Showing posts with label hackers. Show all posts
Showing posts with label hackers. Show all posts

Friday, January 6, 2012

New Denial of Service Attack Takes Its Time on Your Server

DeniedOn Thursday a researcher published a proof-of-concept code that takes a new look on the slow HTTP Denial-of-Service (DoS) attack by simply dragging out the whole process of reading the server's response and, eventually, overwhelming it. Senior Software Engineer at Qualys Sergey Shekyan also added this modified Denial-of-Service attack, which he dubs a Slow Read attack, to his Slowhttptest tool.

As far as the attack goes, Slow Read basically sends a legitimate HTTP request and then takes an excruciatingly long time reading the response. By doing so, the Slow Read attack keeps as many open connections as possible and eventually causes a Denial-of-Service attack.

The Slowhttptest attack tool developed by Shekyan was inspired by related open-source tools Slowloris and OWASP's Slow HTTP Post. Slowloris keeps connections open by sending partial HTTP requests and then sends headers at regular intervals in order to prevent the sockets from closing.

OWASP's Slow HTTP Post Distributed Denial-of-Service (DDoS) tool simulates an attack using POST headers that have a legitimate content-length field. This allows a web server to know just how much data is arriving. Once the headers are delivered, the POST message body is transmitted slowly and gridlocks the connection, as well as the server resources.

Slow HTTP attacks are becoming increasingly more popular, especially among hackers, as a way to quietly insert a Denial-of-Service attack due to the fact that these hacks are relatively simple to perform, require minimal computing resources and are often hard to detect until it is too late.

Source: InformationWeek - New Denial of Service Attack Cripples Servers Slowly

Rack-Mount Server rentals are ideal if your company needs an extra storage unit for company information while you are testing various types of storage solutions.

Whether you need a short-term rental or a long-term lease, we have the right kind of server for your needs.

Friday, September 16, 2011

Security Flaw at Oracle Could Take Down Application Servers

OracleOracle just released an emergency patch that is designed to fix a vulnerability that, according to the company, could bring down HTTP application servers sold by Oracle, ones that are also based on Apache 2.0 or 2.2.

According to a statement released by Oracle, hackers have the ability to exploit weaknesses remotely without the need of a username or password for entry. There are multiple products that are affected by the bug, including Oracle Fusion Middleware 11g Release 1, versions 11.1.1.3.0, 11.1.1.4.0 and 11.1.1.5.0; Oracle Application Server 10g Release 3, version 10.1.1.5.0 and Oracle Application Server 10g Release 2, version 10.1.2.3.0.

The United States Government's National Vulnerability Database has already assigned a Common Vulnerability Scoring System (CVSS) rating of 7.8 to the bug, indicating a "complete Operating System denial of service (dos)", according to the company. However, Oracle did take issue with the assessment in its security alert.

According to the company, "A complete Operating System denial of service is not possible on any platform supported by Oracle, and as a result, Oracle has given the vulnerability a CVSS Base Score of 5.0 indicating a complete denial of service of the Oracle HTTP Server but not the Operating System."

Regardless of how you score it, the bug was, evidently, serious enough for Oracle to release a patch for it outside of the company's usual large quarterly update schedule, the next of which is poised to take place on October 18, 2011.

The hack at Oracle is just the latest in a series of hacks against large corporations, government websites and other companies from multiple hacker groups that like to be known as "hacktivists". These attacks have gotten so bad, actually, that the government has started an all out campaign against these hackers in an attempt to stop them before they cause any extremely serious damage.

Source: PC World - Oracle: Security Flaw Could Bring Down App Servers

SMBnow.com is news of, for and by SMBs!
SMBnow.com... The Small & Medium Business Magazine!