Ticket #1714 (closed defect: fixed)

Opened 12 years ago

Last modified 12 years ago

Denial of service by download files from the network

Reported by: tarmo Owned by: gabor
Priority: blocker Milestone:
Component: generic Version:
Keywords: Cc:
Time planned: Time remaining:
Time spent: 10.0h

Description

Christian points out:

The LeMill software has a DOS vector where you start downloading files from the network to bundle them up or something (Collection.py using downloadFiles function). You can't do that within a Zope request as this will cause Zope to hang up all threads when the other side of the network request is slow. This happened just now and I only could get the software to work again by disabling the function that causes this.

So someone should check this out urgently.

Change History

comment:1 Changed 12 years ago by gabor

  • Owner changed from anonymous to gabor
  • Status changed from new to assigned

comment:2 Changed 12 years ago by gabor

  • Time spent set to 10.0h

(In [2360]) ref #1714 spent 10h Replaced openURL calls with restrictedTraverse calls. Everything seem to be working except for the rss.gif file which isn't that important. If no other problems will arise this ticket can be closed.

comment:3 Changed 12 years ago by jukka

  • Status changed from assigned to closed
  • Resolution set to fixed

No-one has complained about uploading problems for a long time. I'll close this.

Note: See TracTickets for help on using tickets.