Security fix: pause cycling connection-slot squatting DoS - #210
Draft
cursor[bot] wants to merge 1 commit into
Draft
Security fix: pause cycling connection-slot squatting DoS#210cursor[bot] wants to merge 1 commit into
cursor[bot] wants to merge 1 commit into
Conversation
Players that never received outbound relay must not refresh session_setup_started on pause. Otherwise an attacker can cycle pause/unpause every few seconds to hold connection slots indefinitely without consuming media. Co-authored-by: Alexander Wagner <info@alexanderwagnerdev.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Security review finding (Medium)
Issue: #209
Location:
src/session/conn.rsImpact: Unauthenticated RTMP peers can hold server connection slots indefinitely by cycling
pause/unpauseon a playing session that never receives relay media. Withmax_connectionsset, this exhausts available slots and denies legitimate clients.Root cause: The pause handler unconditionally resets
session_setup_started, refreshing the 10-second setup-timeout window on every transition into paused state. An attacker alternatespause(false)andpause(true)every few seconds to preventsession_setup_timed_out()from ever firing.Fix: Only refresh
session_setup_startedon pause whenmedia_bytes_sent > 0, preserving the grace window for viewers that are actually receiving relay while blocking timer reset for squatters.Includes regression tests for both the attack path and legitimate paused viewers.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.