Re: [htdig] possible DoS attack?


Subject: Re: [htdig] possible DoS attack?
From: Geoff Hutchison (ghutchis@wso.williams.edu)
Date: Sun Nov 14 1999 - 09:21:10 PST


At 1:55 PM +0100 11/14/99, Daniel Naber wrote:
>if you submit the attached form htdig will need several minutes to
>perfom the search. The resulting page (second attached file) will
>be incomplete. This happens only if you don't change my default
>values for Match and Format. My default values have very long
>strings that don't make sense.

It also only seems to happen when the CGI submission method is set to
POST. Most servers have limits on the length of URLs they accept and
will trim a GET request to that length.

See http://www.htdig.org/mail/1999/11/0142.html for a patch (yes,
that's a message from Friday).

-Geoff Hutchison
Williams Students Online
http://wso.williams.edu/

------------------------------------
To unsubscribe from the htdig mailing list, send a message to
htdig@htdig.org containing the single word unsubscribe in
the SUBJECT of the message.



This archive was generated by hypermail 2b25 : Sun Nov 14 1999 - 09:32:21 PST