note 52735 added to function.sleep
| From: | tommiboy at osu1 dot php dot net | Date: | Wed, 11 May 2005 11:43:18 +0000 |
| Subject: | note 52735 added to function.sleep | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-89253@lists.php.net to get a copy of this message | ||
Two additions to my previous note:
1. You can of course *always* run a DoS on any server at any time. If you have a few hundred
hijacked machines, then you can incapacitate even huge sites like amazon or worldpay who have really
large resources, as has been done before. Unluckily, there is not much you can do against braindead
crimials. Even if you block them on the IP layer, they can still fill the wire with datagrams :(
However, sleep() makes an attack a lot cheaper. If the target uses for example sleep(5); then the
attacker can safely assume that one request will keep one process running for 5 seconds.
So, only a few dozen requests (w/ dropped connections), will safely run you into
"MaxClients" and you will not be able to accept legitimate requests any more. So what,
increase "MaxClients" then, I hear you say? The attacker can do this for hours, but you
can't...
10MB of memory for a server process is not a unreasonable assumption. If your web server has 2GB of
RAM then it will start thrashing after starting 200 processes. A 32 bit machine is out of virtual
memory after 400. That can be achieved using a 14.4k modem...
2. The <FilesMatch> rule in my example is flawed as it opens access to config files. By mere
coincidence (due to another rule), it has been working fine for a year and a day on my machine, so I
never noticed until now.
It is still a bad mistake. Use your login form's filename rather than "^.*$".
----
Manual Page -- http://www.php.net/manual/en/function.sleep.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+52735
Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+52735&report=yes&reason=added+to+the+manual
Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+52735&report=yes&reason=bad+code
Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+52735&report=yes&reason=spam
Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+52735&report=yes&reason=useless
Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+52735&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+52735&report=yes
Search -- http://master.php.net/manage/user-notes.php