Re: HashDoS
| From: | Stanislav Malyshev | Date: | Fri, 23 Sep 2016 19:47:50 +0000 |
| Subject: | Re: HashDoS | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-96116@lists.php.net to get a copy of this message | ||
Hi!
> That's exactly what we don't want - let the attacker to end our request.
Why not? What else you can do with this request that has clearly bad and
maliciously constructed data?
> All other things like string overflows and memory limits are under our
> control (e.g. we can set limit on the server and reject such requests)
Not sure I understand what you mean. How exactly memory limits are under
your control? If somebody sends a request that blows up your memory
limit, how you control it? In fact, if somebody sends, say, a POST that
goes above your post limit - how you handle it without terminating the
request?
--
Stas Malyshev
smalyshev@gmail.com