Re: News DoS using sendsys

From: Russ Allbery (rraat_private)
Date: Thu Aug 27 1998 - 15:11:54 PDT

  • Next message: Julian Cowley: "Re: News DoS using sendsys"

    Marco Davids <mdavidsat_private> writes:
    > Russ suggested:
    
    >>         sendsys:*:*:drop
    
    > I wonder, whats wrong with sendsys:*.*:log=sendsys ?
    
    > (and logging all, like version,  the others as well)
    
    Because in order for INN to log something, it tries to lock the logfile,
    and to lock the logfile it has to spawn a separate shlock process and then
    clean up the lock afterwards, and INN's locking is known not to be that
    robust (at least currently) under high loads.  Not to mention that it's
    CPU- and process-intensive.
    
    Since the original poster was worrying about a DoS attack on his news
    server, the above has a lot less impact than trying to log the posts.  If
    one really wants a log of incoming sendsys messages, under INN you can
    just create control.sendsys and they'll show up there as regular news
    articles (and you can set whatever expire you want, etc.).
    
    --
    Russ Allbery (rraat_private)         <URL:http://www.eyrie.org/~eagle/>
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:13:46 PDT