Slowloris…

This type of attack is really interesting… I should’ve thought of it though :P…

Well, disregarding the image thats ONLY related by name, Slowloris is an HTTP DoS tool developed by RSnake, John Kinsella and Robert E Lee…

We all expect DoS to flood a server till it crash and whether freeze or restarts… This one doesn’t…

The concept of this attack (In short, as I understood it) is to keep as much HTTP sessions alive as much and long as possible, which could leave the server stop accepting more sessions leaving the server alive and fully functional while the webservice unavailable…

It only effects webservice (And probably database server) and minor side issues… And the whole thing restores functionality when the DoS stops real fast without having to fail the whole system…

For more details and clearer description (In case I misunderstood, which I hope I didn’t), check the Slowloris related post.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.