SHARE
Facebook X Pinterest WhatsApp

How To Defend slowloris DDoS With mod_qos (Apache2 On Debian [Lenny])

Written By
thumbnail
Web Webster
Web Webster
Jul 23, 2009

[ Thanks to Falko
Timme
for this link. ]

“Some servers may have a smaller tolerance for timeouts
than others, but Slowloris can compensate for that by customizing
the timeouts. There is an added function to help you get started
with finding the right sized timeouts as well. As a side note,
Slowloris does not consume a lot of resources so modern operating
systems don’t have a need to start shutting down sockets when they
come under attack, which actually in turn makes Slowloris better
than a typical flooder in certain circumstances. Think of Slowloris
as the HTTP equivalent of a SYN flood.

“I recently had to defend a live attack with slowloris-dos from
a botnet. The load-impact is very low but http quits serving very
fast. A quick approach was to mangle with timeout settings, wich is
fine to defend a single attacker but leads into new issues (ie.
large NAT on client-side).

“mod_qos gives some fine-grained opportunities to scale the
number of used connections and to defend an attack according to
bandwidth limits. Unfortunately it is only available as
source-package and there are many possible settings, wich might be
hard to setup for this special case. So I provide the way that
helped me.”


Complete Story

thumbnail
Web Webster

Web Webster

Web Webster has more than 20 years of writing and editorial experience in the tech sector. He’s written and edited news, demand generation, user-focused, and thought leadership content for business software solutions, consumer tech, and Linux Today, he edits and writes for a portfolio of tech industry news and analysis websites including webopedia.com, and DatabaseJournal.com.

Recommended for you...

How to Install Immich on openSUSE
r00t
Sep 6, 2024
Beginners Guide for ID Command in Linux
Benny Lanco
Sep 5, 2024
[Fixed] An Unexpected Error Occurred on Gnome Extensions
Patrick
Sep 3, 2024
Run a Google Search From the Linux Command Line With Googler
TechRepublic
Aug 27, 2024
Linux Today Logo

LinuxToday is a trusted, contributor-driven news resource supporting all types of Linux users. Our thriving international community engages with us through social media and frequent content contributions aimed at solving problems ranging from personal computing to enterprise-level IT operations. LinuxToday serves as a home for a community that struggles to find comparable information elsewhere on the web.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.