Not logged in
Log in now
Create an account
Subscribe to LWN
Recent Features
LWN.net Weekly Edition for May 23, 2013
An "enum" for Python 3
An unexpected perf feature
LWN.net Weekly Edition for May 16, 2013
A look at the PyPy 2.0 release
The hash complexity attack
Posted Apr 12, 2012 14:44 UTC (Thu) by intgr (subscriber, #39733) [Link]
There was a recent report about how this affects most major web frameworks: http://www.infosecisland.com/blogview/19160-US-CERT-Hash-... http://www.nruns.com/_downloads/advisory28122011.pdf
The figure for Python (Zope+Plone) was 7 minutes of parsing for 1MB of POST data, or 20 kbit/s bandwidth to keep 1 CPU core busy.
Copyright © 2013, Eklektix, Inc. Comments and public postings are copyrighted by their creators. Linux is a registered trademark of Linus Torvalds