Re: [CODE4LIB] Hash table vulnerability - PHP solution

2011-12-30 Thread Peter Murray
Thanks for pointing this out! This one hadn't crossed my radar screen yet. It sounds particularly nasty. Peter On Dec 30, 2011, at 9:59 AM, Yitzchak Schaffer wrote: > Hi all, > > In case y'all haven't heard, there's this mega-evil hash table DDoS > domesday thing? Right. The NY PHP list poi

[CODE4LIB] Hash table vulnerability - PHP solution

2011-12-30 Thread Yitzchak Schaffer
Hi all, In case y'all haven't heard, there's this mega-evil hash table DDoS domesday thing? Right. The NY PHP list pointed out that the problem can be handled deftly on PHP servers by using the Suhosin extension (not the patch) with the suhosin.request.max_vars setting (default should work).