Salut
Am aruncat si eu o privire acolo. Se pare ca ai de-a face cu https://security.stackexchange.com/questions/168375/how-to-prevent-tsource-engine-query-ddos-attack
Cel putin asa vad eu din packete
01:20:05.675519 IP (tos 0xc, ttl 113, id 30221, offset 0, flags [none], proto UDP (17), length 53)
157.166.145.173.29350 > 5.254.116.174.27016: [udp sum ok] UDP, length 25
0x0000: 450c 0035 760d 0000 7111 299f 9da6 91ad E..5v...q.).....
0x0010: 05fe 74ae 72a6 6988 0021 bac3 ffff ffff ..t.r.i..!......
0x0020: 5453 6f75 7263 6520 456e 6769 6e65 2051 TSource.Engine.Q
0x0030: 7565 7279 00 uery.
01:20:05.675691 IP (tos 0xc, ttl 113, id 2253, offset 0, flags [none], proto UDP (17), length 53)
121.140.205.177.55813 > 5.254.116.174.27016: [udp sum ok] UDP, length 25
0x0000: 450c 0035 08cd 0000 7111 7ef5 798c cdb1 E..5....q.~.y...
0x0010: 05fe 74ae da05 6988 0021 3b7a ffff ffff ..t...i..!;z....
0x0020: 5453 6f75 7263 6520 456e 6769 6e65 2051 TSource.Engine.Q
0x0030: 7565 7279 00 uery.
As incerca un filtru pe iptables ceva de genul
iptables -A INPUT -p UDP --dport 27016 -m string --hex-string '|5453 6f75 7263 6520 456e 6769 6e65 2051|' --algo kmp -j DROP
Regula ar aparea ceva de genul:
0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:27016 STRING match "TSource Engine Q" ALGO name kmp TO 65535