代码之家  ›  专栏  ›  技术社区  ›  Display Name Camilo Terevinto

为什么Scott Guthrie建议我们在睡眠中使用一个随机的,小的睡眠延迟错误.aspx?

  •  8
  • Display Name Camilo Terevinto  · 技术社区  · 16 年前

    我不明白,一个随机的,小的睡眠延迟怎么能成为阻止攻击者探测我们网站的解决方案。

    这是他的代码片段:

    <%@ Page Language="C#" AutoEventWireup="true" %>
    <%@ Import Namespace="System.Security.Cryptography" %>
    <%@ Import Namespace="System.Threading" %>
    
    <script runat="server">
    void Page_Load() {
      byte[] delay = new byte[1];
      RandomNumberGenerator prng = new RNGCryptoServiceProvider();
    
      prng.GetBytes(delay);
      Thread.Sleep((int)delay[0]);
    
      IDisposable disposable = prng as IDisposable;
      if (disposable != null) { disposable.Dispose(); }
    }
    </script>
    
    <html>
    <head runat="server">
    <title>Error</title>
    </head>
    <body>
    <div>
        An error occurred while processing your request.
    </div>
    </body>
    </html>
    
    2 回复  |  直到 15 年前
        1
  •  6
  •   Alex    16 年前

    这是为了防止人们不断触发你的错误页面和利用 the recent ASP.NET vulnerability . 他们需要大量的失败才能利用这个漏洞。

    睡眠延迟不会“阻止”访问您的页面。可以把它看作是一个类似于强制输入密码的过程;如果你必须在两次猜测之间等待5秒而不是5秒,那么你将需要更多的时间来找到密码。

        2
  •  4
  •   icedtoast    16 年前

    简单来说,漏洞就是猜测一个很长的密码。(这是用来加密会话状态的密钥吗?)

       bool checkPassword(string userInput)
       {
          for(int index = 0; index < password.length; index++)
          {
            if(userInput[index] != password[index]) {
                 return false;
            }
          }
    
          return true;
       }
    

    这将允许对密码算法进行定时攻击,因为您可以一次检查一个字符,因为它花费的时间越长,您的密码越正确。例如。 假设密码是“carrots”

    有关更多信息,请参阅:

    http://en.wikipedia.org/wiki/Timing_attack

    推荐文章