What Is Billion Laughs Attack?
In Computer Security, a Billion Laughs Attack Is a Type of Denial-of-Service (Dos) Attack Which Is Aimed at Parsers of Xml Documents. It Is Also Referred to as...
In computer security, a billion laughs attack is a type of denial-of-service (DoS) attack which is aimed at parsers of XML documents. It is also referred to as an XML bomb or as an exponential entity expansion attack.
What is an XML bomb?
An XML bomb is a message composed and sent with the intent of overloading an XML parser (typically HTTP server). XML bombs exploit the fact that XML allows defining of entities. For example, let entityOne be defined as of 20 entityTwo's, which themselves are defined as 20 entityThree's.
Must Read
What is quadratic blowup?
An XML quadratic blowup attack is similar to a Billion Laughs attack. Essentially, it exploits the use of entity expansion. Instead of deferring to the use of nested entities, it replicates one large entity using a couple thousand characters repeatedly.