fukamachi / woo

A fast non-blocking HTTP server on top of libev
http://ultra.wikia.com/wiki/Woo_(kaiju)
MIT License
1.27k stars 96 forks source link

crash on hacking attempt via URL #78

Closed gibsonf1 closed 5 years ago

gibsonf1 commented 5 years ago

A hacker was probing for vulnerability and with this url brought the system to a stop. Is there a way to not go into debugger on strange url's? I've been crashed several times this way.

185.100.87.246 - [16/Jan/2019:12:01:39 -09:00] "GET /nice%20ports%2C/Tri%6Eity.txt%2ebak HTTP/1.0" 302 38 "-" "-"

debugger invoked on a FAST-HTTP.ERROR:CB-MESSAGE-COMPLETE in thread

<THREAD "clack-handler-woo" RUNNING {100980E2C3}>:

Callback Error: the message-complete callback failed (A SIMPLE-ERROR was caught when trying to print DEBUG-CONDITION when entering the debugger. Printing was aborted and the SIMPLE-ERROR was stored in SB-DEBUG::NESTED-DEBUG-CONDITION.)

fukamachi commented 5 years ago

Can't reproduce it. What version of fast-http are you using? It might be fixed at https://github.com/fukamachi/fast-http/pull/37.

gibsonf1 commented 5 years ago

Thanks Eitaro - I think the problem was in my code after all - thanks!

Dumb mistake - it was the handling of errors on my side.

Fred Gibson

Founder & CEO

San Francisco

mobile: 415.335.8232

http://graphmetrix.com/

---- On Fri, 01 Feb 2019 00:32:13 -0800 Eitaro Fukamachi mailto:notifications@github.com wrote ----

Can't reproduce it. What version of fast-http are you using?

It might be fixed at https://github.com/fukamachi/fast-http/pull/37.

— You are receiving this because you authored the thread. Reply to this email directly, https://github.com/fukamachi/woo/issues/78#issuecomment-459645726, or https://github.com/notifications/unsubscribe-auth/AAMAl7jR6Dh3b5f5OxZDYtxEPmyL0aK1ks5vI_uNgaJpZM4aEKnP.