Re: Oaf default build...



> > 	3. Remote user invokes any method he wants on interface.
> 
> No they cannot.

How is this prevented?

> > Anyways, what Elliot suggested was to encode the cookie in the object
> > reference so that it would include the cookie in there.
> 
> This is already implemented in ORBit HEAD (and 0.5.1, IIRC).

How do we handle Denial of Service attacks?  If someone sends an 8 gig
message, how does ORBit know if it has to trust it (and keep mallocing
memory), or if it is not a trusted client?

Miguel.




[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]