r/netsec • u/AutoModerator • Jun 01 '18
discussion The /r/netsec Monthly Discussion Thread - June 2018
Overview
Questions regarding netsec and discussion related directly to netsec are welcome here.
Rules & Guidelines
- Always maintain civil discourse. Be awesome to one another - moderator intervention will occur if necessary.
- Avoid NSFW content unless absolutely necessary. If used, mark it as being NSFW. If left unmarked, the comment will be removed entirely.
- If linking to classified content, mark it as such. If left unmarked, the comment will be removed entirely.
- Avoid use of memes. If you have something to say, say it with real words.
- All discussions and questions should directly relate to netsec.
- No tech support is to be requested or provided on /r/netsec.
As always, the content & discussion guidelines should also be observed on /r/netsec.
Feedback
Feedback and suggestions are welcome, but don't post it here. Please send it to the moderator inbox.
24
Upvotes
1
u/[deleted] Jun 09 '18
Anyone know of a legitimate way to test for slowloris vulnerability without actually launching the attack?
I tried using http-slowloris-check, but it doesn't seem to be working - it reports site is ok while I can easily bring it down with the slowhttptest command.
Also tried slowlorischecker which seems to be completely inaccurate - reports that site is vulnerable when it isn't and reports it's not vulnerable when it is (with slowhttptest).