Skip site navigation (1) Skip section navigation (2)

Peripheral Links

Header And Logo

PostgreSQL
| The world's most advanced open source database.

Site Navigation

Search for
  Advanced Search

Re: 404s


  • From: Stefan Kaltenbrunner <stefan(at)kaltenbrunner(dot)cc>
  • To: Guido Barosio <gbarosio(at)gmail(dot)com>
  • Cc: "Joshua D. Drake" <jd(at)commandprompt(dot)com>, Dave Page <dpage(at)pgadmin(dot)org>, Simon Riggs <simon(at)2ndquadrant(dot)com>, pgsql-www(at)postgresql(dot)org
  • Subject: Re: 404s
  • Date: Wed, 28 May 2008 19:22:06 +0200
  • Message-id: <483D94BE(dot)6020301(at)kaltenbrunner(dot)cc>

Guido Barosio wrote:
+1 but without the form and directly triggering an alert to slaves.

404 ? trigger_alert.php?missingurl=param

so anybody with wget and a simply shellscript could can (email) DoS -slaves and wwwmaster in seconds ?


Do not rely on users if you want to improve the experience, though.

keep in mind that we can only detect relative urls on our OWN infrastructure and also that 99% of the website traffic is on www.postgresql.org with ourely static (mirrored) content, no PHP (or whatever) support and are only partly under our control.
only wwwmaster is dynamic but only a fraction of traffic ends up there.


Stefan


  • Follow-Ups:

Home | Main Index | Thread Index

Privacy Policy | PostgreSQL Archives hosted by Command Prompt, Inc. | Designed by tinysofa
Copyright © 1996 – 2008 PostgreSQL Global Development Group