Re: [Vortex] A couple of features to limit BEEP no reply attack
Benoit Amiaux <[email protected]> Wed, 25 Mar 2009 09:49:46 +0100
| Newsgroups | gmane.ietf.beep |
|---|---|
| Message-ID | <[email protected]> |
Hello, Francis Brosnan Blazquez a =E9crit : > Hi, > I've been working on a couple of features that will allow limiting how > BEEP implements some reply requirements that may be used to setup an > attack.=20 > It would be great to known your opinion about this. Just a few newbie comments, as an user of the vortex library. - I'm one of the people forced to use connection termination instead of=20 proper connection closure, due to misbehaving peers. It's very easy to=20 trigger just pause one peer process and wait for the other side to wait=20 indefinitely. I think it's doable to implement this on top of the=20 library without changing the BEEP protocol itself, by enforcing, if the=20 user wants it, a timeout on expected replies. It would allow at least,=20 to try to close the connection properly first, instead of always=20 assuming the worst and terminate it. - About the 'no-reply' option, I'm not sure about whether it's a good=20 idea not knowing whether the peer will reply or not. I like the=20 semantics of an 'NFN' message much more. It would save bandwidth and not=20 disrupt the in-order message mechanism per channel. Bye! Benoit Amiaux