<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Slowloris and Nkiller2 vs. the Cisco CSS load balancer</title>
	<atom:link href="http://www.cupfighter.net/index.php/2009/06/slowloris-css/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.cupfighter.net/index.php/2009/06/slowloris-css/</link>
	<description>A blog by Schuberg Philis colleagues</description>
	<lastBuildDate>Wed, 25 Jan 2012 15:13:39 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: nixmicrosoft &#187; Blog Archive &#187; Slowloris HTTP DoS</title>
		<link>http://www.cupfighter.net/index.php/2009/06/slowloris-css/comment-page-1/#comment-3712</link>
		<dc:creator>nixmicrosoft &#187; Blog Archive &#187; Slowloris HTTP DoS</dc:creator>
		<pubDate>Mon, 05 Apr 2010 03:01:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.cupfighter.net/?p=185#comment-3712</guid>
		<description>[...] Cisco CSS (verified by user community) [...]</description>
		<content:encoded><![CDATA[<p>[...] Cisco CSS (verified by user community) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: My Personal Diary &#187; Blog Archive &#187; Slowloris HTTP DoS Attcak</title>
		<link>http://www.cupfighter.net/index.php/2009/06/slowloris-css/comment-page-1/#comment-1409</link>
		<dc:creator>My Personal Diary &#187; Blog Archive &#187; Slowloris HTTP DoS Attcak</dc:creator>
		<pubDate>Thu, 26 Nov 2009 15:58:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.cupfighter.net/?p=185#comment-1409</guid>
		<description>[...] Cisco CSS (verified by user community) [...]</description>
		<content:encoded><![CDATA[<p>[...] Cisco CSS (verified by user community) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Barrapunto &#124; slowloris: Ataque de denegación de servicio para Apache 1.x &#171; El camello, el Leon y el niño. O la evolución del perro al lobo</title>
		<link>http://www.cupfighter.net/index.php/2009/06/slowloris-css/comment-page-1/#comment-242</link>
		<dc:creator>Barrapunto &#124; slowloris: Ataque de denegación de servicio para Apache 1.x &#171; El camello, el Leon y el niño. O la evolución del perro al lobo</dc:creator>
		<pubDate>Fri, 28 Aug 2009 14:29:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.cupfighter.net/?p=185#comment-242</guid>
		<description>[...] Cisco CSS (verified by user community) [...]</description>
		<content:encoded><![CDATA[<p>[...] Cisco CSS (verified by user community) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Financeportal.eu &#187; Blog Archive &#187; Pozor na závažnú zraniteľnosť Apache-u!</title>
		<link>http://www.cupfighter.net/index.php/2009/06/slowloris-css/comment-page-1/#comment-228</link>
		<dc:creator>Financeportal.eu &#187; Blog Archive &#187; Pozor na závažnú zraniteľnosť Apache-u!</dc:creator>
		<pubDate>Tue, 25 Aug 2009 09:42:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.cupfighter.net/?p=185#comment-228</guid>
		<description>[...] Cisco CSS (potvrdené komunitou) [...]</description>
		<content:encoded><![CDATA[<p>[...] Cisco CSS (potvrdené komunitou) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Reeza</title>
		<link>http://www.cupfighter.net/index.php/2009/06/slowloris-css/comment-page-1/#comment-38</link>
		<dc:creator>Reeza</dc:creator>
		<pubDate>Thu, 02 Jul 2009 07:54:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.cupfighter.net/?p=185#comment-38</guid>
		<description>Hey all, would I be right in concluding that this would be effective whether slowloris or similar attack tool were used by one attack source or many (i.e. Distributed DoS using a botnet)?</description>
		<content:encoded><![CDATA[<p>Hey all, would I be right in concluding that this would be effective whether slowloris or similar attack tool were used by one attack source or many (i.e. Distributed DoS using a botnet)?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan</title>
		<link>http://www.cupfighter.net/index.php/2009/06/slowloris-css/comment-page-1/#comment-30</link>
		<dc:creator>Ryan</dc:creator>
		<pubDate>Mon, 29 Jun 2009 16:23:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.cupfighter.net/?p=185#comment-30</guid>
		<description>&lt;a href=&quot;#comment-25&quot; rel=&quot;nofollow&quot;&gt;@Motoma  &lt;/a&gt; 
I used the -httpready switch with slowloris against a CSS configuration with Delayed Binding, and the HTTP Request still does not make it back to the Apache HTTP Server, I looked at the HTTP Request Header and the HTTP Method is the only thing that changed with the -httpready switch.</description>
		<content:encoded><![CDATA[<p><a href="#comment-25" rel="nofollow">@Motoma  </a><br />
I used the -httpready switch with slowloris against a CSS configuration with Delayed Binding, and the HTTP Request still does not make it back to the Apache HTTP Server, I looked at the HTTP Request Header and the HTTP Method is the only thing that changed with the -httpready switch.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Slowloris HTTP DoS - .:: tt ::.</title>
		<link>http://www.cupfighter.net/index.php/2009/06/slowloris-css/comment-page-1/#comment-26</link>
		<dc:creator>Slowloris HTTP DoS - .:: tt ::.</dc:creator>
		<pubDate>Sun, 28 Jun 2009 03:52:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.cupfighter.net/?p=185#comment-26</guid>
		<description>[...] Cisco CSS (verified by user community) [...]</description>
		<content:encoded><![CDATA[<p>[...] Cisco CSS (verified by user community) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Motoma</title>
		<link>http://www.cupfighter.net/index.php/2009/06/slowloris-css/comment-page-1/#comment-25</link>
		<dc:creator>Motoma</dc:creator>
		<pubDate>Sat, 27 Jun 2009 12:28:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.cupfighter.net/?p=185#comment-25</guid>
		<description>Interesting findings.

