Re: AnonymousURL caused MAXSESSIONS
Library Information Access Team <[email protected]>
| Newsgroups | gmane.education.ezproxy |
|---|---|
| Message-ID | <SY2PR01MB24123DD17AE772C0DD316389A9900@SY2PR01MB2412.ausprd01.prod.outlook.com> |
Thanks Chris, This is the second time in two years we've had this problem, last time it was IEEE and this time it's Informit TV News. The IEEE issue was a browser going crazy hitting the same .gif and with Informit it was a browser trying load a section of an .mp4 However I have some bad news, the ::Limit= directive only works where EZproxy has an actual username. For years we've had ::Limit=2 in place and it didn't stop auto-[IP address] usernames from spawning right up to our MAXSESSIONS limit I'll log a job with OCLC to ask if ::Limit can be applied to auto-[IP Address] usernames as well. The fact that ::Limit= has this deficiency poses a big risk, a single user's browser going haywire really shouldn't be capable of taking out a Library's database access! We were lucky this problem cropped up on a Monday morning and not a Friday evening at the start of a long weekend. Regards, Jai Parker | Information Access Librarian QUT Library | Division of Administrative Services QUT | Kelvin Grove | D Block, Level 1 | Victoria Park Rd Kelvin Grove QLD 4059 P: 07 3138 3381 | E: [email protected]<mailto:[email protected]> | www.qut.edu.au<http://www.qut.edu.au/> ABN: 83 791 724 622 | CRICOS No. 00213J From: Gonzales, Christopher <[email protected]> Sent: Tuesday, 15 October 2019 1:04 AM To: Library Information Access Team <[email protected]>; [email protected] Subject: RE: [EZPROXY-L] AnonymousURL caused MAXSESSIONS Jai, We recently saw this happen. We tracked it back to an iPad but couldn't determine the cause. There is a user.txt directive we are testing. We have it set to the default value of 1 and haven't heard any problems with our test group. This uses an additional limit.htm you create to display a message to the end user. We use that page to trigger email alerts to see how often that happens. I'm not sure this would solve the problem because we haven't seen the issue pop up again but that's what we are hoping will prevent it. I could ask OCLC but I never get straight answers from them. Limit concurrent logins https://help.oclc.org/Library_Management/EZproxy/Authenticate_users/Directives_and_configurations_for_authentication/Limit_concurrent_logins Error pages https://help.oclc.org/Library_Management/EZproxy/Manage_EZproxy/Error_pages Chris Gonzales Technology Program Manager Library Technical Services LSC-University Park 20515 State Highway 249 Houston, TX 77070 281.290.3632 281.290.2979 fax [email protected]<mailto:[email protected]> LoneStar.edu [lscs] From: EZproxy List <[email protected]<mailto:[email protected]>> On Behalf Of Library Information Access Team Sent: Sunday, October 13, 2019 10:11 PM To: [email protected]<mailto:[email protected]> Subject: [EZPROXY-L] AnonymousURL caused MAXSESSIONS CAUTION: This email originated from outside of Lone Star College. Do not click links or open attachments unless you recognize the sender and know the content is safe. This morning we had a case of a user's browser going haywire and causing a database with an AnonymousURL directive to spawn thousands of sessions, which quickly hit our MAXSESSIONS 6000 limit. The same thing happened about a year ago (different database, same issue). To prevent this recurring we've turned out MAXSESSIONS up to a lofty 100000 and set up a Splunk alert that emails our team as soon as EZproxy breaches 6000. Two questions for the collective wisdom of this list: 1. Has anyone else experienced the problem I described? 2. Is setting MAXSESSIONS at 100000 as a risk mitigation strategy going to cause something else to fail? Note that normally we don't get above 3000, I initially put 6000 as a high number but raising to 100000 is just to buy us more time if this happens again. Thanks, Jai Parker | Information Access Librarian QUT Library | Division of Administrative Services QUT | Kelvin Grove | D Block, Level 1 | Victoria Park Rd Kelvin Grove QLD 4059 P: 07 3138 3381 | E: [email protected]<mailto:[email protected]> | www.qut.edu.au<https://linkprotect.cudasvc.com/url?a=http%3a%2f%2fwww.qut.edu.au%2f&c=E,1,kXjWMpdEBS-gIr6_DVDXeXhTgIzinXOt9Xhy85-2Nx20EIKmfT8AN91zg0OQwehVJM3MxGJ-Ae_Q10bF1IggEOiouIZFL53Y1btOR9ms8cgQBLY,&typo=1> ABN: 83 791 724 622 | CRICOS No. 00213J ________________________________ To unsubscribe from the EZPROXY-L list, click the following link: http://listserv.oclclists.org/scripts/wa.exe?SUBED1=EZPROXY-L&A=1<https://linkprotect.cudasvc.com/url?a=http%3a%2f%2flistserv.oclclists.org%2fscripts%2fwa.exe%3fSUBED1%3dEZPROXY-L%26A%3d1&c=E,1,SUztOp73Hp4IsCKNcwvTZa37J_JJjJdP-Ex2znTeHrcuVvwx3MlQB8HZcVr9TRirM6Pi8RexrYev9XHlfWeDU6KFF4csoyWLUf__33cPBXM,&typo=1> ******************************************************************** If you wish to stop receiving messages from EZPROXY-L or otherwise amend your preferences, you can do so <a href="https://www.oclc.org/forms/internet-subscription.en.html">here</a>. Or email [email protected] including the relevant text below in the body of the email: • To unsubscribe: "unsubscribe EZPROXY-L" • To receive EZPROXY-L in digest form: "set EZPROXY-L digest" • To set your options to no mail: "set EZPROXY-L nomail" • To receive these messages in the future "set EZPROXY-L mail" To contact the list owners directly please send your message to [email protected]. If you unsubscribe from EZPROXY-L, you will no longer be able to participate in any of its features, including the public forum. To unsubscribe from all OCLC marketing email communications (including all OCLC listervs, OCLC Connect emails, OCLC event notifications, product/service/cooperative updates and newsletters), please email us at [email protected].
image001.gif
(image/gif, 3.3 KB) - not displayed