Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

New DoS: too much data in MapServer #38

Open
juagargi opened this issue Mar 24, 2023 · 0 comments
Open

New DoS: too much data in MapServer #38

juagargi opened this issue Mar 24, 2023 · 0 comments

Comments

@juagargi
Copy link
Member

A new attack surface appears with the MapServer. If a malicious CA creates an absurd number of entries for a domain name, those will be recorded by the CT Log Server, and afterwards by the MapServer.
A client requesting the material for that domain name will receive as much data as the attacker decides, rendering the connection to the MapServer useless.

  • Decide what attacker models appear because of this.
  • Decide how to solve or mitigate this.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant