Tau: Difference between revisions
Jump to navigation
Jump to search
(Created page with "Due to tau's spree of crashing, relevant information on tau will be recorded here for referencing [root@he shm]# date Wed Sep 21 20:09:55 PDT 2016 [root@he shm]# virt-fil...") |
(slowloris mitigation included) |
||
Line 1: | Line 1: | ||
tau is one of our webservers which hosts zinc12, zinc15, irwinlab, and dude18 | |||
===slowloris mitigation=== | |||
A slowloris attacker is causing websites hosted on the tau webserver to get hung up and connection timeout. ZINC12, ZINC15, irwinlab, and dude18 all hung during this time. I've determined this is due to a slowloris attack judging by the fact that /var/log/httpd/error_log displays the MaxClients value has been maxed out and that tau.compbio.ucsf.edu/server-status shows every single server socket getting occupied by a '..reading..' value. | |||
https://ma.ttias.be/effectively-using-detecting-the-slowloris-http-dos-tool/ | |||
Latest revision as of 23:33, 28 December 2018
tau is one of our webservers which hosts zinc12, zinc15, irwinlab, and dude18
slowloris mitigation
A slowloris attacker is causing websites hosted on the tau webserver to get hung up and connection timeout. ZINC12, ZINC15, irwinlab, and dude18 all hung during this time. I've determined this is due to a slowloris attack judging by the fact that /var/log/httpd/error_log displays the MaxClients value has been maxed out and that tau.compbio.ucsf.edu/server-status shows every single server socket getting occupied by a '..reading..' value.
https://ma.ttias.be/effectively-using-detecting-the-slowloris-http-dos-tool/