This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "Testing for Denial of Service"
Amro Ahmed (talk | contribs) |
|||
(15 intermediate revisions by 4 users not shown) | |||
Line 1: | Line 1: | ||
− | + | {{Template:OWASP Testing Guide v3}} | |
− | {{Template:OWASP Testing Guide | ||
− | ''' 4. | + | ''' 4.9 Denial of Service Testing ''' |
---- | ---- | ||
− | + | A denial of service (DoS) attack is an attempt to make a resource unavailable to its legitimate users. | |
+ | Traditionally, denial of service (DoS) attacks have been network based: a malicious user floods a target machine with enough traffic to make it incapable of servicing its intended users. When the attack is launched by leveraging a large number of machines, the attack is typically called a distributed denial of service (DDoS) attack. In general, network DoS attacks are beyond the scope of what application developers can prevent within their own code. This type of “battle of the network pipes” is best mitigated via network architecture solutions. | ||
− | There are, however, types of vulnerabilities | + | There are, however, types of vulnerabilities at the application level that can allow a malicious user to make certain functionality or, sometimes, the entire website unavailable. These problems are caused by bugs in the application and often are triggered by malicious or unexpected user input. This section will focus on application layer attacks against availability that can be launched by just one malicious user on a single machine. |
− | Here are the DoS | + | Here are the DoS tests we will talk about: |
− | + | ||
− | #[[DoS | + | #[[Testing for SQL Wildcard Attacks (OWASP-DS-001)]] |
− | #[[DoS | + | #[[Testing for DoS Locking Customer Accounts (OWASP-DS-002)]] |
− | #[[DoS | + | #[[Testing for DoS Buffer Overflows (OWASP-DS-003)]] |
− | #[[ | + | #[[Testing for DoS User Specified Object Allocation (OWASP-DS-004)]] |
− | #[[ | + | #[[Testing for User Input as a Loop Counter (OWASP-DS-005)]] |
− | #[[DoS | + | #[[Testing for Writing User Provided Data to Disk (OWASP-DS-006)]] |
− | #[[ | + | #[[Testing for DoS Failure to Release Resources (OWASP-DS-007)]] |
+ | #[[Testing for Storing too Much Data in Session (OWASP-DS-008)]] | ||
==References== | ==References== | ||
− | Stephen de Vries, Application denial of service (DoS) attacks: http://www. | + | Stephen de Vries, Application denial of service (DoS) attacks: http://www.infosecwriters.com/text_resources/pdf/application_level_DoS_attacks.pdf<br> |
+ | HTTP Get and HTTP Post attacks: http://www.owasp.org/index.php/OWASP_HTTP_Post_Tool | ||
<br> | <br> | ||
− | |||
[[Category:Denial of Service Attack]] | [[Category:Denial of Service Attack]] |
Latest revision as of 16:51, 17 February 2013
OWASP Testing Guide v3 Table of Contents
This article is part of the OWASP Testing Guide v3. The entire OWASP Testing Guide v3 can be downloaded here.
OWASP at the moment is working at the OWASP Testing Guide v4: you can browse the Guide here
4.9 Denial of Service Testing
A denial of service (DoS) attack is an attempt to make a resource unavailable to its legitimate users. Traditionally, denial of service (DoS) attacks have been network based: a malicious user floods a target machine with enough traffic to make it incapable of servicing its intended users. When the attack is launched by leveraging a large number of machines, the attack is typically called a distributed denial of service (DDoS) attack. In general, network DoS attacks are beyond the scope of what application developers can prevent within their own code. This type of “battle of the network pipes” is best mitigated via network architecture solutions.
There are, however, types of vulnerabilities at the application level that can allow a malicious user to make certain functionality or, sometimes, the entire website unavailable. These problems are caused by bugs in the application and often are triggered by malicious or unexpected user input. This section will focus on application layer attacks against availability that can be launched by just one malicious user on a single machine.
Here are the DoS tests we will talk about:
- Testing for SQL Wildcard Attacks (OWASP-DS-001)
- Testing for DoS Locking Customer Accounts (OWASP-DS-002)
- Testing for DoS Buffer Overflows (OWASP-DS-003)
- Testing for DoS User Specified Object Allocation (OWASP-DS-004)
- Testing for User Input as a Loop Counter (OWASP-DS-005)
- Testing for Writing User Provided Data to Disk (OWASP-DS-006)
- Testing for DoS Failure to Release Resources (OWASP-DS-007)
- Testing for Storing too Much Data in Session (OWASP-DS-008)
References
Stephen de Vries, Application denial of service (DoS) attacks: http://www.infosecwriters.com/text_resources/pdf/application_level_DoS_attacks.pdf
HTTP Get and HTTP Post attacks: http://www.owasp.org/index.php/OWASP_HTTP_Post_Tool