How is it possible to connect 4 times in a row without disconnecting? Or does the log not show disconnections?
If for every new connection like this a SYN packet is sent to the server, that would be some sort of a "brute-force", kinda, sorta. What one could do with this is block a host/IP that tries to send the SYN packet to the LFS server port like 2 times in a second(Or maybe play around with these times and amounts).
Don't know if and how this can be done under Windoze tho(iptables FTW)
Feb 18 01:14:44 Send Track : 87.248.*******
Feb 18 01:14:44 Send Track : 87.248.*******
Feb 18 01:14:48 Alive : 87.248.********
Feb 18 01:14:49 Connect : 87.248.*******
Feb 18 01:14:49 A new guest is connecting
Feb 18 01:14:50 STORE : OVERFLOW - ADMIN
Feb 18 01:14:50 FATAL TCP ERROR : CONNABORTED
Feb 18 01:14:50 Steve Meade Designs^L connected (vivatkamil11^L)
Feb 18 01:14:50 Lost connection to DH™ Dogukan
Feb 18 01:14:50 Lost connection to 06 YM 058
Feb 18 01:14:50 Steve Meade Designs^L connected (vivatkamil11^L)
Feb 18 01:14:50 Steve Meade Designs^L connected (vivatkamil11^L)
Feb 18 01:14:50 Steve Meade Designs^L connected (vivatkamil11^L)
Feb 18 01:14:51 Lost connection to Fazкoq
Feb 18 01:14:59 Steve Meade Designs^L timed out
Feb 18 01:15:11 BLANK : OVERFLOW - ADMIN
Feb 18 01:15:29 › HOST : Emergency Restart
Feb 18 01:15:31 Exit : clean up
Feb 18 01:15:31 Exit : delete
Feb 18 01:15:31 Host will restart in 3 seconds
Feb 18 01:15:34 Track loaded
I'm wondering, wouldn't it be possible to take a look at the packets he's bombarding you with and block them specifically? He must have some kind of script to DoS you like this. Perhaps a full network traffic log recorded with Wireshark or something could be useful...