Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
FulsomFrank
Sep 11, 2005

Hard on for love

SirSamVimes posted:

lmao how am I going to gently caress this up



I mean the answer is clearly "hubris" but what specifically is going to obliterate me? Note: I got all those muts from a pair of mutation potions I found on D1.

edit:I plan on 15 runing and have the Justice pledge, so let's be real it'll be Tomb or Cerebov.

Nice gear so far for sure but you're definitely lacking in the elemental resist department and that will be your death if you're not careful. I would ditch the flying/stealth ring for something with pips toward resistances ASAP especially if you go into branches with different focuses. Hopefully you'll find some art cloaks/boots and a better helmet during your adventures too.

Adbot
ADBOT LOVES YOU

Captainsalami
Apr 16, 2010

I told you you'd pay!

SirSamVimes posted:

lmao how am I going to gently caress this up



I mean the answer is clearly "hubris" but what specifically is going to obliterate me? Note: I got all those muts from a pair of mutation potions I found on D1.

edit:I plan on 15 runing and have the Justice pledge, so let's be real it'll be Tomb or Cerebov.

You on kelbi?

rchandra
Apr 30, 2013


SirSamVimes posted:

Hey I decided to try getting back into this game, and I've got a problem. For some reason whenever I try to move south or southwest using the numpad, the game just tells me I don't know any spells. I've tried erasing my rc completely, and it did nothing.


Check if there's a macro on those keys. ~ or ctrl-D or *d should get you there.

SirSamVimes
Jul 21, 2008

~* Challenge *~


Captainsalami posted:

You on kelbi?

Project357 but I went to sleep right after posting that.

Dropbear
Jul 26, 2007
Bombs away!
Got a merfolk skald to a pretty promising place - level 27, alright skills, pretty good gear etc. Only have one win (3 rune) before this, so figured I'd go a bit further this time; I've never really seen much of the optional endgame stuff. I've been worshipping Ashenzari so far and it's been very useful, but it seems that tapers off somewhat; I figured I'd switch him to the Shining One.

That might have been a mistake. The -4 skill-thing hurts more than it sounds, and I didn't even realize how much I've relied on scrying until I can't anymore. Oh well, got to deal with it now. All of the easy branches (vaults, elf, crypts, depths, everything under lair) is cleared; I wonder if it's worth wandering around Abyss 1 to get some Shining One favor & get rid of Ashenzari's bad feels? Never really been much into the abyss (lucked into getting the rune by getting banished almost next to it), 1 isn't that deadly for an endgame character, right?

Araganzar
May 24, 2003

Needs more cowbell!
Fun Shoe

Araganzar posted:

Here is a poll on the latest changes as well as a number of changes to vanilla trunk since we diverged.

Direct URL is https://forms.gle/xAkRrnkMgmnxFtqx5

The vanilla changelog is at https://github.com/crawl/crawl/blob/master/crawl-ref/docs/changelog.txt if you want to review, I tried to pull stuff that was pretty contained but if there is stuff I missed people want we can add it to the next poll.

Poll reminder - we have 7 responses so far. Not sure how many we need to be considered a consensus but maybe 20?

Got the daemon working for Fork-based Scoring so you should see your wins and losses at least as quickly as you see them on CAO for trunk. I've splatted about 12 characters across 3 servers and 3 forks and I'm seeing them all flow through. Let me know if you encounter any games you don't see recorded, to be clear you should see your scores from any game you play on any fork on any server.

Plan is to (a) work with Bloodnok on a fix for stoat soup (presently presents as git without extra SQL), (b) add back the old queries from CAO with server name and fork included, and (c) find a way to throw banners up for pledges players have completed.

SirSamVimes posted:

Project357 but I went to sleep right after posting that.

https://crawl.project357.org/morgue/SirSamVimes/SirSamVimes.txt if you're wanting to review the last dump, Cap.

Looks good, you could probably get 2-3 EV with minimal investment in Dodging, other than that would echo that extended will be difficult if you don' t find some more resists, particularly another decent randart ring. Still a lot of game left before that decision though. Finisher is strong esp with some haste. Zin makes it hard to just straight up die. I'd go for it.

