Comment 19 for bug 1394370

Revision history for this message
Tristan Cacqueray (tristan-cacqueray) wrote : Re: horizon login page is vulnerable to DOS attack

@Eric Well the attack vector remains if adding a fake cookie trigger the extra session creation.
And the one hour timeout proposed seems to big according to comment #13 assumption where only 1/2 hours is required to overwhelm the service...

How about the monkey patch of SessionStore.load method, wouldn't it be easer to implement ?