|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
From: Wong Yu Liang (wong.yuliang
vads.com)
Date: Tue Jul 21 2009 - 20:54:41 CDT
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Hi,
Not sure if anyone suggested syn flooding. Jolt is pretty cool.
Regards
Yuliang
-----Original Message-----
From: listbounce
securityfocus.com [mailto:listbounce
securityfocus.com] On Behalf Of Shankar Arjunan
Sent: Tuesday, July 21, 2009 3:18 PM
To: Benjamin Greenfield
Cc: pen-test
securityfocus.com
Subject: Re: DoS test on specific TCP Port
Hi Benjamin / All,
Thank you all for the responses.
It is for an inhouse application which is going to be live soon, before
going live thought of doing a stress test on specific port for DoS type
attacks and see the outcomes.
I will use hping and do a test.
Regards
Shankar
----- Original Message -----
From: "Benjamin Greenfield" <bcg
struxural.com>
To: <shankar.arjunan
gmail.com>
Cc: <pen-test
securityfocus.com>
Sent: Saturday, July 18, 2009 5:56 AM
Subject: Re: DoS test on specific TCP Port
You can try using hping3 to send out all sorts of traffic in all kinds
of different frequencies and bursts. However, the first thing you
should do is verify with your client that they consent to you trying a
DoS attack. Depending on application / service / OS is connected to
that port there may be particular vulnerabilities and / or exploits
that result in DoS conditions as well.
As far as determining the effectiveness of the attack, you'd need to
log all the incoming responses and evaluate them I suppose. I would
expect subtle differences would account for things like an IPS
blacklisting your IP versus the host actually going offline or slowing
due to load, and depending on the specifics it may not actually be
possible to determine what precisely occurred target-side happened.
Seriously, verify that the client wants you to test a DoS first though...
On Thu, Jul 16, 2009 at 9:18 PM, <shankar.arjunan
gmail.com> wrote:
> Dear All,
>
> I am performing a pentest on server, can anyone tell me if there is any
> script or tool or a method available to test a specific TCP port (eg:
> 1310) for server load test by doing DoS/DDoS type attacks. This is to
> check how the server responds for attack on specific port, any
> possibilities of server going down or to check any degrade of performance.
>
> Please advice.
>
> Regards
> Shankar
>
> ------------------------------------------------------------------------
> This list is sponsored by: Information Assurance Certification Review
> Board
>
> Prove to peers and potential employers without a doubt that you can
> actually do a proper penetration test. IACRB CPT and CEPT certs require a
> full practical examination in order to become certified.
>
> http://www.iacertification.org
> ------------------------------------------------------------------------
>
>
------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board
Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified.
http://www.iacertification.org
------------------------------------------------------------------------
DISCLAIMER
This message may contain confidential and privileged information for its intended recipient(s) only. If you are not an intended recipient, you are hereby notified that any review, dissemination and distribution, printing or copying of this message or any part thereof is strictly prohibited. Please delete the entire message and inform the sender of the error. Any opinions, conclusions and other information in this message that are unrelated to the official business of VADS Berhad are those of the individual sender and shall be understood as neither explicitly given nor endorsed by VADS Berhad. VADS Berhad does not authorise any of its employees to make any defamatory or seditious statements which is contrary to the laws of Malaysia. Any such communications by such employees are outside their scope of employment and VADS Berhad shall not be liable for such communications.
------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board
Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified.
http://www.iacertification.org
------------------------------------------------------------------------
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]