Selamat Datang

Jumat, 02 Juni 2023

Vulcan DoS Vs Akamai

In the past I had to do several DoS security audits, with mĂșltiples types of tests and intensities. Sometimes several DDoS protections were present like Akamai for static content, and Arbor for absorb part of the bandwith.

One consideration for the DoS/DDoS tools is that probably it will loss the control of the attacker host, and the tool at least has to be able to stop automatically with a timeout, but can also implement remote response checks.

In order to size the minimum mbps needed to flood a service or to retard the response in a significant amount of time, the attacker hosts need a bandwith limiter, that increments in a logarithmic way up to a limit agreed with the customer/isp/cpd.

There are DoS tools that doesn't have this timeouts, and bandwith limit based on mbps, for that reason I have to implement a LD_PRELOAD based solution: bwcontrol

Although there are several good tools for stressing web servers and web aplications like apache ab, or other common tools used for pen-testing, but I also wrote a fast web flooder in c++ named wflood.

As expected the most effective for taking down the web server are the slow-loris, slow-read and derivatives, few host were needed to DoS an online banking. 
Remote attacks to database and highly dynamic web content were discarded, that could be impacted for sure.

I did another tool in c++ for crafting massive tcp/udp/ip malformed packets, that impacted sometimes on load balancers and firewalls, it was vulcan, it freezed even the firewall client software.

The funny thing was that the common attacks against Akamai hosts, where ineffective, and so does the slow-loris family of attacks, because are common, and the Akamai nginx webservers are well tunned. But when tried vulcan, few intensity was enough to crash Akamai hosts.

Another attack vector for static sites was trying to locate the IP of the customer instead of Akamai, if the customer doesn't use the Akamai Shadow service, it's possible to perform a HTTP Host header scan, and direct the attack to that host bypassing Akamai.

And what about Arbor protection? is good for reducing the flood but there are other kind of attacks, and this protection use to be disabled by default and in local holidays can be a mess.

