發表文章

目前顯示的是 10月, 2020的文章

how to open VNC in HP-UX

open VNCviewer connect x.x.x.36:5901

10.29 Slow HTTP Denial of Service Attack (Slowloris)

站長日誌 109.10.29 弱點掃描偵測到Slow HTTP Denial of Service Attack弱點一隻 Server-Specific Recommendations Applying the above steps to the HTTP servers tested in the previous article indicates the following server-specific settings: Apache Using the < Limit > and < LimitExcept > directives to drop requests with methods not supported by the URL alone won’t help, because Apache waits for the entire request to complete before applying these directives. Therefore, use these parameters in conjunction with the  LimitRequestFields ,  LimitRequestFieldSize ,  LimitRequestBody ,  LimitRequestLine ,  LimitXMLRequestBody  directives as appropriate. For example, it is unlikely that your web app requires an 8190 byte header, or an unlimited body size, or 100 headers per request, as most default configurations have.  Set reasonable  TimeOut  and  KeepAliveTimeOut  directive values. The default value of 300 seconds for  TimeOut  is overkill for most situations. ListenBackLog ’s default value of 511 cou