Claim Astaro

ASG Section

Astaro Security Gateway

All in One - The Unified Theat Management Appliance that brings Enterprise-Class Network, Web and Email Security to small and medium sized businesses.

Learn more Try now

AMG Section

Astaro Mail Gateway

Stop Spam - The Mail Security Appliance that keeps your inbox clean, filters malware and encrypts emails.

Learn more Try now

AWG Section

Astaro Web Gateway

Stop wasting time - The Web Security Appliance that blocks unproductive web surfing, controls IM and P2P usage and filters malware.

Learn more Try now

ACC Section

Astaro Command Center

Keep Control - The Central Management Appliance to monitor, maintain and configure all your Astaro Gateway installations.

Learn more Try now

Product Selector Toolbar

« AxG Beta 7.460 Released | Main | Up2Date 7.404 Released »

As Slowloris HTTP DoS Rises, Astaro is Ready

Recently the Slowloris Denial of Service attack has jumped in popularity. This attack is similar to SYN flood, but uses HTTP instead, basically consuming sockets on the Web Server vs. trying to saturate all the bandwidth. This is an interesting attack, particularly because it does not require a lot of bandwidth by the attacker. Indeed it is possible to DoS even large sites simply using a common residential Internet connection, and using Slowloris to eat-up the Web Server's ability to respond to other HTTP requests, by sending partial ones itself and thus holding the sockets open. You can read more about this DoS technique here.

While the approach is not new, the working implementation of it "for the masses" is starting to appear more commonly.

As we have already received dozens of queries about how to stop this attack, we'd like to inform you that Astaro installations with current/updated Intrusion Protection Patterns will be protected against this, so neither admins or their Web Servers need to fear. The ID for this new rule is #1000023, and is located in the HTTP Servers Group under the Apache category. If your ASG installation is showing pattern revision 9857 or better, you are protected.

Current Versions
  • ASG V7: 7.504
  • ACC V2: 2.100
  • ASC V9: 9.2
  • ASG V6: 6.315 (EOL)
  • ARM V4: 4.6
Release Notes
Known Issues Lists
Hardware Compatibility Lists
Links
Subscribe to this blog's feed
By Product
Recent Posts
By Month