6 ms·
> but unless you're defending against some sort of denial of service attack, in practice it rarely matters. That "rarely" contains most sites/webservices. Befo
by Good4boothee 6d ago
> but unless you're defending against some sort of denial of service attack, in practice it rarely matters.
That "rarely" contains most sites/webservices. Before programming languages started defending against it by applying randomization (and sometimes replacing degraded maps/buckets with treemaps) it was a real threat. I remember people were able to trigger DoS either by specially crafted query string params or HTTP headers. After all both are shoved into some kind of map by frameworks, before request is even passed to application code.