Welcome! Log In Create A New Profile

Advanced

Re: Is nginx vulnerable to the Hash Table Vulnerability (n.runs AG)?

Justin Hart
January 01, 2012 01:00AM
Thank you for the confirmation - I read through the parts of code in
question but wanted to get a second opinion.

How about the lua and/or the perl modules? It looks as if they are
using the nginx functions?

Sent from my iPhone

On Dec 31, 2011, at 10:54 PM, agentzh <agentzh@gmail.com> wrote:

> On Sun, Jan 1, 2012 at 2:37 AM, Justin Hart <onyxraven@gmail.com> wrote:
>> http://www.securityweek.com/hash-table-collision-attacks-could-trigger-ddos-massive-scale
>>
>> Without going through the way nginx parses an incoming request, I'm unsure
>> if nginx isn't vulnerable to this, because of the availability to grab the
>> value of a GET parameter
>> via http://wiki.nginx.org/HttpCoreModule#.24arg_PARAMETER. My hope is that
>> especially if an $arg_PARAMETER isn't used in the config, it is not
>> vulnerable because it wouldn't even attempt to parse the parameters, but I
>> can't be sure.
>>
>
> Well, the $arg_PARAMETER variable is not implemented with hash tables
> at all ;) It scans the URI query string at every invocation :)
>
> Regards,
> -agentzh
>
> _______________________________________________
> nginx mailing list
> nginx@nginx.org
> http://mailman.nginx.org/mailman/listinfo/nginx

_______________________________________________
nginx mailing list
nginx@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx
Subject Author Posted

Is nginx vulnerable to the Hash Table Vulnerability (n.runs AG)?

Justin Hart December 31, 2011 01:40PM

Re: Is nginx vulnerable to the Hash Table Vulnerability (n.runs AG)?

Maxim Dounin December 31, 2011 07:36PM

Re: Is nginx vulnerable to the Hash Table Vulnerability (n.runs AG)?

agentzh January 01, 2012 12:56AM

Re: Is nginx vulnerable to the Hash Table Vulnerability (n.runs AG)?

Justin Hart January 01, 2012 01:00AM

Re: Is nginx vulnerable to the Hash Table Vulnerability (n.runs AG)?

agentzh January 01, 2012 09:22AM

Re: Is nginx vulnerable to the Hash Table Vulnerability (n.runs AG)?

Nginx User January 01, 2012 09:32AM

Re: Is nginx vulnerable to the Hash Table Vulnerability (n.runs AG)?

Sergey A. Osokin January 01, 2012 01:40PM

Re: Is nginx vulnerable to the Hash Table Vulnerability (n.runs AG)?

agentzh January 04, 2012 06:50AM

Re: Is nginx vulnerable to the Hash Table Vulnerability (n.runs AG)?

Nginx User January 04, 2012 03:04PM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 200
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready