curl-and-python

Re: aborting a transaction

From: <johansen_at_sun.com>
Date: Thu, 24 Sep 2009 10:07:51 -0700

On Thu, Sep 24, 2009 at 05:55:58AM +0200, Daniel Stenberg wrote:
> lib/transfer.c:readwrite_http_headers() is the responsible function. I
> guess at least some kind of fixed maximum header length (like a 100KB or
> 1MB or so) is suitable to use there. Wouldn't you agree on that?

That seems entirely reasonable. I believe Seth said that he configured
a limit of 2mb using the HEADERFUNCTION.

Has anyone detailed the possible client DoS scenarios beyond what's been
written in the tutorial, or is it better to have that discussion on
curl-library, instead?

Many thanks,

-j
_______________________________________________
http://cool.haxx.se/cgi-bin/mailman/listinfo/curl-and-python
Received on 2009-09-24