The git protocol and DoS
- From
- H. Peter Anvin <hpa@zytor.com>
- Date
- Oct 19, 2005, 20:00 UTC
- Message-ID
- <4356A5C5.5080905@zytor.com>
I've been concerned for a while that the git protocol may be inherently vulnerable to a "SYNful DoS" attack (spraying raw TCP SYN packets with enough data to start substantial server activity.) Although SYN cookies protect against this to some degree, it makes me wonder if something should be added to the protocol itself.
One way to do this would be to start the transaction by having the server transmit a cookie to the client, and to require the client to send a SHA1 of the (cookie + request) together with the request. This would be done with a fairly short timeout.
It would, however, require a protocol change; I would like to hear what people think about this at this stac=ge.
-hpa