CGDevTools Forum

Welcome to the Official CGDevTools Support Community Forums.

Blocked session hangs one CPU core

General discussion

by Jorge Sousa » 17 Jan 2014 15:55

Hi

However it's very easy to know why OnBrowserCheck is get called

You just debug, put a breakpoint in OnBrowserCheck hander, and see the WebApplication.Request and the call stack.
Best Regards
CGDevTools Develop / Support Team
Home Page: http://www.cgdevtools.com
Jorge Sousa
 
Posts: 4261
Joined: 17 May 2012 09:58

by magosk » 11 Mar 2014 07:50

Hi again! I just wanted to share with you that we run into problems when one of our customers did a penetration test of our web application, see my latest post in https://forums.embarcadero.com/thread.jspa?messageID=638446#638446. I know that this has nothing to do with your components, but since this (probably) affects everyone using the IntraWeb platform, I wanted to ask if you as a third party developer with a large user base can aid us in putting some extra pressure on Atozed to fix this issue? In the worst case, if we cannot remove this vulnerability, we would probably be forced to leave the IntraWeb platform altogether.
magosk
 
Posts: 181
Joined: 07 Oct 2013 08:41

by Jorge Sousa » 11 Mar 2014 10:48

Well

It's... Interesting... the way you say that is an Intraweb issue.... without any solid and technical prove.

How do we know that isn't your code?

Is your code thread-safe in every places?

Are you using the RTLFix unit?

Do you have any log event tool?

Can you show us any evidence?

We always submit elaborated test cases to Atozed, that undoubtedly prove any issue.

Please tell us how we can help you, we know that would help, if you let tale a look at your code, using remote session, for instance, to not compromise any copyright.

We would love to help you in this.
Best Regards
CGDevTools Develop / Support Team
Home Page: http://www.cgdevtools.com
Jorge Sousa
 
Posts: 4261
Joined: 17 May 2012 09:58

by Jorge Sousa » 11 Mar 2014 12:06

We used nikto

And the result was:

perl nikto.pl -h http://www.cgdevtools.com/demo/JQMobile ... _ISAPI.dll

6544 items checked: 0 error(s) and 1828 item(s) reported on remote host

CPU was always Idle
Best Regards
CGDevTools Develop / Support Team
Home Page: http://www.cgdevtools.com
Jorge Sousa
 
Posts: 4261
Joined: 17 May 2012 09:58

by Jorge Sousa » 11 Mar 2014 13:26

After taking a closer look, this is creating many many new sessions.....

How does the memory of your web app behaves in such conditions?
Best Regards
CGDevTools Develop / Support Team
Home Page: http://www.cgdevtools.com
Jorge Sousa
 
Posts: 4261
Joined: 17 May 2012 09:58

by magosk » 12 Mar 2014 09:27

Hi and thanks for your extensive feedback on this! For some reason, I did not get e-mail notifications on your replies (cannot find them in my spam folders either), so I did not read it until now. Anyway, Alexandre Machado on Atozed did reply to my post yesterday and have put in some effort to the case this time, and it seems that he might have a solution soon. Hopefully I can verify it later today. If it does not solve the problem, I can provide feedback to your questions above. I just want to point out that my intention in posting here was not to give you guys a lot of extra work, only to ask if you had any contacts at Atozed. I do much appreciate your efforts, your support is excellent as always!
magosk
 
Posts: 181
Joined: 07 Oct 2013 08:41

by Jorge Sousa » 12 Mar 2014 11:11

Hello

No problem about the extra work, and we did contacted Atozed - Alexandre Machado.
Best Regards
CGDevTools Develop / Support Team
Home Page: http://www.cgdevtools.com
Jorge Sousa
 
Posts: 4261
Joined: 17 May 2012 09:58

by magosk » 12 Mar 2014 13:38

Hi again!

We have now confirmed that the new IntraWeb 12.2.29 release solves our problem, which is a great relief! Thanks for talking to Atozed, they seem to have given this problem high priority this time.

It seems like your installer for IW 12.2.26 is not compatible with IW 12.2.29. Would it be possible for you to generate a 2.0.0.3409 installer for IW 12.2.29 (or a newer develop version if that is easier)?
magosk
 
Posts: 181
Joined: 07 Oct 2013 08:41

by Jorge Sousa » 12 Mar 2014 15:08

Hi

Would it be possible for you to generate a 2.0.0.3409 installer for IW 12.2.29 (or a newer develop version if that is easier)?


Yes it will be possible to generate a newer develop version today. We cannot change the build count (3409) of released versions.
Best Regards
CGDevTools Develop / Support Team
Home Page: http://www.cgdevtools.com
Jorge Sousa
 
Posts: 4261
Joined: 17 May 2012 09:58

Previous

Return to General

Who is online

Users browsing this forum: No registered users and 4 guests

Contact Us.