[ 
https://issues.apache.org/jira/browse/DIRSERVER-1260?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Emmanuel Lecharny resolved DIRSERVER-1260.
------------------------------------------

    Resolution: Fixed

Fixed. A new parameter has been added into the server.xml file (maxPDUSize) for 
the DirectoryService bean.

http://svn.apache.org/viewvc?rev=722452&view=rev

> Add a protection agains DoS attacks
> -----------------------------------
>
>                 Key: DIRSERVER-1260
>                 URL: https://issues.apache.org/jira/browse/DIRSERVER-1260
>             Project: Directory ApacheDS
>          Issue Type: New Feature
>    Affects Versions: 1.5.4
>            Reporter: Emmanuel Lecharny
>            Assignee: Emmanuel Lecharny
>             Fix For: 1.5.5
>
>
> A malicious user can send hand crafted PDUs which can break the server in OOM 
> errors. Another kind of attack would be to send big images, leading to OOM 
> too.
> We must implement some protection against such DoS attacks (which may not be 
> malicious).

-- 
This message is automatically generated by JIRA.
-
You can reply to this email to add a comment to the issue online.

Reply via email to