For feature requests, please see: http://www.mattermost.org/feature-requests/.
For troubleshooting questions, please post in the following format:
We managed to DDoS Mattermost and our applications, thanks to a link in a message
Steps to reproduce
How can we reproduce the issue (what version are you using?)
We are using Mattermost version 5.3.1.
Here are the steps to reproduce:
- Call a invalid url in our application, that create an error in our application
- The application generates a notification to Mattermost containing the called url in payload
- Mattermost (I don’t why and how) called the url included in notification
- The application send a new notification
- Repeat until DDoS both Mattermost and our application
Describe your issue in detail
Mattermost should not call the url that is in a message.
What did you see happen? Please include relevant error messages and/or screenshots.
Our application and Mattermost are on 2 different servers. We detect that our application was DDoSed by client with user agent Go Http Client from the same IP address than Mattermost server.
We stop one by one services running on this server, and the flood only stop when we shutdown Mattermost server.
I can’t provide screenshot for the moment because we stop Mattermost until we have more details of what causing this bug.