Re: Critical Denial of Service bugs in Discover

2022-03-08 Thread Ben Cooksley
On Mon, Mar 7, 2022 at 1:16 PM Aleix Pol wrote: > > On Sat, Mar 5, 2022 at 8:36 AM Ben Cooksley wrote: > >> On Fri, Mar 4, 2022 at 12:49 AM Aleix Pol wrote: >> >>> I'd say wireshark is too low level for what the problem is here. We are >>> talking about having too many HTTP requests for

Re: Critical Denial of Service bugs in Discover

2022-03-06 Thread Aleix Pol
On Sat, Mar 5, 2022 at 8:36 AM Ben Cooksley wrote: > On Fri, Mar 4, 2022 at 12:49 AM Aleix Pol wrote: > >> I'd say wireshark is too low level for what the problem is here. We are >> talking about having too many HTTP requests for specific URLs. >> > > Correct, I guess the difference in our

Re: Critical Denial of Service bugs in Discover

2022-03-04 Thread Ben Cooksley
On Fri, Mar 4, 2022 at 12:49 AM Aleix Pol wrote: > I'd say wireshark is too low level for what the problem is here. We are > talking about having too many HTTP requests for specific URLs. > Correct, I guess the difference in our approaches comes from a "before release" to a "monitor after

Re: Critical Denial of Service bugs in Discover

2022-03-03 Thread Aleix Pol
I'd say wireshark is too low level for what the problem is here. We are talking about having too many HTTP requests for specific URLs. I can think two main measures: - Trigger an alarm (an e-mail notification?) if there's a specific UserAgent that has a specific portion of the queries we have in

Re: Critical Denial of Service bugs in Discover

2022-03-03 Thread Ben Cooksley
On Thu, Mar 3, 2022 at 8:41 AM Aleix Pol wrote: > (dropping the distros list) > > @sysadmin have you been able to look into any tools we devs can have to > make sure this situation doesn't repeat in the future? > Hi Aleix, To be honest i've been struggling to think of ways that we could detect

Re: Critical Denial of Service bugs in Discover

2022-03-02 Thread Aleix Pol
(dropping the distros list) @sysadmin have you been able to look into any tools we devs can have to make sure this situation doesn't repeat in the future? Aleix On Thu, Feb 10, 2022 at 1:10 PM Aleix Pol wrote: > On Thu, Feb 10, 2022 at 11:05 AM Ben Cooksley wrote: > > > > > > > > On Thu, Feb

Re: Critical Denial of Service bugs in Discover

2022-02-28 Thread Fabian Vogt
Moin, Am Sonntag, 6. Februar 2022, 21:54:13 CET schrieb Fabian Vogt: > Am Sonntag, 6. Februar 2022, 19:27:11 CET schrieb Ben Cooksley: > > On Sun, Feb 6, 2022 at 1:07 PM Fabian Vogt wrote: > > > The first URL is used by kfontinst.knsrc from plasma-workspace: > > >

Re: Critical Denial of Service bugs in Discover

2022-02-25 Thread Ben Cooksley
On Fri, Feb 25, 2022 at 10:09 PM Harald Sitter wrote: > On Mon, Feb 21, 2022 at 11:05 AM Ben Cooksley wrote: > > > > On Mon, Feb 21, 2022 at 10:01 PM Harald Sitter wrote: > >> > >> On Thu, Feb 10, 2022 at 1:11 PM Aleix Pol wrote: > >> > > >> > On Thu, Feb 10, 2022 at 11:05 AM Ben Cooksley >

Re: Critical Denial of Service bugs in Discover

2022-02-25 Thread Harald Sitter
On Mon, Feb 21, 2022 at 11:05 AM Ben Cooksley wrote: > > On Mon, Feb 21, 2022 at 10:01 PM Harald Sitter wrote: >> >> On Thu, Feb 10, 2022 at 1:11 PM Aleix Pol wrote: >> > >> > On Thu, Feb 10, 2022 at 11:05 AM Ben Cooksley wrote: >> > > >> > > >> > > >> > > On Thu, Feb 10, 2022 at 8:20 AM Aleix

Re: Critical Denial of Service bugs in Discover

2022-02-21 Thread Ben Cooksley
On Mon, Feb 21, 2022 at 10:01 PM Harald Sitter wrote: > On Thu, Feb 10, 2022 at 1:11 PM Aleix Pol wrote: > > > > On Thu, Feb 10, 2022 at 11:05 AM Ben Cooksley wrote: > > > > > > > > > > > > On Thu, Feb 10, 2022 at 8:20 AM Aleix Pol wrote: > > >> > > >> [Snip] > > >> > > >> We still haven't

Re: Critical Denial of Service bugs in Discover

2022-02-21 Thread Harald Sitter
On Thu, Feb 10, 2022 at 1:11 PM Aleix Pol wrote: > > On Thu, Feb 10, 2022 at 11:05 AM Ben Cooksley wrote: > > > > > > > > On Thu, Feb 10, 2022 at 8:20 AM Aleix Pol wrote: > >> > >> [Snip] > >> > >> We still haven't discussed here is how to prevent this problem from > >> happening again. > >> >

