R
Railway3mo ago
tavin

DoS attack

Someone found a vulnerability that leads to a DoS attack on my api, but I suspect it's Railway related. Can someone contact on DM? Or is there a better place to disclose this?
17 Replies
Brody
Brody3mo ago
may i ask what makes you think this is railway related?
tavin
tavin3mo ago
Application still runs, doesn't crash and doesn't appear to use all available resources, but requests fail with CORS error, while the malicious requests are running
Brody
Brody3mo ago
what status code though?
tavin
tavin3mo ago
No description
tavin
tavin3mo ago
works fine when we dont run the reqs
Brody
Brody3mo ago
may you tell me the status code please
tavin
tavin3mo ago
the connection times out so no status code
Brody
Brody3mo ago
seems like your app has soft locked with all this traffic at this time, im not seeing any issues with railway itself
tavin
tavin3mo ago
mb
tavin
tavin3mo ago
No description
tavin
tavin3mo ago
503 app still running tho
Brody
Brody3mo ago
that was what i thought, seems like a softlock what kind of app is this
tavin
tavin3mo ago
it's a rest api
Brody
Brody3mo ago
do you have cloudflare in front?
tavin
tavin3mo ago
no, do you think it would solve this?
Brody
Brody3mo ago
thats what cloudflare's main selling point is
JFKingsley
JFKingsley3mo ago
If you’re concerned this is a platform issue please provide as much info as possible to security@railway.app for triage