ͨ¹ý¹¹ÔìHash³åͻʵÏÖ¸÷ÖÖÓïÑԵľܾø·þÎñ¹¥»÷
ÔÎÄ£ºhttp://www.laruence.com/2011/12/29/2412.html
ÉÏÖܵÄʱºòDmitryͻȻÔÚ5.4·¢²¼ÔÚ¼´µÄʱºò, ÒýÈëÁËÒ»¸öеÄÅäÖÃÏî:
Added max_input_vars directive to prevent attacks based on hash collision
Õâ¸öÔ¤·ÀµÄ¹¥»÷, ¾ÍÊÇ¡±Í¨¹ýµ÷ÓÃHash³åͻʵÏÖ¸÷ÖÖÓïÑԵľܾø·þÎñ¹¥»÷©¶´¡±(multiple implementations denial-of-service via hash algorithm collision).
¹¥»÷µÄÔÀíºÜ¼òµ¥, Ä¿Ç°ºÜ¶àÓïÑÔ, ʹÓÃhashÀ´´æ´¢k-vÊý¾Ý, °üÀ¨³£ÓõÄÀ´×ÔÓû§µÄPOSTÊý¾Ý, ¹¥»÷Õß¿ÉÒÔͨ¹ý¹¹ÔìÇëÇóÍ·, ²¢°éËæPOST´óÁ¿µÄÌØÊâµÄ¡±k¡±Öµ(¸ù¾Ýÿ¸öÓïÑÔµÄHashËã·¨²»Í¬¶ø¶¨ÖÆ), ʹµÃÓïÑԵײ㱣´æPOSTÊý¾ÝµÄHash±íÒòΪ¡±³åÍ»¡±(Åöײ)¶øÍË»¯³ÉÁ´±í.
ÕâÑùÒ»À´, Èç¹ûÊý¾ÝÁ¿×ã¹»´ó, ÄÇô¾Í¿ÉÒÔʹµÃÓïÑÔÔÚ¼ÆËã, ²éÕÒ, ²åÈëµÄʱºò, Ôì³É´óÁ¿µÄCPUÕ¼ÓÃ, ´Ó¶øʵÏ־ܾø·þÎñ¹¥»÷.
PHP5.4ÊÇͨ¹ýÔö¼ÓÒ»¸öÏÞÖÆÀ´¾¡Á¿±ÜÃâ±»´ËÀ๥»÷Ó°Ïì:
- max_input_vars - specifies how many GET/POST/COOKIE input variables may be accepted. default value 1000
Ä¿Ç°ÒÑÖªµÄÊÜÓ°ÏìµÄÓïÑÔÒÔ¼°°æ±¾ÓÐ::
Java, ËùÓа汾
JRuby <= 1.6.5
PHP <= 5.3.8, <= 5.4.0RC3
Python, ËùÓа汾
Rubinius, ËùÓа汾
Ruby <= 1.8.7-p356
Apache Geronimo, ËùÓа汾
Apache Tomcat <= 5.5.34, <= 6.0.34, <= 7.0.22
Oracle Glassfish <= 3.1.1
Jetty, ËùÓа汾
Plone, ËùÓа汾
Rack, ËùÓа汾
V8 JavaScript Engine, ËùÓа汾
²»ÊÜ´ËÓ°ÏìµÄÓïÑÔ»òÕßÐÞ¸´°æ±¾µÄÓïÑÔÓÐ::
PHP >= 5.3.9, >= 5.4.0RC4
JRuby >= 1.6.5.1
Ruby >= 1.8.7-p357, 1.9.x
Apache Tomcat >= 5.5.35, >= 6.0.35, >= 7.0.23
Oracle Glassfish, N/A (Oracle reports that the issue is fixed in the main codeline and scheduled for a future CPU)
CVE: CVE-2011-4885 (PHP), CVE-2011-4461 (Jetty), CVE-2011-4838 (JRuby), CVE-2011-4462 (Plone), CVE-2011-4815 (Ruby)
ÍƼöÐÅÏ¢
- ¡¾ÊÓƵ²¥·Å¡¿JplayerÊÓƵ²¥·ÅÆ÷µÄʹÓÃ
- memcacheÄÚ´æÔÀí
- Memcache¼¼Êõ·ÖÏí£º½éÉÜ¡¢Ê¹Óᢴ洢¡¢Ëã·¨¡¢ÓÅ»¯....
- php³£ÓÃÕýÔò±í´ïʽ
- phpÐÔÄܼà²âÄ£¿éXHProf
- ÈÃCI¿ò¼ÜÖ§³Öservice²ã
- ʹÓÃPHPÉú³É´øLOGOµÄ¸öÐÔ»¯¶þάÂëͼÏñ
- ¹ØÓÚCodeIgniterÄã¿ÉÄܲ»ÖªµÀµÄ5¸ö֪ʶµã
- Memcache ºÁÃ뼶³¬Ê±¼°ÆäËû³£¼ûÎÊÌâ»ã×Ü
- [PHP±Ê¼Ç]PHPQueryÒ»¸ö´¦ÀíDOMµÄÀûÆ÷
ÈÈÃÅÐÅÏ¢
- nohup: redirecting stderr to stdou....
- ʹÓÃlog_formatΪNginx·þÎñÆ÷ÉèÖøüÏêϸµÄÈÕÖ¾¸ñʽ
- jquery easyUI--dataGrid-Json
- [Ô´´]·ÂGoogle Reader¡¢ÐÂÀË΢²©¡¢ÌÚѶ΢²©µ....
- ÀûÓÃKeepalived+mysql¹¹½¨¸ß¿ÉÓÃMySQLË«Ö÷×Ô¶....
- Nginx+keepalivedʵÏÖ¸ºÔؾùºâºÍË«»úÈȱ¸¸ß¿ÉÓÃ
- jqueryʵÏÖÒ³Ãæ¼ÓÔؽø¶ÈÌõ
- Rolling cURL: PHP²¢·¢×î¼Ñʵ¼ù
- codeigniter ·ÓÉÖÕ¼«ÓÅ»¯(url rewrite)
- linuxÏÂÉèÖÃsshÎÞÃÜÂëµÇ¼
×î½ü¸üÐÂ
- PHP»ñÈ¡Óû§µÄÕæʵIP£¬²¢ÅжÏÊÇ·ñÄÚÍøIP
- PHP ´íÎóÈÕÖ¾ error_log
- ÀûÓÃbigpipe»úÖÆʵÏÖÒ³ÃæÄ£¿éµÄÒì²½äÖȾ chunked¼¼Êõ
- php¿ØÖÆÎļþÏÂÔØËÙ¶È
- js + php ¶ÁÈ¡¡¢²¥·ÅÊÓƵÁ÷ ¼æÈÝfirefox£¬c....
- ¡¾ÊÓƵ²¥·Å¡¿JplayerÊÓƵ²¥·ÅÆ÷µÄʹÓÃ
- UNICODE Óë UTF-8 µÄ¹Øϵ
- memcacheÄÚ´æÔÀí
- Memcache¼¼Êõ·ÖÏí£º½éÉÜ¡¢Ê¹Óᢴ洢¡¢Ëã·¨¡¢ÓÅ»¯....
- phpʹÓÃmb_detect_encoding¼ì²â×Ö·û´®±àÂë
ÆÀÂÛ