httpd-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Randy Terbush <ra...@Covalent.NET>
Subject Re: [PATCH] fast os_escape_path
Date Fri, 27 Feb 1998 13:37:57 GMT
Dean Gaudet <> writes:

> Folks might remember a while back it was pointed out that one of the two
> "beck" attacks was still a bit choking on the server, and it was because
> os_escape_path is way slow.  I posted a patch that used a precomputed
> table to speed things up... well here is that patch done again properly.
> In this case we precompute the table at compile time.  It contains a few
> other bits.
> This isn't really tested well, I'm posting because: 
> (a) I want to know how win32 folks are going to deal with the need to run
> gen_istable at compile time. 
> (b) I'm not going to bother finishing it unless folks are going to accept
> it into 1.3.
> Dean

Looks like this would be a nice addition to 1.3. I would support it
and begin lobbying that we choose a freeze date for 1.3 and put the
wraps on it. ??

View raw message