Skip to content
This repository has been archived by the owner on Apr 26, 2024. It is now read-only.

We shouldn't let people DoS us via /sync (SYN-660) #1239

Open
matrixbot opened this issue Mar 22, 2016 · 2 comments
Open

We shouldn't let people DoS us via /sync (SYN-660) #1239

matrixbot opened this issue Mar 22, 2016 · 2 comments
Labels
A-Sync defects related to /sync T-Defect Bugs, crashes, hangs, security vulnerabilities, or other reported issues.

Comments

@matrixbot
Copy link
Member

Submitted by @​matthew:matrix.org
If people are hammering us too rapidly on /sync without a timeout or with too small a timeout, presumably we should insert an implicit timeout to slow them down. c.f. the current DoS from 93.92.200.183

(Imported from https://matrix.org/jira/browse/SYN-660)

@matrixbot matrixbot changed the title We shouldn't let people DoS us via /sync (SYN-660) We shouldn't let people DoS us via /sync (https://github.com/matrix-org/synapse/issues/1239) Nov 7, 2016
@matrixbot matrixbot changed the title We shouldn't let people DoS us via /sync (https://github.com/matrix-org/synapse/issues/1239) We shouldn't let people DoS us via /sync (SYN-660) Nov 7, 2016
@richvdh
Copy link
Member

richvdh commented Feb 26, 2020

we also shouldn't let them DoS us via initial /sync.

See also #6998.

@olmari
Copy link
Contributor

olmari commented Apr 26, 2022

This can be abused very easily with request that one does not care answer for, just fire away... sent PoC on security email. In order of seconds to make our quite beefy HS to OOM...

@dkasak dkasak added T-Defect Bugs, crashes, hangs, security vulnerabilities, or other reported issues. A-Sync defects related to /sync labels Apr 26, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
A-Sync defects related to /sync T-Defect Bugs, crashes, hangs, security vulnerabilities, or other reported issues.
Projects
None yet
Development

No branches or pull requests

4 participants