Jump to content

Recommended Posts

Posted

Guys open your eyes this has the SOURCE CODE of phx which means phx can be 100% fixable..

 

fixable?

There is not and there will never be server side protection.

About client side protections, people have cracked even l2.exe files that didn't allow them to log, so you imagine that everything client sided can be bypassed.

Posted

tl;dr

 

Note: I asked TehGeorge if i am allowed to post it and he said post it but with +1 karma hide, else delete it!

 

I have already c/p it, i could delete your thread and post it bymyself with 0 postcount lolz

Posted

tl;dr

 

I have already c/p it, i could delete your thread and post it bymyself with 0 postcount lolz

 

Either do it (nah maybe not it will look lame) or edit his hide (that would look great).

Posted

tl;dr

 

I have already c/p it, i could delete your thread and post it bymyself with 0 postcount lolz

 

 

if you dont like my post then delete it but dont repost it...

 

he said it +1 karma because it is at vip section.

 

 

also you will delete my thread i will report to maxtor + k4rma will delete your thread!

 

 

why you dont you respect others people work? its like you will say ok ty DragonHunter you made the tool i delete your topic and repost it with no hide. right?

Posted

@Sillent, 1st of all you should learn some more english.

 

if you dont like my post then delete it but dont repost it...

 

I didnt say i didnt like it, you just dont know what the acronym tl;dr means.

 

he said it +1 karma because it is at vip section.

 

I could find it at another forum maybe?

 

also you will delete my thread

 

So you can see future?

 

i will report to maxtor + k4rma will delete your thread

 

wait wait, the 1st line you wrote was "you can delete it, but dont repost it"

 

You change your mind really fast!

 

why you dont you respect others people work? its like you will say ok ty DragonHunter you made the tool i delete your topic and repost it with no hide. right?

 

If you think just a lil bit you would realase that getting here +1 karma it's easier than walking, it would be better to hide the thread for posts. 

 

Tbh, no one will read this thread (not beacuse they cant, just beacuse it's longer than the bible)

 

Good luck with your super duper share!

Posted

@Sillent, 1st of all you should learn some more english.

 

I didnt say i didnt like it, you just dont know what the acronym tl;dr means.

 

I could find it at another forum maybe?

 

So you can see future?

 

wait wait, the 1st line you wrote was "you can delete it, but dont repost it"

 

You change your mind really fast!

 

If you think just a lil bit you would realase that getting here +1 karma it's easier than walking, it would be better to hide the thread for posts.  

 

Tbh, no one will read this thread (not beacuse they cant, just beacuse it's longer than the bible)

 

Good luck with your super duper share!

 

lol twister or what?? whats going on here??

wtf is wrong with you guys OMG dont like it ? then dont post... and what if is uber big its against the rules??

1 saying "change the hide" the other say "i can delete it and repost it" the other1 "go make a book"...

he explained everything should be explain for the post and for his action's.

 

Btw i didnt see him claiming that is super duber share or that he make it, omg you guys read or what?

If his post is right.. just let it be and stop making "flames"

the only right quote was tl;dr: "too long didnt read"

Posted
Guys open your eyes this has the SOURCE CODE of phx which means phx can be 100% fixable..

 

maked me launght.  ;D

l2ph(x) - open source project, we got a pub "read only" svn. want link ? or gonna google it by youself XD

ph - its a sniffer, what allows you manipulate with packets / use scripts for "action automation", etc.

 

you going to fix sniffer  ?! so you need to crypt your gs-client traffick.. you can do it, its not hard.

but, you also must include reverse function in client, hah, max few hours in olly and we have a newxor that will bypass that protection XD

also. ph can be runned on dedicated pc, so no way will be to detect it. hah.

 

about all that "hiding for karma", guys, i don't sure that you need to do it, there a translated official faq ? taken from official site ? right ?

its will be useful for people who using it's first time. most of here dont have any karma :P (me 2)

 

at last i think theese interface sections must be unhided: file\settings, connection frame, dev\scripts\support functions

 

about examples of plugins structures.. dont sure that you need include it (i did some changes in plugins structure last 2 release) coz they can be found on svn in pluggincodding folder.

and units\usharedstructs.pas also placed on svn.

 

Tbh, no one will read this thread (not beacuse they cant, just beacuse it's longer than the bible)

official one got not small size 2 ;)

its was written coz i borred with writing answers on such questions "how to configure it", "i want send a packet ? but dont know where i must fdo it!", "how to read a string from say2 packet" etc. etc. etc. a lot of same questions.

 

its usefull where such information in one place. you can just give link.

and, for sure, its must be translatted Well.

coz "[3.2.3]plugin_demo.dpr; work packages"

must be translated as : plugin_demo.dpr; working with packets

 

there a lot of mistakes.. =\

 

Posted

its nice to have the function reference in english rather than loading up google translate :p

the rest isnt that useful but ok lol

by the way it would be nice if phx had a delay function and something to intercept/modify the LS packets easily ;) (yes, its different, i know, but loading another tool for it u know.. xD)

Posted

mmm, ctrl+space in editor also helps a lot (:P)

anyway names of constant/procedures/functions and its parameters in english, and its simple to understand what they do :>

 

interface explanation usefull, for people who making first steps (babbyes? hah.).

 

by the way it would be nice if phx had a delay function

sleep() ?

but, remember.. its freezing script engine, and as result freesing traffick. also huge delays dangerous for client (we have omly 64kb buffer in socket engine. its can be filled till delay and as reasult - client will be crashed.)

 

you need to use timer or "penetrating delay" to avoid freezing.

or using sleep in timer handle function (after stopping this timer), there a lot of ways to make delay.

"different situations - different sollutions" ©

 

and something to intercept/modify the LS packets easily Wink (yes, its different, i know, but loading another tool for it u know

newer!! XD

i don't want topick's like "its dont work" on coderx XD

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now


  • Posts

    • Added the protection module to the demo.   DDoS Guard Pro v2.0 is a system protection module for PlayMMO CMS designed to reduce the load on the website during HTTP floods, bot activity, suspicious frequent requests, and attacks on individual pages or API methods. Unlike simple global limiters, DDoS Guard Pro v2.0 supports flexible rules based on routes and HTTP methods. This allows you to block the entire site in a targeted manner, rather than blocking the entire site equally. You can set up protection for specific areas of the site, such as login, registration, APIs, administration, forms, and other sensitive areas. What is the purpose of the module? DDoS Guard Pro v2.0 helps protect your site from basic L7 attacks at the HTTP request level. The module is useful when your site receives: frequent requests from a single IP address; HTTP page floods; login or registration form flooding; automatic requests from bots; URL scanning; frequent API requests; suspicious activity spikes; load on individual CMS methods or pages. The module helps to reduce the load on PHP and CMS by limiting suspicious activity before it starts to create a serious load on the site. Main features Per-route and per-method Rate Limit In the new version, protection is configured not only globally, but also according to specific rules. You can set limits separately for: GET; POST; PUT; PATCH; DELETE; ALL. This allows you to flexibly protect different parts of your website. For example: for the login page, you can set a strict limit; for registration, you can set a separate limit; for the API, you can set a limit for reading and a limit for changing data; for regular website pages, you can set a soft limit or not set a limit at all. This approach reduces the risk of accidentally blocking regular users and makes the protection more accurate. Flexible rule system The module supports setting rules in the following format: METHODS|PATTERN|LIMIT|WINDOW|BURST_LIMIT|BURST_WINDOW|BLOCK_SECONDS|IDENTITY|NAME Example of rules: POST|*login*|10|60|5|10|600|ip|login_post POST|*register*|8|60|4|10|600|ip|register_post GET|*api*|300|60|80|10|120|ip|api_get PUT,PATCH,DELETE|*api*|80|60|20|10|300|ip|api_write This allows you to specify exactly: which HTTP methods to protect; which URLs or URL patterns to consider; how many requests are allowed; over what time period; what burst limit to use;  how many seconds to block the offender;  by which ID to count the limit;  what the rule is called. Burst protection against sharp spikes  In addition to the regular request limit, the module monitors sharp spikes of activity.  This is useful when a bot makes many requests in a few seconds. In this case, the protection can be activated faster, without waiting for the overall limit per minute.  Burst protection is especially useful for: authorization pages; registration; API; search; data submission forms; administrative sections. Support for different types of requests DDoS Guard Pro v2.0 works not only with POST requests. The module can control: GET — regular pages, API requests, search; POST — forms, login, registration, data submission; PUT — updating data via API; PATCH — partial data update; DELETE — data deletion; ALL — all methods at once. This makes the module suitable not only for regular sites, but also for CMS with API, personal accounts, game panels and administrative actions. Limit storage: Redis, APCu and file fallback In the new version, the module supports several options for storing temporary data. Available modes: Redis; APCu; file fallback. The auto mode tries to use the most suitable option: Redis; APCu; file storage as a fallback. Redis or APCu are suitable for more efficient operation, while the file storage is left as a fallback option for simple hosting environments that do not have additional extensions. JSONL logging The module records protection events in JSON Lines format. Logs are saved in the following file: storage/logs/ddos_guard.jsonl This format is more convenient than a regular text log, because each event is stored as a separate JSON record. The logs can record the following information: event time; IP address; HTTP method; URL; name of the triggered rule; reason for blocking; number of requests; action status; user-agent; protection mode. The JSONL format is convenient for analysis by external tools, log agents, and monitoring systems. Prometheus metrics DDoS Guard Pro v2.0 adds an endpoint for receiving metrics in Prometheus format. Endpoint: /?ddos_guard_metrics=TOKEN The token is set in the module settings. Metrics allow you to track: the number of processed requests; the number of rule activations; the number of blocks; activity by limits; protection events; module status. This allows you to connect monitoring and configure alerts so that the administrator can see when suspicious activity starts on the site. LOG ONLY mode The module has a LOG ONLY mode. In this mode, DDoS Guard Pro does not block users, but only records events and potential triggers in the log. This mode is recommended to be used after installation, in order to first see which rules are triggered, and only then to enable the real blocking.  This helps to avoid too strict limits and random blocking of regular users.  Support for Cloudflare and proxy  The module supports working behind Cloudflare or another reverse proxy.  With proper configuration, it is possible to take into account the real IP of the user, and not the IP of the proxy server.  This is important for sites that use:  Cloudflare; nginx reverse proxy; load balancers; CDN; hosting proxy protection. Nginx-recommendations DDoS Guard Pro v2.0 contains an example nginx-config: modules/ddos_guard/nginx-ddos-guard-example.conf This allows you to use the module as an additional application layer of protection, and to move the main coarse limits to the nginx level. Recommended protection scheme: Cloudflare / nginx / firewall → DDoS Guard Pro → PlayMMO CMS This approach is more correct than trying to solve all problems only at the PHP level.
  • Topics

×
×
  • Create New...

Important Information

This community uses essential cookies to function properly. Non-essential cookies and third-party services are used only with your consent. Read our Privacy Policy and We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue..