5 ms·
What kind of DOS patterns are you trying to prevent? People requesting the same image repeatedly, or people requesting random images? Generally, DOS attacks are
by marketer 19y ago
What kind of DOS patterns are you trying to prevent? People requesting the same image repeatedly, or people requesting random images? Generally, DOS attacks are prevented by making the client do some non-trivial amount of work, like answering a computational challenge, or filling out a catchpa.
- brianr 19y agoPeople requesting random images. A captcha won't work because the images are in <img> tags in every page in the application... I don't want to make users type in a captcha before each pageview.
- mrtron 19y agoSorry to nitpick, but that really isn't a DOS. That is more of a crawl that you are trying to prevent, which could be quite taxing on your system but it is not intended to be. So, that being said, your approach should be roughly good enough to prevent that.
- tlrobinson 19y agoIf an attacker requesting hundred of these image can bring the system to it's knees, it's a denial of service attack.
- mrtron 19y agoA 'hacker' could request the same image hundreds of time right now even with this layer of obscurity! They are two separate issues.
- tlrobinson 19y agoNo. The expensive part is dynamically generating the image. Once the image is generated it is cached and served up statically like any other plain html or image file.
- deleted 19y ago[deleted]