Re: DoS Server Crash: Cache Manager for 2.3 Stable 2

From: Alex Rousskov <rousskov@dont-contact.us>
Date: Sun, 12 Mar 2000 11:16:45 -0700 (MST)

Rudy,

        I am not sure I understand your report. If your machine is
"hard crashing", it may be the problem with your kernel or hardware
rather than user-level tools such as Squid or Cache Manager.

If Squid is "hard crashing", we need more information about the crash.
That is, what exactly is causing the crash? Any messages in cache.log?
Was there a core file left?

BTW, when I checked last time, cache manager would expire password
information after some hard coded timeout. That may have changed since
then though.

Alex.

On Sat, 11 Mar 2000, Rudy Komsic wrote:

> Hello,
>
> I found a Denial of Service Server Crash bug with Cache Manager under
> Squid. When a session under the cache manager expires or if the
> squid service crashed and restarted before, during, and after
> refreshing the general information about the cache, the server will
> hard crash and reboot.
>
> this needs to be isolated or set an expire page. Another solution is
> to create an active session timeout similar to ASP pages where the
> username and password are not displayed in the URL.
>
>
>
>
Received on Sun Mar 12 2000 - 11:20:27 MST

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 16:52:03 MST