[squid-dev] [PATCH] Reuse reserved Negotiate and NTLM helpers after an idle timeout.

Alex Rousskov rousskov at measurement-factory.com
Mon Jul 31 16:40:23 UTC 2017


On 07/31/2017 09:24 AM, Amos Jeffries wrote:

>>> To do so otherwise would randomly
>>> allow replay attacks to succeed 

Please give a specific example where the proposed changes would allow a
new kind of replay attacks to succeed, given a correctly functioning
Squid and a correctly functioning helper. I cannot think of any
realistic examples, but this is not my area of expertise.


Thank you,

Alex.


More information about the squid-dev mailing list