This has been fixed in 2.2.16 by enabling the module mod-reqtimeout. It has been enabled by default in the next release in Debian already. I think this is an important fix for lucid that should be necessary. I have attached the debdiff and build log. I have ran ab against it and it has not affected my server. If you have any questions please let me know.
Regards chuck ** Summary changed: - apache2 DoS attack using slowloris + [FFE] apache2 DoS attack using slowloris -- [FFE] apache2 DoS attack using slowloris https://bugs.launchpad.net/bugs/392759 You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to apache2 in ubuntu. -- Ubuntu-server-bugs mailing list Ubuntu-server-bugs@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs