Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Editor Blogs > Security

December 29th, 2011, 10:52 GMT · By Eduard Kovacs

BLOG

PHP Vulnerable to Algoritmic Complexity Attacks

SHARE:

Adjust text size:


PHP vulnerable to DoS attacks Enlarge picture - PHP vulnerable to DoS attacks
Researchers showed that some programing language implementations didn’t sufficiently randomize their hash functions or provide means to limit key collision attacks. Among the ones affected by this issue is PHP 5.

“PHP 5 uses the DJBX33A (Dan Bernstein's times 33, addition) hash function and parses POST form data into the $_POST hash table. Because of the structure of the hash function, it is vulnerable to an equivalent substring attack,” reads the n.runs AG advisory.

The PHP Group didn’t release an official statement regarding the issue, but PHP 5.4.0 RC4 adds a max_input_vars directive to help mitigate hash collision attacks. However, this release is not stable.

Until the vendor responds, users are advised to limit the CPU time that a request is allowed to take by configuring the max_input_time parameter. Another way to mitigate an attack is to limit the maximal POST size.

Those who use Suhosin, the open source patch for PHP that comes with some security improvements, can use suhosin.post.max_vars to define the maximum number of variables that may be registered through a POST request.

Other web programing languages and applications are also susceptible to a similar DoS attack. Learn how this is possible.

PHP 5.3.8 / 5.4.0 RC4
is available for download here.

TELL US WHAT YOU THINK:

2,098 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Microsoft Releases Out-of-Band Security Bulletin for ASP.NET/IIS on All Windows Versions

Simple Machines Forum Project Releases 2.0.2 and 1.1.16 Security Patches

Ruby Flaw Allows Hackers to Launch DoS Attacks

Rails 3.1.2 Fixes XSS Vulnerability

HP Releases Firmware Update to Prevent Unauthorized Access

READER COMMENTS:


Comment #1 by: jc on 29 Dec 2011, 15:30 UTC reply to this comment

Are you freaking kidding me? 'fixed' by limiting max number of POST parameters ? Sinking to the level of Perl I see...

Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM