airdcpp / airdcpp-windows

http://www.airdcpp.net
GNU General Public License v3.0
82 stars 19 forks source link

Search spam detected (False Positive Behavior) #94

Closed ryehamstrawberry closed 5 months ago

ryehamstrawberry commented 1 year ago

Prerequisites

Describe the issue

After the latest v4.21 update, myself and many other users are CONSTANTLY receiving the following error: *** Search spam detected from <IP> (<username>) (severe). The hub will be disconnected in order to preserve system resources. If you continue receiving this error, it may indicate that the hub utilizes its users in a DDoS attack.

In some cases, this causes users to actually disconnect from the hub itself.

This issue was NEVER present in previous AirDC versions.

I would posit that whatever was implemented or "fixed" in the latest update is now causing many false positive results due to being too aggressive. Please consider removing, changing or otherwise toning down whatever is causing AirDC to interpret normal search queries as "attacks". In all my years using DC, I've never heard of anyone utilizing it for DDoS attacks, so whatever this latest version is supposed to "fix" is probably causing MORE issues than it solves.

Expected behavior

No disconnection from hubs.

Actual behavior

In some cases just the message is received but in other situations, entire hub userlists are being disconnected simultaneously.

Steps to reproduce the behavior if needed

No response

Screenshot

No response

Crash log

No response

AirDC++ version and architecture (x86 or x64)

4.21 x64

Operating System name, version and architecture

Windows 10 21H2 x64

Additional information

No response

maksis commented 5 months ago

The current limit for severe search spam is 60 searches within 60 seconds. As I don't know that how much searching is considered to be normal by the author, I'm not sure what to do here. The current limit isn't causing issues for me.