Re: HashDoS
| From: | Stanislav Malyshev | Date: | Fri, 23 Sep 2016 19:16:57 +0000 |
| Subject: | Re: HashDoS | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-96113@lists.php.net to get a copy of this message | ||
Hi!
> We could patch zend_hash.c in two ways: SipHash (sloooow) or only fatals
> (very bad for e.g. servers written in PHP. When they have to decode some
Why very bad?
> JSON, it's trivial for an attacker to crash them very easily). As that's
Fatal error is not crash. It's a normal ending of the request, of the
server can not tolerate it, how can it deal with memory limits, string
overflows, etc.? There's a lot of things right now that can cause fatal
error.
--
Stas Malyshev
smalyshev@gmail.com