Open
Description
Describe the bug
Bad actors can easily get the backend server ip by logging the web requests. This in turn can allow bad actors to easily ddos the backend server.
Steps to Reproduce
- Click on a random video
- Press F12
- Go to network
- Click play
- Find a web request to googlevideo.com
- The ip is located in the request url, making cloudflare/other ddos protection services useless.
Screenshots
Additional context
- Browser (if applicable): Brave 1.25.70
- OS (if applicable): Windows 10 Pro 20H2
Is there any important reason why the server ip address needs to be sent in a request, or can this easily be removed?
Thanks.
Metadata
Metadata
Assignees
Type
Projects
Status
To Do - Administration misc