Which attack involves sending partial HTTP requests that leave the server waiting for completion?

Prepare for the Certified Ethical Hacker Version 11 Exam with a comprehensive test featuring flashcards and multiple choice questions, each accompanied by hints and explanations to ensure a thorough understanding. Ace your ethical hacking exam with confidence!

Multiple Choice

Which attack involves sending partial HTTP requests that leave the server waiting for completion?

Explanation:
Slowloris works by tying up a web server’s available connections with incomplete HTTP requests. It opens many connections to the target and sends only partial requests, then periodically sends additional header data to keep each connection alive and waiting for the rest of the request. Because the server must hold those connections open until the request is completed or timeouts occur, the pool of available connections fills up, preventing legitimate users from connecting and causing a denial of service. This behavior is distinctive: the attack relies on partial requests and anticipation of completion to exhaust resources rather than flooding with finished requests or using reflectors.

Slowloris works by tying up a web server’s available connections with incomplete HTTP requests. It opens many connections to the target and sends only partial requests, then periodically sends additional header data to keep each connection alive and waiting for the rest of the request. Because the server must hold those connections open until the request is completed or timeouts occur, the pool of available connections fills up, preventing legitimate users from connecting and causing a denial of service. This behavior is distinctive: the attack relies on partial requests and anticipation of completion to exhaust resources rather than flooding with finished requests or using reflectors.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy