<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Any defenses against slow HTTP Post DOS? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/any-defenses-against-slow-http-post-dos/m-p/51065#M37577</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.darkreading.com/vulnerability_management/security/attacks/showArticle.jhtml?articleID=228000532&amp;amp;cid=nl_DR_daily_2010-11-02_html"&gt;http://www.darkreading.com/vulnerability_management/security/attacks/showArticle.jhtml?articleID=228000532&amp;amp;cid=nl_DR_daily_2010-11-02_html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just wondering if there is anything our PA can do to protect from this kind of exploit?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 02 Nov 2010 13:42:25 GMT</pubDate>
    <dc:creator>JKoss</dc:creator>
    <dc:date>2010-11-02T13:42:25Z</dc:date>
    <item>
      <title>Any defenses against slow HTTP Post DOS?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/any-defenses-against-slow-http-post-dos/m-p/51065#M37577</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.darkreading.com/vulnerability_management/security/attacks/showArticle.jhtml?articleID=228000532&amp;amp;cid=nl_DR_daily_2010-11-02_html"&gt;http://www.darkreading.com/vulnerability_management/security/attacks/showArticle.jhtml?articleID=228000532&amp;amp;cid=nl_DR_daily_2010-11-02_html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just wondering if there is anything our PA can do to protect from this kind of exploit?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Nov 2010 13:42:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/any-defenses-against-slow-http-post-dos/m-p/51065#M37577</guid>
      <dc:creator>JKoss</dc:creator>
      <dc:date>2010-11-02T13:42:25Z</dc:date>
    </item>
    <item>
      <title>Re: Any defenses against slow HTTP Post DOS?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/any-defenses-against-slow-http-post-dos/m-p/51066#M37578</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jim,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;We are looking into this. I'll send an update when I have more information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Sandeep &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Nov 2010 18:08:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/any-defenses-against-slow-http-post-dos/m-p/51066#M37578</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2010-11-02T18:08:28Z</dc:date>
    </item>
    <item>
      <title>Re: Any defenses against slow HTTP Post DOS?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/any-defenses-against-slow-http-post-dos/m-p/51067#M37579</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Anything happening with this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Sep 2013 15:48:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/any-defenses-against-slow-http-post-dos/m-p/51067#M37579</guid>
      <dc:creator>JKoss</dc:creator>
      <dc:date>2013-09-03T15:48:10Z</dc:date>
    </item>
    <item>
      <title>Re: Any defenses against slow HTTP Post DOS?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/any-defenses-against-slow-http-post-dos/m-p/51068#M37580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are a few candidates in the threatvault:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This event indicates that someone want to exhaust the apache resources, as described by slowloris.&lt;/P&gt;&lt;P&gt;&lt;A href="https://threatvault.paloaltonetworks.com/Home/ThreatDetail/40018" title="https://threatvault.paloaltonetworks.com/Home/ThreatDetail/40018"&gt;https://threatvault.paloaltonetworks.com/Home/ThreatDetail/40018&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This event indicates a DOS attack against IIS server.&lt;/P&gt;&lt;P&gt;&lt;A href="https://threatvault.paloaltonetworks.com/Home/ThreatDetail/40019" title="https://threatvault.paloaltonetworks.com/Home/ThreatDetail/40019"&gt;https://threatvault.paloaltonetworks.com/Home/ThreatDetail/40019&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Among others.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is also zone-protection but I cant find any good setting regarding "slow" connections in there (only stuff like number of concurrent sessions etc).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edit: Hopefully these docs might be helpful:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" data-containerid="2027" data-containertype="14" data-objectid="1746" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-1746"&gt;https://live.paloaltonetworks.com/docs/DOC-1746&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" data-containerid="2027" data-containertype="14" data-objectid="3767" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-3767"&gt;https://live.paloaltonetworks.com/docs/DOC-3767&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Sep 2013 18:48:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/any-defenses-against-slow-http-post-dos/m-p/51068#M37580</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-09-03T18:48:30Z</dc:date>
    </item>
  </channel>
</rss>

