Re: Apache DoS Attack

From: Jonathan Freeman (freemanat_private)
Date: Tue Aug 11 1998 - 15:02:34 PDT

  • Next message: Alec Kosky: "Re: Eudora executes (Java) URL"

    We just tested the Sioux (Apache DoS) bug on:
    
        <>    IIS 3.0  (Service Pack 3)
    
                   causes immediate jump to 100% CPU for approx. 5 seconds
                   multiple attacks can keep the CPU in the 90% range
    
        <>    IIS 4.0  (Service Pack 3)
    
                   causes immediate jump to 80% CPU for approx. a half second
                   multiple attacks DO NOT cause more thank 40% sustained CPU
    range
    
        <>    Apache 1.1.1 (Unix)  (Caldera OpenLinux)
    
                   causes jump to 66% CPU for each get request and attempts
                   to use all available swap space for memory.  Can be DoS'd
    easily.
    
        <>     WebSitePro 2.3.4  (Service Pack 3)
    
                   causes immediate jump to 99% CPU for approx. 5 seconds
                   unknown if DoS would be possible for multiple attacks
    
    
    Regards,
    
    Jonathan Freeman
    
    -----Original Message-----
    From: Jamie Orzechowski <mhzat_private>
    To: BUGTRAQat_private <BUGTRAQat_private>
    Date: Tuesday, August 11, 1998 1:39 PM
    Subject: Apache DoS Attack
    
    
    >I tried the sioux bug on Website c2.3 for NT and I noticed in the processes
    >that the CPU jumped upto 99% ... any ideas?
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:12:06 PDT