<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Kommentarer til: Using Varnish and iptables_recent to fend off Slowloris attacks on CentOS</title>
	<atom:link href="http://www.klittum.dk/2009/06/25/using-varnish-and-iptables_recent-to-fend-off-slowloris-attacks-on-centos/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.klittum.dk/2009/06/25/using-varnish-and-iptables_recent-to-fend-off-slowloris-attacks-on-centos/</link>
	<description>Vir prudens non contra ventum mingit</description>
	<lastBuildDate>Sun, 23 Aug 2009 13:35:39 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Af: Administrator</title>
		<link>http://www.klittum.dk/2009/06/25/using-varnish-and-iptables_recent-to-fend-off-slowloris-attacks-on-centos/comment-page-1/#comment-350</link>
		<dc:creator>Administrator</dc:creator>
		<pubDate>Sun, 23 Aug 2009 13:35:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.klittum.dk/2009/06/25/using-varnish-and-iptables_recent-to-fend-off-slowloris-attacks-on-centos/#comment-350</guid>
		<description>Hi André,

It appears to be a problem with Varnish, when it is recieving more than 4000 requests per second. This URL states so anyway:

http://osdir.com/ml/web.varnish.misc/2007-10/msg00003.html

4000+ requests/s is a very high number, and it is way beyond where Apache gives up, så my solution should still be valid in most cases. However, you may be able to tweak Varnish to handle this in some way - however, this must be up others to test. And please report back if successful.</description>
		<content:encoded><![CDATA[<p>Hi André,</p>
<p>It appears to be a problem with Varnish, when it is recieving more than 4000 requests per second. This URL states so anyway:</p>
<p><a href="http://osdir.com/ml/web.varnish.misc/2007-10/msg00003.html" rel="nofollow">http://osdir.com/ml/web.varnish.misc/2007-10/msg00003.html</a></p>
<p>4000+ requests/s is a very high number, and it is way beyond where Apache gives up, så my solution should still be valid in most cases. However, you may be able to tweak Varnish to handle this in some way &#8211; however, this must be up others to test. And please report back if successful.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Af: André Cardoso</title>
		<link>http://www.klittum.dk/2009/06/25/using-varnish-and-iptables_recent-to-fend-off-slowloris-attacks-on-centos/comment-page-1/#comment-348</link>
		<dc:creator>André Cardoso</dc:creator>
		<pubDate>Sun, 23 Aug 2009 08:53:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.klittum.dk/2009/06/25/using-varnish-and-iptables_recent-to-fend-off-slowloris-attacks-on-centos/#comment-348</guid>
		<description>Hi.
I followed your guide, but when I attack the server with slowloris and try to access a page through the browser, I just get a 200 OK, with empty content -- a blank page! So it seems that my varnish is not stopping slowloris!

Can you give me some help?</description>
		<content:encoded><![CDATA[<p>Hi.<br />
I followed your guide, but when I attack the server with slowloris and try to access a page through the browser, I just get a 200 OK, with empty content &#8212; a blank page! So it seems that my varnish is not stopping slowloris!</p>
<p>Can you give me some help?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
