Micheas Herman

... life on the left coast.

  • Increase font size
  • Default font size
  • Decrease font size

Apache DOS exploit in the wild

E-mail Print

With the release of the Slowlaris Denial Of Service (DOS) client I have moved my sites back to lighttpd from apache.

This seems to almost be pick your poison, as I have had stability issues with lighttpd under FreeBSD. However, I expect that people will use this time to try out the new exploit listed on the front page of slashdot.

This follows yesterdays clean up of a clients website that had been defaced.

There is a hint that there is a an ancient patch for FreeBSD and apache 1.3 that might solve the problem, but it never seems to have made it into wide spread use.