Re: [W3af-develop] [W3af-users] Regular expression DoS

2012-08-02 Thread Andres Riancho
Got it :) Thanks to Shay Chen for pointing me in the right direction. http://www.youtube.com/watch?v=3k_eJ1bcCro&feature=plcp Now all I need to do is install the puzzlemall in the latest moth. On Thu, Aug 2, 2012 at 11:02 AM, Achim Hoffmann wrote: > Note that the OWASP page [1] (see below) is ju

Re: [W3af-develop] [W3af-users] Regular expression DoS

2012-08-02 Thread Achim Hoffmann
Note that the OWASP page [1] (see below) is just an excerpt of Adar's original paper. http://www.checkmarx.com/white_papers/redos-regular-expression-denial-of-service/ Andrés, I don't have a solution for python, but you can use the regex and patterns as described in https://github.com/E

Re: [W3af-develop] [W3af-users] Regular expression DoS

2012-08-02 Thread Andres Riancho
Carlos, On Wed, Aug 1, 2012 at 10:04 PM, Carlos Pantelides wrote: > Andres: > > I'm in the oven, I'll try to read the links and make something up. > Meanwhile, what are you asking for is a language or library that suffers for > this kind of vulnerability, aren't you? > > I did not try the javascr

Re: [W3af-develop] [W3af-users] Regular expression DoS

2012-08-02 Thread Carlos Pantelides
Andres: I'm in the oven, I'll try to read the links and make something up. Meanwhile, what are you asking for is a language or library that suffers for this kind of vulnerability, aren't you? I did not try the javascript code [1], isn't what are you asking for? Carlos Pantelides @dev4sec