Menu

#57 Mutella doesn't handle GWC replies properly

open
nobody
None
5
2004-03-08
2004-03-08
No

I've seen several requests from Mutella 0.4.3 clients
which sent an URL like
"host1.example.org\rhost2.example.com\rhost3.example.com\r".
Apparently,
Mutella doesn't strip trailing spaces from URLs and/or
doesn't check whether URLs are valid resp. reasonable.
URLs containing unencoded spaces are surely not valid.

Also, keep in mind that you cannot trust a GWC or its
users. Someone
could misuse it for an DoS attack or worse. Do NOT
accept or use
URLs which are invalid or unlikely to point to a GWC!

Discussion


Log in to post a comment.

MongoDB Logo MongoDB