[TOOL] Apache mod_evasive - Evasive Maneuvers for Apache
- From: SecuriTeam <support@xxxxxxxxxxxxxx>
- Date: 7 Feb 2007 17:58:06 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
Apache mod_evasive - Evasive Maneuvers for Apache
------------------------------------------------------------------------
SUMMARY
DETAILS
mod_evasive is an evasive maneuvers module for Apache to provide evasive
action in the event of an HTTP DoS or DDoS attack or brute force attack.
It is also designed to be a detection and network management tool, and can
be easily configured to talk to ipchains, firewalls, routers, and
etcetera. mod_evasive presently reports abuses via email and syslog
facilities.
Detection is performed by creating an internal dynamic hash table of IP
Addresses and URIs, and denying any single IP address from any of the
following:
* Requesting the same page more than a few times per second
* Making more than 50 concurrent requests on the same child per second
* Making any requests while temporarily blacklisted (on a blocking list)
This method has worked well in both single-server script attacks as well
as distributed attacks, but just like other evasive tools, is only as
useful to the point of bandwidth and processor consumption (e.g. the
amount of bandwidth and processor required to receive/process/respond to
invalid requests), which is why it's a good idea to integrate this with
your firewalls and routers for maximum protection.
This module instantiates for each listener individually, and therefore has
a built-in cleanup mechanism and scaling capabilities. Because of this
per-child design, legitimate requests are never compromised (even from
proxies and NAT addresses) but only scripted attacks. Even a user
repeatedly clicking on 'reload' should not be affected unless they do it
maliciously. mod_evasive is fully tweakable through the Apache
configuration file, easy to incorporate into your web server, and easy to
use.
ADDITIONAL INFORMATION
The information has been provided by Jonathan A. Zdziarski.
To keep updated with the tool visit the project's homepage at:
<http://www.zdziarski.com/projects/mod_evasive/>
http://www.zdziarski.com/projects/mod_evasive/
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Prev by Date: [NEWS] Firefox Phishing Protection Bypass Vulnerability (Multiple /)
- Next by Date: [NT] FreeProxy HTTP Proxy Server DoS
- Previous by thread: [NEWS] Firefox Phishing Protection Bypass Vulnerability (Multiple /)
- Next by thread: [NT] FreeProxy HTTP Proxy Server DoS
- Index(es):
Relevant Pages
- [UNIX] Multiple Vendor X Font Server Multiple Vulnerabilities
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... System font server is used
to render fonts for the X server. ... Remote exploitation of a multiple vulnerabilities
in X.Org Foundation's X ... QueryXBitmaps and QueryXExtents protocol requests. ...
(Securiteam) - [NT] RaidenHTTPD Directory Traversal
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Due to improper testing by RaidenHTTPD
of user provided filename, ... "/../" into HTTP requests, but the program doesn't well
manage the initial ... The web server will return the requested file if available in the
disk ... (Securiteam) - [TOOL] mod_dosevasive, Apache Evasive Maneuvers Module
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... * Making any requests
while temporarily blacklisted ... This method has worked well in both single-server script
attacks as well ... (Securiteam) - [NEWS] Java JNI/DNS Queries DoS
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... unhandled exception on a Java
application if the application is tricked ... Java uses an 'InitialDirContext' to perform DNS
lookups. ... the next 32768 requests. ... (Securiteam) - [REVS] Acoustic Cryptanalysis: On Nosy People and Noisy Machines
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... emitted by a computer's CPU.
... systems is side-channel attacks: ... desktop and laptop computers, and
in all cases it was possible to ... (Securiteam)