Threat Bulletin 0328: Slowloris against a online casino platform in Latin America
Slowloris against a online casino platform in Latin America, peaking at 128.5 million requests per second. Mitigated in 0.827 seconds.
Slowloris against a online casino platform in Latin America, peaking at 128.5 million requests per second. Mitigated in 0.827 seconds.
HTTP GET flood against a crypto exchange platform in Western Europe, peaking at 428.1 million requests per second. Mitigated in 0.144 seconds.
UDP reflection (DNS) against a retail banking platform in Western Europe, peaking at 253.2 Gbps. Mitigated in 0.770 seconds.
We get asked about credential stuffing volumes after the latest combo-list leak more than almost anything else, so here is the long answer.What actually happens during a floodThe first thing to fail…
HTTP POST flood against a municipal services platform in Western Europe, peaking at 146.5 million requests per second. Mitigated in 0.479 seconds.
WebSocket connection flood against a healthcare portal platform in the UK, peaking at 467.7 million requests per second. Mitigated in 0.913 seconds.
SYN flood against a airline booking platform in North America, peaking at 101.8 Gbps. Mitigated in 0.351 seconds.
login endpoint flood against a ticketing platform in Latin America, peaking at 292.6 million requests per second. Mitigated in 0.246 seconds.
HTTP/2 rapid reset against a sports betting platform in the Middle East, peaking at 464.1 million requests per second. Mitigated in 0.529 seconds.
Slowloris against a crypto exchange platform in the Benelux, peaking at 895.7 million requests per second. Mitigated in 0.658 seconds.
ACK flood against a news publisher platform in Southeast Asia, peaking at 247.8 Gbps. Mitigated in 0.256 seconds.
Over the last few months we have spent a lot of time on hacktivist floods around elections: a field guide. This is what we learned.What we got wrongOur first version challenged too…