Äú¿ÉÒÔ¾èÖú£¬Ö§³ÖÎÒÃǵĹ«ÒæÊÂÒµ¡£

1Ôª 10Ôª 50Ôª





ÈÏÖ¤Â룺  ÑéÖ¤Âë,¿´²»Çå³þ?Çëµã»÷Ë¢ÐÂÑéÖ¤Âë ±ØÌî



  ÇóÖª ÎÄÕ ÎÄ¿â Lib ÊÓÆµ iPerson ¿Î³Ì ÈÏÖ¤ ×Éѯ ¹¤¾ß ½²×ù Model Center   Code  
»áÔ±   
   
 
     
   
 ¶©ÔÄ
  ¾èÖú
»ª°²½âÃÜÖ®DDoS¹¥·À-07HTTPÔ­ÀíÆª HTTP POST Flood&ÂýËÙ¹¥»÷
 
×÷Õߣº»ª°²
  3230  次浏览      30
2020-9-1 
 
±à¼­ÍƼö:
±¾ÎÄÖ÷Òª½²½âÁËHTTP POST Flood¹¥»÷Óë·ÀÓù£¬°üÀ¨£ºÖض¨ÏòÈÏÖ¤¡¢ÑéÖ¤ÂëÈÏÖ¤¡¢URI¶¯Ì¬Ö¸ÎÆÑ§Ï°ºÍURIÐÐΪ¼à²â£¬ HTTPÂýËÙ¹¥»÷Óë·ÀÓù ϰüÀ¨£ºSlow Headers ¡¢Slow POSTµÈÄÚÈÝ¡£
±¾ÎÄÀ´×ÔÓÚ»ªÎªÆóÒµ»¥¶¯ÉçÇø£¬ÓÉ»ðÁú¹ûÈí¼þAnna±à¼­¡¢ÍƼö¡£

0x01 HTTP POST Flood¹¥»÷Óë·ÀÓù

Êé½ÓÉϻأ¬±¾ÆªÎÒÃÇÀ´½éÉÜHTTP POST Flood¹¥»÷ºÍHTTPÂýËÙ¹¥»÷µÄÔ­Àí¼°·ÀÓù·½Ê½£¬ÏÈÀ´¿´HTTP POST Flood¹¥»÷¡£¹¥»÷ÕßÀûÓù¥»÷¹¤¾ß»òÕß²Ù×ݽ©Ê¬Ö÷»ú£¬ÏòÄ¿±ê·þÎñÆ÷·¢Æð´óÁ¿µÄHTTP POST±¨ÎÄ£¬ÏûºÄ·þÎñÆ÷×ÊÔ´£¬Ê¹·þÎñÆ÷ÎÞ·¨ÏìÓ¦Õý³£ÇëÇó£¬Õâ¾ÍÊÇHTTP POST Flood¹¥»÷¡£

»ªÎªAnti-DDoS½â¾ö·½°¸·ÀÓùHTTP POST Flood¹¥»÷Óë·ÀÓùGET Flood¹¥»÷ÀàËÆ£¬³£ÓÃÊÖ¶ÎÒ²ÊÇÔ´ÈÏÖ¤£¬°üÀ¨Öض¨ÏòÈÏÖ¤ºÍÑéÖ¤ÂëÈÏÖ¤¡£

ÖØ¶¨ÏòÈÏÖ¤

Anti-DDoSϵͳ´úÌæ·þÎñÆ÷Ïò¿Í»§¶ËÏìÓ¦307״̬Â루Õë¶ÔPOSTÇëÇó·½·¨µÄÖØ¶¨Ïò£©£¬Í¬Ê±Ïò¿Í»§¶ËµÄä¯ÀÀÆ÷×¢ÈëCookie£¬¿Í»§¶ËÔٴη¢ÆðÇëÇóʱ»áÔÚHTTP±¨Í·Éϸ½¼ÓCookieÐÅÏ¢£¬Anti-DDoSÉèϵͳͨ¹ýÑéÖ¤CookieÐÅÏ¢µÄÕæÊµÐÔÀ´ÑéÖ¤¿Í»§¶Ë¡£

