python / python/cpython

urllib http client vulnerable to DOS attack

Đang mở
#89,953 12 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

3.10 3.11 3.12 stdlib type-feature
Ngôn ngữ chính
Python
Star
77.2k
Fork
36k
Chỉ số merge pull request
Chỉ số pull request đang chờ

Mô tả

BPO 45795
Nosy @orsenthil, @tiran, @blind-intruder
Files
  • server.py: server.py file to start a evil server
  • max_time.png
  • curl.png
  • Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.

    Show more details

    GitHub fields:

    assignee = None
    closed_at = None
    created_at = <Date 2021-11-12.15:55:25.359>
    labels = ['type-security', 'library', '3.10']
    title = 'urllib http client vulnerable to DOS attack'
    updated_at = <Date 2021-11-26.16:05:09.328>
    user = 'https://github.com/blind-intruder'
    

    bugs.python.org fields:

    activity = <Date 2021-11-26.16:05:09.328>
    actor = 'orsenthil'
    assignee = 'none'
    closed = False
    closed_date = None
    closer = None
    components = ['Library (Lib)']
    creation = <Date 2021-11-12.15:55:25.359>
    creator = 'haqsek2'
    dependencies = []
    files = ['50436', '50448', '50449']
    hgrepos = []
    issue_num = 45795
    keywords = []
    message_count = 10.0
    messages = ['406220', '406349', '406519', '406531', '406532', '406537', '406543', '406556', '407047', '407061']
    nosy_count = 3.0
    nosy_names = ['orsenthil', 'christian.heimes', 'haqsek2']
    pr_nums = []
    priority = 'normal'
    resolution = None
    stage = None
    status = 'open'
    superseder = None
    type = 'security'
    url = 'https://bugs.python.org/issue45795'
    versions = ['Python 3.10']
    

    Hướng dẫn đóng góp

    Mở hướng dẫn đóng góp

    Bắt đầu từ đâu

    1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
    2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
    3. Fork repository và làm thay đổi trên một nhánh.
    4. Mở pull request có tham chiếu số hiệu của issue.

    Hướng nghiên cứu

    Bắt đầu với bản tái hiện server.py đã tải lên và hành vi của HTTP client urllib mà nó nhắm tới; issue cũng bao gồm max_time.png và curl.png dưới dạng các kết quả quan sát được. Xác định đường đi xử lý request dễ bị tấn công và xác minh rằng kịch bản evil-server được cung cấp không còn gây ra tình trạng từ chối dịch vụ.

    Do mô hình lập chỉ mục viết ra từ nội dung của issue.

    Đánh giá

    Công nghệ
    python
    Lĩnh vực
    networking, security
    Loại issue
    Lỗi
    Độ khó
    4/5
    Thời gian dự kiến
    3-5 ngày
    Mức độ hoạt động
    Đình trệ
    Độ rõ ràng
    Cần làm rõ
    Mức phù hợp với người mới
    25/100

    Nhận issue mới trong hộp thư của bạn

    Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.