Patch for abuse of 401 Unathorized responses

67 views
Skip to first unread message

Lisa Maginnis

unread,
Oct 31, 2024, 7:08:42 AM10/31/24
to TURN Server (Open-Source project)
Hello everyone!

We've been seeing abuse of our Coturn servers via spoofed UDP packets allowing an actor to reflect and moderately amplify their traffic to a desired target.

To remedy this I've written a patch to allow for 401 responses to be relate-limited over a window of time (for example: 100 requests that result in a 401 response in 60 seconds). After the window has expired, 401 responses can be sent again.

This patch is meant to mitigate abuse to Coturn servers, more details can be found in the pull request here: https://github.com/coturn/coturn/pull/1588

I think it is also worth mentioning potential 401 Response based abuse found in the wild:


Any feedback is appreciated,
~Lisa Marie Maginnis
Reply all
Reply to author
Forward
0 new messages