1¡¢µ±Á¬ÐøÒ»¶Îʱ¼äÄÚÈ¥ÍùÄ¿±êWeb·þÎñÆ÷µÄHTTP POSTÇëÇó±¨Îij¬¹ý¸æ¾¯ãÐÖµºó£¬Anti-DDoSϵͳÆô¶¯Ô´ÈÏÖ¤»úÖÆ¡£Ô´ÈÏÖ¤»úÖÆÆô¶¯ºó£¬Anti-DDoSϵͳ½«»á´úÌæ·þÎñÆ÷Óë¿Í»§¶Ë½¨Á¢TCPÈý´ÎÎÕÊÖ¡£

2¡¢Anti-DDoSϵͳÀ¹½ØHTTPÇëÇ󣬴úÌæWeb·þÎñÆ÷»ØÓ¦307״̬Â룬²¢ÔÚÏìӦͷ²¿¸½¼ÓÉÏÓɿͻ§¶ËIPÉú³ÉµÄCookie¡£

3¡¢Èç¹ûÕâ¸öÔ´ÊÇÐé¼ÙÔ´£¬»òÕß²»Ö§³ÖÍêÕûHTTPЭÒéÕ»µÄ¹¥»÷¹¤¾ß£¬²»»áÖØÐ·¢ÆðÇëÇó¡£

4¡¢Èç¹ûÕâ¸öÔ´ÊÇÕæÊµ¿Í»§¶Ë£¬Anti-DDoSϵͳÉú³ÉµÄCookie»áдÈëµ½ä¯ÀÀÆ÷ÖУ¬²¢ÇÒ¿Í»§¶Ë»áÖØÐ·¢ÆðÇëÇó£¬ÇëÇóÍ·²¿¾Í»á´øÓиÃCookieÐÅÏ¢¡£Anti-DDoSϵͳÊÕµ½ÇëÇóºó£¬ÑéÖ¤CookieÊÇ·ñÕýÈ·£¬Èç¹ûÕýÈ·Ôò½«¸Ã¿Í»§¶ËµÄÔ´IPµØÖ·¼ÓÈë°×Ãûµ¥¡£È»ºóAnti-DDoSϵͳ»á»ØÓ¦408״̬Â룬±íʾÇëÇó³¬Ê±£¬Ê¹¿Í»§¶ËÖØÐ·¢Æð·ÃÎÊ¡£

5¡¢ºóÐøÕâ¸ö¿Í»§¶Ë·¢³öµÄHTTPÇëÇó±¨ÎÄÃüÖа×Ãûµ¥Ö±½Óͨ¹ý¡£

ÎÒÃǽáºÏÒ»×é×¥°üÐÅÏ¢À´¿´Ò»Ï½»»¥±¨ÎĵľßÌåÇé¿ö¡£

1¡¢Anti-DDoSϵͳ´úÌæWeb·þÎñÆ÷Óë¿Í»§¶Ë½¨Á¢TCPÈý´ÎÎÕÊÖ£¬È»ºó¿Í»§¶Ë·¢Æð·ÃÎÊÇëÇó¡£

2¡¢Anti-DDoSϵͳ´úÌæWeb·þÎñÆ÷»ØÓ¦307״̬Â룬ͬʱÔÚÏìӦͷ²¿¸½¼ÓÉÏÓɿͻ§¶ËIPÉú³ÉµÄCookie£¬È»ºóË«·½¹Ø±ÕÁ¬½Ó¡£

3¡¢ÕæÊµ¿Í»§¶Ë»áÔÙ´ÎÓëAnti-DDoSϵͳ½¨Á¢TCPÈý´ÎÎÕÊÖ£¬²¢ÇÒ»áÖØÐ·¢ÆðÇëÇó£¬ÇëÇóÍ·²¿¾Í»á´øÓÐCookieÐÅÏ¢¡£

