4 ms·
I think it still works. You have two scenarios where the attacker is efficiently using goroutines; (1) you also use goroutines or (2) you do not. In the latter,
by aesh2Xa1 3y ago
I think it still works. You have two scenarios where the attacker is efficiently using goroutines; (1) you also use goroutines or (2) you do not. In the latter, the attack is more expensive for you.
Another detail is that an attacker with many idle connections to your host might not instantiate any new ones.
Of course, in the scenarios where the attacker is not using goroutines then you have the upper hand as well.
- gnfargbl 3y agoThis isn't a real ssh server, so the "cost" to you of the attack isn't really relevant. You can choose not to run this software at all, and the additional cost to you is zero.