RSSAmplifier

The Fuzzing Project · Jan 10, 2017

htpasswDoS: Local Denial of Service via Apache httpd password hashes

0
Sign in to vote or save

This site does not allow itself to be embedded. You can still read it on the original site — the toolbar below keeps your place in the directory.

The way the Apache httpd web server handles password hashes can be abused by a malicious user on a server to cause resource exhaustion and denial of service of the web server. I reported this a while ago to the Apache security team - which led to a lengthy discussion where I was a bit appalled about some of the statements I got from the Apache developers. They can be summed up in a way that major…

Read on blog.fuzzing-project.org

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.

    Reading · The Fuzzing Project · RSS Amplifier