4¡¢Anti-DDoSϵͳÊÕµ½ÇëÇóºó£¬Í¨¹ýÑéÖ¤CookieÀ´Åж¨¸Ã¿Í»§¶ËÎªÕæÊµ¿Í»§¶Ë£¬½«ÆäIPµØÖ·¼ÓÈë°×Ãûµ¥¡£È»ºóAnti-DDoSϵͳ»á»ØÓ¦408״̬Â룬±íʾÇëÇó³¬Ê±£¬Ê¹¿Í»§¶ËÖØÐ·¢Æð·ÃÎÊ¡£

ÉÏÃæ½éÉܵÄ307ÖØ¶¨ÏòÈÏÖ¤·½Ê½Äܹ»ºÜºÃµØ·ÀÓùHTTP POST Flood¹¥»÷£¬µ«ÊÇÕâÖÖ·½Ê½Ò²¾ßÓÐÒ»¶¨µÄ¾ÖÏÞÐÔ¡£ÆäÒ»£¬ÒÀÀµÓÚ¿Í»§¶Ëä¯ÀÀÆ÷µÄCookieµÄ»úÖÆ£¬Êܰ²È«¼¶±ðÏÞÖÆ¡£Èç¹û¿Í»§¶ËµÄä¯ÀÀÆ÷°²È«¼¶±ð½Ï¸ß¶øÎÞ·¨Ð´ÈëCookie£¬»áµ¼ÖÂÈÏÖ¤²»Í¨¹ý£»Æä¶þ£¬µÚÒ»½×¶ÎÖØ¶¨Ïò½áÊøºó£¬ÐèÒª¿Í»§¶ËÔÙ´ÎÊÖ¶¯Ö´ÐÐÌá½»µÈ²Ù×÷£¬²ÅÄÜÖØÐ·¢ÆðPOSTÇëÇó¡£

ͬHTTP GET FloodµÄ·ÀÓù·½Ê½ÏàËÆ£¬HTTP POST FloodµÄÔ´ÈÏÖ¤·ÀÓùÒ²Ö§³ÖÔöÇ¿·½Ê½£¬¼´ÑéÖ¤ÂëÈÏÖ¤¡£

ÑéÖ¤ÂëÈÏÖ¤

´Ë´¦µÄÑéÖ¤ÂëÈÏÖ¤ÓëHTTP GET FloodÖеÄÑéÖ¤Âë»úÖÆÏàͬ£¬Anti-DDoSϵͳҪÇó¿Í»§¶ËÊäÈëÑéÖ¤Â룬ÒÔ´ËÀ´ÅжÏÇëÇóÊÇ·ñÓÉÕæÊµµÄÓû§·¢Æð¡£Æä±×¶ËÒ²ÊÇÐèÒªÈË»ú½»»¥ÊäÈëÑéÖ¤Â룬Óû§ÌåÑéÉÔ²îһЩ¡£¾ßÌåµÄ¹¤×÷Ô­ÀíÇë²Î¿¼HTTP GET Flood¹¥»÷Óë·ÀÓù²¿·ÖÖеĽéÉÜ£¬´Ë´¦²»ÔÙ׸Êö¡£

URI¶¯Ì¬Ö¸ÎÆÑ§Ï°ºÍURIÐÐΪ¼à²â

·ÀÓùHTTP POST Flood¹¥»÷ʱ£¬Ò²¿ÉÒÔʹÓÃURI¶¯Ì¬Ö¸ÎÆÑ§Ï°ºÍURIÐÐΪ¼à²â·ÀÓù·½Ê½£¬×÷ΪԴÈÏÖ¤·½Ê½µÄ²¹³ä£¬Âú×㲻ͬ³¡¾°µÄÐèÇ󡣯ä·ÀÓùÔ­ÀíÎÒÃÇÔÚÉÏÃæµÄHTTP GET Flood¹¥»÷Óë·ÀÓù²¿·ÖÖÐÒѾ­½éÉܹý£¬ÔÚ´ËÒ²²»×¸ÊöÁË¡£

