Games are susceptible to repeated DDoS attacks, resulting in >86% playercount decrease in my game

Know what else is repetitive? ai slop comments like this ragebait comment of yours

6 Likes

Same thing is happening to us. Seems to be one guy and he started doing it around August 13th, last attack was yesterday. We lost a few hundred ccu due to this.
Booga Booga | Play on Roblox

2 Likes

I see.

This means the best way to protect our games would not be to block these bad actors completely (We can’t do that, sadly), but mitigate it as best as we can.

One can assume that all Publicly accessible games/places are at a higher risk (including places behind Hubs/Checkpoints), thanks to the way these attacks are occurring.

This means primarily secure servers are at a significantly lower risk at these attacks, as I presume secure servers (such as Private/Reserved) have a secure token, or other secure way to validate the user

Say, all publicly accessible servers in your average Story game gets attacked. (The story game consists of a Join Checkpoint, the Actual Lobby, and the Game).
Once players are in said reserved server in the Game, they are essentially isolated from the Lobby, and therefore, have a significantly reduced chance of being attacked. (Note that the risk still remains for the isolated server to be attacked, if the attacker grabs hold of the secure token)

Using this theory, smaller games may benefit from creating dedicated Private/Reserved servers that ensure a player, verified by an external source (eg a Unique, Per-Player Code off a Discord Server, Daily Refreshing Private Server Link, etc) and experience reduced attacks.

While this would essentially block anyone without access to the verified access method (particularly those U16), it’s a good temporary measure. Smaller games may wish to have both a dedicated attack-resistant (eg Private/Reserved) and a publicly accessible server, too,

However, in general, especially for quite a few of the roleplay games and others that centralise players, that are being targeted, such as the OP’s and the O&I, this solution would not be ideal as games like these require new players to thrive.
Often, these new players may not be in the Group or Server, too, which is an important part to consider.

Scanning new players may also not work too, because there is always the potential for the attacker to already has access to said verification method.
But, if these attacks are indeed automated, it may be possible to tag each player with an access identifier and see which identifiers have passed through a fresh new server to deduce the compromised token
(Although, note that you shouldn’t use or share this identifier between games to abide by ToS’s tracking restrictions!)

Another mitigation could be a server browser, as the OP has mentioned using, as it adds a UI block. Potentially pressing a series of buttons before accessing the browser could help to mitigate automated attacks even more. (quite literally like a Captcha)

TL;DR, though, mitigation tactics like external access methods (eg Private servers, Secret code) or automation blocks (eg a UI Captcha-style block) may just help to reduce the attacks, even if by a tiny bit.

2 Likes

This is the most insensitive comment I have seen on a developer forum yet. You think we are all terrible developers and some games LISTED haved been around for years, with large teams developing these games and you think posting something like this was helpful by any kind? If you even took a hour out of your day to read this forum STAFF themselves have also said this is a roblox issue and confirmed a issue, Some of use these games to fund college, or housing, or extra rent money. Please going forward think about how you communicate within this community we are all trying our hardest to be one. Thank you.

3 Likes

grok generate me ragebait comment

3 Likes

You should genuinely be ashamed of what you wrote. The problem is real, and you came here solely to offend people who are watching their games constantly crash and have absolutely no way to do anything about it.

Flagged the comment, hope it get removed ASAP

8 Likes

They’ve been able to crash literal empty baseplates. Your comment is hypocritical.

7 Likes

In my case remotes aren’t being overwhelmed and the memory scaling isn’t on the game level. Please don’t always assume that it’s an error on the developer end.

Roblox acknowledged the issue, so there’s no need for whatever you’re doing here.

If you’re not having the issue, good for you. Leave it at that.

6 Likes

I’m happy to report that a fix has rolled out to new servers on version 736, and our telemetry indicates it has significantly reduced server crashes related to DOS attacks.

Thank you all very much for your patience. In light of these attacks, we are taking a proactive and diligent pass at our server defense mechanisms so that this doesn’t happen again.

39 Likes

Thank you for the update and for listening to the developers who have been affected by this. We really appreciate Roblox taking this seriously and working on a platform-level fix.

We’ll continue monitoring our servers closely to see if the issue occurs again, and we’ll let you know if we notice any further incidents or unusual crash patterns. We appreciate your efforts in improving the server defenses.

6 Likes

Would be a great idea to compensate affected developers.

4 Likes

I doubt they would do this. I’ve given refunds to my players for private servers (including the Roblox 30% cut) to help with this and I don’t expect that Roblox will provide anything for it.

If only though…

2 Likes

This is a godsend, thanks a lot brother. We’ll be sure to let you guys know if anything else occurs. :flexed_biceps:

2 Likes

Hey!

Just a follow-up on the service that was causing this problem.

As most people know, its name was “Nullstrike”, (there was also minor service btw) which was the most well-known one. After @PlumJar announced the patch, their server was terminated, including the bot that was also posted in the first topic here.

The service was terminated thanks to a report I submitted. Following this, all of their social media accounts were also removed, most likely by the authors themselves.

This effectively marks the end of the DDoS attacks and means that, this time, Roblox took the correct action and successfully addressed the issue.

Big thanks to the entire networking team for addressing the issue. Since they can no longer operate their service, those people have effectively been forced to shut down their operation and can no longer continue their business.

As in every story, the good guys always win, while the bad guys fall and perish. (I’ll leave another old story with a happy ending for people who know a bit of roblox story:
Exploit Prevention Update - Synapse X End


14 Likes

Glad to hear this is all resolved now.
Props to ROBLOX for taking it seriously

1 Like

I was one of the original reporters of this issue & it has been confirmed by ROBLOX staff to be a genuine DDOS issue. I managed to get an exploiter to crash a completely empty baseplate.

My initial thought was also insecure remotes, until the baseplate confirmed otherwise, we cannot jump to assumptions in situations like these especially since so many people reported this issue being the exact same set of circumstances…

“Also, keep in mind that private servers, reserved servers, and rank-locked servers are often not affected because they are not publicly accessible.” - although this is trueish - users were implementing public server browsers not private servers - so any remote exploits would still be completely possible inside of them. The reason this fixed the issue was actually because it was much harder for the specific services to get the server IP and send packets.

3 Likes

Unfortunately, our servers are still being DDoS attacked for unknown reasons; it is currently unclear who is behind it and what methods they are using.

We are seeing server crashes across varying uptimes, and the servers were running on engine version 736.

Classified as “Platform Crashes”
Game: Bobruisk RP
Screenshots:


13 Likes

Issue is also still not resolved on my end. My game faces the problem of people using paid stressers to occasionally take down our servers. Are you guys still looking into this issue?

4 Likes

plumjar, the issue is still not resolved. the same person who was ddosing my game is making new threats, and he ddosed another server just to prove that if we don’t pay him, he will start attacking our servers again.

unfortunately, this issue needs to be fixed or at least mitigated. a lot of developers are being attacked and extorted because of a long-standing flaw, and what’s even worse is that the ccu we had before the attacks still hasn’t recovered. what can i realistically do in this situation? it feels like a time bomb that i have no control over.

my game link: Metropolis RP | Play on Roblox

8 Likes

I just wanted to ask if there is any information about fixing the authentication bypass by capture replay vulnerability with the teleportToken? In my own testing I found that teleportTokens can be captured and re-used within their lifespan.

I reported this to HackerOne and they said they were aware of this behavior, but it really sucks that secure server teleports can be bypassed.

1 Like