Re: Feature request

Linda Bauer <[email protected]> Wed, 07 Apr 2004 09:42:43 -0500
Newsgroups gmane.comp.version-control.vss.sourceoffsite.classic
Message-ID <[email protected]>
Hi, David,

Thanks for using SourceOffSite.

I'm not sure how much we want SOS involved in network management, but we'll 
look into this.

We've heard from SOS Customers who use their firewalls to limit access by 
unauthorized IP's. That seems like a common solution.

It's also possible to get these error messages from legitimate logins that 
fail for some reason.

We appreciate your feedback. Suggestions from users like you help us to 
build a better product.

Linda Bauer
SourceGear
Technical Support

visit our support forum at
http://support.sourcegear.com

  At 12:40 PM 4/5/2004, David Pipe wrote:

>I'm seeing more apparent attacks, probes or general poking around by 
>computers/people who have no business trying to connect to our SOS 
>database.  Here's an example from this weekend's log.
>
>Fri Apr 02 15:10:14 MST 2004 - FLTT2 (218.94.81.144) - Connection Established
>Fri Apr 02 15:10:14 MST 2004 - FLTT2 (218.94.81.144) - Error processing 
>client message
>Fri Apr 02 15:10:15 MST 2004 - FLTT2 (218.94.81.144) - User "null" 
>disconnected
>
>Sat Apr 03 02:06:39 MST 2004 - 80.109.221.51 (80.109.221.51) - Connection 
>Established
>Sat Apr 03 02:06:48 MST 2004 - 80.109.221.51 (80.109.221.51) - Error 
>processing client message
>Sat Apr 03 02:06:49 MST 2004 - 80.109.221.51 (80.109.221.51) - User "null" 
>disconnected
>
>Sat Apr 03 02:07:09 MST 2004 - 80.109.221.51 (80.109.221.51) - Connection 
>Established
>Sat Apr 03 02:07:13 MST 2004 - 80.109.221.51 (80.109.221.51) - Error 
>processing client message
>Sat Apr 03 02:07:14 MST 2004 - 80.109.221.51 (80.109.221.51) - User "null" 
>disconnected
>
>None are successful, but  if you'd kindly implement as a server response 
>some major multifaceted DOS attack on the clients that send the SOS server 
>really unintelligible requests, this would be much appreciated.
>
>Oh OK, I should just filter out unauthorized IP addresses, but the first 
>solution is a lot more satisfying.  Wait, maybe there is a legitimate 
>feature request here--have SOS respond to only authorized IP addresses (as 
>an example the way Windows NT/2000 server does it in IIS).  I guess my 
>question is:  Where is the most appropriate place to approve/deny service 
>requests based on IP address?  The router?  The computer?  Or SOS? Some of 
>these components are out of my control, so I'd rather see it handled in SOS.
>
>
>David Pipe
>Systems Programmer
>
>Bio-Rad Laboratories
>518 28 Rd Ste A202
>Grand Junction, CO 81501
>USA
>
>Phone: +1 970-242-6676
>Fax: +1 970-242-3125
>Web: http://www.knowitall.com
>e-mail: [email protected]