Á˽âÁ½ÖÖFloodÀ๥»÷ºó£¬ÏÂÃæÎÒÃÇÀ´ÈÏʶÁíÍâÒ»ÖÖÕë¶ÔHTTPЭÒéµÄDDoS¹¥»÷£ºÂýËÙ¹¥»÷¡£ÓëFloodÀ๥»÷¿¿º£Á¿µÄÊý¾ÝºéÁ÷¡°ÑÍû¡±Ä¿±ê·þÎñÆ÷²»Í¬£¬ÂýËÙ¹¥»÷·´ÆäµÀ¶øÐÐÖ®£¬Í¨¹ý·¢ËͺÜÉÙµÄÊý¾ÝÀ´Î¬³ÖÁ¬½Ó״̬£¬³ÖÐøÏûºÄÄ¿±ê·þÎñÆ÷µÄ×ÊÔ´¡£

0x02 HTTPÂýËÙ¹¥»÷Óë·ÀÓù

HTTPÂýËÙ¹¥»÷ÊÇÀûÓÃHTTPЭÒéµÄÕý³£½»»¥»úÖÆ£¬ÏÈÓëÄ¿±ê·þÎñÆ÷½¨Á¢Ò»¸öÁ¬½Ó£¬È»ºó³¤Ê±¼ä±£³Ö¸ÃÁ¬½Ó²»ÊÍ·Å¡£Èç¹û¹¥»÷Õß³ÖÐøÓëÄ¿±ê·þÎñÆ÷½¨Á¢ÕâÑùµÄÁ¬½Ó£¬¾Í»áʹĿ±ê·þÎñÆ÷ÉϵĿÉÓÃ×ÊÔ´ºÄ¾¡£¬ÎÞ·¨ÌṩÕý³£·þÎñ¡£

HTTPÂýËÙ¹¥»÷Ö÷Òª°üÀ¨Õë¶ÔHTTPÇëÇó±¨ÎÄÍ·²¿½áÊø·ûµÄSlow Headers¹¥»÷£¬ÒÔ¼°Õë¶ÔPOSTÇëÇó±¨ÎÄÊý¾Ý³¤¶ÈµÄSlow POST¹¥»÷¡£

Slow Headers

ÎÒÃÇÔÚHTTPЭÒé»ù´¡²¿·ÖÖнéÉÜHTTPÇëÇó±¨ÎÄʱ£¬Ìáµ½¹ýÇëÇóÍ·²¿µÄºóÃæ»á´æÔÚÒ»¸ö¿ÕÐУ¨½áÊø·û£©£¬ÆäÖаüÀ¨»Ø³µ·ûºÍ»»Ðзû£¬¸æÖª·þÎñÆ÷ÇëÇóÍ·²¿½áÊø£¬ºóÃæ²»ÔÙÓÐÇëÇóÍ·¡£Èç¹û·þÎñÆ÷ûÓÐÊÕµ½Õâ¸ö¿ÕÐÐÔò»áÒ»Ö±±£³ÖÁ¬½Ó¡£

Slow Headers¹¥»÷ÕýÊÇÀûÓÃÕâÒ»µã£¬¹¥»÷ÕßʹÓÃGET»òPOSTÇëÇó·½·¨ÓëÄ¿±ê·þÎñÆ÷½¨Á¢Á¬½Ó£¬È»ºó³ÖÐø·¢ËͲ»°üº¬½áÊø·ûµÄHTTPÍ·²¿±¨ÎÄ£¬Ä¿±ê·þÎñÆ÷»áÒ»Ö±µÈ´ýÇëÇóÍ·²¿ÖеĽáÊø·û¶øµ¼ÖÂÁ¬½ÓʼÖÕ±»Õ¼Óá£Èç¹û¹¥»÷Õß¿ØÖÆ´óÁ¿µÄ½©Ê¬Ö÷»úÏòÄ¿±ê·þÎñÆ÷·¢ÆðÕâÖÖ¹¥»÷£¬½«»áµ¼Ö·þÎñÆ÷×ÊÔ´ºÄ¾¡£¬ÎÞ·¨Õý³£Ìṩ·þÎñ¡£