RSnake mentioned in his article that HTTPReady was originally considered to be a tool for mitigating the SlowLoris attack because it holds connections until full requests come through. The way SlowLoris gets around this is by issuing POST requests instead of GET. To do this, you only need to enable the -httpready flag in SlowLoris.

It would be interesting to see how the Load Balancer handles POST requests. POSTs are different, because they can contain large amounts of data; were the Load Balancer to buffer these, one could overwhelm the it by sending a large number of big POSTs.</description>
		<content:encoded><![CDATA[<p>Interesting findings.</p>
<p>RSnake mentioned in his article that HTTPReady was originally considered to be a tool for mitigating the SlowLoris attack because it holds connections until full requests come through. The way SlowLoris gets around this is by issuing POST requests instead of GET. To do this, you only need to enable the -httpready flag in SlowLoris.</p>
<p>It would be interesting to see how the Load Balancer handles POST requests. POSTs are different, because they can contain large amounts of data; were the Load Balancer to buffer these, one could overwhelm the it by sending a large number of big POSTs.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan</title>
		<link>http://www.cupfighter.net/index.php/2009/06/slowloris-css/comment-page-1/#comment-22</link>
		<dc:creator>Ryan</dc:creator>
		<pubDate>Fri, 26 Jun 2009 17:10:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.cupfighter.net/?p=185#comment-22</guid>
		<description>&lt;a href=&quot;#comment-10&quot; rel=&quot;nofollow&quot;&gt;@Ennioac &lt;/a&gt; 
Cisco CSS must have a front side delayed binding configuration applied the the HTTP content rule, this can be accomplished by putting a url in the content rule, for example:
content site_80_load_balanced
vip address 10.88.55.2
protocol tcp 
port 80
url &quot;/*&quot;
add service server1
add service server2
active

If you have a SSL passing through your CSS to an Apache based server (and there are more than you think, for example IBM has a few!) you can configure back-end ssl on the CSS, refer to http://www.cisco.com/en/US/products/hw/contnetw/ps792/products_configuration_example09186a0080220dab.shtml</description>
		<content:encoded><![CDATA[<p><a href="#comment-10" rel="nofollow">@Ennioac </a><br />
Cisco CSS must have a front side delayed binding configuration applied the the HTTP content rule, this can be accomplished by putting a url in the content rule, for example:<br />
content site_80_load_balanced<br />
vip address 10.88.55.2<br />
protocol tcp<br />
port 80<br />
url &#8220;/*&#8221;<br />
add service server1<br />
add service server2<br />
active</p>
<p>If you have a SSL passing through your CSS to an Apache based server (and there are more than you think, for example IBM has a few!) you can configure back-end ssl on the CSS, refer to <a href="http://www.cisco.com/en/US/products/hw/contnetw/ps792/products_configuration_example09186a0080220dab.shtml" rel="nofollow">http://www.cisco.com/en/US/products/hw/contnetw/ps792/products_configuration_example09186a0080220dab.shtml</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pozor na závažnú zraniteľnosť Apache-u!</title>
		<link>http://www.cupfighter.net/index.php/2009/06/slowloris-css/comment-page-1/#comment-12</link>
		<dc:creator>Pozor na závažnú zraniteľnosť Apache-u!</dc:creator>
		<pubDate>Thu, 25 Jun 2009 00:35:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.cupfighter.net/?p=185#comment-12</guid>
		<description>[...] Cisco CSS (potvrdené komunitou) [...]</description>
		<content:encoded><![CDATA[<p>[...] Cisco CSS (potvrdené komunitou) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ennioac</title>
		<link>http://www.cupfighter.net/index.php/2009/06/slowloris-css/comment-page-1/#comment-10</link>
		<dc:creator>Ennioac</dc:creator>
		<pubDate>Wed, 24 Jun 2009 15:56:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.cupfighter.net/?p=185#comment-10</guid>
		<description>Hi Frank and Gert, I understand that the Cisco CSS is immune (wonderful work I might add!) but did the CSS need to be tweeked at all or was is a basic config?

Again, awesome work! :) Thanks and take care.
Ennio</description>
		<content:encoded><![CDATA[<p>Hi Frank and Gert, I understand that the Cisco CSS is immune (wonderful work I might add!) but did the CSS need to be tweeked at all or was is a basic config?</p>
<p>Again, awesome work! <img src='http://www.cupfighter.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  Thanks and take care.<br />
Ennio</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mnomic</title>
		<link>http://www.cupfighter.net/index.php/2009/06/slowloris-css/comment-page-1/#comment-8</link>
		<dc:creator>mnomic</dc:creator>
		<pubDate>Tue, 23 Jun 2009 11:55:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.cupfighter.net/?p=185#comment-8</guid>
		<description>Hi Frank,

FYI: 
http://isc.sans.org/diary.html?storyid=6622

Regards.</description>
		<content:encoded><![CDATA[<p>Hi Frank,</p>
<p>FYI:<br />
<a href="http://isc.sans.org/diary.html?storyid=6622" rel="nofollow">http://isc.sans.org/diary.html?storyid=6622</a></p>
<p>Regards.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Trey Guinn</title>
		<link>http://www.cupfighter.net/index.php/2009/06/slowloris-css/comment-page-1/#comment-7</link>
		<dc:creator>Trey Guinn</dc:creator>
		<pubDate>Tue, 23 Jun 2009 08:15:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.cupfighter.net/?p=185#comment-7</guid>
		<description>Nicely done, guys!</description>
		<content:encoded><![CDATA[<p>Nicely done, guys!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dennis</title>
		<link>http://www.cupfighter.net/index.php/2009/06/slowloris-css/comment-page-1/#comment-6</link>
		<dc:creator>Dennis</dc:creator>
		<pubDate>Mon, 22 Jun 2009 21:19:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.cupfighter.net/?p=185#comment-6</guid>
		<description>Good stuff Frank + Gert. 

Good to hear that the Cisco CSS mitigates this DDOS risk introduced by these tools. I&#039;ll update the corresponding ITSEC ticket for our customer resp inform them about your findings.

Again, excellent work gents!</description>
		<content:encoded><![CDATA[<p>Good stuff Frank + Gert. </p>
<p>Good to hear that the Cisco CSS mitigates this DDOS risk introduced by these tools. I&#8217;ll update the corresponding ITSEC ticket for our customer resp inform them about your findings.</p>
<p>Again, excellent work gents!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

