httpd-wiki-changes mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Apache Wiki <wikidi...@apache.org>
Subject [Httpd Wiki] Update of "DoS" by niq
Date Thu, 25 Jun 2009 01:15:55 GMT
Dear Wiki user,

You have subscribed to a wiki page or wiki category on "Httpd Wiki" for change notification.

The following page has been changed by niq:
http://wiki.apache.org/httpd/DoS

New page:
The "slowloris" script is not a new attack.  But by demonstrating the attack and giving it
a personality, it has drawn attention to a significant weakness in Apache HTTPD.  We need
a response to that, with information on risks and mitigation for server admins.

The slowloris script: threat and limitations

MaxClients, Memory usage, Threaded vs Unthreaded MPM, Event MPM not a solution!
Timeout
Resource limits
AcceptFilter

TCP-level defences: e.g. iptables

Modules: e.g. mod_evasive

Mime
View raw message