Related posts


  1. Hacking Tools 2019
  2. How To Install Pentest Tools In Ubuntu
  3. Hacking Tools Name
  4. Hack App
  5. Tools 4 Hack
  6. Hacker Security Tools
  7. Hack Tools For Windows
  8. Pentest Tools Alternative
  9. How To Make Hacking Tools
  10. Pentest Recon Tools
  11. Hacker Tools List
  12. Pentest Tools Port Scanner
  13. Pentest Tools Review
  14. Best Hacking Tools 2019
  15. Hack Tools For Windows
  16. Hack Tools For Windows
  17. Pentest Tools Github
  18. Hacker Security Tools
  19. Bluetooth Hacking Tools Kali
  20. Nsa Hack Tools Download
  21. Pentest Tools Website
  22. Hacker Search Tools
  23. Hack Tools For Mac
  24. Hacker Security Tools
  25. Hacking Tools For Pc
  26. Hacking Tools Hardware
  27. Hacking Tools And Software
  28. Hacking Tools For Windows 7
  29. Hacker Tools Linux
  30. Hacker Tools 2019
  31. Pentest Automation Tools
  32. Wifi Hacker Tools For Windows
  33. Hacker Tools Github
  34. Hacker
  35. Pentest Tools Github
  36. Tools Used For Hacking
  37. Pentest Reporting Tools
  38. Hack Website Online Tool
  39. Hack Tools For Games
  40. Hacking Tools For Beginners
  41. Hacking Tools Download
  42. Pentest Tools
  43. Hack Tools For Pc
  44. Hack Tools For Windows
  45. New Hack Tools
  46. Hack Tools Pc
  47. Black Hat Hacker Tools
  48. Pentest Tools Subdomain
  49. Hacker Tools Mac
  50. Hacking Tools Online
  51. Hacking App
  52. Growth Hacker Tools
  53. What Are Hacking Tools
  54. What Are Hacking Tools
  55. Hacking Tools Hardware
  56. Hack App
  57. Hacker Tools Hardware
  58. Hacking Tools For Windows 7
  59. Pentest Tools Port Scanner
  60. Pentest Tools For Ubuntu
  61. Hackrf Tools
  62. Hacking Tools For Kali Linux
  63. Physical Pentest Tools
  64. Hacking Tools Pc
  65. Pentest Tools Nmap
  66. Hacking Tools For Mac
  67. Blackhat Hacker Tools
  68. Hack App
  69. Best Pentesting Tools 2018
  70. Hacker Tools For Windows
  71. Pentest Box Tools Download
  72. Pentest Tools Website Vulnerability
  73. Pentest Tools Url Fuzzer
  74. Hacker Tools Apk Download
  75. Android Hack Tools Github
  76. Hacking Tools For Pc
  77. Pentest Tools Website
  78. Hacker Tools
  79. Pentest Tools Review
  80. Hacker Tools For Ios
  81. What Are Hacking Tools
  82. Hacking Tools For Mac
  83. Hacking Tools Pc
  84. Hacker Search Tools
  85. Hacks And Tools
  86. Wifi Hacker Tools For Windows
  87. Hacks And Tools
  88. Hacker Tools For Mac
  89. Pentest Tools
  90. Hacking Tools Github
  91. Tools 4 Hack
  92. Hacking Tools For Windows Free Download
  93. Pentest Tools Review
  94. How To Hack
  95. Hacking Tools For Windows
  96. Hack And Tools
  97. Hacker Tools Windows
  98. Hacker Tools 2019
  99. Hacker Tools
  100. Pentest Tools Framework
  101. Hacking Tools Github
  102. Hack Tools Mac
  103. Hacking Tools 2020
  104. Pentest Tools Free
  105. Hack Tools Pc
  106. Hacker Tools
  107. Hacking Tools Mac
  108. Black Hat Hacker Tools
  109. Pentest Tools Open Source
  110. Hack Tools
  111. Pentest Reporting Tools
  112. Pentest Tools Nmap
  113. Hackers Toolbox
  114. Hacks And Tools
  115. Hacker
  116. Hack Tools For Windows
  117. Hack Tools
  118. Hacker Tools List
  119. Hacking Tools For Windows Free Download
  120. Hacker Tools 2019
  121. Hacker
  122. Tools Used For Hacking
  123. Hacking Tools Hardware
  124. Hack Tools For Pc
  125. Hacking Tools For Mac
  126. Pentest Tools Nmap
  127. Pentest Tools Apk
  128. Pentest Tools Download
  129. World No 1 Hacker Software
  130. Hack Tools For Windows
  131. Hacking Tools For Windows
  132. Hacking Tools For Kali Linux
  133. Beginner Hacker Tools
  134. Pentest Recon Tools
  135. Pentest Tools For Ubuntu
  136. Top Pentest Tools
  137. Hacker Tools Mac
  138. Pentest Tools Port Scanner
  139. Hack Tools Online
  140. Hacker Tools For Pc
  141. Hacking Tools Usb
  142. Hacker Hardware Tools
  143. Pentest Tools Website Vulnerability
  144. Pentest Tools Website Vulnerability
  145. Hack Tools For Pc
  146. Hack Tools For Ubuntu
  147. Hacker Tools Hardware
  148. Hack Tools For Ubuntu
  149. Top Pentest Tools
  150. Hacking Tools Mac
  151. Hacking Tools Usb
  152. Pentest Tools
  153. Best Hacking Tools 2019
  154. Pentest Tools Android
  155. Underground Hacker Sites
  156. Hacking Tools Mac
  157. How To Hack
  158. Hack And Tools
  159. Hacker Hardware Tools
  160. Pentest Tools Review
  161. Hack Tools Pc
  162. Pentest Tools Free
  163. Pentest Automation Tools
  164. Black Hat Hacker Tools
  165. Physical Pentest Tools
  166. Pentest Tools Review
  167. Hack Website Online Tool
  168. Blackhat Hacker Tools
  169. Wifi Hacker Tools For Windows
  170. Hack Tool Apk No Root

Tidak ada komentar:

Posting Komentar