ÈçÏÂͼËùʾ£¬Õý³£µÄHTTP±¨ÎÄÖÐÇëÇóÍ·²¿µÄºóÃæ»áÓнáÊø·û0x0d0a£¨\r\nµÄÊ®Áù½øÖƱíʾ·½Ê½£©£¬¶ø¹¥»÷±¨ÎÄÖв»°üº¬½áÊø·û£¬²¢ÇÒ¹¥»÷Õß»á³ÖÐø·¢ËͲ»°üº¬½áÊø·ûµÄHTTPÍ·²¿±¨ÎÄ£¬Î¬³ÖÁ¬½Ó״̬£¬ÏûºÄÄ¿±ê·þÎñÆ÷µÄ×ÊÔ´¡£

Slow Headers¹¥»÷ÐÐΪµÄÌØÕ÷±È½ÏÃ÷ÏÔ£¬»ªÎªAnti-DDoS½â¾ö·½°¸·ÀÓùSlow Headers¹¥»÷ʱ£¬»á¶ÔHTTP±¨ÎĽøÐмì²é¡£Èç¹û·¢ÏÖij¸öÔ´·¢³öµÄÁ¬Ðø¶à¸öHTTP GET/POSTÇëÇó±¨Îĵı¨ÎÄÍ·Öж¼Ã»ÓнáÊø·û¡°\r\n¡±£¬ÔòÈÏΪ·¢ÉúSlow Headers¹¥»÷£¬½«¸ÃÔ´IPµØÖ·¼ÓÈëºÚÃûµ¥¡£

Slow POST

Slow POST¹¥»÷ÀûÓõÄÊÇPOSTÇëÇó·½·¨£¬¹¥»÷ÕßÏòÄ¿±ê·þÎñÆ÷·¢ËÍPOSTÇëÇó±¨ÎÄÌá½»Êý¾Ý£¬Êý¾ÝµÄ³¤¶ÈÉèÖÃΪһ¸öºÜ´óµÄÊýÖµ£¬µ«ÊÇÔÚËæºóµÄÊý¾Ý·¢ËÍÖУ¬Ã¿´ÎÖ»·¢ËͺÜСµÄ±¨ÎÄ£¬ÕâÑù¾ÍÊǵ¼ÖÂÄ¿±ê·þÎñÆ÷Ò»Ö±µÈ´ý¹¥»÷Õß·¢ËÍÊý¾Ý¡£Èç¹û¹¥»÷Õß¿ØÖÆ´óÁ¿µÄ½©Ê¬Ö÷»úÏòÄ¿±ê·þÎñÆ÷·¢ÆðÕâÖÖ¹¥»÷£¬½«»áµ¼Ö·þÎñÆ÷×ÊÔ´ºÄ¾¡£¬ÎÞ·¨Õý³£Ìṩ·þÎñ¡£

ÈçÏÂͼËùʾ£¬Slow POST¹¥»÷±¨ÎÄÖУ¬POSTÇëÇóÍ·²¿µÄContent-Length¹Ø¼ü×ÖµÄÖµÉèÖÃΪ8192£¬±íʾÊý¾Ý³¤¶ÈΪ8192×Ö½Ú£¬µ«Êǹ¥»÷ÕߺóÐøÃ¿´ÎÖ»·¢ËÍ1¸ö×ֽڵı¨ÎÄ£¬µ¼ÖÂÁ¬½ÓÒ»Ö±±»Õ¼Óã¬ÏûºÄÁË·þÎñÆ÷µÄ×ÊÔ´¡£

 

»ªÎªAnti-DDoS½â¾ö·½°¸·ÀÓùSlow POST¹¥»÷ʱ£¬·ÀÓù·½·¨Ò²ÊǶÔHTTP±¨ÎĽøÐмì²é¡£Èç¹û·¢ÏÖij¸öÔ´·¢³öµÄÁ¬Ðø¶à¸öHTTP POSTÇëÇó±¨Îĵij¤¶ÈÉèÖõĺܴ󣬵«ÊÇʵ¼Ê±¨ÎĵÄÊý¾Ý²¿·Ö³¤¶È¶¼ºÜС£¬ÔòÈÏΪ·¢ÉúSlow POST¹¥»÷£¬½«¸ÃÔ´IPµØÖ·¼ÓÈëºÚÃûµ¥¡£

