Req #60655 [Opn]: add max_input_vars for json/serialize
| From: | laruence@php.net | Date: | Thu, 05 Jan 2012 14:04:50 +0000 |
| Subject: | Req #60655 [Opn]: add max_input_vars for json/serialize | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-166241@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=60655&edit=1
ID: 60655
Updated by: laruence@php.net
Reported by: laruence@php.net
Summary: add max_input_vars for json/serialize
Status: Open
Type: Feature/Change Request
Package: *General Issues
PHP Version: 5.3.9RC4
Block user comment: N
Private report: N
New Comment:
yes, the hash value of string index is the same, but the index = hash_value %
nTableSize,
we don't use the hash value as index directly,
didn't I misunderstand you?
Previous Comments:
------------------------------------------------------------------------
[2012-01-05 11:53:37] sesser@php.net
You are mistaken to believe that randomizing the TableSize will stop predictable
collisions: This is only true if you try to exploit the problem with numerical
indicies.
The moment you use alpha numerical keys and produce collisions in the DJB
hashing function the table size does not matter anymore, because the return
value of the hash function is the same.
------------------------------------------------------------------------
[2012-01-05 11:29:15] laruence@php.net
sorry, didn't get your point?
the collision can not be predicatible any more, why this patch doesn't solve the
problem?
------------------------------------------------------------------------
[2012-01-05 11:24:44] sesser@php.net
Your patch does not fix the problem.
It will make the first X hashtable grow operations random.
But the moment you already inserte 65536 entries the HashTable is now big enough
to launch the attack.
Maybe your test script already breaks your patch the moment you try to insert
2^17 entries.
Otherwise the attack script might need some tweaking. Anyway, your patch will
not solve the problem.
------------------------------------------------------------------------
[2012-01-05 08:09:18] laruence@php.net
The following patch has been added/updated:
Patch Name: rand_hash_resize.patch
Revision: 1325750958
URL: https://bugs.php.net/patch-display.php?bug=60655&patch=rand_hash_resize.patch&revision=1325750958
------------------------------------------------------------------------
[2012-01-05 05:04:53] laruence@php.net
The following patch has been added/updated:
Patch Name: max_input_vars.patch
Revision: 1325739893
URL: https://bugs.php.net/patch-display.php?bug=60655&patch=max_input_vars.patch&revision=1325739893
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=60655
--
Edit this bug report at https://bugs.php.net/bug.php?id=60655&edit=1