Forum Moderators: phranque

Message Too Old, No Replies

Slow DoS attack possible

Load Balance your systems....

         

tangor

2:59 am on Jun 20, 2009 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Security guru Robert "RSnake" Hansen has released a novel DoS attack tool that points to a significant flaw in Apache and other webservers.

Hansen calls his creation "Slowloris - the low bandwidth yet greedy and poisonous HTTP client." Unlike an old school Denial of Service attack, which ties up a website by bombarding the thing with epic amounts of traffic, Slowloris achieves the same result with a handful of packets.

"A typical request-flooder [DoS attack] might need a 1000 machines to take down a single web server, because you need that much bandwidth to pull enough traffic to saturate the actual physical lines so no one else can come through," Rsnake tells The Reg. "But Slowloris uses almost no traffic at all. You need few 1000 packets to get started and then a few hundred on a regular integrated basis to continue - 200 to 300 packets per minute.

"You can easily do it with a single machine."

Reported at The Register
[theregister.co.uk...]

Just a heads up!

jdMorgan

2:27 pm on Jun 20, 2009 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



See also: [webmasterworld.com...]

Jim