Full Disclosure mailing list archives

Re: how to detect DDoS attack through HTTP response analysis(throuput)


From: Ferenc Kovacs <tyra3l () gmail com>
Date: Wed, 29 Jun 2011 09:40:05 +0200

2011/6/29 coderman <coderman () gmail com>:
2011/6/26 김무성 <kimms () infosec co kr>:
...
I'm looking for meterials or information, research about that how to detect
DDoS attack through HTTP response analysis(throuput).

you're asking the wrong question.

instead of asking "How can I automagically detect exploitation of my
shitty app via HTTP Resp. codes"

ask: "Why is my webapp so shitty that any number of arbitrary requests
lead to resource exhaustion?"


because fetching(or imitating to fetch) the result is always less
resource intense than generating it?
o_O

Tyrael

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: