The Broadband Guide
SG
search advanced

Websites and Apps Vulnerable to Low-Bandwidth, Bot-Free Takedown

2011-12-30 09:59 by
Tags: ,

 

Researchers recently revealed a flaw that exists in a wide variety of Web application platforms, including Python, PHP, ASP.NET, and others. It is an insidiously simple attack that can bring a Web server to its knees by consuming all of the processing power and effectively creating a denial-of-service (DoS).

"An HTTP request that is merely 100KB in size can lock up 100 percent of a single CPU core for almost 2 minutes on the ASP.NET platform. Attackers could repeatedly send these requests and cause the server’s performance to degrade significantly and cause a denial of service," eWeek's Fahmida Y. Rashid added, nothing that experts believe that the attack "could even impact multicore servers and server clusters."

In a follow-up message, Microsoft announced it was shipping an "out-of-band," or emergency update today. The update was released at 1 p.m. ET. Designated MS11-100 , it also fixed three other bugs in ASP .Net, one tagged "critical." None of those three had been disclosed publicly prior to today.

Read more -here-

 

  Post your review/comments
    rate:
   avg:
News Glossary of Terms FAQs Polls Cool Links SpeedGuide Teams SG Premium Services SG Gear Store
Registry Tweaks Broadband Tools Downloads/Patches Broadband Hardware SG Ports Database Security Default Passwords User Stories
Broadband Routers Wireless Firewalls / VPNs Software Hardware User Reviews
Broadband Security Editorials General User Articles Quick Reference
Broadband Forums General Discussions
Advertising Awards Link to us Server Statistics Helping SG About