BUEN FIN DE CUATRIMESTRE...!! A DISFRUTAR DE ESTAS MERECIDAS VACACIONES.. NOS VEMOS EL PRÓXIMO :)

jueves, 18 de enero de 2024

Vulcan DoS Vs Akamai

In the past I had to do several DoS security audits, with múltiples types of tests and intensities. Sometimes several DDoS protections were present like Akamai for static content, and Arbor for absorb part of the bandwith.

One consideration for the DoS/DDoS tools is that probably it will loss the control of the attacker host, and the tool at least has to be able to stop automatically with a timeout, but can also implement remote response checks.

In order to size the minimum mbps needed to flood a service or to retard the response in a significant amount of time, the attacker hosts need a bandwith limiter, that increments in a logarithmic way up to a limit agreed with the customer/isp/cpd.

There are DoS tools that doesn't have this timeouts, and bandwith limit based on mbps, for that reason I have to implement a LD_PRELOAD based solution: bwcontrol

Although there are several good tools for stressing web servers and web aplications like apache ab, or other common tools used for pen-testing, but I also wrote a fast web flooder in c++ named wflood.

As expected the most effective for taking down the web server are the slow-loris, slow-read and derivatives, few host were needed to DoS an online banking. 
Remote attacks to database and highly dynamic web content were discarded, that could be impacted for sure.

I did another tool in c++ for crafting massive tcp/udp/ip malformed packets, that impacted sometimes on load balancers and firewalls, it was vulcan, it freezed even the firewall client software.

The funny thing was that the common attacks against Akamai hosts, where ineffective, and so does the slow-loris family of attacks, because are common, and the Akamai nginx webservers are well tunned. But when tried vulcan, few intensity was enough to crash Akamai hosts.

Another attack vector for static sites was trying to locate the IP of the customer instead of Akamai, if the customer doesn't use the Akamai Shadow service, it's possible to perform a HTTP Host header scan, and direct the attack to that host bypassing Akamai.

And what about Arbor protection? is good for reducing the flood but there are other kind of attacks, and this protection use to be disabled by default and in local holidays can be a mess.

Related word


  1. Hacking Tools Windows
  2. Hak5 Tools
  3. Pentest Tools Windows
  4. Hackrf Tools
  5. Hacking Tools Hardware
  6. Hacker Tools For Ios
  7. Physical Pentest Tools
  8. Growth Hacker Tools
  9. Hacker Techniques Tools And Incident Handling
  10. Hack Tools For Windows
  11. Hack Tools Online
  12. Hack Website Online Tool
  13. Hacking Apps
  14. Hack Tools Pc
  15. Hacker Security Tools
  16. How To Make Hacking Tools
  17. Beginner Hacker Tools
  18. Pentest Tools Free
  19. Pentest Tools Android
  20. Hacking Tools For Games
  21. Hacker Hardware Tools
  22. Pentest Tools Kali Linux
  23. Pentest Tools Website Vulnerability
  24. Hack Website Online Tool
  25. Hacking Tools For Windows Free Download
  26. Hack Tools Pc
  27. Hack Tools For Games
  28. Hack Tools For Ubuntu
  29. Pentest Tools Subdomain
  30. Pentest Tools Find Subdomains
  31. Hack Apps
  32. Best Hacking Tools 2019
  33. Hack Tool Apk
  34. Hacking Tools For Beginners
  35. Hacker Tools Free
  36. Hack Tools For Windows
  37. Hack Tools For Ubuntu
  38. Pentest Tools Linux
  39. Hacking Tools And Software
  40. Hacker Tools For Pc
  41. Hack App
  42. Top Pentest Tools
  43. Hack Tools
  44. Hacker Tools Apk
  45. Hacker Tools For Mac
  46. Pentest Tools Framework
  47. Pentest Tools Nmap
  48. Pentest Tools Nmap
  49. Hacker Tools
  50. What Is Hacking Tools
  51. Beginner Hacker Tools
  52. Pentest Tools Online
  53. Usb Pentest Tools
  54. Pentest Tools Nmap
  55. Hacker Tools Windows
  56. Hacking Apps
  57. Pentest Tools Windows
  58. Best Pentesting Tools 2018
  59. Hack Tool Apk No Root
  60. Hacker Tools 2019
  61. Pentest Tools Download
  62. Hacker Tools Apk Download
  63. Hacking Tools For Kali Linux
  64. Hacking Tools For Windows Free Download
  65. Underground Hacker Sites
  66. Hacker Tools Windows
  67. Hacking Tools Windows
  68. Pentest Tools Android
  69. Pentest Tools For Windows
  70. Kik Hack Tools
  71. Hack App
  72. Hacking Tools And Software
  73. Hack Tools For Windows
  74. Hack Tools For Pc
  75. Game Hacking
  76. Hacking Tools For Beginners
  77. Hacker Tools Software
  78. Pentest Tools For Windows
  79. Hacks And Tools
  80. Hack Tools Pc
  81. Hackers Toolbox
  82. Underground Hacker Sites
  83. Hack Tool Apk
  84. Hacker Security Tools
  85. Hackrf Tools
  86. What Are Hacking Tools
  87. Pentest Tools Subdomain
  88. Pentest Tools Open Source
  89. Install Pentest Tools Ubuntu
  90. Hacking Tools For Windows 7
  91. Best Pentesting Tools 2018
  92. Hacker Tools For Ios
  93. Best Hacking Tools 2020
  94. Hacking Tools For Windows Free Download
  95. What Is Hacking Tools
  96. Pentest Tools Kali Linux
  97. Hacking Apps
  98. Hacker Security Tools
  99. Tools For Hacker
  100. Hack Tool Apk
  101. Hacker Tool Kit
  102. Hack Tools Download
  103. Hacking Tools Usb
  104. Hack Tool Apk No Root
  105. Hacker Search Tools
  106. Install Pentest Tools Ubuntu
  107. Growth Hacker Tools
  108. Pentest Tools Alternative
  109. Tools For Hacker
  110. Hack Tools Pc
  111. Hacker Tools For Windows
  112. Hak5 Tools
  113. Wifi Hacker Tools For Windows
  114. Pentest Recon Tools
  115. Hacking Tools Pc
  116. Pentest Tools Alternative
  117. Hacker Search Tools
  118. Game Hacking
  119. Best Hacking Tools 2020
  120. Hack Tool Apk
  121. Hacking Tools Pc
  122. Pentest Tools Website Vulnerability
  123. Hacking Tools Pc
  124. Pentest Tools Website Vulnerability
  125. Hack Tools Online
  126. Hacking Tools Kit
  127. Top Pentest Tools
  128. Pentest Tools Github
  129. Hack Tools
  130. Hacker Tools List
  131. Best Hacking Tools 2019
  132. Pentest Tools Url Fuzzer
  133. Hack Rom Tools
  134. Hack Apps
  135. Hacking Tools Github
  136. Pentest Tools Find Subdomains
  137. Pentest Tools For Android
  138. New Hacker Tools
  139. Pentest Tools For Windows
  140. Free Pentest Tools For Windows
  141. New Hack Tools
  142. Best Hacking Tools 2020
  143. Hacker Tools For Ios
  144. Easy Hack Tools
  145. Pentest Tools For Android
  146. Best Hacking Tools 2019
  147. Pentest Tools Free
  148. New Hacker Tools
  149. Hack Tools For Ubuntu
  150. Pentest Tools For Ubuntu
  151. What Are Hacking Tools
  152. Kik Hack Tools
  153. Hack Website Online Tool
  154. Easy Hack Tools
  155. Hack Tools
  156. Physical Pentest Tools
  157. Bluetooth Hacking Tools Kali
  158. Hack Tools Online
  159. Black Hat Hacker Tools
  160. Pentest Recon Tools
  161. Pentest Tools Website Vulnerability
  162. Hacking Tools
  163. Hacking Tools Pc
  164. Pentest Tools Framework
  165. Hacking Tools Online
  166. Pentest Tools Url Fuzzer
  167. Hack Tools
  168. Pentest Tools For Android
  169. Kik Hack Tools
  170. Hack Rom Tools
  171. Hacker Tools 2019
  172. Hack Tools For Games

No hay comentarios:

Publicar un comentario

Escríbe tus dudas, comentarios o sugerencias a:

Historia de la Educación

recetas de cocina