[ https://issues.apache.org/jira/browse/TS-1030?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13156480#comment-13156480 ]
weijin commented on TS-1030: ---------------------------- the function hdrtoken_tokenize should check the content of string equality rather than just check the hash and string length. Maybe someone can give us a perfect hash for it. @Leif, @John > hash collation in hdrtoken_hash > ------------------------------- > > Key: TS-1030 > URL: https://issues.apache.org/jira/browse/TS-1030 > Project: Traffic Server > Issue Type: Bug > Components: HTTP > Affects Versions: 3.1.2, 3.0.1 > Reporter: Zhao Yongming > Priority: Critical > > we have find out a 3 characters collation: > SPX == PUT > that will crash TS, we need to take more care of those hash, or bad guys may > put some magic headers and crash all TS in your production, that is the most > powerful DOS -- This message is automatically generated by JIRA. If you think it was sent incorrectly, please contact your JIRA administrators: https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa For more information on JIRA, see: http://www.atlassian.com/software/jira