Possible Parse Bomb
| From: | Zak Greant | Date: | Sat, 09 Dec 2000 11:46:53 +0000 |
| Subject: | Possible Parse Bomb | ||
| Groups: | php.qa | ||
| Request: | Send a blank email to php-qa+get-1769@lists.php.net to get a copy of this message | ||
Hello All,
Zeev recently highlighted possible problems with PHP failing to parse
requests properly. I would like for us to attempt to recreate this problem.
Does anyone have any suggestions on good ways to perform these tests?
Mark J. Hershenson proposed using ab to do the tests -- this sounds like a
good idea to me - at least for the initial purpose of attempting to verify
if the problem exists.
Based on Mark's suggestions, I have a few ideas:
Create a nice clean custom log ( + format) to track the results of the
tests. This will make it easier for us to parse the data.
In the interests of time, we should probably start with the simplest set of
tests. Run a simple test many times and see if we get anything that looks
like a parse bomb. If we don't get any results this way, perhaps move to a
more complex text that calls a wide range of functions.
As soon as we can recreate the problem, then move to trying to capture what
is actually going on. I don't know if there is any way to easily capture
the pages output by ab - I am guessing that there is not. If not, and we can
recreate the problem, then we should look at writing a script that requests
a file, compares the length of the content served to the expected length and
captures any odd results.
Thoughts, comments?
Zak