lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <CALCvwp7Q=FMAzOh3JG-RHFnnsZAHo7h9ovKNx2jOo8siT0jt5g@mail.gmail.com> Date: Tue, 1 Nov 2011 09:48:58 +1100 From: xD 0x41 <secn3t@...il.com> To: coderman <coderman@...il.com> Cc: full-disclosure@...ts.grok.org.uk Subject: Re: THC SSL DOS tool released make it. if JTR has it then, im sure a fairly decent c coder could... (hell i know i could...)... If this is something you like alot then, why wait for others . cheers. On 1 November 2011 09:37, coderman <coderman@...il.com> wrote: > On Tue, Oct 25, 2011 at 8:15 AM, BH <lists@...ckhat.bz> wrote: >>... >>> To make it more difficult to DOS servers using SSL, the protocol could >>> somehow be modified to challenge the client with some useless** ... >> >> One problem I can foresee with this is a way to scale this in a secure >> manner. > > no syn cookies for TLS :( yet, they mention proper fix on page: > disable renegotiation. use hw accel. > > > > speaking of GPUs: http://shader.kaist.edu/sslshader/ > > there are HSM+Accel cards that do 70k+ sessions/sec if you want the > hardware protection for your secrets in addition to performance. > > > > what i really want to know! > > when does thc-ssl-dos get GPU support? > > "Taking on larger server farms who make use of SSL Load balancer > required 20 average size laptops and about 120kbit/sec of traffic." - > what kind of shitty LB was this? an old as dirt F5 BigIP? > > _______________________________________________ > Full-Disclosure - We believe in it. > Charter: http://lists.grok.org.uk/full-disclosure-charter.html > Hosted and sponsored by Secunia - http://secunia.com/ > _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists