Bug #72346 [Opn]: mysql_query() not subject to max_execution_time()
| From: | maggus dot staab at googlemail dot com | Date: | Mon, 06 Jun 2016 16:26:35 +0000 |
| Subject: | Bug #72346 [Opn]: mysql_query() not subject to max_execution_time() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-201484@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72346&edit=1
ID: 72346
User updated by: maggus dot staab at googlemail dot com
Reported by: maggus dot staab at googlemail dot com
Summary: mysql_query() not subject to max_execution_time()
Status: Open
Type: Bug
-Package: *General Issues
+Package: *Database Functions
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
fixed package
Previous Comments:
------------------------------------------------------------------------
[2016-06-06 16:04:13] maggus dot staab at googlemail dot com
Description:
------------
similar to https://bugs.php.net/bug.php?id=72345
A DOS attack vector for SQL injections uses the mysql SELECT SLEEP() command, as it will block a PHP
process which is waiting for the mysql result and also one connection to the database itself.
this renders this kind of attack as very effective because you easily can bring either apache/php or
mysql above its processlimits.
Additionally the mysql version distributed with ubuntu12lts and ubuntu14lts is not recent enough to
contain server side timouts on a per statement basis.
Test script:
---------------
<?php
$start = time();
set_time_limit(2);
define("DB_HOSTNAME", "localhost");
define("DB_USERNAME", "root");
define("DB_PASSWORD", "");
define("DB_NAME", "mysql");
$connection_id = mysql_connect(DB_HOSTNAME, DB_USERNAME, DB_PASSWORD, false);
mysql_query('SELECT SLEEP(5)', $connection_id);
$end = time();
echo $end - $start;
Expected result:
----------------
mysql query should be interrupted after 2 seconds with a fatal error
Actual result:
--------------
no error, no timeouts triggered.
echos "5"
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=72346&edit=1