Re: [Mod-fcgid-users] security problem, possible DoS : fcgid large file uploading and input buffering

2007-05-09 Thread Janis Volbergs
On May 9, 2007, at 10:54 AM, Gabriel Barazer wrote: > On 05/08/2007 21:41:41 +0200, Janis Volbergs <[EMAIL PROTECTED]> wrote: > >> Why not limit maximum size of the data to be uploaded? This should be >> an easy patch to mod_fcgi. And about buffering, it would be more safe >> to have temporary fi

Re: [Mod-fcgid-users] security problem, possible DoS : fcgid large file uploading and input buffering

2007-05-09 Thread Gabriel Barazer
On 05/08/2007 21:41:41 +0200, Janis Volbergs <[EMAIL PROTECTED]> wrote: > Why not limit maximum size of the data to be uploaded? This should be > an easy patch to mod_fcgi. And about buffering, it would be more safe > to have temporary files. However, this might get insecure, if the > server

Re: [Mod-fcgid-users] security problem, possible DoS : fcgid large file uploading and input buffering

2007-05-08 Thread Janis Volbergs
Hi! Why not limit maximum size of the data to be uploaded? This should be an easy patch to mod_fcgi. And about buffering, it would be more safe to have temporary files. However, this might get insecure, if the server has multiuser environment. E.g. other users might easily steal those file

Re: [Mod-fcgid-users] security problem, possible DoS : fcgid large file uploading and input buffering

2007-05-08 Thread Gabriel Barazer
Hello, BTW, no one other than me is worried by the security problem due to large file uploading I described below ? On 04/30/2007 15:21:29 +0200, Gabriel Barazer <[EMAIL PROTECTED]> wrote: > Hello, > > I experienced recently some problmes since a customer is doing large > file uploads with PH