Bug #70644 [NEW]: trivial hash complexity DoS attack
| From: | ondrej@php.net | Date: | Mon, 05 Oct 2015 15:34:51 +0000 |
| Subject: | Bug #70644 [NEW]: trivial hash complexity DoS attack | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-196406@lists.php.net to get a copy of this message | ||
From: ondrej
Operating system:
PHP version: 5.6.14
Package: *Encryption and hash functions
Bug Type: Bug
Bug description:trivial hash complexity DoS attack
Description:
------------
As reported here: https://bugs.debian.org/800564 by
brian m. carlson:
Applies to all PHP versions.
PHP uses the DJB "times 33" hash to hash strings in its hash tables,
without the use of any secret key. Hash values are therefore the same
between multiple invocations. As a result, it's trivial to precompute
a
set of values that all hash to the same bucket and cause positively
abysmal performance.
If a script accepts untrusted hash keys, such as from JSON input, it is
subject to a DoS attack. PHP implemented the max_input_vars option,
but
this is not effective in the general case, especially in the era of
JSON-laden POST requests. Perl, Python, and Ruby have all addressed
their CVEs properly, but PHP has not and as a result is still
vulnerable.
Cloning my example repository[0] and running
"php scripts/exploited.php < example/1048576.json" demonstrates the
problem very quickly. The similar Perl and Python scripts are not
vulnerable to this attack. A JSON file containing only 65536 entries
takes PHP 5.6 22 seconds to process.
A new CVE should probably be allocated and the bug should be fixed
correctly this time, probably by seeding a key from /dev/urandom and
using SipHash-2-4 or the like.
Python had CVE-2012-1150 and CVE-2013-7040. Ruby had CVE-2011-4815. I
can't find a CVE for Perl's 2003 fix, if one exists. The fix, which
went into 5.8, was incomplete and was addressed by CVE-2013-1667.
[0] https://github.com/bk2204/php-hash-dos
Test script:
---------------
https://github.com/bk2204/php-hash-dos
--
Edit bug report at https://bugs.php.net/bug.php?id=70644&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=70644&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=70644&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=70644&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=70644&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=70644&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=70644&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=70644&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=70644&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=70644&r=support
Expected behavior: https://bugs.php.net/fix.php?id=70644&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=70644&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=70644&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=70644&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=70644&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=70644&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=70644&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=70644&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=70644&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=70644&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=70644&r=mysqlcfg