The Fuzzing Project · Jan 10, 2017
htpasswDoS: Local Denial of Service via Apache httpd password hashes
0Sign in to vote or save
This site does not allow itself to be embedded. You can still read it on the original site — the toolbar below keeps your place in the directory.
The way the Apache httpd web server handles password hashes can be abused by a malicious user on a server to cause resource exhaustion and denial of service of the web server. I reported this a while ago to the Apache security team - which led to a lengthy discussion where I was a bit appalled about some of the statements I got from the Apache developers. They can be summed up in a way that major…
Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.