Feature request

"David Pipe" <[email protected]> Mon, 5 Apr 2004 11:40:04 -0600
Newsgroups gmane.comp.version-control.vss.sourceoffsite.classic
Message-ID <OFE2377717.F83CEFB8-ON87256E6D.005DE053-87256E6D.00610CE9@bio-rad.com>
This is a multipart message in MIME format.
--=_alternative 00610AF787256E6D_=
Content-Type: text/plain; charset="us-ascii"

I'm seeing more apparent attacks, probes or general poking around by 
computers/people who have no business trying to connect to our SOS 
database.  Here's an example from this weekend's log.

Fri Apr 02 15:10:14 MST 2004 - FLTT2 (218.94.81.144) - Connection 
Established
Fri Apr 02 15:10:14 MST 2004 - FLTT2 (218.94.81.144) - Error processing 
client message
Fri Apr 02 15:10:15 MST 2004 - FLTT2 (218.94.81.144) - User "null" 
disconnected

Sat Apr 03 02:06:39 MST 2004 - 80.109.221.51 (80.109.221.51) - Connection 
Established
Sat Apr 03 02:06:48 MST 2004 - 80.109.221.51 (80.109.221.51) - Error 
processing client message
Sat Apr 03 02:06:49 MST 2004 - 80.109.221.51 (80.109.221.51) - User "null" 
disconnected

Sat Apr 03 02:07:09 MST 2004 - 80.109.221.51 (80.109.221.51) - Connection 
Established
Sat Apr 03 02:07:13 MST 2004 - 80.109.221.51 (80.109.221.51) - Error 
processing client message
Sat Apr 03 02:07:14 MST 2004 - 80.109.221.51 (80.109.221.51) - User "null" 
disconnected

None are successful, but  if you'd kindly implement as a server response 
some major multifaceted DOS attack on the clients that send the SOS server 
really unintelligible requests, this would be much appreciated.

Oh OK, I should just filter out unauthorized IP addresses, but the first 
solution is a lot more satisfying.  Wait, maybe there is a legitimate 
feature request here--have SOS respond to only authorized IP addresses (as 
an example the way Windows NT/2000 server does it in IIS).  I guess my 
question is:  Where is the most appropriate place to approve/deny service 
requests based on IP address?  The router?  The computer?  Or SOS? Some of 
these components are out of my control, so I'd rather see it handled in 
SOS.


David Pipe
Systems Programmer

Bio-Rad Laboratories
518 28 Rd Ste A202
Grand Junction, CO 81501
USA

Phone: +1 970-242-6676
Fax: +1 970-242-3125
Web: http://www.knowitall.com
e-mail: [email protected]
--=_alternative 00610AF787256E6D_=
Content-Type: text/html; charset="us-ascii"


<br><font size=2 face="sans-serif">I'm seeing more apparent attacks, probes or general poking around by computers/people who have no business trying to connect to our SOS database. &nbsp;Here's an example from this weekend's log.<br>
</font>
<br><font size=2 face="sans-serif">Fri Apr 02 15:10:14 MST 2004 - FLTT2 (218.94.81.144) - Connection Established</font>
<br><font size=2 face="sans-serif">Fri Apr 02 15:10:14 MST 2004 - FLTT2 (218.94.81.144) - Error processing client message</font>
<br><font size=2 face="sans-serif">Fri Apr 02 15:10:15 MST 2004 - FLTT2 (218.94.81.144) - User &quot;null&quot; disconnected</font>
<br>
<br><font size=2 face="sans-serif">Sat Apr 03 02:06:39 MST 2004 - 80.109.221.51 (80.109.221.51) - Connection Established</font>
<br><font size=2 face="sans-serif">Sat Apr 03 02:06:48 MST 2004 - 80.109.221.51 (80.109.221.51) - Error processing client message</font>
<br><font size=2 face="sans-serif">Sat Apr 03 02:06:49 MST 2004 - 80.109.221.51 (80.109.221.51) - User &quot;null&quot; disconnected</font>
<br>
<br><font size=2 face="sans-serif">Sat Apr 03 02:07:09 MST 2004 - 80.109.221.51 (80.109.221.51) - Connection Established</font>
<br><font size=2 face="sans-serif">Sat Apr 03 02:07:13 MST 2004 - 80.109.221.51 (80.109.221.51) - Error processing client message</font>
<br><font size=2 face="sans-serif">Sat Apr 03 02:07:14 MST 2004 - 80.109.221.51 (80.109.221.51) - User &quot;null&quot; disconnected</font>
<br>
<br><font size=2 face="sans-serif">None are successful, but &nbsp;if you'd kindly implement as a server response some major multifaceted DOS attack on the clients that send the SOS server really unintelligible requests, this would be much appreciated.</font>
<br>
<br><font size=2 face="sans-serif">Oh OK, I should just filter out unauthorized IP addresses, but the first solution is a lot more satisfying. &nbsp;Wait, maybe there is a legitimate feature request here--have SOS respond to only authorized IP addresses (as an example the way Windows NT/2000 server does it in IIS). &nbsp;I guess my question is: &nbsp;Where is the most appropriate place to approve/deny service requests based on IP address? &nbsp;The router? &nbsp;The computer? &nbsp;Or SOS? Some of these components are out of my control, so I'd rather see it handled in SOS.</font>
<br>
<br><font size=2 face="sans-serif"><br>
David Pipe<br>
Systems Programmer<br>
<br>
Bio-Rad Laboratories<br>
518 28 Rd Ste A202<br>
Grand Junction, CO 81501<br>
USA<br>
<br>
Phone: +1 970-242-6676<br>
Fax: +1 970-242-3125<br>
Web: http://www.knowitall.com<br>
e-mail: [email protected]</font>
--=_alternative 00610AF787256E6D_=--