Re: Web servers / possible DOS Attack / mime header flooding

From: Rich Wood (richat_private)
Date: Thu Sep 03 1998 - 13:49:19 PDT

  • Next message: Lars Eilebrecht: "Re: Web servers / possible DOS Attack / mime header flooding"

    On 3 Sep 98, at 12:34, Laurent FACQ wrote:
    > #       => by sending a crazy amount of 8000 bytes headers, it's possible
    > #       to consume a lot of memory (and of course CPU). The point
    > #       is that httpd daemons grow and STAY at this big size (or die
    > #       if you send too much)
    
    Tried against apache 1.3.1 on FreeBSD 2.2.6 (DX2-66 16Mb), script hung
    after 2500 headers with apache using 30Mb.
    
    Tried against apache 1.3.1 on NT4 (workstation) SP3 (P200 64Mb), after
    7500 headers, apache was using 120Mb RAM and the box ground to a halt.
    
    It didn't actually crash apache on either box, but severely reduced the
    usefulness of the systems.
    
    Rich
    --
    Rich Wood
    richat_private
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:14:54 PDT