Re: Critical Denial of Service bugs in Discover

2022-02-12 Thread Ben Cooksley
On Fri, Feb 11, 2022 at 10:22 AM Fabian Vogt wrote: > Moin, > > Am Sonntag, 6. Februar 2022, 21:54:13 CET schrieb Fabian Vogt: > > Am Sonntag, 6. Februar 2022, 19:27:11 CET schrieb Ben Cooksley: > > > On Sun, Feb 6, 2022 at 1:07 PM Fabian Vogt > wrote: > > > > The first URL is used by

Re: Critical Denial of Service bugs in Discover

2022-02-10 Thread Aleix Pol
On Thu, Feb 10, 2022 at 11:05 AM Ben Cooksley wrote: > > > > On Thu, Feb 10, 2022 at 8:20 AM Aleix Pol wrote: >> >> [Snip] >> >> We still haven't discussed here is how to prevent this problem from >> happening again. >> >> If we don't have information about what is happening, we cannot fix

Re: Critical Denial of Service bugs in Discover

2022-02-10 Thread Ben Cooksley
On Thu, Feb 10, 2022 at 8:20 AM Aleix Pol wrote: > [Snip] > > We still haven't discussed here is how to prevent this problem from > happening again. > > If we don't have information about what is happening, we cannot fix > problems. > Part of the issue here is that the problem only came to

Re: Critical Denial of Service bugs in Discover

2022-02-09 Thread Aleix Pol
On Tue, Feb 8, 2022 at 7:00 PM Ben Cooksley wrote: > > On Tue, Feb 8, 2022 at 4:24 AM Aleix Pol wrote: >> >> On Sat, Feb 5, 2022 at 10:16 PM Ben Cooksley wrote: >> > >> > Hi all, >> > >> > Over the past week or so Sysadmin has been dealing with an extremely high >> > volume of traffic directed

Re: Critical Denial of Service bugs in Discover

2022-02-08 Thread Ben Cooksley
On Tue, Feb 8, 2022 at 4:24 AM Aleix Pol wrote: > On Sat, Feb 5, 2022 at 10:16 PM Ben Cooksley wrote: > > > > Hi all, > > > > Over the past week or so Sysadmin has been dealing with an extremely > high volume of traffic directed towards both download.kde.org and > distribute.kde.org. > > > >

Re: Critical Denial of Service bugs in Discover

2022-02-07 Thread Aleix Pol
On Sat, Feb 5, 2022 at 10:16 PM Ben Cooksley wrote: > > Hi all, > > Over the past week or so Sysadmin has been dealing with an extremely high > volume of traffic directed towards both download.kde.org and > distribute.kde.org. > > This traffic volume is curious in so far that it is directed at

Re: Critical Denial of Service bugs in Discover

2022-02-07 Thread Fabian Vogt
Moin, Am Sonntag, 6. Februar 2022, 19:27:11 CET schrieb Ben Cooksley: > On Sun, Feb 6, 2022 at 1:07 PM Fabian Vogt wrote: > > The first URL is used by kfontinst.knsrc from plasma-workspace: > > ProvidersUrl=https://distribute.kde.org/khotnewstuff/fonts-providers.xml > > > > The second URL is

Re: Critical Denial of Service bugs in Discover

2022-02-07 Thread Fabian Vogt
Hi, Am Samstag, 5. Februar 2022, 22:16:28 CET schrieb Ben Cooksley: > Hi all, > > Over the past week or so Sysadmin has been dealing with an extremely high > volume of traffic directed towards both download.kde.org and > distribute.kde.org. > > This traffic volume is curious in so far that it

Re: Critical Denial of Service bugs in Discover

2022-02-06 Thread Tom Zander
On zaterdag 5 februari 2022 22:16:28 CET Ben Cooksley wrote: > This indicates that the bug lies solely within Plasma's > Discover component - more precisely it's updater. For those responsible with that component, here some ideas on how this can be fixed from a seasoned software dev. *

Re: Critical Denial of Service bugs in Discover

2022-02-06 Thread Ben Cooksley
On Sun, Feb 6, 2022 at 1:07 PM Fabian Vogt wrote: > Hi, > > Am Samstag, 5. Februar 2022, 22:16:28 CET schrieb Ben Cooksley: > > Hi all, > > > > Over the past week or so Sysadmin has been dealing with an extremely high > > volume of traffic directed towards both download.kde.org and > >

Critical Denial of Service bugs in Discover

2022-02-05 Thread Ben Cooksley
Hi all, Over the past week or so Sysadmin has been dealing with an extremely high volume of traffic directed towards both download.kde.org and distribute.kde.org. This traffic volume is curious in so far that it is directed at two paths specifically: -