webalizer vs awstats in fc3

Alan Cox alan at redhat.com
Wed Jul 7 16:46:17 UTC 2004


On Wed, Jul 07, 2004 at 06:32:40PM +0200, Leonard den Ottolander wrote:
> Hi Alan,
> 
> > Oh webalizer is pretty broken, and the lack of ipv6 means either merging
> > more gunge or taking the opportunity to say "its broken" and fix it
> 
> What does "pretty broken" mean exactly? Any details you want to share?
> Is the code just ugly or did you encounter possible overflows while
> auditing?

I encountered various problems with it ranging from leap second processing
(and yes someone *actually* hit that way back when) to lack of robustness 
given junk data. No mega exploitable holes but given bogus data it will
happily produce totally junk results and think they are valid.





More information about the devel mailing list