activemq-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Gary Tully (JIRA)" <j...@apache.org>
Subject [jira] [Commented] (AMQ-498) Secure the server from simple DoS attacks
Date Tue, 25 Sep 2012 11:43:08 GMT

    [ https://issues.apache.org/jira/browse/AMQ-498?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13462668#comment-13462668
] 

Gary Tully commented on AMQ-498:
--------------------------------

with http://svn.apache.org/viewvc?rev=1389817&view=rev in 5.7, the default maxFrameSize
is unlimited and there is an explicit limit in the xml config for the transportConnector.
                
> Secure the server from simple DoS attacks
> -----------------------------------------
>
>                 Key: AMQ-498
>                 URL: https://issues.apache.org/jira/browse/AMQ-498
>             Project: ActiveMQ
>          Issue Type: Improvement
>          Components: Broker
>         Environment: An untrusted network.  DoS attack attempts are common.
>            Reporter: Hiram Chirino
>            Assignee: Hiram Chirino
>             Fix For: 5.6.0
>
>
> Originating from http://forums.logicblaze.com/posts/list/205.page
> Simply start the 4.0 server (I used the stock config) 
> in another window telnet to localhost 61616 
> you will receieve: 
> ActiveMQ^[[?1;2c 
> type asdfasdf 
> The connection will close by itself. 
> All future TCP connections, either from telnet or from real JMS clients, will hang. 

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators
For more information on JIRA, see: http://www.atlassian.com/software/jira

Mime
View raw message