CVE-2011-1473 fixed version

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



> I wasn't involved at the time, but reading about it now CVE-2011-1473
> essentially says (as I understand it) that if you fire lots of SSL
> handshakes at a server it could cause a DoS because it is much cheaper on
> the client side than it is on the server side.
That's pretty disingenuous. You can open lots of connections to a
server and eventually the server will exhaust resources. Sigh....

I've got an improvement on the attack: use a botnet to have
compromised hosts open one or two connections each to evade
firewalls....


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Index of Archives]     [Linux ARM Kernel]     [Linux ARM]     [Linux Omap]     [Fedora ARM]     [IETF Annouce]     [Security]     [Bugtraq]     [Linux]     [Linux OMAP]     [Linux MIPS]     [ECOS]     [Asterisk Internet PBX]     [Linux API]

  Powered by Linux