Solved

Slow attach vulnerability

Posted on 2014-02-19
3
1,707 Views
Last Modified: 2014-03-03
I have a site which returned the following vulnerability in one specific page.
How can I prevent it ?

#1 Response
Export...Vulnerable to slow HTTP POST attack
Connection with partial POST body remained open for: 305297 milliseconds
Server resets timeout after accepting request data from peer.
0
Comment
Question by:amucinobluedot
3 Comments
 
LVL 15

Accepted Solution

by:
pateljitu earned 500 total points
Comment Utility
Vulnerable to slow HTTP POST attack a.k.a (DoS), this vulnerability may result into Denial of Service attack. As indicated by error there are certain POST request which are taking 5 minutes to complete, in which case if there are thousand of simultaneous request made it would result in your server to respond very slowly and become unresponsive (D0S).

Please see following article explaining vulnerability and possible fix by changing IIS settings, other solution is to work with WAF which would help detect and prevent DoS attack.

https://community.qualys.com/blogs/securitylabs/2011/07/07/identifying-slow-http-attack-vulnerabilities-on-web-applications

Recommended IIS settings (assuming you have IIS web server):
http://cagdasulucan.blogspot.ca/2013/02/iis-recommendations-against-slow-http.html

https://community.qualys.com/blogs/securitylabs/2011/11/02/how-to-protect-against-slow-http-attacks

Web Application Firewall (WAF):
http://www.applicure.com/Products/dotdefender
0
 

Author Comment

by:amucinobluedot
Comment Utility
Excellent ! thanks !
0

Featured Post

Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

Join & Write a Comment

Read about achieving the basic levels of HRIS security in the workplace.
Using SQL Scripts we can save all the SQL queries as files that we use very frequently on our database later point of time. This is one of the feature present under SQL Workshop in Oracle Application Express.
The viewer will learn how to create and use a small PHP class to apply a watermark to an image. This video shows the viewer the setup for the PHP watermark as well as important coding language. Continue to Part 2 to learn the core code used in creat…
The viewer will get a basic understanding of what section 508 compliance can entail, learn about skip navigation links, alt text, transcripts, and font size controls.

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now