Hacker News new | ask | show | jobs
by jchung 4530 days ago
Possible detection method (server side)? If the request is too long due to cookie length, then look at the last URL the client IP hit. That should be the URL creating the long cookies. Remove the offending URL / resource.
1 comments

That won't work, and could be easily abused by crafting your own requests to blame any arbitrary URL of your choosing.

Plus, servers drop huge requests because they are most likely malformed or DOS attempts. Attempting to do extra work (like tracking down previous visits by the client) will only make matters worse for the server.

Hmmm. Yes,I see the potential for abuse. Why do you say it would not work though?