<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: What needs to be put in place to protect web servers from DOS attacks?</title>
	<atom:link href="http://www.wrgross.com/blogs/security/2008/10/27/what-needs-to-be-put-in-place-to-protect-web-servers-from-dos-attacks/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.wrgross.com/blogs/security/2008/10/27/what-needs-to-be-put-in-place-to-protect-web-servers-from-dos-attacks/</link>
	<description>All manner of goodness respecting the secure operation of digital systems.</description>
	<pubDate>Tue, 07 Feb 2012 18:49:06 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.1</generator>
		<item>
		<title>By: Orlando Stevenson</title>
		<link>http://www.wrgross.com/blogs/security/2008/10/27/what-needs-to-be-put-in-place-to-protect-web-servers-from-dos-attacks/#comment-275</link>
		<dc:creator>Orlando Stevenson</dc:creator>
		<pubDate>Sat, 26 Dec 2009 08:00:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.wrgross.com/blogs/security/?p=164#comment-275</guid>
		<description>It's worth noting that one particularly nasty DOS attack is &lt;a href="http://en.wikipedia.org/wiki/Sockstress" rel="nofollow"&gt;SockStress&lt;/a&gt;.  It doesnt require much in the way of resources, just a stateful TCP connection to the target.   Migitations center on just not letting communication take place - i.e. filtering or blocking the attacking system.

More: &lt;a href="https://www.cert.fi/haavoittuvuudet/2008/tcp-vulnerabilities.html" rel="nofollow"&gt;CERT-FI Advisory on the Outpost24 TCP Issues&lt;/a&gt; provide a number of vendor responses to this issue.</description>
		<content:encoded><![CDATA[<p>It&#8217;s worth noting that one particularly nasty DOS attack is <a href="http://en.wikipedia.org/wiki/Sockstress" rel="nofollow">SockStress</a>.  It doesnt require much in the way of resources, just a stateful TCP connection to the target.   Migitations center on just not letting communication take place - i.e. filtering or blocking the attacking system.</p>
<p>More: <a href="https://www.cert.fi/haavoittuvuudet/2008/tcp-vulnerabilities.html" rel="nofollow">CERT-FI Advisory on the Outpost24 TCP Issues</a> provide a number of vendor responses to this issue.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

