Re: HashDoS

From: Date: Fri, 23 Sep 2016 19:33:30 +0000
Subject: Re: HashDoS
References: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18  Groups: php.internals 
Request: Send a blank email to internals+get-96114@lists.php.net to get a copy of this message
Hi, On Fri, Sep 23, 2016 at 8:16 PM, Stanislav Malyshev <smalyshev@gmail.com> wrote: > Hi! > > > We could patch zend_hash.c in two ways: SipHash (sloooow) or only fatals > > (very bad for e.g. servers written in PHP. When they have to decode some > > Why very bad? > > > JSON, it's trivial for an attacker to crash them very easily). As that's > > Fatal error is not crash. It's a normal ending of the request, of the > server can not tolerate it, how can it deal with memory limits, string > overflows, etc.? There's a lot of things right now that can cause fatal > error. > > That's exactly what we don't want - let the attacker to end our request. All other things like string overflows and memory limits are under our control (e.g. we can set limit on the server and reject such requests) but this isn't. Cheers Jakub

« previous php.internals (#96114) next »