Skip to content
This repository has been archived by the owner. It is now read-only.

Lightning with wrong crendentals saved DOS'es calendarserver #298

Closed
macosforgebot opened this issue Apr 13, 2010 · 6 comments
Closed

Lightning with wrong crendentals saved DOS'es calendarserver #298

macosforgebot opened this issue Apr 13, 2010 · 6 comments

Comments

@macosforgebot
Copy link

@macosforgebot macosforgebot commented Apr 13, 2010

rahul@… originally submitted this as ticket:376

  • Cc: rahul@…, mcepl@…

Steps to reproduce:

  1. Setup Calendarserver (I installed Calendarserver 2.4 on Debian Lenny)
  2. Install Thunderbird with Lightning plugin
  3. Add the caldav url to lightninig
  4. Upon prompting for password, enter wrong credentials, check "Use Password Manager to remember this password" and click on OK.

Now monitor the server. Authentication requests are sent continuously and the calendar server CPU usage goes very high.

While I understand that this is primarily a bug in Lightning, it is also a problem with Calendarserver because it is susceptible to DOS attacks. I believe the developers are aware of this issue. If not, kindly take this into consideration for the next major release.

@macosforgebot
Copy link
Author

@macosforgebot macosforgebot commented Apr 13, 2010

rahul@… originally submitted this as comment:1:⁠ticket:376

  • Cc rahul@… added
@macosforgebot
Copy link
Author

@macosforgebot macosforgebot commented Aug 1, 2011

@wsanchez originally submitted this as comment:2:⁠ticket:376

  • Radar deleted
  • Milestone changed from CalendarServer-2.5 to CalendarServer-3.x
@macosforgebot
Copy link
Author

@macosforgebot macosforgebot commented Aug 1, 2011

@wsanchez originally submitted this as comment:3:⁠ticket:376

@macosforgebot
Copy link
Author

@macosforgebot macosforgebot commented Nov 30, 2011

@wsanchez originally submitted this as comment:4:⁠ticket:376

  • Summary changed from Lightning with wrong crendentals saved crashes calendarserver to Lightning with wrong crendentals saved DOS'es calendarserver
  • Milestone changed from CalendarServer-3.x to Later
@macosforgebot
Copy link
Author

@macosforgebot macosforgebot commented Feb 16, 2014

mcepl@… originally submitted this as comment:11:⁠ticket:376

  • Cc mcepl@… added
@macosforgebot
Copy link
Author

@macosforgebot macosforgebot commented Mar 26, 2015

@wsanchez originally submitted this as comment:12:⁠ticket:376

  • Status changed from new to closed
  • Resolution set to Not to be fixed

Expiring old bugs with unknown state and impact.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Linked pull requests

Successfully merging a pull request may close this issue.

None yet
3 participants
You can’t perform that action at this time.