62 <p>The background for this project is that some regular expressions are |
62 <p>The background for this project is that some regular expressions are |
63 “<A HREF="http://en.wikipedia.org/wiki/ReDoS#Examples">evil</A>” |
63 “<A HREF="http://en.wikipedia.org/wiki/ReDoS#Examples">evil</A>” |
64 and can “stab you in the back” according to |
64 and can “stab you in the back” according to |
65 this <A HREF="http://tech.blog.cueup.com/regular-expressions-will-stab-you-in-the-back">blog post</A>. |
65 this <A HREF="http://tech.blog.cueup.com/regular-expressions-will-stab-you-in-the-back">blog post</A>. |
66 For example, if you use in <A HREF="http://www.python.org">Python</A> or |
66 For example, if you use in <A HREF="http://www.python.org">Python</A> or |
67 in <A HREF="http://www.ruby-lang.org/en/">Ruby</A> (probably also in other mainstream programming languages) the |
67 in <A HREF="http://www.ruby-lang.org/en/">Ruby</A> (probably also other mainstream programming languages) the |
68 innocently looking regular expression <code>a?{28}a{28}</code> and match it, say, against the string |
68 innocently looking regular expression <code>a?{28}a{28}</code> and match it, say, against the string |
69 <code>aaaaaaaaaaaaaaaaaaaaaaaaaaaa</code> (that is 28 <code>a</code>s), you will soon notice that your CPU usage goes to 100%. In fact, |
69 <code>aaaaaaaaaaaaaaaaaaaaaaaaaaaa</code> (that is 28 <code>a</code>s), you will soon notice that your CPU usage goes to 100%. In fact, |
70 Python and Ruby need approximately 30 seconds of hard work for matching this string. You can try it for yourself: |
70 Python and Ruby need approximately 30 seconds of hard work for matching this string. You can try it for yourself: |
71 <A HREF="http://www.dcs.kcl.ac.uk/staff/urbanc/cgi-bin/repos.cgi/afl-material/raw-file/tip/progs/re.py">re.py</A> (Python version) and |
71 <A HREF="http://www.dcs.kcl.ac.uk/staff/urbanc/cgi-bin/repos.cgi/afl-material/raw-file/tip/progs/re.py">re.py</A> (Python version) and |
72 <A HREF="http://www.dcs.kcl.ac.uk/staff/urbanc/cgi-bin/repos.cgi/afl-material/raw-file/tip/progs/re-internal.rb">re.rb</A> |
72 <A HREF="http://www.dcs.kcl.ac.uk/staff/urbanc/cgi-bin/repos.cgi/afl-material/raw-file/tip/progs/re-internal.rb">re.rb</A> |