Comment 6 for bug 1549855

Revision history for this message
chro eric (chrorxu) wrote :

The openstack logging DoS vulnerability key cause is openstack server keep record every generated log while repeat do GET request with long url, and openstack server does not reset the long connection, untill openstack log is exhausted.

I test apache with repeat python submit GET request, apache response with 1. after about 14000 request,the server reset the connection; 2.apache only record some repeat log, it does not generate every log record in logger file.