Sunday, 20 May 2012 11:18

HULK DDoS Tool Smash Web Servers

Written by 
Rate this item
(0 votes)
HULK DDoS Tool Smash Web Servers

Researchers from Kapersky Lab recently reported on a new distributed denial-of-service (DDoS) tool. The HTTP Unbearable Load King (HULK) tool is different from others of its kind in that it does not simply hit a server with a massive load of TCP SYN requests or other predictable packets.

Instead, HULK generates numerous unique requests designed to prevent server defenses from recognizing a pattern and filtering the attack traffic. The HULK DDoS tool is the work of Barry Shteiman, a security pro who developed it out of frustration with the obvious patterns produced by other such tools.

In order to confuse the target Web server as thoroughly as possible, Shteiman has included a number of different features in HULK, including the ability to hide the actual user agent and obfuscate the referrer for each request. In his own tests, Shteiman said that the attack tool had no trouble taking down a target server within a minute or so.

"Basically my test web server with 4gb of Ram running Microsoft IIS7 was brought to its knees under less than a minute, running all requests from a single host," Shteiman said.

Read 495 times Last modified on Tuesday, 22 May 2012 11:42
Rich Wermske

I am a native Houstonian, disabled American veteran, aspiring Buddhist, and a 40-Something information technology leader, paralegal, and management wonk, living life on life's terms, with my partner of eleven years.

While I still struggle with humility, I strive to make willingness, honesty, and open-mindedness a cornerstone in all my affairs. I work hard, and I believe I play well with others.  Eleven years of sobriety has taught me that none of "this" means a damn thing if I'm unwilling, dishonest, or close-minded.

While I've lived the roller-coaster, today I rarely have to defend or justify the actions of that person I see looking back at me in the mirror...

Website: www.wermske.com
I don't agree with all of this, but it's food for thought. -rw