rabbitmq / rabbitmq-web-mqtt

Provides support for MQTT over WebSockets
Other
55 stars 16 forks source link

Possible DoS On MQTT Server #41

Closed grant-traynor closed 5 years ago

grant-traynor commented 5 years ago

Hi,

There are a few tickets floating around related to limiting connections per user, etc, so this may be related to that. But I think we have a scenario where a DoS can be made, fairly simply on the MQTT client. The AMQP interface seems a little more immune.

My erlang is non-existant, so I'm having trouble positively contributing, and I don't want to publish the details here until you've had a chance to look at the example.

Can I ask someone to e-mail me at mailto:grant.traynor@switchdin.com so that I can pass on the details directly?

Cheers, Grant.

michaelklishin commented 5 years ago

rabbitmq.com lists a responsible disclosure email address but we will reach out.