Results 1 to 5 of 5

Thread: me making a DOS attack??

Hybrid View

Previous Post Previous Post   Next Post Next Post
  1. #1
    NeoGen's Avatar
    NeoGen is offline AMD Users Alchemist Moderator
    Site Admin
    Join Date
    Oct 2003
    Location
    North Little Rock, AR (USA)
    Posts
    8,451

    me making a DOS attack??

    That's the message that norton internet security gave me once when boitho was running!

    Details: Attempted Intrusion "HTTP Apache Redundant Slashes DoS" from your machine against 80.77.88.227 was detected and blocked.
    Intruder: localhost(1349).
    Risk Level: Medium.
    Protocol: TCP.
    Attacked IP: 80.77.88.227.
    Attacked Port: http(80).
    I must be crawling too much... :P

  2. #2
    AMDave's Avatar
    AMDave is offline Seeker of the exit clause Moderator
    Site Admin
    Join Date
    Jun 2004
    Location
    Deep in a while loop
    Posts
    9,658
    extracted from a usenet discussion...(David W. Hodgins Aug 4 2005, 9:35 am)
    It only affects webservers running apache 1.24 or older.
    what the bug actually does is cause the server to stop responding, if someone
    enters a url like http://some.domain.invalid/pub////////////file
    The extra slashes would be removed (if you had enough ram), but it would take a
    long time. Without enough ram, it would crash the server.
    It seems that amongst the boitho list of URLs to be checked there may be a few bad eggs.

    Recommend you email the Project Team so that they can weed them out otherwise their volunteers may become unpopular very quickly.

  3. #3
    NeoGen's Avatar
    NeoGen is offline AMD Users Alchemist Moderator
    Site Admin
    Join Date
    Oct 2003
    Location
    North Little Rock, AR (USA)
    Posts
    8,451
    You mean that just putting too many slashes in the address can be hazardous to a server?
    Imagine if, accidentally or otherwise, a guy posted a link on slashdot to a site but with those extra slashes in the address?

    Hmm... thinking better there's no need for specific DoS attack really... slashdot users on their own already make up strong attacks on servers

  4. #4
    Seems that a hi number of leading slashes in a url will trigger this. I will add a test for this to our url filter.

    Symantec's info: http://www.symantec.com/avcenter/att...gs/s20510.html

  5. #5
    NeoGen's Avatar
    NeoGen is offline AMD Users Alchemist Moderator
    Site Admin
    Join Date
    Oct 2003
    Location
    North Little Rock, AR (USA)
    Posts
    8,451
    I happened to be near the computer and noticed one more of these warnings by my firewall today.

    I guess not all url's have been filtered out yet. :?

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •