Hi,

I noticed that requests (POST in the case) that are missing both the Content-Length and also Transfer-encoding, are not logged (as invalid) in Tomcat/6.0.18. Seems potential for stealth mis-use (DoS etc).

I'm not sure of this is core or org.apache.catalina.valves.AccessLogValve (would appear to be a org/apache/coyote/http11/ Processor?)

Regards,

ken



---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscr...@tomcat.apache.org
For additional commands, e-mail: users-h...@tomcat.apache.org

Reply via email to