+ All Categories
Home > Software > Application-level Denial of Service

Application-level Denial of Service

Date post: 22-Jan-2017
Category:
Upload: vladimir-garbuz
View: 98 times
Download: 0 times
Share this document with a friend
21
Vladimir Garbuz FILLING THE VOID: Application-level DoS
Transcript

Vladimir Garbuz

FILLING THE VOID:Application-level DoS

fear the XML: billion laughs

fear the XML: oversized XXE

fear the XML: soap arrays

fear the XML: too much to handle

fear the XML: large soap for DOM parsers

fear the XML: xslt processing

fear the XML: signatures - many, xslt

fear the XML: signatures – RetrievalMethod

fear the XML: signatures/encryption reference

fear the XML: nested encryption

processing oversized data

REDoS – catastrophic backtracking

complex operations – look-alike, globbing, etc

logic fuckups – multiple sorting, grouping, etc

zero-bytes in input

unpacking: recursion

unpacking: large low-entropy data

heavy functionality invokation

slow HTTP

Questions and Discussion


Recommended