Forums / Developer / [Ez Crew] How to stop this kind of DB flood ?! [IMPORTANT]

[Ez Crew] How to stop this kind of DB flood ?! [IMPORTANT]

Author Message

Selmah Maxim

Sunday 01 June 2003 8:29:08 am

Hi ..

[I THINK]

With small lines of js i can make ez.no DB full ( eznode_assignment table,ezcontentobject_link table, ezcontentobject_version table, maybe more tables) within minutes , i mean i some houre you will find more than 1xxxxx in 1 table !!

I think u know what result you get if someone start such flood for db !
Check the draft system, and versions system !!!

if you think it`s ok, give try, flood try .

am trying now to stop draft, versions for users,editors, and maybe also for admin, this must be option for site owner i think .

if what am talking about is crap, then sorry for your time !

Björn Dieding@xrow.de

Sunday 01 June 2003 3:48:02 pm

Hi Selma,

I recommend this book.

http://www.amazon.com/exec/obidos/tg/detail/-/0194314561/ref=pd_sim_books_3/002-7599755-3522407?v=glance&s=books

You might need it for futher discussions on certain topics.

It is good that you are aware of certain security issues of web-based software. Those kind and similar kinds of DOS attacks are possible with a lot of common web-based software. You can try to tear down all of them, if this is the point of your existance.

Björn Dieding

Looking for a new job? http://www.xrow.com/xrow-GmbH/Jobs
Looking for hosting? http://hostingezpublish.com
-----------------------------------------------------------------------------
GMT +01:00 Hannover, Germany
Web: http://www.xrow.com/

Selmah Maxim

Monday 02 June 2003 1:06:20 am

Ohh ... thx for this recommendation ;)

But am feeling well with my english grammar , and am not interested to learn more than this, coz i feel good with knowledge 4 language, plus the english, and it`s the most difficulty language in world (Hungarian,Hebrew,arabic,turkish) ... just try to learn 1 of them, then come with ur recommendation !!

The point is that u understand what am talking about (maybe), and the and still the solution waiting !

btw ... did u read the therad topic ,,, is was Ez crew, ez programmers !

Bård Farstad

Monday 02 June 2003 1:32:08 am

There is a potential db flood with eZ publish, you're right about that. However you can lock this down by saying that anonymous users are not allowed to create any objects.

You can also lock down specific modules/functions in eZ publish to set up a site which does not allow for anything but read access.

-bård

Documentation: http://ez.no/doc

Selmah Maxim

Monday 02 June 2003 1:38:48 am

Hi ..

I know this solution, but the better if we can lock down the draft system and versions for users.

I had made some section which request registered users, and if user have account he can flood also the DB with his account, he can make alot of drafts and copies of his account !

Can we stop the draft system and veriosns for users, from ini files ?

eZ debug

Timing: Jan 18 2025 05:18:21
Script start
Timing: Jan 18 2025 05:18:21
Module start 'content'
Timing: Jan 18 2025 05:18:22
Module end 'content'
Timing: Jan 18 2025 05:18:22
Script end

Main resources:

Total runtime0.9641 sec
Peak memory usage4,096.0000 KB
Database Queries202

Timing points:

CheckpointStart (sec)Duration (sec)Memory at start (KB)Memory used (KB)
Script start 0.00000.0082 589.0000180.8125
Module start 'content' 0.00820.8021 769.8125603.0547
Module end 'content' 0.81030.1537 1,372.8672337.3516
Script end 0.9641  1,710.2188 

Time accumulators:

 Accumulator Duration (sec) Duration (%) Count Average (sec)
Ini load
Load cache0.00400.4134210.0002
Check MTime0.00150.1517210.0001
Mysql Total
Database connection0.00210.213110.0021
Mysqli_queries0.883991.68462020.0044
Looping result0.00220.22732000.0000
Template Total0.928296.320.4641
Template load0.00240.247320.0012
Template processing0.925896.025320.4629
Template load and register function0.00020.015710.0002
states
state_id_array0.00140.149610.0014
state_identifier_array0.00510.528520.0025
Override
Cache load0.00190.1984340.0001
Sytem overhead
Fetch class attribute can translate value0.00160.166740.0004
Fetch class attribute name0.00080.086070.0001
XML
Image XML parsing0.00150.152840.0004
class_abstraction
Instantiating content class attribute0.00000.001070.0000
General
dbfile0.00340.3548340.0001
String conversion0.00000.000630.0000
Note: percentages do not add up to 100% because some accumulators overlap

