git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: The git protocol and DoS

From
Petr Baudis <pasky@suse.cz>
Date
Oct 19, 2005, 22:20 UTC
Message-ID
<20051019222044.GP30889@pasky.or.cz>
In-Reply-To
<4356A5C5.5080905@zytor.com>

Dear diary, on Wed, Oct 19, 2005 at 10:00:05PM CEST, I got a letter where "H. Peter Anvin" <hpa@zytor.com> told me that...

> One way to do this would be to start the transaction by having the 
> server transmit a cookie to the client, and to require the client to 
> send a SHA1 of the (cookie + request) together with the request.  This 
> would be done with a fairly short timeout.
  If (well, it sounds like a good idea, so rather "when") you do this,
it would be a good idea to do in a way that makes it easy to later add
support for some kind of authentication (really, not everyone wants to
give away ssh accounts). Let's say it works like:

[client] git-upload-pack <path> [server] challenge somethingnonsensical [client] challenge-response <username>:sha1(somethingnonsensical<password>) [server] All right, the pack goes like this...

  Suddenly you have support for hopefully secure authentication, and at
the same time you have the cookie implemented in backwards-compatible
fashion (in the sense that new client will be able to talk to old
server) - just assume the username and password empty. This might be
even hardcoded for now, just leave a room for its addition (in an
elegant and compatible way) in the protocol, please.
  Thanks,
-- 
				Petr "Pasky" Baudis
Stuff: http://pasky.or.cz/
VI has two modes: the one in which it beeps and the one in which
it doesn't.
Previous: H. Peter AnvinNext: Tony Luck
Message 9 of 12 in “The git protocol and DoS”
  1. H. Peter AnvinOct 19, 2005
  2. Junio C HamanoOct 19, 2005
  3. H. Peter AnvinOct 19, 2005
  4. Junio C HamanoOct 19, 2005
  5. H. Peter AnvinOct 19, 2005
  6. Linus TorvaldsOct 19, 2005
  7. Junio C HamanoOct 19, 2005
  8. H. Peter AnvinOct 19, 2005
  9. Petr BaudisOct 19, 2005
  10. Tony LuckOct 19, 2005
  11. David BrownOct 20, 2005
  12. Andreas EricssonOct 20, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.