Quantcast
Channel: Sendy Forum
Viewing all articles
Browse latest Browse all 1406

Is Sendy vulnerable to Denial of Service type attacks?

$
0
0

I'm new so please forgive if this is an obvious question....

If, say, I have a double opt-in arrangement set up what will happen if some peeved customer, or group of customers, should keep subscribing with fictitious email addresses? So Sendy keeps automatically sending out response emails (to non-existent addresses) that request confirmation of subscription - and these emails are being bounced back and therefore Amazon SES doesn't like me anymore ? !!! Presumably Amazon SES strikes me off its Christmas card list and the MySQL email database grows to a size that is too big for its own good ? !!

I have in mind that one way of detecting and preventing this situation would be to store the ip address and registration date of all customers that need to confirm their subscription and then check the ip of each new registration against the ip's of the mails that are awaiting acknowledgement - and if, say, more than 5 (Sendy user/operator definable) emails were already outstanding and hadn't been confirmed then some action would be taken - which might be deleting the oldest outstanding email ('cos unlikely now to be confirmed) and processing the new request as per normal.

And presumably there is no way of preventing a DoS attack at all if only a single opt-in method is used?

Regards


Viewing all articles
Browse latest Browse all 1406

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>