Re: squid logging full GET URL

From: Evan Champion <>
Date: Sun, 22 Jun 1997 11:38:38 -0400

Cord Beermann wrote:
> <IMHO>I think that security hole is the one who wrote the cgi (or
> whatever) which puts passwords on the URL.</IMHO>

I totally agree, but that doesn't change the fact that people still do

> If I produce statistics I strip all data after the ? from the URL.

Yes, but data after the ? is still in the access log. It doesn't really
contribute much to me, and is a big security hole.

