[ 
https://issues.apache.org/jira/browse/TS-1030?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13156480#comment-13156480
 ] 

weijin commented on TS-1030:
----------------------------

the function hdrtoken_tokenize should check the content of string equality 
rather than just check the hash and string length. Maybe someone can give us a 
perfect hash for it.
@Leif, @John
                
> hash collation in hdrtoken_hash
> -------------------------------
>
>                 Key: TS-1030
>                 URL: https://issues.apache.org/jira/browse/TS-1030
>             Project: Traffic Server
>          Issue Type: Bug
>          Components: HTTP
>    Affects Versions: 3.1.2, 3.0.1
>            Reporter: Zhao Yongming
>            Priority: Critical
>
> we have find out a 3 characters collation:
> SPX == PUT
> that will crash TS, we need to take more care of those hash, or bad guys may 
> put some magic headers and crash all TS in your production, that is the most 
> powerful DOS

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators: 
https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

Reply via email to