Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 65 guests and 1 member online
 
Free Business and Tech Magazines and eBooks

You are here: Home
EH-Net
May 18, 2013, 07:33:30 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1]
1  Ethical Hacking Discussions and Related Certifications / Programming / Re: Some inputs on JavaScript on: January 12, 2012, 01:45:23 PM
I actually found this - 

http://www.devarticles.com/c/a/JavaScript/Programmatic-POST-Requests-with-JavaScript-Form-Emulator-in-Action/4/

which gives a backgroudn on how to create an HTTP POST flooding attack. But I'm looking for a way to slow down the requests.... I think it can theoretically be done. But I'm not sure how.
2  Ethical Hacking Discussions and Related Certifications / Programming / Some inputs on JavaScript on: January 06, 2012, 08:27:05 AM
Hi!

I'm a student doing a research with ModSecurity. I'm coming up with some rules to prevent * HTTP POST DoS attack on the Apache server by using javascript cookies. ModSecurity injects the JavaScript code on any webpage then ModSecurity is then configured to drop requests without these cookies. My main assumption is that most bots especially those that use the slow HTTP DoS POST attack don't use browsers and thus don't use JavaScript. Can anyone here give me some insights as to how effective/not effective that prevention is? Can someone also use JavaScript to create a Slow HTTP POST attack tool that triggers or steals that cookie and proceed with the attack?


As an example, some said that Javascript code can easily be stolen even with obfuscation.

Sorry not a I'm not Javascript expert at all.


Article on slow post DoS attacks can be found

here -http://www.darkreading.com/vulnerability-management/167901026/security/attacks-breaches/228000532/researchers-to-demonstrate-new-attack-that-exploits-http.html.

and here http://blog.spiderlabs.com/2011/07/advanced-topic-of-the-week-mitigating-slow-http-dos-attacks.html.

Many Thanks!
3  EH-Net / Calendar Of Events / Re: BSidesVienna 2011 on: June 13, 2011, 02:52:19 PM
 Smiley Excited for this one.
4  Ethical Hacking Discussions and Related Certifications / eCPPT - eLearnSecurity Certified Professional Penetration Tester / Re: eCPPT Certified! on: December 29, 2010, 02:57:42 PM
 Cheesy This is just the kind of review on eCPPT I was looking for. I will be taking this next month to start my year right. Then, I will be following this with the PWB course.

This really helped me map out my certifications plans.

Thank your so much for a detailed review.
Pages: [1]
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.071 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.