Synopsis
I believe that my game is a target of frequent DDoS attacks. These services are monetizing the crashing of Roblox games.
Example of an illicit server’s pricing page, specifically designed for DDoSing Roblox games
Our playercount after these attacks started has dropped from peaks of around 200 to lows of 20 during the attacks.
Some of these services are attached in a private report to support investigation (not shared publicly to prevent spreading of the servers).
Supporting information
I understand that it is definitely possible that an exploiter could be crashing my game through RemoteEvent spam or other issues. However, I believe this is not the case because of the following reasons:
- Similar games are being crashed at the same time as our game, indicating a universal exploit.
- The crashes only happen to our main servers, not any private servers or reserved servers that are rank locked.
- The servers sometimes last for days, but once an attack is initiated the servers repeatedly crash for the duration of the attack before returning to normal.
Additionally, we had locked our game temporarily to only returning players and the attacks continued, supporting evidence that exploiters did not need to be inside of the game. We also scanned all players and had extensive RemoteEvent logging and a large staff presence inspecting and removing any suspicious players. Alas, the server crashed still. I believe this is further evidence that they are utilizing a UDMUX bypass exploit, as they must receive the game server IP from the roblox server page
For more context, our game is a game revolving around a high playercount per server, but centralized in one server, making it particularly vulnerable to attacks like these.
Crash Images
Supplied by players of the game.
Playercount data
Playercount graph after attacks started - players can be seen being crashed and attempting to rejoin multiple times
Typical playercount graph (~4 days ago)
Possible mitigations
If possible, I would really appreciate getting a DDoS protected server, as I believe similar games have received this in the past.
I also understand there are some mitigations to make it more difficult to DDoS like making a server browser, but this would be easily bypassable if a malicious actor navigated into the primary server, thus receiving the IP of the game server and then being able to crash it.
A private message is associated with this bug report








