OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.


Help: OASIS Mailing Lists Help | MarkMail Help



   Re: [xml-dev] SAX characters event and external entities

[ Lists Home | Date Index | Thread Index ]

>Here's an easy attack -- send you a start tag, then just keep sending
>random alphanumeric characters until your system chokes.  An arbitrary
>limit -- even a very high one, like a few gigabytes -- would be useful.

This seems like the wrong level to deal with it.  If your worry is
memory use, limit memory use, not the length of element names.  Either
use the operating system's facilities for limiting memory, or have a
special purpose allocator.  (Or is that too difficult in languages like

I had to address this in my on-line validator, and did it by using
unix's memory and cpu time limits.

-- Richard


News | XML in Industry | Calendar | XML Registry
Marketplace | Resources | MyXML.org | Sponsors | Privacy Statement

Copyright 2001 XML.org. This site is hosted by OASIS