|
Hello, we're using the Acunetix vulnerability scanner to search for vulnerabilities in our application. Recently Acunetix discovered a slowloris vulnerability here : http://www.funtoo.org/wiki/Slowloris_DOS_Mitigation_Guide We're using Jetty Version 8.1.7.v20120910. Do you have any further knowledge of this vulnerability together with Jetty 8? It seems that the only possibility how this attack can be avoided is to set the maxIdleTime < 10sec which I do not like very much. Do you have any advice for me what I can do to avoid this finding, besides from setting the maxIdleTime so low? Thank you and best regards, René Hartwig --
René
Hartwig Befine
Solutions AG - The Cryptshare Company Tel: +49 (0) 761 38913
0 ========================================================================= Your attachments are
too large or too confidential for e-mail? ========================================================================= |
_______________________________________________ jetty-users mailing list [email protected] https://dev.eclipse.org/mailman/listinfo/jetty-users


