SlowHTTPTest - Application Layer DoS attack simulator
SlowHTTPTest is a highly configurable tool that simulates some
Application Layer Denial of Service attacks. It works on majority of
Linux platforms, OSX and Cygwin - a Unix-like environment and
command-line interface for Microsoft Windows.
It implements most common low-bandwidth Application Layer DoS attacks, such as slowloris, Slow HTTP POST, Slow Read attack (based on TCP persist timer exploit) by draining concurrent connections pool, as well as Apache Range Header attack by causing very significant memory and CPU usage on the server.
Slowloris
and Slow HTTP POST DoS attacks rely on the fact that the HTTP protocol,
by design, requires requests to be completely received by the server
before they are processed. If an HTTP request is not complete, or if the
transfer rate is very low, the server keeps its resources busy waiting
for the rest of the data. If the server keeps too many resources busy,
this creates a denial of service. This tool is sending partial HTTP
requests, trying to get denial of service from target HTTP server.
SlowHTTPTest - Application Layer DoS attack simulator
Reviewed by Zion3R
on
9:03 PM
Rating: