SlowHTTPTest

A tool to test for slow HTTP DoS vulnerabilities
Download

SlowHTTPTest Ranking & Summary

Advertisement

  • Rating:
  • License:
  • Apache
  • Publisher Name:
  • Sergey Shekyan
  • Publisher web site:
  • http://code.google.com/u/114299738134114505639/
  • Operating Systems:
  • Mac OS X
  • File Size:
  • 103 KB

SlowHTTPTest Tags


SlowHTTPTest Description

SlowHTTPTest is a free, open-source and highly configurable application that mimics some Application Layer Denial of Service attacks.In other words, SlowHTTPTest implements the most common low-bandwidth Application Layer DoS attacks, like slowloris, Slow HTTP POST, Slow Read attack (based on TCP persist timer exploit) by draining concurrent connections pool, as well as Apache Range Header attack by causing very significant memory and CPU usage on the server.The Slowloris and Slow HTTP POST DoS attacks rely on the fact that the HTTP protocol, by default, needs requests to be completely received by the server before being processed. If an HTTP request is not complete, or if the transfer rate is very low, the server keeps its resources busy waiting for the rest of the data. If the server keeps too many resources busy, this creates a denial of service. SlowHTTPTest is sending partial HTTP requests, trying to get denial of service from target HTTP server.


SlowHTTPTest Related Software