Re: svnserve DoS attack (1.7.8)

2013-05-19 Thread Daniel Shahaf
On Sun, May 19, 2013 at 11:18:49AM +0200, Stefan Sperling wrote: > In the future, please report security problems to the security@ list. > I've just noticed that security@ is not listed on our mailing-lists.html > page. I'll try to fix that ASAP. Boris indicates he just did what the Big Yellow Box

Svnserve DoS

2011-11-08 Thread Bostjan Skufca
Hello, (firstly I apologise for mailing to both lists simultaneously but this concerns both products) One of our developers accidentaly stumbled upon an effective way to DoS the whole server by unknowingly trying to access parts of SVN repo he was not authorized for. The svnserve daemon spawned a