually from random IPs. The one I could track in its entirety led me to a cyber-security firm, who was making random requests to test for vulnerabilities, as per their website.

As such, I came to the conclusion that these random packet requests were just automated scanners looking for unsecured connections and/or vulnerabilities they could exploit.
Could it be a malicious request - I'd say totally!
Is there something to worry about - I wouldn't give 2 fks about it since they couldn't get through.

The server closed the connection, and that's what matters. They'll prolly receive an `attempt failed/connection refused` response in their logs.

i think you are right sir , chat gpt told me there are actors scanning internet non stop maybe for vulnerable ips or something , this is weird i don't remember this happening in 2014 at all 😄 

  • 0
Posted

This ip can try to check some info by using a PROTOCOL_VERSION packet as PTS like format.

 

On PTS if connected client will send a PROTOCOL_VERSION requiest with -1 or less value - it will wait a response as "server status" or "current online".

 

65534 or -2 - ping

65533 or -3 - sends a server id, max online, current online, private store online.

  • 0
Posted (edited)

I’d suggest you take a closer look at those unknown packets from the Los Angeles IP. Sometimes, these can be linked to network scans or even someone testing their setup. If you're worried about security or tracking, you could consider blocking the IP or running a quick scan on your system. If it’s a recurring issue, it might even be worth looking into using a booter service to test your network’s strength and security. Just be sure you’re not violating any terms of service!

Edited by Meissgenry

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now


  • Posts

    • looking for someone who has cache cleaner for h5 
    • I’m looking to buy GeoEngine compatible with L2Scripts (Essence). A test server must be provided so I can verify functionality before purchase. DM here or through Telegram: @nick77737
    • fixed !.. thank you veru much @NevesOma  someone lock it
    • OFFICIAL DEVELOPERS Undetected since : Release Updated for last patch : 29/11/2025 After payment you will receive: Product download link1 Activation key for the selected period. Free support for the duration of the product subscription.   ✅AC - Undetected ▸WINDOWS 10/11 (All versions, even 24H2) ▸INTEL / AMD ▸Our software mainly targets player wanting to cheat legitimately. . Precision. Stealth. Performance.   The external ARC Raiders cheats from stern designed to elevate your gameplay without slowing your system. Fully compatible with Windows 10/11 — Intel & AMD ready.   Our Functions: AIMBOT **Enable Aim requires a mandatory confirmation popup, so there’s zero risk of activating it by accident for users who don’t want to use it. Aimbot Aimbot Drone Fov Aim (Draw fov circle) Target Line (Draw targetline) Arrow Fov (Draw arrow fov) Visible Check (Aim visible) Humanize (Aim randomize) Custom Aim Key Fov Value / Smooth Value / Aim Delay Arrow Size & Spacing VISUALS – PLAYERS Box ESP (2D / Corner) Health / Shield Bar Skeleton ESP Distance ESP Name ESP Tracers / Player Lines Visible & Invisible Check Squad Name ESP Draw Eyes Directions Radar ESP Radar Distance ESP Players Flags (corpse/knocked/exit/alive) VISUALS – ENTITY Pickup Base ESP Drone ESP Probe Crashed ESP Apricot ESP Mullein ESP Agave ESP MossRock ESP Crate ESP Salvage Container ESP Rsr Lockers ESP Raiders Cache Esp Bin Trash Esp Shredder Esp Fruit Basket ESP Ammo Box ESP Computer ESP Backpack ESP Leaper ESP Probe ESP Mushroom ESP Cargo Ship ESP Firewall ESP Assault Rifle ESP Battle Rifle ESP SMG ESP Grenade ESP Medical Bag ESP Turret ESP Sentinel Esp Weapon Case Esp Extraction ESP All Weapons ESP Max Distance & Fade distance MISC FOV Arrow Player Count Display Custom Arrow Size & Distance Streamproof (Invisible in recordings & screenshots) External (No injection) Maximum Privacy & Security 24/7 Support Available: replies within minutes Our prices: Prices must be checked directly on our website, as they may change at any time to control sales — however, we remain among the most competitive in the market.   Discover our website   GET GOOD, GET STERN
    • I paid this guy yesterday (i got screen for the payment for proof), he told me that someone will log to send me my adena. Then he said he had some problems and couldn't send me the adena. Waited and waited and waited until he replied that he can't find the guy and he will return the money i gave him. Today still no money returned and he doesn't reply to the discord messages. If he doesn't return the money i paid or send the adena he promised in game, i will report him in every single website and many more. Stay away. I have all the discussion screenshot on discord with him. He knows who i am so he better keep his promise legit.
  • Topics

×
×
  • Create New...

AdBlock Extension Detected!

Our website is made possible by displaying online advertisements to our members.

Please disable AdBlock browser extension first, to be able to use our community.

I've Disabled AdBlock