Skip to content
This repository has been archived by the owner on Apr 26, 2024. It is now read-only.

Synapse spams servers with requests to /_matrix/federation/v1/get_groups_publicised #3032

Closed
jevolk opened this issue Mar 26, 2018 · 3 comments
Labels
z-bug (Deprecated Label) z-p2 (Deprecated Label)

Comments

@jevolk
Copy link

jevolk commented Mar 26, 2018

When the server responds with a 404 to this endpoint, synapse infinitely loops on hitting it again.

Be advised that this can be used as part of a denial of service attack.
screenshot from 2018-03-26 14-06-56

@neilisfragile neilisfragile added z-bug (Deprecated Label) z-p2 (Deprecated Label) labels Mar 27, 2018
@jevolk
Copy link
Author

jevolk commented Mar 28, 2018

FTR the endpoint is not satisfied with a 200 OK, an empty {} or even {"users": {}}

It doesn't stop until you repeat back the users it asked for in the request with empty arrays for each one.

@maxidorius
Copy link
Contributor

I'm also seeing this on mxhsd

@squahtx
Copy link
Contributor

squahtx commented Oct 5, 2022

#12563 and related PRs removed the groups feature.
The endpoint in question no longer exists and is no longer requested.

@squahtx squahtx closed this as completed Oct 5, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
z-bug (Deprecated Label) z-p2 (Deprecated Label)
Projects
None yet
Development

No branches or pull requests

4 participants