note 52735 deleted from function.sleep by danbrown

From: Date: Sat, 14 Mar 2009 14:38:41 +0000
Subject: note 52735 deleted from function.sleep by danbrown
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-151881@lists.php.net to get a copy of this message
Note Submitter: tommiboy ---- Two additions to my previous note: 1. You can of course *always* run a DoS on any server at any time. If you have a few hundred hijacked machines, then you can incapacitate even huge sites like amazon or worldpay who have really large resources, as has been done before. Unluckily, there is not much you can do against braindead crimials. Even if you block them on the IP layer, they can still fill the wire with datagrams :( However, sleep() makes an attack a lot cheaper. If the target uses for example sleep(5); then the attacker can safely assume that one request will keep one process running for 5 seconds. So, only a few dozen requests (w/ dropped connections), will safely run you into "MaxClients" and you will not be able to accept legitimate requests any more. So what, increase "MaxClients" then, I hear you say? The attacker can do this for hours, but you can't... 10MB of memory for a server process is not a unreasonable assumption. If your web server has 2GB of RAM then it will start thrashing after starting 200 processes. A 32 bit machine is out of virtual memory after 400. That can be achieved using a 14.4k modem... 2. The <FilesMatch> rule in my example is flawed as it opens access to config files. By mere coincidence (due to another rule), it has been working fine for a year and a day on my machine, so I never noticed until now. It is still a bad mistake. Use your login form's filename rather than "^.*$".

« previous php.notes (#151881) next »