Answer the question
In order to leave comments, you need to log in
Hash collision attack in PHP
Can someone explain in a simple and understandable way what a hash collision attack is, how it manifests itself in PHP before version 5.3.9, and what it threatens?
Answer the question
In order to leave comments, you need to log in
habrahabr.ru/blogs/infosecurity/135530/
The article contains general words, and in the comments - explanations on the fingers.
This, apparently, is a kind of attack when such data is sent to the script as input, which, when parsing parameters or further processing, forms many hash function collisions. As a result, arrays containing this data start to work terribly slowly. Those. It turns out this is a kind of DoS attack. Why it threatens PHP up to version 5.3.9, I don't know. Perhaps a simple hash function was used there, to which it is easy to pick up collisions.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question