Speleothing
May 6, 2008

Spare batteries are pretty key.

Dropbear posted:

Got a merfolk skald to a pretty promising place - level 27, alright skills, pretty good gear etc. Only have one win (3 rune) before this, so figured I'd go a bit further this time; I've never really seen much of the optional endgame stuff. I've been worshipping Ashenzari so far and it's been very useful, but it seems that tapers off somewhat; I figured I'd switch him to the Shining One.

That might have been a mistake. The -4 skill-thing hurts more than it sounds, and I didn't even realize how much I've relied on scrying until I can't anymore. Oh well, got to deal with it now. All of the easy branches (vaults, elf, crypts, depths, everything under lair) is cleared; I wonder if it's worth wandering around Abyss 1 to get some Shining One favor & get rid of Ashenzari's bad feels? Never really been much into the abyss (lucked into getting the rune by getting banished almost next to it), 1 isn't that deadly for an endgame character, right?

Yeah abyss 1 is usually a safe place to hang out by then.

girl dick energy
Sep 30, 2009

You think you have the wherewithal to figure out my puzzle vagina?

Speleothing posted:

Yeah abyss 1 is usually a safe place to hang out by then.
The secret to surviving in Abyss is to keep moving, killing only dangerous abyss-specific enemies (starcursed masses, wretched stars, ancient zymes, worldbinders) and only stopping to heal when the geography literally traps you.

girl dick energy fucked around with this message at 23:33 on Jan 22, 2020

SirSamVimes
Jul 21, 2008

~* Challenge *~


the answer was neglecting to bring rcorr to dis and getting my 50 AC corroded to 24

:smith:

girl dick energy
Sep 30, 2009

You think you have the wherewithal to figure out my puzzle vagina?

SirSamVimes posted:

the answer was neglecting to bring rcorr to dis and getting my 50 AC corroded to 24

:smith:
:smith:

code:
PoisonMushroom the Fencer (AbAc)                   Turns: 31705, Time: 02:35:18

Health: 165/165    AC: 36    Str: 19    XL:     20   Next: 25%
Magic:  28/28      EV:  5    Int: 17    God:    Gozag
Gold:   1384       SH: 19    Dex:  9    Spells: 26/30 levels left

rFire    + . .     SeeInvis +   a - +7 Singing Sword {slice, sonic wave}
rCold    + + .     Gourm    .   S - +0 shield {reflect}
rNeg     + + +     Faith    .   T - +9 scales of the Dragon King {rPois rF+ rC+ MR+}
rPois    +         Spirit   .   l - +2 helmet
rElec    .         Reflect  +   z - +1 cloak {MR+}
rCorr    +         Harm     .   J - +0 pair of boots
MR       ++...     Clarity  +   E - +6 amulet of reflection
Stlth    ..........             (no ring)
HPRegen  1.77/turn              (no ring)
MPRegen  0.21/turn

@: regenerating
A: tentacle arms, two strong arms, no magic resistence, amphibious, 8 rings,
fangs 1, clarity, regeneration 1, strong 1, heat vulnerability 2
}: 2/15 runes: serpentine, barnacled
a: Release Permanent Buffs, Potion Petition, Call Merchant, Bribe Branch,
Renounce Religion
code:
 o - a ring of positive energy (on tentacle)
 r - a ring of see invisible (left tentacle)
 x - a ring of positive energy (on tentacle)
 C - a ring of protection from fire (right tentacle)
 E - a +6 amulet of reflection (around neck)
 G - a ring of resist corrosion (on tentacle)
 U - a ring of wizardry (on tentacle)
 V - the ring of False Hope (on tentacle) {rF+ MR+ Slay+5}
 Z - the ring of Symmetry (on tentacle) {rC+ rN+ MR- Int+2 Slay+6}
Full dump

Had lots of luck from floorgod this game with armor, I had +10 randart plate that gave MR+ before the scales, and +2 plate of MR+ before that. It's been very feast or famine, though, as the boots probably give away. Where am I going next? Depths to 4? Vault to 4? Abyss? Slime? My gut says maybe Slime, since my resists are still kinda garbage even after just spending $5k summoning a jewelry shop and getting two good randart rings. The screaming from my sword might be able to clear out the royal's trash, but then again, without any option for summons, I'm really gonna be up poo poo creek if it doesn't work out.

Edit: Went for Slime, found acquirement, wished Jewelry.

code:
D - the ring of Sloth (on tentacle) {rF+ MR+++ Int+4 Dex-3}
Yeah, that'll work. :stonklol:

girl dick energy fucked around with this message at 03:55 on Jan 23, 2020

HisMajestyBOB
Oct 21, 2010


College Slice

Araganzar posted:

Dev seems to be stable, going to change out conjure flame and dazzling spray and pull in recent FK changes to the main branch. I've also added limited voice recognition for laptop keyboards where you can shout the direction you want to move at the screen. Please don't be alarmed if you see your microphone and camera turning on as you play! You have to be really loud, if it's not working try being much louder.

Here is a poll on the latest changes as well as a number of changes to vanilla trunk since we diverged.

Direct URL is https://forms.gle/xAkRrnkMgmnxFtqx5

The vanilla changelog is at https://github.com/crawl/crawl/blob/master/crawl-ref/docs/changelog.txt if you want to review, I tried to pull stuff that was pretty contained but if there is stuff I missed people want we can add it to the next poll.

I don't like drain on bat form, but otherwise the Vampire changes could be worth a try. I don't like how drain in general gas become a crutch for "this option should have a downside."

girl dick energy
Sep 30, 2009

You think you have the wherewithal to figure out my puzzle vagina?
Gozag + Vault bombing =

Araganzar
May 24, 2003

Needs more cowbell!
Fun Shoe

PMush Perfect posted:

Gozag + Vault bombing =



My current Ab^Gozag has Finisher and it's the biggest pain in the rear end in the world. I bet I spend half my turns picking up 1-2 gold pieces at a time.

Mr. Lobe
Feb 23, 2007

... Dry bones...


PMush Perfect posted:

The secret to surviving in Abyss is to keep moving, killing only dangerous abyss-specific enemies (starcursed masses, wretched stars, ancient zymes, worldbinders) and only stopping to heal when the geography literally traps you.

Also having good regeneration resources and, if caster, channeling

Araganzar
May 24, 2003

Needs more cowbell!
Fun Shoe

HisMajestyBOB posted:

I don't like drain on bat form, but otherwise the Vampire changes could be worth a try. I don't like how drain in general gas become a crutch for "this option should have a downside."

Drain on bat form is probably negotiable. I'm okay with it on flight although I wish it was a forced stop message by default.

So this was an interesting fight...
pre:
 44870 | Crypt:2  | Killed Khufu
 44880 | Crypt:2  | Killed Margery
 44892 | Crypt:2  | Killed Boris
 44895 | Crypt:2  | Killed Mara
Demonstrating the importance of establishing a strong defensive position with Chei:

Shady Amish Terror
Oct 11, 2007
I'm not Amish by choice. 8(
Chei has always been a much better god than most people will give them credit for, due to the weird, awkward playstyle. My main problem with Chei is that they're the God of Killing You For A Single Miss-key. :v:

Rodney The Yam II
Mar 3, 2007




HisMajestyBOB posted:

I don't like drain on bat form, but otherwise the Vampire changes could be worth a try. I don't like how drain in general gas become a crutch for "this option should have a downside."

I kinda hate the bat drain. I guess it makes it more of an emergency option but it doesn't feel very... Vampire-y to me

Serephina
Nov 8, 2005

恐竜戦隊
ジュウレンジャー

What's going on here? Why are there no walls? Why can't you see the hell knights directly south of yourself?

It took me FAR too long to parse that image and differentiate the walls from the floor, wow. Does that need reviewing? Is it just me?

Cardiovorax
Jun 5, 2011

I mean, if you're a successful actress and you go out of the house in a skirt and without underwear, knowing that paparazzi are just waiting for opportunities like this and that it has happened many times before, then there's really nobody you can blame for it but yourself.
It's probably easier to see when the door is closed, and it's not like you can approach an open door without seeing where your FOV starts to extend into an open space. Seems like it should be very low-priority, if it's even worth fixing at all.

cock hero flux
Apr 17, 2011



Shady Amish Terror posted:

Chei has always been a much better god than most people will give them credit for, due to the weird, awkward playstyle. My main problem with Chei is that they're the God of Killing You For A Single Miss-key. :v:

i like chei because i like being able to cast spells in full plate

i hate chei because i hate to accidentally fat finger a movement key and have an entire platoon of hell knights kramer into vision and gently caress my poo poo up

Dachshundofdoom
Feb 14, 2013

Pillbug
Barachians of Chei are really nice because of the free semi-controlled blink, you just have to get past the first 10 floors without your speed and +LOS getting you splattered.

Araganzar
May 24, 2003

Needs more cowbell!
Fun Shoe
Yeah Crypt walls and floors all seem to look kind of samey. We should probably have like catacomb walls with embedded bones....

Gooncrawl server is getting closer to completion. I figured out the player status cgi-bin issue, the scoring daemon is done and going nonstop with updates against forks on multiple servers, and the secure socket issues seem to have worked out. Both http and https have been up for several days without crashing. Spectating in console play has also been fixed as have a number of annoying console issues. The issue where people couldn't edit their rcfile in goondev has been fixed. Our local beem has been up for weeks.

Still need to add more forks, set up ttyrec compression daily, set up eatthepurple.org redirects, resolve the "git" issue with stoat soup, and add server name to the scoring.

If you have a chance and have played a bit online, please check https://eatthepurple.com/scoring/ and see if you find any issues with your games or statistics. I will be adding the CAO queries back but I want to make sure this is not screwing up before I invest the time.


Poll news; it looks like unless we have a last minute wave we'll push reaver changes and then I'll be trying to resolve the conflicts with Yeti and Carcine to get them in. After the weekend will post the response totals - so far people seem to mostly want the staff changes and the auto-IDing of monster-wielded weapons. Throwing Darts and Ghost Vaults are very popular as well. We also had a write in for the new Labyrinths which are definitely cool but looked like quite a bit of work.

girl dick energy
Sep 30, 2009

You think you have the wherewithal to figure out my puzzle vagina?
Aw, hell, lost my bomb 'Bom in a zig, 20th floor. Even with statue form and actively playing my harp, I just couldn't keep up with the sheer absurd number of Torments and damnation coming at me. In retrospect, I might have survived if I'd read fog in between reading blink and wildly chugging potions. Ah well. It was absolutely a victory lap, character could have gotten through Zot while asleep.

Dachshundofdoom posted:

Barachians of Chei are really nice because of the free semi-controlled blink, you just have to get past the first 10 floors without your speed and +LOS getting you splattered.
I love Barachi of Chei. Get Faith and spam Slouch and crowds just cease to exist.

SirSamVimes
Jul 21, 2008

~* Challenge *~


I'm gonna splat some AbAc because getting incinerated by an orc wizard seems fun.

Does rF-- increase the damage taken more than rF-, or does it just mean that the first pip of resistance we get does nothing?

girl dick energy
Sep 30, 2009

You think you have the wherewithal to figure out my puzzle vagina?

SirSamVimes posted:

I'm gonna splat some AbAc because getting incinerated by an orc wizard seems fun.

Does rF-- increase the damage taken more than rF-, or does it just mean that the first pip of resistance we get does nothing?
It increases the damage significantly more. IDK the exact amount, but... it's bad.

Cardiovorax
Jun 5, 2011

I mean, if you're a successful actress and you go out of the house in a skirt and without underwear, knowing that paparazzi are just waiting for opportunities like this and that it has happened many times before, then there's really nobody you can blame for it but yourself.
It makes no difference. According to the Crawl wiki, any level of negative resistance increases your damage from projectiles by 50% and from melee attacks by 100%, regardless of how much of a vulnerability to that element you have. If that hasn't changed since 0.18, then you're pretty much still as good as you were, but yes, the first pip of resistance just counteracts the second pip of vulnerability. You'd need a total of three pips to Rf+ to have any fire resistance at all.

SirSamVimes
Jul 21, 2008

~* Challenge *~


Getting two different pieces of info here, is this just something that's different in Gooncrawl and therefore the wiki not applicable?

Also, ended up being para'd to death in Spider by Norris, was a fun run though. Managed to find two Octopus King rings before the ride ended.

cock hero flux
Apr 17, 2011



Are prometheans skillcapped or something? I had my weaponskill get capped out at 13 and it wouldn't me train it any higher. I'm definitely sure I didn't pick the conduct that does that.

Araganzar
May 24, 2003

Needs more cowbell!
Fun Shoe

SirSamVimes posted:

Getting two different pieces of info here, is this just something that's different in Gooncrawl and therefore the wiki not applicable?
Also, ended up being para'd to death in Spider by Norris, was a fun run though. Managed to find two Octopus King rings before the ride ended.

Here's the entirety of the player resist code in Gooncrawl:
code:
    else if (res < 0)
        resistible = resistible * 15 / 10;
If you'd like I can change it to resistible = resistible * (10 + 5 * abs(res)), then rf-- would be 200% damage and rf--- would be 250%.


cock hero flux posted:

Are prometheans skillcapped or something? I had my weaponskill get capped out at 13 and it wouldn't me train it any higher. I'm definitely sure I didn't pick the conduct that does that.

That sounds like the pledge is being applied, maybe it's a save game issue. Hit # to get a dump, if you have a pledge it will say "You have taken the pledge of the xxxxxxxx." right below your character info and before your abilities.

I don't see anywhere you can see your pledge in-game. Maybe we should give the player a non-functional mutation e.g. MUT_PLEDGE_LOREKEEPER?

cock hero flux
Apr 17, 2011



Araganzar posted:

That sounds like the pledge is being applied, maybe it's a save game issue. Hit # to get a dump, if you have a pledge it will say "You have taken the pledge of the xxxxxxxx."

I would do this but I died like 2 minutes after noticing it

cock hero flux
Apr 17, 2011



I just looked through the morgue file and it says "you have taken the pledge of the lorekeeper"

I totally didn't

Cardiovorax
Jun 5, 2011

I mean, if you're a successful actress and you go out of the house in a skirt and without underwear, knowing that paparazzi are just waiting for opportunities like this and that it has happened many times before, then there's really nobody you can blame for it but yourself.

Araganzar posted:

quote:

else if (res < 0)
resistible = resistible * 15 / 10;
If you'd like I can change it to resistible = resistible * (10 + 5 * abs(res)), then rf-- would be 200% damage and rf--- would be 250%.
In other words, it's currently a flat fifty percent of extra damage taken across the board, instead of 100% specifically only for melee attacks.

Personally, I prefer it as it is. A vulnerability is already harmful enough without making it hurt even worse.

Araganzar
May 24, 2003

Needs more cowbell!
Fun Shoe
So I have a problem. I get constant hack attempts on the server, mostly brute force attacks, and it's been compromised once.

quote:

An attempt to brute-force account passwords over SSH/FTP by a machine in your domain or in your network has been detected. Attached are the host who attacks and time / date of activity. Please take the necessary action(s) to stop this activity immediately. If you have any questions please reply to this email.

Telnet is disabled, I have a secure key on SSH. I loaded fail2ban the first day it kills attempts but they keep coming back. I just installed denyhosts and changed the root password to something ridiculously long.

I generally work on secured intranets so I don't know how to handle these constant attacks.

pre:
Jan 24 08:41:36 eatpurple.com login[7201]: FAILED LOGIN (2) on '/dev/pts/3' from '114-35-127-139.HINET-IP.hinet.net' FOR 'root', Authentication failure
Jan 24 08:41:36 eatpurple.com login[7199]: pam_securetty(login:auth): access denied: tty '/dev/pts/8' is not secure !
Jan 24 08:41:36 eatpurple.com login[7203]: FAILED LOGIN (1) on '/dev/pts/4' from '114-35-143-130.HINET-IP.hinet.net' FOR 'root', Authentication failure
Jan 24 08:41:36 eatpurple.com login[7201]: pam_securetty(login:auth): access denied: tty '/dev/pts/3' is not secure !
Jan 24 08:41:36 eatpurple.com login[7207]: pam_securetty(login:auth): access denied: tty '/dev/pts/2' is not secure !
Jan 24 08:41:36 eatpurple.com login[7203]: pam_securetty(login:auth): access denied: tty '/dev/pts/4' is not secure !
Jan 24 08:41:36 eatpurple.com login[7205]: pam_securetty(login:auth): access denied: tty '/dev/pts/5' is not secure !
Jan 24 08:41:38 eatpurple.com login[7197]: FAILED LOGIN (4) on '/dev/pts/7' from '131-0-95-249.ip.siqueiralink.com.br' FOR 'root', Authentication failure
Jan 24 08:41:38 eatpurple.com login[7201]: FAILED LOGIN (3) on '/dev/pts/3' from '114-35-127-139.HINET-IP.hinet.net' FOR 'root', Authentication failure
Jan 24 08:41:38 eatpurple.com login[7207]: FAILED LOGIN (1) on '/dev/pts/2' from 'h169.251.21.98.static.ip.windstream.net' FOR 'root', Authentication failure
Jan 24 08:41:39 eatpurple.com login[7203]: FAILED LOGIN (2) on '/dev/pts/4' from '114-35-143-130.HINET-IP.hinet.net' FOR 'root', Authentication failure
Jan 24 08:41:39 eatpurple.com login[7196]: FAILED LOGIN (4) on '/dev/pts/6' from '220-134-201-62.HINET-IP.hinet.net' FOR 'root', Authentication failure
Jan 24 08:41:39 eatpurple.com login[7201]: pam_securetty(login:auth): access denied: tty '/dev/pts/3' is not secure !
Jan 24 08:41:39 eatpurple.com login[7197]: pam_securetty(login:auth): access denied: tty '/dev/pts/7' is not secure !
Jan 24 08:41:39 eatpurple.com login[7203]: pam_securetty(login:auth): access denied: tty '/dev/pts/4' is not secure !
Jan 24 08:41:39 eatpurple.com login[7199]: FAILED LOGIN (3) on '/dev/pts/8' from '103-101-197-18.Dhaka.carnival.com.bd' FOR 'root', Authentication failure
Jan 24 08:41:39 eatpurple.com login[7196]: pam_securetty(login:auth): access denied: tty '/dev/pts/6' is not secure !
Jan 24 08:41:39 eatpurple.com login[7207]: pam_securetty(login:auth): access denied: tty '/dev/pts/2' is not secure !
Jan 24 08:41:39 eatpurple.com login[7205]: FAILED LOGIN (1) on '/dev/pts/5' from '123-194-87-150.dynamic.kbronet.com.tw' FOR 'root', Authentication failure
Jan 24 08:41:40 eatpurple.com login[7199]: pam_securetty(login:auth): access denied: tty '/dev/pts/8' is not secure !
Jan 24 08:41:40 eatpurple.com login[7205]: pam_securetty(login:auth): access denied: tty '/dev/pts/5' is not secure !
Jan 24 08:41:42 eatpurple.com login[7201]: FAILED LOGIN (4) on '/dev/pts/3' from '114-35-127-139.HINET-IP.hinet.net' FOR 'root', Authentication failure
Jan 24 08:41:42 eatpurple.com login[7197]: FAILED LOGIN (5) on '/dev/pts/7' from '131-0-95-249.ip.siqueiralink.com.br' FOR 'root', Authentication failure
Jan 24 08:41:42 eatpurple.com login[7197]: TOO MANY LOGIN TRIES (5) on '/dev/pts/7' from '131-0-95-249.ip.siqueiralink.com.br' FOR 'root'

Dropbear
Jul 26, 2007
Bombs away!
I heard some dude had won Crawl something like 43 times in a row. How is that even possible, or did he always just run 3-runes with the same builds with easy earlygames? I mean, just today I've had two deaths in floors 1 & 2 where I had no clue what I could have done to prevent it.

First was a floor 1 kobold that came into range & immediately pummeled me to lethal amounts of poison. Drank all my potions, none were curing, dead.
Second was going down the stairs. Sigmund is next to me, follows me back up, dead.

I was a formicid, so -maybe- I could have blinked away from Sigmund if I had that even identified, but still. Seems.. unlikely to not die to a shaft trap or something random in any of 40+ games.

Floodkiller
May 31, 2011

cock hero flux posted:

I just looked through the morgue file and it says "you have taken the pledge of the lorekeeper"

I totally didn't

Can you try to repeat this so I can debug it? If you can get it to happen again, please go into detail every step you took to get it to happen.

Araganzar
May 24, 2003

Needs more cowbell!
Fun Shoe
Server is hyperfucked - from the hosting admin:

quote:

Once a server is compromised, it can't be trusted. There can be so many back doors or trojans that you can't possibly guarantee it's cleaned.

I have backups of milestones and logfiles, your save games and account registrations, all the fork repos, even the ttyrec recordings of games. So those will not be lost. I also have my code changes to fork updates and scoring.

Other than that, I have to restore the initial server image and start over from scratch. Basically the house burned down and I grabbed what I could but it's a depressing amount of work lost.

I still need help securing the system. I work on intranets mainly and this is not a skill I have. I just don't know where that help is going to come from.

Cardiovorax
Jun 5, 2011

I mean, if you're a successful actress and you go out of the house in a skirt and without underwear, knowing that paparazzi are just waiting for opportunities like this and that it has happened many times before, then there's really nobody you can blame for it but yourself.
I'd help if I could, but other than basic concepts like not allowing more than one login attempt per three seconds or so to discourage brute forcing I really don't have a lot of up-to-date technical skills in that area. That's really the most basic thing you can do, though, and most webservers I know of allow that as a setting. It really slows down all sorts of attacks and rarely inconveniences users in a meaningful way.

Araganzar
May 24, 2003

Needs more cowbell!
Fun Shoe

Cardiovorax posted:

I'd help if I could, but other than basic concepts like not allowing more than one login attempt per three seconds or so to discourage brute forcing I really don't have a lot of up-to-date technical skills in that area. That's really the most basic thing you can do, though, and most webservers I know of allow that as a setting. It really slows down all sorts of attacks and rarely inconveniences users in a meaningful way.

I was running fail2ban and denyhosts, they were working and didn't seem to interfere with the webtiles server or web server. I think it will be secure now, basically I just need to uninstall telnet when I'm back up and never install it again. I thought it was disabled but of course Ubuntu has some different voodoo method for that.

I had almost completed a Harvest pledge when I had to take it down, seemed to work fine for both random uniques and other uniques like His Royal Jelliness. My only question is if portals should be included since you aren't really going to another dungeon or branch level and it's not like you can stairs dance with an ice cave portal.

girl dick energy
Sep 30, 2009

You think you have the wherewithal to figure out my puzzle vagina?
Oh! Guess I’m wrong about resists. I’ll believe the code over my apocrypha and personal memory. My bad!

girl dick energy fucked around with this message at 19:49 on Jan 24, 2020

Adbot
ADBOT LOVES YOU

Vadun
Mar 9, 2011

I'm hungrier than a green snake in a sugar cane field.

Araganzar posted:

So I have a problem. I get constant hack attempts on the server, mostly brute force attacks, and it's been compromised once.


Telnet is disabled, I have a secure key on SSH. I loaded fail2ban the first day it kills attempts but they keep coming back. I just installed denyhosts and changed the root password to something ridiculously long.

I generally work on secured intranets so I don't know how to handle these constant attacks.


You can't stop people from attempting to authenticate unless you're willing to totally destroy the player experience, doing somelike like having a jumpserver or whitelisted IP addresses that can even attempt to connect. So you shouldn't do that.

There are various ways to catalog what you would consider to be bad actors, and prevent them from trying to log in again. Basically take x number of failed attempts, or even better failed attempts against known bad accounts and blacklist those IP addresses either forever or for a period of time.

If possible, only allow ROOT to be accessed from your IP address, assuming you have a static or a jump server. If you have non-authentication logs, or logs showing what specific URLs or paths these guys are trying to hit I can also tell you what else they're attempting to do and if its something you need to worry about.

Another, possibly more complicated scenario would be restricting ROOT access to certificate authentication. See https://www.ssh.com/ssh/key

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply