Re: [Bug 11] Protection against XML Denial Of Service attacks

bugzilla@soe.ucsc.edu wrote:
> http://ietf.cse.ucsc.edu:8080/bugzilla/show_bug.cgi?id=11
> 
> lisa@osafoundation.org changed:
> 
>            What    |Removed                     |Added
> ----------------------------------------------------------------------------
>          AssignedTo|lisa@osafoundation.org      |julian.reschke@greenbytes.de
>              Status|ASSIGNED                    |NEW
> 
> 
> 
> ------- Additional Comments From lisa@osafoundation.org  2005-11-30 14:42 -------
> I didn't understand the part about removing the section on 503 -- what's wrong
> with it?  
> 
> The part about XML entities I've fixed.

We discussed this during the conference call: 5xx is a server error, in 
particular 503 means "not now but maybe later". If a server detects a 
DOS attack, that's the last thing it would want to tell the client.

Servers are free to do whatever they want should they detect a DOS 
attack. If they want to be friendly, a 4xx with explanation would be right.

Best regards, Julian

Received on Thursday, 1 December 2005 17:27:26 UTC