Sitelet https://github.com/Altinity/altinity-oauth-helper/issues/70
Skip to content

security: prevent unauthenticated LDAP requests from exhausting connection slots #70

Description

@BorisTyshkevich

Security finding

Unauthenticated complete LDAP requests can keep every one of the 256 connection slots occupied indefinitely.

Evidence

The server admits sockets before authentication, renews the read deadline before every message, and silently accepts a structurally valid Abandon request without authentication. It has neither a pre-Bind absolute deadline nor a request budget.

Reproduction

Open 256 connections and repeatedly send the valid Abandon PDU:

30 06 02 01 01 50 01 01

No Bind or valid JWT is needed. Sending a complete request before each read deadline renews every slot. In the bounded regression, a 500 ms deadline was sustained for more than two deadline periods and the 257th client was closed.

Impact

One permitted network peer can deny fresh authentication at very low request volume. The global cap bounds resource use but provides no fairness between unauthenticated attackers and ClickHouse. The TCP readiness probe can still succeed before an excess connection is closed, so it is not a reliable saturation signal.

Proposed direction

Apply an absolute deadline or small operation budget before first successful Bind. Close or restrict unauthenticated no-op requests, and consider carefully designed per-peer quotas or independently budgeted authenticated connections. Shared ClickHouse source addresses must remain supported.

Validation

Add real-TCP regressions for repeated unauthenticated Abandon, pre-Bind operation limits, successful Bind/Search behavior, and slot reuse.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workinggoPull requests that update go code

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions