Re: The git protocol and DoS
- From
- Tony Luck <tony.luck@gmail.com>
- Date
- Oct 19, 2005, 22:39 UTC
- Message-ID
- <12c511ca0510191539w3dd76f89ra5fe48e1d84750d6@mail.gmail.com>
- In-Reply-To
- <20051019222044.GP30889@pasky.or.cz>
On 10/19/05, Petr Baudis <pasky@suse.cz> wrote:
> [client] git-upload-pack <path> > [server] challenge somethingnonsensical > [client] challenge-response <username>:sha1(somethingnonsensical<password>) > [server] All right, the pack goes like this...
I think this requires that the server store the cleartext version of the password so that it can validate sha1(somethingnonsensical<password>) ... which is generally thought to be a bad idea.
-Tony