git/list[1] front-page[2] threads[3] people[4] search[5] about
 

The git protocol and DoS

From
HAH. Peter Anvin <hpa@zytor.com>
Date
Oct 19, 2005, 20:00 UTC
Message-ID
<4356A5C5.5080905@zytor.com>

I've been concerned for a while that the git protocol may be inherently vulnerable to a "SYNful DoS" attack (spraying raw TCP SYN packets with enough data to start substantial server activity.) Although SYN cookies protect against this to some degree, it makes me wonder if something should be added to the protocol itself.

One way to do this would be to start the transaction by having the server transmit a cookie to the client, and to require the client to send a SHA1 of the (cookie + request) together with the request. This would be done with a fairly short timeout.

It would, however, require a protocol change; I would like to hear what people think about this at this stac=ge.

	-hpa
Next: Junio C Hamano
Message 1 of 12 in “The git protocol and DoS”
  1. H. Peter AnvinOct 19, 2005
  2. Junio C HamanoOct 19, 2005
  3. H. Peter AnvinOct 19, 2005
  4. Junio C HamanoOct 19, 2005
  5. H. Peter AnvinOct 19, 2005
  6. Linus TorvaldsOct 19, 2005
  7. Junio C HamanoOct 19, 2005
  8. H. Peter AnvinOct 19, 2005
  9. Petr BaudisOct 19, 2005
  10. Tony LuckOct 19, 2005
  11. David BrownOct 20, 2005
  12. Andreas EricssonOct 20, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.