CVSROOT:        /cvs
Module name:    ports
Changes by:     st...@cvs.openbsd.org   2012/04/11 07:37:27

Log message:
    import www/slowhttptest, ok ajacoutot@
    
    SlowHTTPTest is a highly configurable tool that simulates some
    Application Layer Denial of Service attacks.
    
    It implements most common low-bandwidth Application Layer DoS attacks,
    such as slowloris, Slow HTTP POST, Slow Read attack (based on TCP persist
    timer exploit) by draining concurrent connections pool, as well as Apache
    Range Header attack by causing very significant memory and CPU usage on the
    server.
    
    Slowloris and Slow HTTP POST DoS attacks rely on the fact that the HTTP
    protocol, by design, requires requests to be completely received by the
    server before they are processed. If an HTTP request is not complete, or if
    the transfer rate is very low, the server keeps its resources busy waiting
    for the rest of the data. If the server keeps too many resources busy, this
    creates a denial of service. This tool is sending partial HTTP requests,
    trying to get denial of service from target HTTP server.
    
    Slow Read DoS attack aims the same resources as slowloris and slow POST,
    but instead of prolonging the request, it sends legitimate HTTP request and
    reads the response slowly.
    
    Status:
    
    Vendor Tag: sthen
    Release Tags:       sthen_20121104
    
    N ports/www/slowhttptest/Makefile
    N ports/www/slowhttptest/distinfo
    N ports/www/slowhttptest/pkg/PLIST
    N ports/www/slowhttptest/pkg/DESCR
    
    No conflicts created by this import

Reply via email to