Apache: escaping control characters in logs

Post by Phil Howa » Mon, 10 May 1999 04:00:00

Before I spend the time to do this critical hack in 1.3.6, I'd like to
first check and see if anyone else has done this already.  The issue
is formatting a log file (probably a custom format) where no request
can possibly inject anything into the log that would fool any parsing.
For example, injecting quotes and newline characters can easily make
up false log entries.

Yes, I read the documentation where the writer referred to some log ago
statement about being concerned about escape characters.  However, my
concerns are entirely on security.

Phil Howard           KA9WGN


