Re: Critical Denial of Service bugs in Discover

2022-03-03 Thread Aleix Pol
I'd say wireshark is too low level for what the problem is here. We are talking about having too many HTTP requests for specific URLs. I can think two main measures: - Trigger an alarm (an e-mail notification?) if there's a specific UserAgent that has a specific portion of the queries we have in a

Re: Critical Denial of Service bugs in Discover

2022-03-03 Thread Ben Cooksley
On Thu, Mar 3, 2022 at 8:41 AM Aleix Pol wrote: > (dropping the distros list) > > @sysadmin have you been able to look into any tools we devs can have to > make sure this situation doesn't repeat in the future? > Hi Aleix, To be honest i've been struggling to think of ways that we could detect