Solved

Slow attach vulnerability

Posted on 2014-02-19
3
1,805 Views
Last Modified: 2014-03-03
I have a site which returned the following vulnerability in one specific page.
How can I prevent it ?

#1 Response
Export...Vulnerable to slow HTTP POST attack
Connection with partial POST body remained open for: 305297 milliseconds
Server resets timeout after accepting request data from peer.
0
Comment
Question by:amucinobluedot
3 Comments
 
LVL 15

Accepted Solution

by:
pateljitu earned 500 total points
ID: 39873887
Vulnerable to slow HTTP POST attack a.k.a (DoS), this vulnerability may result into Denial of Service attack. As indicated by error there are certain POST request which are taking 5 minutes to complete, in which case if there are thousand of simultaneous request made it would result in your server to respond very slowly and become unresponsive (D0S).

Please see following article explaining vulnerability and possible fix by changing IIS settings, other solution is to work with WAF which would help detect and prevent DoS attack.

https://community.qualys.com/blogs/securitylabs/2011/07/07/identifying-slow-http-attack-vulnerabilities-on-web-applications

Recommended IIS settings (assuming you have IIS web server):
http://cagdasulucan.blogspot.ca/2013/02/iis-recommendations-against-slow-http.html

https://community.qualys.com/blogs/securitylabs/2011/11/02/how-to-protect-against-slow-http-attacks

Web Application Firewall (WAF):
http://www.applicure.com/Products/dotdefender
0
 

Author Comment

by:amucinobluedot
ID: 39873912
Excellent ! thanks !
0

Featured Post

Master Your Team's Linux and Cloud Stack!

The average business loses $13.5M per year to ineffective training (per 1,000 employees). Keep ahead of the competition and combine in-person quality with online cost and flexibility by training with Linux Academy.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
easy to understand video about affiliated marketing for a beginner 3 37
Html form and modal / img src -problem 3 30
Obtaining data on ASP 8 29
Insert Button on a table 16 38
Provide an easy one stop to quickly get the relevant information on common asked question on Ransomware in Expert Exchange.
When crafting your “Why Us” page, there are a plethora of pitfalls to avoid. Follow these five tips, and you’ll be well on your way to creating an effective page.
The viewer will learn how to look for a specific file type in a local or remote server directory using PHP.
This tutorial will teach you the core code needed to finalize the addition of a watermark to your image. The viewer will use a small PHP class to learn and create a watermark.

860 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question