Post subject: Update on protection against slowloris
PostPosted: Wed Sep 30, 2009 10:46 pm 
   
Hi list!

We tested mod_antiloris 0.4 and found it quite efficient, but before
putting it in production, we would like to hear some feedback from
freebsd users. We are using Apache 2.2.x on Freebsd 6.2 and 7.2. Is
anyone using it? Do you have any other way to patch against Slowloris
other than putting a proxy in front or using the HTTP accept filter?

Thanks for your feedback,

Martin
_______________________________________________
freebsd-security@freebsd.org mailing list
http://lists.freebsd.org/mailman/listin ... d-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


 
 Post subject: Re: Update on protection against slowloris
PostPosted: Thu Oct 01, 2009 7:40 am 
Martin Turgeon wrote:
Quote:
Hi list!

We tested mod_antiloris 0.4 and found it quite efficient, but before
putting it in production, we would like to hear some feedback from
freebsd users. We are using Apache 2.2.x on Freebsd 6.2 and 7.2. Is
anyone using it? Do you have any other way to patch against Slowloris
other than putting a proxy in front or using the HTTP accept filter?

Thanks for your feedback,

Martin
_______________________________________________
freebsd-security@freebsd.org mailing list
http://lists.freebsd.org/mailman/listin ... d-security
To unsubscribe, send any mail to
"freebsd-security-unsubscribe@freebsd.org"
Hello,


I am using it succesfully although not under any serious load, same
Apache and FreeBSD versions. I found it easy (compared to the
alternatives) and efficient, and no I don't know of any other ways of
blocking the attack, short of using Varnish or similar. However,
accf_http doesn't help at all, since HTTP POST requests bypass the
filter. HTTP POST can be enabled by passing the -httpready switch to
Slowloris.

Please report back with your findings, I've been wondering how it
would perform under load.

Best of luck with it,

Thomas Rasmussen
_______________________________________________
freebsd-security@freebsd.org mailing list
http://lists.freebsd.org/mailman/listin ... d-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


 
 Post subject: Re: Update on protection against slowloris
PostPosted: Thu Oct 01, 2009 3:01 pm 
On Thu, 2009-10-01 at 02:40 +0200, Thomas Rasmussen wrote:
Quote:
Martin Turgeon wrote:
Hi list!

We tested mod_antiloris 0.4 and found it quite efficient, but before
putting it in production, we would like to hear some feedback from
freebsd users. We are using Apache 2.2.x on Freebsd 6.2 and 7.2. Is
anyone using it? Do you have any other way to patch against Slowloris
other than putting a proxy in front or using the HTTP accept filter?

Thanks for your feedback,

Martin
_______________________________________________
freebsd-security@freebsd.org mailing list
http://lists.freebsd.org/mailman/listin ... d-security
To unsubscribe, send any mail to
"freebsd-security-unsubscribe@freebsd.org"
Hello,

I am using it succesfully although not under any serious load, same
Apache and FreeBSD versions. I found it easy (compared to the
alternatives) and efficient, and no I don't know of any other ways of
blocking the attack, short of using Varnish or similar. However,
accf_http doesn't help at all, since HTTP POST requests bypass the
filter. HTTP POST can be enabled by passing the -httpready switch to
Slowloris.

Please report back with your findings, I've been wondering how it
would perform under load.

Best of luck with it,

Thomas Rasmussen

We use Apache 2.2 with the event MPM. This configuration is immune to
slowloris, as it was designed (several years before 'slowloris' came
along) to solve that exact problem.

Cheers

Tom

_______________________________________________
freebsd-security@freebsd.org mailing list
http://lists.freebsd.org/mailman/listin ... d-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


 





SitemapIndex SitemapIndex RSS Feed RSS Feed Channel list Channel list
 © 0x61.com 2009 - Internet Forums and much more! - All rights reserved.