R
Railway9mo ago
tavin

DoS attack

Someone found a vulnerability that leads to a DoS attack on my api, but I suspect it's Railway related. Can someone contact on DM? Or is there a better place to disclose this?
17 Replies
Brody
Brody9mo ago
may i ask what makes you think this is railway related?
tavin
tavinOP9mo ago
Application still runs, doesn't crash and doesn't appear to use all available resources, but requests fail with CORS error, while the malicious requests are running
Brody
Brody9mo ago
what status code though?
tavin
tavinOP9mo ago
No description
tavin
tavinOP9mo ago
works fine when we dont run the reqs
Brody
Brody9mo ago
may you tell me the status code please
tavin
tavinOP9mo ago
the connection times out so no status code
Brody
Brody9mo ago
seems like your app has soft locked with all this traffic at this time, im not seeing any issues with railway itself
tavin
tavinOP9mo ago
mb
tavin
tavinOP9mo ago
No description
tavin
tavinOP9mo ago
503 app still running tho
Brody
Brody9mo ago
that was what i thought, seems like a softlock what kind of app is this
tavin
tavinOP9mo ago
it's a rest api
Brody
Brody9mo ago
do you have cloudflare in front?
tavin
tavinOP9mo ago
no, do you think it would solve this?
Brody
Brody9mo ago
thats what cloudflare's main selling point is
JFKingsley
JFKingsley9mo ago
If you’re concerned this is a platform issue please provide as much info as possible to [email protected] for triage
Want results from more Discord servers?
Add your server