<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>DDoSInfo - Information about DDoS and Denial of Service Attacks</title>
	<atom:link href="http://www.ddosinfo.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ddosinfo.com</link>
	<description></description>
	<lastBuildDate>Mon, 06 Feb 2012 14:21:36 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Update on the Kelihos botnet</title>
		<link>http://www.ddosinfo.com/ddos-criminals/update-on-the-kelihos-botnet/</link>
		<comments>http://www.ddosinfo.com/ddos-criminals/update-on-the-kelihos-botnet/#comments</comments>
		<pubDate>Mon, 06 Feb 2012 14:21:36 +0000</pubDate>
		<dc:creator>Enurrendy</dc:creator>
				<category><![CDATA[DDoS Criminals]]></category>
		<category><![CDATA[DDoS Vendors]]></category>
		<category><![CDATA[Security Websies]]></category>
		<category><![CDATA[computers]]></category>
		<category><![CDATA[css]]></category>
		<category><![CDATA[ddos]]></category>
		<category><![CDATA[fbi]]></category>
		<category><![CDATA[kelihos]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[mac]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[podcasts]]></category>
		<category><![CDATA[preceding]]></category>
		<category><![CDATA[viral-facebook]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.ddosinfo.com/uncategorized/update-on-the-kelihos-botnet/</guid>
		<description><![CDATA[Reports that the Kelihos botnet is back online and that its original operators are again trying to take over its reigns have been premature, says Microsoft. "Contrary to some reports, Kaspersky ... <a href="http://www.ddosinfo.com/ddos-criminals/update-on-the-kelihos-botnet/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Reports that the Kelihos botnet is back online and that its original operators are again trying to take over its reigns have been premature, says Microsoft. &#8220;Contrary to some reports, Kaspersky &#8230;</p>
<p>See more here:<br />
<a target="_blank" href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/4JcIsKDkiqQ/malware_news.php" title="Update on the Kelihos botnet">Update on the Kelihos botnet</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosinfo.com/ddos-criminals/update-on-the-kelihos-botnet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Smaller DDoS attacks can be deadlier than big ones</title>
		<link>http://www.ddosinfo.com/ddos-vendors/smaller-ddos-attacks-can-be-deadlier-than-big-ones/</link>
		<comments>http://www.ddosinfo.com/ddos-vendors/smaller-ddos-attacks-can-be-deadlier-than-big-ones/#comments</comments>
		<pubDate>Mon, 06 Feb 2012 12:03:43 +0000</pubDate>
		<dc:creator>Enurrendy</dc:creator>
				<category><![CDATA[DDoS Vendors]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[budget]]></category>
		<category><![CDATA[css]]></category>
		<category><![CDATA[enterprise]]></category>
		<category><![CDATA[fbi]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[network-security]]></category>
		<category><![CDATA[validator]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.ddosinfo.com/uncategorized/smaller-ddos-attacks-can-be-deadlier-than-big-ones/</guid>
		<description><![CDATA[Contrary to conventional thinking that large bandwidth cyber attacks wreak the most damage on enterprises, security experts at Radware instead found that bigger problems usually come in small packages... <a href="http://www.ddosinfo.com/ddos-vendors/smaller-ddos-attacks-can-be-deadlier-than-big-ones/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Contrary to conventional thinking that large bandwidth cyber attacks wreak the most damage on enterprises, security experts at Radware instead found that bigger problems usually come in small packages&#8230;</p>
<p>View article:<br />
<a target="_blank" href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/AAnCILdWw9M/secworld.php" title="Smaller DDoS attacks can be deadlier than big ones">Smaller DDoS attacks can be deadlier than big ones</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosinfo.com/ddos-vendors/smaller-ddos-attacks-can-be-deadlier-than-big-ones/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Kelihos botnet rises up again</title>
		<link>http://www.ddosinfo.com/ddos-criminals/kelihos-botnet-rises-up-again/</link>
		<comments>http://www.ddosinfo.com/ddos-criminals/kelihos-botnet-rises-up-again/#comments</comments>
		<pubDate>Fri, 03 Feb 2012 14:13:08 +0000</pubDate>
		<dc:creator>Enurrendy</dc:creator>
				<category><![CDATA[DDoS Criminals]]></category>
		<category><![CDATA[DDoS Vendors]]></category>
		<category><![CDATA[Security Websies]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[ddos]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[fbi]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[network-warrior]]></category>
		<category><![CDATA[podcasts]]></category>
		<category><![CDATA[ros]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.ddosinfo.com/uncategorized/kelihos-botnet-rises-up-again/</guid>
		<description><![CDATA[Kelihos - the botnet whose operation was disrupted last September by Microsoft and Kaspersky Lab by shutting down its C&#038;C servers and making its bots contact a sinkhole instead - is back and working. ... <a href="http://www.ddosinfo.com/ddos-criminals/kelihos-botnet-rises-up-again/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Kelihos &#8211; the botnet whose operation was disrupted last September by Microsoft and Kaspersky Lab by shutting down its C&#038;C servers and making its bots contact a sinkhole instead &#8211; is back and working. &#8230;</p>
<p>Read More:<br />
<a target="_blank" href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/gMDGQtc21ic/malware_news.php" title="Kelihos botnet rises up again">Kelihos botnet rises up again</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosinfo.com/ddos-criminals/kelihos-botnet-rises-up-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Detecting the DNS Changer malware</title>
		<link>http://www.ddosinfo.com/ddos-criminals/detecting-the-dns-changer-malware/</link>
		<comments>http://www.ddosinfo.com/ddos-criminals/detecting-the-dns-changer-malware/#comments</comments>
		<pubDate>Wed, 01 Feb 2012 15:17:56 +0000</pubDate>
		<dc:creator>Enurrendy</dc:creator>
				<category><![CDATA[DDoS Criminals]]></category>
		<category><![CDATA[Security Websies]]></category>
		<category><![CDATA[dcwg]]></category>
		<category><![CDATA[ddos]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[ros]]></category>
		<category><![CDATA[servers]]></category>
		<category><![CDATA[validator]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.ddosinfo.com/uncategorized/detecting-the-dns-changer-malware/</guid>
		<description><![CDATA[January marked half-time for the folks at the DNS Changer Working Group (DCWG) who are now running the DNS servers originally used in the Rove botnet. Ever since a multi-national task force dismantled... <a href="http://www.ddosinfo.com/ddos-criminals/detecting-the-dns-changer-malware/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>January marked half-time for the folks at the DNS Changer Working Group (DCWG) who are now running the DNS servers originally used in the Rove botnet. Ever since a multi-national task force dismantled&#8230;</p>
<p>See original article:<br />
<a target="_blank" href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/GCh2lHNhm_c/malware_news.php" title="Detecting the DNS Changer malware">Detecting the DNS Changer malware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosinfo.com/ddos-criminals/detecting-the-dns-changer-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Botnet suspect denies involvement</title>
		<link>http://www.ddosinfo.com/ddos-news/botnet-suspect-denies-involvement/</link>
		<comments>http://www.ddosinfo.com/ddos-news/botnet-suspect-denies-involvement/#comments</comments>
		<pubDate>Fri, 27 Jan 2012 18:55:03 +0000</pubDate>
		<dc:creator>Enurrendy</dc:creator>
				<category><![CDATA[DDoS News]]></category>
		<category><![CDATA[DDoS Vendors]]></category>
		<category><![CDATA[absolutely-not]]></category>
		<category><![CDATA[behind-the-kelihos]]></category>
		<category><![CDATA[being-behind]]></category>
		<category><![CDATA[botnet-attack]]></category>
		<category><![CDATA[ddos]]></category>
		<category><![CDATA[ddos news]]></category>
		<category><![CDATA[kelihos]]></category>
		<category><![CDATA[man-accused]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[russian]]></category>

		<guid isPermaLink="false">http://www.ddosinfo.com/uncategorized/botnet-suspect-denies-involvement/</guid>
		<description><![CDATA[The Russian man accused by Microsoft of being behind the Kelihos botnet attack insists he is "absolutely not guilty". <a href="http://www.ddosinfo.com/ddos-news/botnet-suspect-denies-involvement/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p> The Russian man accused by Microsoft of being behind the Kelihos botnet attack insists he is &#8220;absolutely not guilty&#8221;.</p>
<p>Read more here:<br />
<a target="_blank" href="http://www.bbc.co.uk/go/rss/int/news/-/news/technology-16757150" title="Botnet suspect denies involvement">Botnet suspect denies involvement</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosinfo.com/ddos-news/botnet-suspect-denies-involvement/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hacker allegedly leaks 100K Facebook account credentials of Arab users</title>
		<link>http://www.ddosinfo.com/ddos-vendors/hacker-allegedly-leaks-100k-facebook-account-credentials-of-arab-users/</link>
		<comments>http://www.ddosinfo.com/ddos-vendors/hacker-allegedly-leaks-100k-facebook-account-credentials-of-arab-users/#comments</comments>
		<pubDate>Tue, 24 Jan 2012 15:44:41 +0000</pubDate>
		<dc:creator>Enurrendy</dc:creator>
				<category><![CDATA[DDoS Vendors]]></category>
		<category><![CDATA[Security Websies]]></category>
		<category><![CDATA[economics]]></category>
		<category><![CDATA[french]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[mac]]></category>
		<category><![CDATA[podcasts]]></category>
		<category><![CDATA[ros]]></category>
		<category><![CDATA[validator]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.ddosinfo.com/uncategorized/hacker-allegedly-leaks-100k-facebook-account-credentials-of-arab-users/</guid>
		<description><![CDATA[The slew of hacks, leaks of credit card information, DDoS attacks and defacements executed by Arab and Israeli hackers that transferred part of the longstanding, real world conflict to the Internet ha... <a href="http://www.ddosinfo.com/ddos-vendors/hacker-allegedly-leaks-100k-facebook-account-credentials-of-arab-users/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>The slew of hacks, leaks of credit card information, DDoS attacks and defacements executed by Arab and Israeli hackers that transferred part of the longstanding, real world conflict to the Internet ha&#8230;</p>
<p>Read More:<br />
<a target="_blank" href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/N7BmpjFksPw/secworld.php" title="Hacker allegedly leaks 100K Facebook account credentials of Arab users">Hacker allegedly leaks 100K Facebook account credentials of Arab users</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosinfo.com/ddos-vendors/hacker-allegedly-leaks-100k-facebook-account-credentials-of-arab-users/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft names botnet &#8216;suspect&#8217;</title>
		<link>http://www.ddosinfo.com/security-websies/microsoft-names-botnet-suspect/</link>
		<comments>http://www.ddosinfo.com/security-websies/microsoft-names-botnet-suspect/#comments</comments>
		<pubDate>Tue, 24 Jan 2012 13:04:43 +0000</pubDate>
		<dc:creator>Enurrendy</dc:creator>
				<category><![CDATA[Security Websies]]></category>
		<category><![CDATA[ddos]]></category>
		<category><![CDATA[ddos news]]></category>
		<category><![CDATA[illegal-botnet]]></category>
		<category><![CDATA[russian]]></category>
		<category><![CDATA[said-it-suspects]]></category>

		<guid isPermaLink="false">http://www.ddosinfo.com/uncategorized/microsoft-names-botnet-suspect/</guid>
		<description><![CDATA[Microsoft said it suspects a former Russian antivirus company employee is behind an illegal botnet operation. <a href="http://www.ddosinfo.com/security-websies/microsoft-names-botnet-suspect/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p> Microsoft said it suspects a former Russian antivirus company employee is behind an illegal botnet operation.</p>
<p>More here:<br />
<a target="_blank" href="http://www.bbc.co.uk/go/rss/int/news/-/news/technology-16700192" title="Microsoft names botnet 'suspect'">Microsoft names botnet &#8216;suspect&#8217;</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosinfo.com/security-websies/microsoft-names-botnet-suspect/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Kelihos malware author, botnet herder named by Microsoft</title>
		<link>http://www.ddosinfo.com/ddos-news/kelihos-malware-author-botnet-herder-named-by-microsoft/</link>
		<comments>http://www.ddosinfo.com/ddos-news/kelihos-malware-author-botnet-herder-named-by-microsoft/#comments</comments>
		<pubDate>Tue, 24 Jan 2012 11:33:42 +0000</pubDate>
		<dc:creator>Enurrendy</dc:creator>
				<category><![CDATA[DDoS News]]></category>
		<category><![CDATA[DDoS Vendors]]></category>
		<category><![CDATA[Security Websies]]></category>
		<category><![CDATA[css]]></category>
		<category><![CDATA[ddos]]></category>
		<category><![CDATA[ddos news]]></category>
		<category><![CDATA[economics]]></category>
		<category><![CDATA[french]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[kelihos]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[mac]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[podcasts]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.ddosinfo.com/uncategorized/kelihos-malware-author-botnet-herder-named-by-microsoft/</guid>
		<description><![CDATA[Microsoft has named a new defendant in the ongoing Kelihos case. His name is Andrey N. Sabelnikov, of St. Petersburg, Russian Federation, and is believed to have written the code for and either cr... <a href="http://www.ddosinfo.com/ddos-news/kelihos-malware-author-botnet-herder-named-by-microsoft/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Microsoft has named a new defendant in the ongoing Kelihos case. His name is Andrey N. Sabelnikov, of St. Petersburg, Russian Federation, and is believed to have written the code for and either cr&#8230;</p>
<p>Link:<br />
<a target="_blank" href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/xJroAJ3Mw5k/malware_news.php" title="Kelihos malware author, botnet herder named by Microsoft">Kelihos malware author, botnet herder named by Microsoft</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosinfo.com/ddos-news/kelihos-malware-author-botnet-herder-named-by-microsoft/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tool used in Anonymous Megaupload campaign</title>
		<link>http://www.ddosinfo.com/security-websies/tool-used-in-anonymous-megaupload-campaign/</link>
		<comments>http://www.ddosinfo.com/security-websies/tool-used-in-anonymous-megaupload-campaign/#comments</comments>
		<pubDate>Mon, 23 Jan 2012 10:18:51 +0000</pubDate>
		<dc:creator>Enurrendy</dc:creator>
				<category><![CDATA[Security Websies]]></category>
		<category><![CDATA[advisories]]></category>
		<category><![CDATA[brazil]]></category>
		<category><![CDATA[ddos]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[mac]]></category>
		<category><![CDATA[podcasts]]></category>
		<category><![CDATA[preceding]]></category>
		<category><![CDATA[ros]]></category>

		<guid isPermaLink="false">http://www.ddosinfo.com/uncategorized/tool-used-in-anonymous-megaupload-campaign/</guid>
		<description><![CDATA[Once again, Anonymous is using the low orbit ion canon (LOIC) to DDoS websites. This tool was developed by white hat hackers to stress test websites. Not surprisingly, the tool they are using is ex... <a href="http://www.ddosinfo.com/security-websies/tool-used-in-anonymous-megaupload-campaign/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Once again, Anonymous is using the low orbit ion canon (LOIC) to DDoS websites. This tool was developed by white hat hackers to stress test websites. Not surprisingly, the tool they are using is ex&#8230;</p>
<p>See the article here:<br />
<a target="_blank" href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/uDNZWtY_XrE/secworld.php" title="Tool used in Anonymous Megaupload campaign">Tool used in Anonymous Megaupload campaign</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosinfo.com/security-websies/tool-used-in-anonymous-megaupload-campaign/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Major Denial of Service Vulnerability Affects Most Web Servers</title>
		<link>http://www.ddosinfo.com/uncategorized/major-denial-of-service-vulnerability-affects-most-web-servers/</link>
		<comments>http://www.ddosinfo.com/uncategorized/major-denial-of-service-vulnerability-affects-most-web-servers/#comments</comments>
		<pubDate>Wed, 04 Jan 2012 05:07:00 +0000</pubDate>
		<dc:creator>Enurrendy</dc:creator>
				<category><![CDATA[DDoS News]]></category>
		<category><![CDATA[DDoS Vendors]]></category>
		<category><![CDATA[Security Websies]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[ddos news]]></category>
		<category><![CDATA[return-decode]]></category>

		<guid isPermaLink="false">http://www.ddosinfo.com/uncategorized/major-denial-of-service-vulnerability-affects-most-web-servers/</guid>
		<description><![CDATA[ Security researcher Alexander Klink and Julian Wälde revealed a serious vulnerability that until recently affected the vast majority of web server. The attack only requires a single HTTP request that is specially designed to create hash code collisions in POST form data. When first discovered this attack affected Python, Ruby, PHP, Java, and ASP.NET, but vendors have been working with the researchers to produce patches. Tomcat  updates 7.0.23 and 6.0.35 address this issue by limiting the number of POST form fields to 10,000. The  change log  says that this is configurable, but no details were provided. The patch for  ASP.NET  was released on December 29. The patch will be automatically applied for Windows Azure customers with the default servicing policy. The patch works by limiting the number of POST form fields in a single request to 1,000, which is well below the number needed for a denial of service attack.  This value is configurable  using the appSettings key “aspnet:MaxHttpCollectionKeys”. Currently this can only be applied site-wide, but there have been requests for page-specific overrides. A fix was also added for related flaws in the JSON input and deserialization logic. PHP  5.4.0, which is only a release candidate also offers a max_input_vars directive. The  release notes  do not state what the default value is. So far every vendor we’ve discussed has addressed the issue at the web server level by limiting the number of fields in a single request. Another option is the use of a randomized hash code formula for strings.  Ruby  is one such language. .NET does this as well, but only for internal builds. Production releases currently have a set formula, but given the severity of this issue that may change the next time the CLR is updated. For Java it is not quite so easy; the JVM specifies the hash code formula for strings, which means developers may be relying on it to be consistent across all versions. An update for  Oracle Glassfish  is supposedly complete, but not yet available. There is no information of the method used to address the issue. More information about this issue is available on  Ars Technica  and the  Chaos Communication Congress  website.  <a href="http://www.ddosinfo.com/uncategorized/major-denial-of-service-vulnerability-affects-most-web-servers/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p> Security researcher Alexander Klink and Julian Wälde revealed a serious vulnerability that until recently affected the vast majority of web server. The attack only requires a single HTTP request that is specially designed to create hash code collisions in POST form data. When first discovered this attack affected Python, Ruby, PHP, Java, and ASP.NET, but vendors have been working with the researchers to produce patches. Tomcat  updates 7.0.23 and 6.0.35 address this issue by limiting the number of POST form fields to 10,000. The  change log  says that this is configurable, but no details were provided. The patch for  ASP.NET  was released on December 29. The patch will be automatically applied for Windows Azure customers with the default servicing policy. The patch works by limiting the number of POST form fields in a single request to 1,000, which is well below the number needed for a denial of service attack.  This value is configurable  using the appSettings key “aspnet:MaxHttpCollectionKeys”. Currently this can only be applied site-wide, but there have been requests for page-specific overrides. A fix was also added for related flaws in the JSON input and deserialization logic. PHP  5.4.0, which is only a release candidate also offers a max_input_vars directive. The  release notes  do not state what the default value is. So far every vendor we’ve discussed has addressed the issue at the web server level by limiting the number of fields in a single request. Another option is the use of a randomized hash code formula for strings.  Ruby  is one such language. .NET does this as well, but only for internal builds. Production releases currently have a set formula, but given the severity of this issue that may change the next time the CLR is updated. For Java it is not quite so easy; the JVM specifies the hash code formula for strings, which means developers may be relying on it to be consistent across all versions. An update for  Oracle Glassfish  is supposedly complete, but not yet available. There is no information of the method used to address the issue. More information about this issue is available on  Ars Technica  and the  Chaos Communication Congress  website. </p>
<p>Excerpt from:<br />
<a target="_blank" href="http://www.ddosattacks.net/2012/01/04/major-denial-of-service-vulnerability-affects-most-web-servers/" title="Major Denial of Service Vulnerability Affects Most Web Servers">Major Denial of Service Vulnerability Affects Most Web Servers</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosinfo.com/uncategorized/major-denial-of-service-vulnerability-affects-most-web-servers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

