View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
0009363 | 10000-002: Security | Spec | public | 2024-01-17 16:56 | 2024-02-27 17:47 |
Reporter | Martin Regen | Assigned To | Paul Hunkar | ||
Priority | normal | Severity | minor | Reproducibility | N/A |
Status | assigned | Resolution | open | ||
Product Version | 1.05.03 | ||||
Target Version | 1.05.04 RC1 | ||||
Summary | 0009363: Proposal to add advanced security validation to the first hello/reverse hello message | ||||
Description | The security WG discussed this topic on Jan 17th 24. The problem was discovered on the .NET server when a misconfigured http service keeps trying to open the server endpoint. In fact the connection was initiated by a http GET request: GET /metrics HTTP/1.1 where /met is interpreted as the message size. The malicious connection was only identified by the bad buffer size and caused a channel fault. in the worst case the misconfigured service spams just the log files, but a malicious service could use the vector to cause some sort of DoS attack. The conclusion of the discussion was to recommend to add a more sophisticated first packet inspection when the first hello/reverso hello message is parsed. | ||||
Tags | No tags attached. | ||||
Commit Version | |||||
Fix Due Date | |||||
Date Modified | Username | Field | Change |
---|---|---|---|
2024-01-17 16:56 | Martin Regen | New Issue | |
2024-02-27 17:40 | Jim Luth | Assigned To | => Randy Armstrong |
2024-02-27 17:40 | Jim Luth | Status | new => assigned |
2024-02-27 17:46 | Jim Luth | Project | 10000-006: Mappings => 10000-002: Security |
2024-02-27 17:46 | Jim Luth | Assigned To | Randy Armstrong => Paul Hunkar |
2024-02-27 17:47 | Jim Luth | Note Added: 0020868 |