View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0009363 | 10000-002: Security | Spec | public | 2024-01-17 16:56 | 2025-07-08 16:26 |
| Reporter | Martin Regen | Assigned To | Paul Hunkar | ||
| Priority | normal | Severity | minor | Reproducibility | N/A |
| Status | closed | Resolution | fixed | ||
| Product Version | 1.05.03 | ||||
| Target Version | 1.05.04 RC1 | Fixed in Version | 1.05.06 RC1 | ||
| Summary | 0009363: Proposal to add advanced security validation to the first hello/reverse hello message | ||||
| Description | The security WG discussed this topic on Jan 17th 24. The problem was discovered on the .NET server when a misconfigured http service keeps trying to open the server endpoint. In fact the connection was initiated by a http GET request: GET /metrics HTTP/1.1 where /met is interpreted as the message size. The malicious connection was only identified by the bad buffer size and caused a channel fault. in the worst case the misconfigured service spams just the log files, but a malicious service could use the vector to cause some sort of DoS attack. The conclusion of the discussion was to recommend to add a more sophisticated first packet inspection when the first hello/reverso hello message is parsed. | ||||
| Tags | No tags attached. | ||||
| Commit Version | |||||
| Fix Due Date | |||||
|
|
Add section to Part 2 about mitigating DOS effects by log throttling. |
|
|
added text recommending statistical counters instead of verbose logging |
|
|
Agreed to changes edited in Web Meeting. |
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2024-01-17 16:56 | Martin Regen | New Issue | |
| 2024-02-27 17:40 | Jim Luth | Assigned To | => Randy Armstrong |
| 2024-02-27 17:40 | Jim Luth | Status | new => assigned |
| 2024-02-27 17:46 | Jim Luth | Project | 10000-006: Mappings => 10000-002: Security |
| 2024-02-27 17:46 | Jim Luth | Assigned To | Randy Armstrong => Paul Hunkar |
| 2024-02-27 17:47 | Jim Luth | Note Added: 0020868 | |
| 2025-07-08 01:41 | Paul Hunkar | Status | assigned => resolved |
| 2025-07-08 01:41 | Paul Hunkar | Resolution | open => fixed |
| 2025-07-08 01:41 | Paul Hunkar | Fixed in Version | => 1.05.06 RC1 |
| 2025-07-08 01:41 | Paul Hunkar | Note Added: 0023091 | |
| 2025-07-08 16:26 | Jim Luth | Status | resolved => closed |
| 2025-07-08 16:26 | Jim Luth | Note Added: 0023095 |