CSS/JS files loaded with "ezjscPacker" during request:

CacheTypePacklevelSourceFiles
CSS0extension/community/design/community/stylesheets/ext/jquery.autocomplete.css
extension/community_design/design/suncana/stylesheets/scrollbars.css
extension/community_design/design/suncana/stylesheets/tabs.css
extension/community_design/design/suncana/stylesheets/roadmap.css
extension/community_design/design/suncana/stylesheets/content.css
extension/community_design/design/suncana/stylesheets/star-rating.css
extension/community_design/design/suncana/stylesheets/syntax_and_custom_tags.css
extension/community_design/design/suncana/stylesheets/buttons.css
extension/community_design/design/suncana/stylesheets/tweetbox.css
extension/community_design/design/suncana/stylesheets/jquery.fancybox-1.3.4.css
extension/bcsmoothgallery/design/standard/stylesheets/magnific-popup.css
extension/sevenx/design/simple/stylesheets/star_rating.css
extension/sevenx/design/simple/stylesheets/libs/fontawesome/css/all.min.css
extension/sevenx/design/simple/stylesheets/main.v02.css
extension/sevenx/design/simple/stylesheets/main.v02.res.css
JS0extension/ezjscore/design/standard/lib/yui/3.17.2/build/yui/yui-min.js
extension/ezjscore/design/standard/javascript/jquery-3.7.0.min.js
extension/community_design/design/suncana/javascript/jquery.ui.core.min.js
extension/community_design/design/suncana/javascript/jquery.ui.widget.min.js
extension/community_design/design/suncana/javascript/jquery.easing.1.3.js
extension/community_design/design/suncana/javascript/jquery.ui.tabs.js
extension/community_design/design/suncana/javascript/jquery.hoverIntent.min.js
extension/community_design/design/suncana/javascript/jquery.popmenu.js
extension/community_design/design/suncana/javascript/jScrollPane.js
extension/community_design/design/suncana/javascript/jquery.mousewheel.js
extension/community_design/design/suncana/javascript/jquery.cycle.all.js
extension/sevenx/design/simple/javascript/jquery.scrollTo.js
extension/community_design/design/suncana/javascript/jquery.cookie.js
extension/community_design/design/suncana/javascript/ezstarrating_jquery.js
extension/community_design/design/suncana/javascript/jquery.initboxes.js
extension/community_design/design/suncana/javascript/app.js
extension/community_design/design/suncana/javascript/twitterwidget.js
extension/community_design/design/suncana/javascript/community.js
extension/community_design/design/suncana/javascript/roadmap.js
extension/community_design/design/suncana/javascript/ez.js
extension/community_design/design/suncana/javascript/ezshareevents.js
extension/sevenx/design/simple/javascript/main.js

Templates used to render the page:

UsageRequested templateTemplateTemplate loadedEditOverride
1node/view/full.tplfull/forum_topic.tplextension/sevenx/design/simple/override/templates/full/forum_topic.tplEdit templateOverride template
5content/datatype/view/ezxmltext.tpl<No override>extension/community_design/design/suncana/templates/content/datatype/view/ezxmltext.tplEdit templateOverride template
6content/datatype/view/ezxmltags/paragraph.tpl<No override>extension/ezwebin/design/ezwebin/templates/content/datatype/view/ezxmltags/paragraph.tplEdit templateOverride template
1content/datatype/view/ezxmltags/line.tpl<No override>design/standard/templates/content/datatype/view/ezxmltags/line.tplEdit templateOverride template
2content/datatype/view/ezimage.tpl<No override>extension/sevenx/design/simple/templates/content/datatype/view/ezimage.tplEdit templateOverride template
1pagelayout.tpl<No override>extension/sevenx/design/simple/templates/pagelayout.tplEdit templateOverride template
 Number of times templates used: 16
 Number of unique templates used: 6

Time used to render debug report: 0.0002 secs