long-string-attack

1 article
sort: new top best
clear filter
0 6/10
vulnerability

An application-level denial-of-service vulnerability exploitable by sending excessively long strings (100,000+ characters) to input fields, causing CPU and memory exhaustion through vulnerable string hashing implementations. The technique can be applied to password fields, usernames, email addresses, and other text inputs across authentication and search functions.

Jerry Shah HackerOne Freedium
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details