Regular Expression Denial of Service

看板Bugtraq作者時間16年前 (2009/09/12 02:01), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串2/6 (看更多)
Checkmarx Research Lab presents a new attack vector on Web applications. = By exploiting the Regular Expression Denial of Service (ReDoS) = vulnerability an attacker can make a Web application unavailable to its intended users. = ReDoS is commonly known as a =93bug=94 in systems, but Alex Roichman and Adar = Weidman from Checkmarx show how serious it is and how using this technique, = various applications can be =93ReDoSed=94. These include, among others, = Server-side of Web applications and Client-side Browsers. The art of attacking the Web = by ReDoS is by finding inputs which cannot be matched by Regexes and on = these Regexes a Regex-based Web systems get stuck. For further reading: http://www.checkmarx.com/NewsDetails.aspx?id=3D23&cat=3D3 Alex=A0Roichman Chief Architect, Checkmarx Ltd.=A0 Mobile: +972 54=A0774=A05198=A0=A0 Fax:=A0 +972-3-6870794=A0=A0 Website: = www.Checkmarx.com
文章代碼(AID): #1Agf1YVu (Bugtraq)
文章代碼(AID): #1Agf1YVu (Bugtraq)