Feature request
"David Pipe" <[email protected]> Mon, 5 Apr 2004 11:40:04 -0600
| Newsgroups | gmane.comp.version-control.vss.sourceoffsite.classic |
|---|---|
| Message-ID | <OFE2377717.F83CEFB8-ON87256E6D.005DE053-87256E6D.00610CE9@bio-rad.com> |
This is a multipart message in MIME format. --=_alternative 00610AF787256E6D_= Content-Type: text/plain; charset="us-ascii" I'm seeing more apparent attacks, probes or general poking around by computers/people who have no business trying to connect to our SOS database. Here's an example from this weekend's log. Fri Apr 02 15:10:14 MST 2004 - FLTT2 (218.94.81.144) - Connection Established Fri Apr 02 15:10:14 MST 2004 - FLTT2 (218.94.81.144) - Error processing client message Fri Apr 02 15:10:15 MST 2004 - FLTT2 (218.94.81.144) - User "null" disconnected Sat Apr 03 02:06:39 MST 2004 - 80.109.221.51 (80.109.221.51) - Connection Established Sat Apr 03 02:06:48 MST 2004 - 80.109.221.51 (80.109.221.51) - Error processing client message Sat Apr 03 02:06:49 MST 2004 - 80.109.221.51 (80.109.221.51) - User "null" disconnected Sat Apr 03 02:07:09 MST 2004 - 80.109.221.51 (80.109.221.51) - Connection Established Sat Apr 03 02:07:13 MST 2004 - 80.109.221.51 (80.109.221.51) - Error processing client message Sat Apr 03 02:07:14 MST 2004 - 80.109.221.51 (80.109.221.51) - User "null" disconnected None are successful, but if you'd kindly implement as a server response some major multifaceted DOS attack on the clients that send the SOS server really unintelligible requests, this would be much appreciated. Oh OK, I should just filter out unauthorized IP addresses, but the first solution is a lot more satisfying. Wait, maybe there is a legitimate feature request here--have SOS respond to only authorized IP addresses (as an example the way Windows NT/2000 server does it in IIS). I guess my question is: Where is the most appropriate place to approve/deny service requests based on IP address? The router? The computer? Or SOS? Some of these components are out of my control, so I'd rather see it handled in SOS. David Pipe Systems Programmer Bio-Rad Laboratories 518 28 Rd Ste A202 Grand Junction, CO 81501 USA Phone: +1 970-242-6676 Fax: +1 970-242-3125 Web: http://www.knowitall.com e-mail: [email protected] --=_alternative 00610AF787256E6D_= Content-Type: text/html; charset="us-ascii" <br><font size=2 face="sans-serif">I'm seeing more apparent attacks, probes or general poking around by computers/people who have no business trying to connect to our SOS database. Here's an example from this weekend's log.<br> </font> <br><font size=2 face="sans-serif">Fri Apr 02 15:10:14 MST 2004 - FLTT2 (218.94.81.144) - Connection Established</font> <br><font size=2 face="sans-serif">Fri Apr 02 15:10:14 MST 2004 - FLTT2 (218.94.81.144) - Error processing client message</font> <br><font size=2 face="sans-serif">Fri Apr 02 15:10:15 MST 2004 - FLTT2 (218.94.81.144) - User "null" disconnected</font> <br> <br><font size=2 face="sans-serif">Sat Apr 03 02:06:39 MST 2004 - 80.109.221.51 (80.109.221.51) - Connection Established</font> <br><font size=2 face="sans-serif">Sat Apr 03 02:06:48 MST 2004 - 80.109.221.51 (80.109.221.51) - Error processing client message</font> <br><font size=2 face="sans-serif">Sat Apr 03 02:06:49 MST 2004 - 80.109.221.51 (80.109.221.51) - User "null" disconnected</font> <br> <br><font size=2 face="sans-serif">Sat Apr 03 02:07:09 MST 2004 - 80.109.221.51 (80.109.221.51) - Connection Established</font> <br><font size=2 face="sans-serif">Sat Apr 03 02:07:13 MST 2004 - 80.109.221.51 (80.109.221.51) - Error processing client message</font> <br><font size=2 face="sans-serif">Sat Apr 03 02:07:14 MST 2004 - 80.109.221.51 (80.109.221.51) - User "null" disconnected</font> <br> <br><font size=2 face="sans-serif">None are successful, but if you'd kindly implement as a server response some major multifaceted DOS attack on the clients that send the SOS server really unintelligible requests, this would be much appreciated.</font> <br> <br><font size=2 face="sans-serif">Oh OK, I should just filter out unauthorized IP addresses, but the first solution is a lot more satisfying. Wait, maybe there is a legitimate feature request here--have SOS respond to only authorized IP addresses (as an example the way Windows NT/2000 server does it in IIS). I guess my question is: Where is the most appropriate place to approve/deny service requests based on IP address? The router? The computer? Or SOS? Some of these components are out of my control, so I'd rather see it handled in SOS.</font> <br> <br><font size=2 face="sans-serif"><br> David Pipe<br> Systems Programmer<br> <br> Bio-Rad Laboratories<br> 518 28 Rd Ste A202<br> Grand Junction, CO 81501<br> USA<br> <br> Phone: +1 970-242-6676<br> Fax: +1 970-242-3125<br> Web: http://www.knowitall.com<br> e-mail: [email protected]</font> --=_alternative 00610AF787256E6D_=--