This I did not know, I assumed it had to be corrected via module or something in my kernel from what another said on the Gentoo forum. I am lost with networking etc…will change /proc/sys/net/ipv4/ip_default_ttl and report back. Thanks
Edit: Thanks so much, I learned something from this. I was unaware I could change that value without a recompile. Cheers, it worked!
Just tested this this on Manjaro. Instantly fixed! Had to use sysctl method to change ttl, but yeah. Lets hope this continues to work and we get to play now!
After narrowing this down last night and proving it is a issue focused on linux and passive fingerprinting
Here is the info you all need to review to understand what they are doing and why, perhaps some windows 10 users have similar ‘strange out of spec’ packets. (perhaps they ran some network customization tools?)
Please review an external PDF paper from SFU university here on this topic:
SFU article on DDOS and packet fingerprinting (TTL is #1 stealth method) => journals.sfu.ca/apan/index.php/apan/article/download/14/5
UPDATE: windows 10 users may want to try this fix that was recently posted after we narrowed this down for linux users.
For linux users please check around on the internet for solutions based on your distro on how to change your TTL
The values listed in the PDF link explain what other odd TTL’s different linux distros may use, windows generally defaults to 128 (but this can change to)
Yes mask your TTL as something else besides 64 via proc, most distro’s it is like this:
echo 128 > /proc/sys/net/ipv4/ip_default_ttl
If that works for you scan there is a perm way to adjust this, it is the best work around we have right now until blizz corrects the way they are doing their passive packet checks.
The above all depends on the distro you use, so find what works for your OS using a search engine.
Can confirm, getting error WOW51900328 also on a Windows 10
ISP Comcast
I believe my account is Flagged because of other Blizzard Products working not on that account.
Blizzard has had a ticket submitted for 8 hours now and no response. I hope to be compensated for the time loss I have suffered and paid for…
Think back to the march update that broke linux + wine with a graphics update. It was the linux community that found 1 or 2 work around whether you used lutris to set up your wine install or like do I use wine-staging without any extra config.
At least the current work around still works this morning. Testing purely for academic purposes of course while having my 1st cuppa for the day.
Best thing to do would be to check Untangle forums (if that is what you use) or contact their support. Not worth banging your head on a desk to figure this out
Others have been able to get this changed in their router so it could be a setting somewhere YMMV.
Cmon people don’t delete your posts. We need to know how many linux users (or windows users) [or other users] are impacted by this and if anything worked for you.
I had the issue yesterday as well. Since yesterday, I logged on the account on my wife Windows10 computer. Maybe this marks the account as being suspicious because of different kind of fingerprint but it comes from the same external IP so IDK.