netsec-ethz / fpki

4 stars 1 forks source link

New DoS: too much data in MapServer #38

Open juagargi opened 1 year ago

juagargi commented 1 year ago

A new attack surface appears with the MapServer. If a malicious CA creates an absurd number of entries for a domain name, those will be recorded by the CT Log Server, and afterwards by the MapServer. A client requesting the material for that domain name will receive as much data as the attacker decides, rendering the connection to the MapServer useless.