On 2013.08.21, at 11:06, Francesco Lazzarino wrote:
> with the slow-play interaction they still handle it correctly but at
> (virtually) no expense to the rest of the requests being handled?
Yeah. And I think they're in a good position to know they're being
slow-played. But I haven't had time to check on this myself with pipes
and/or conduit.
Basically, it's usually a mistake for servers to think everything is OK
as long as they hear something from the client within some amount of
time. It's more like they need to recieve a complete request from the
client within a certain amount of time, or something like that.
> with ftp clients, is the risk that a newline will never come?
Right. If you write a network service scanner that collects banners
and/or tries to interact with the services to find out about them or
check basic things, you have to deal with all kinds of weird stuff.
People may put chargen on port 21.
Servers and clients both really need to protect themselves.
> are machines pass�?
I've heard they're cool, but sort of experimental. pipes and conduit are
the industrial-strength packages right now.