[Date Prev][Date Next] [Chronological] [Thread] [Top]

slapd-crash in web directory?



Not a problem as such, but I happened to notice this in my Apache log:

    164.132.162.164 - - [03/Dec/2017:11:57:00 +1100] "GET /slapd-crash/ HTTP/1.1" 404 210 "-" "Mozilla/5.0 (compatible; AhrefsBot/5.2; +http://ahrefs.com/robot/)"

AhrefsBot, for the uninitiated, is a web spider that tends to ignore such bothersome conventions as "content=noindex" and "robots.txt" etc, but anyway...

Is it common practice to store SLAPD coredumps where every man and his dog can retrieve them? Note that I am not suggesting that OpenLDAP does this (but somebody obviously is), but I'm curious to know how widespread this silly practice is.

--
Dave Horsfall DTM (VK2KFU)  "Those who don't understand security will suffer."