翻訳と辞書
Words near each other
・ Slowed rotor
・ Slower ball
・ Slower Speeds Initiative
・ Slower Than Church Music
・ Slowest animals
・ Slowey
・ Slowhand
・ Slowhand at 70 – Live at the Royal Albert Hall
・ Slowhands
・ SlowHill
・ Slowik (surname)
・ Slowing Down the World
・ Slowinski
・ Slowinski's corn snake
・ Slowlife
Slowloris (software)
・ Slowly (Ghost album)
・ Slowly (Webb Pierce song)
・ Slowly but Surely
・ Slowly changing dimension
・ Slowly Going the Way of the Buffalo
・ Slowly growing Mycobacteria
・ Slowly I Turned
・ Slowly pulsating B-type star
・ Slowly Slipping Away
・ Slowly varying envelope approximation
・ Slowly varying function
・ Slowly We Rot
・ Slowly, Slowly
・ Slowmotion Apocalypse


Dictionary Lists
翻訳と辞書 辞書検索 [ 開発暫定版 ]
スポンサード リンク

Slowloris (software) : ウィキペディア英語版
Slowloris (software)

Slowloris is a piece of software written by Robert "RSnake" Hansen which allows a single machine to take down another machine's web server with minimal bandwidth and side effects on unrelated services and ports.
Slowloris tries to keep many connections to the target web server open and hold them open as long as possible. It accomplishes this by opening connections to the target web server and sending a partial request. Periodically, it will send subsequent HTTP headers, adding to—but never completing—the request. Affected servers will keep these connections open, filling their maximum concurrent connection pool, eventually denying additional connection attempts from clients.〔
==Affected web servers==

This affects a number of webservers that use threaded processes and set a limit on the number of threads/processes that can be automatically spawned in order to keep from exhausting the memory on the server. This limit is intended to keep the server from slowing down due to lack of memory on the machine, but under this particular attack, the solution of the "use too much memory" problem is maliciously leveraged to cause an "all the permitted threads are busy" problem.
The server says "well, I can't start too many threads, or I will run out of memory. I will therefore set a limit, say, 200, and refuse to start more threads if I have 200 currently serving a request." The attacker says "Ok, fine...I'll just submit 200 requests that talk to the server in a deliberately slow way, taking up all the lines you made available."
This includes but is not necessarily limited to the following:〔
* Apache 1.x
* Apache 2.x
* dhttpd
* WebSense "block pages" (unconfirmed)
* Trapeze Wireless Web Portal (unconfirmed)
* Verizon's MI424-WR FIOS Cable modem (unconfirmed)
* Verizon's Motorola Set-top box (port 8082 and requires auth - unconfirmed)
* BeeWare WAF (unconfirmed)
* Deny All WAF (patched) 〔http://www.denyall.com/files/090703-Flash-Presse-contre-Slowloris.pdf〕
Because Slowloris exploits problems handling thousands of connections, the attack has less of an effect on servers that handle large numbers of connections well:
* Hiawatha 〔(【引用サイトリンク】title=Performance testing while under attack )
* IIS 〔
* lighttpd 〔
* Squid 〔
* NGINX 〔
* Cherokee (verified by user community)
* Cisco CSS (verified by user community) 〔
* Varnish 〔https://www.varnish-cache.org/docs/trunk/index.html〕

抄文引用元・出典: フリー百科事典『 ウィキペディア(Wikipedia)
ウィキペディアで「Slowloris (software)」の詳細全文を読む



スポンサード リンク
翻訳と辞書 : 翻訳のためのインターネットリソース

Copyright(C) kotoba.ne.jp 1997-2016. All Rights Reserved.