ÖÁ´Ë£¬ÎÒÃǽ²½âÁËHTTPЭÒéµÄ»ù´¡ÖªÊ¶£¬²¢·ÖÎöÁËÕë¶ÔHTTPЭÒéµÄDDoS¹¥»÷·½Ê½ÒÔ¼°·ÀÓùÔ­Àí£¬

   
3230 ´Îä¯ÀÀ       30
 
Ïà¹ØÎÄÕÂ

iOSÓ¦Óð²È«¿ª·¢£¬Äã²»ÖªµÀµÄÄÇЩÊÂÊõ
Web°²È«Ö®SQL×¢Èë¹¥»÷
ÒÆ¶¯APP°²È«ÔÚÉøÍ¸²âÊÔÖеÄÓ¦ÓÃ
´ÓGoogle±¸·Ý»¥ÁªÍø¿´¡°Êý¾Ý°²È«¡±
 
Ïà¹ØÎĵµ

web°²È«Éè¼ÆÓë·À»¤
»¥ÁªÍøº£Á¿ÄÚÈݰ²È«´¦Àí¼¼Êõ
ºÚ¿Í¹¥»÷Óë·À·¶¼¼Êõ
WEBºÚºÐ°²È«¼ì²â
 
Ïà¹Ø¿Î³Ì

WEBÍøÕ¾ÓëÓ¦Óð²È«Ô­ÀíÓëʵ¼ù
webÓ¦Óð²È«¼Ü¹¹Éè¼Æ
´´½¨°²È«µÄJ2EE WebÓ¦ÓôúÂë
ÐÅÏ¢°²È«ÎÊÌâÓë·À·¶
×îл¼Æ»®
DeepSeekÔÚÈí¼þ²âÊÔÓ¦ÓÃʵ¼ù 4-12[ÔÚÏß]
DeepSeek´óÄ£ÐÍÓ¦Óÿª·¢Êµ¼ù 4-19[ÔÚÏß]
UAF¼Ü¹¹ÌåϵÓëʵ¼ù 4-11[±±¾©]
AIÖÇÄÜ»¯Èí¼þ²âÊÔ·½·¨Óëʵ¼ù 5-23[ÉϺ£]
»ùÓÚ UML ºÍEA½øÐзÖÎöÉè¼Æ 4-26[±±¾©]
ÒµÎñ¼Ü¹¹Éè¼ÆÓ뽨ģ 4-18[±±¾©]
 
×îÐÂÎÄÕÂ
ÎïÁªÍø°²È«¸ÅÊö
Ê·ÉÏ×îÏêϸµÄÇø¿éÁ´¼¼Êõ¼Ü¹¹·ÖÎö
Ò»ÎĶÁ¶®Çø¿éÁ´ÕûÌå¼Ü¹¹¼°Ó¦Óð¸Àý
Çø¿éÁ´¼¼Êõ¼Ü¹¹
°²È«¼Ü¹¹ÆÀÉóʵս
×îпγÌ
WebÓ¦Óð²È«¼Ü¹¹¡¢ÈëÇÖ¼ì²âÓë·À»¤
ÎïÁªÍø¹Ø¼ü¼¼Êõ¡¢°²È«Óë±ßÔµ¼ÆËã
Çø¿éÁ´°²È«¼¼Êõʵ¼ùÖ¸ÄÏ
ÔÆ·þÎñÓ밲ȫ¼Ü¹¹
»¥ÁªÍø°²È«¿ª·¢·½·¨Óëʵ¼ù
³É¹¦°¸Àý
ÖйúÒøÐÐ ÐÅÏ¢°²È«¼¼Êõ¼°Éî¶È·ÀÓù
±±¾© WebÓ¦Óð²È«¼Ü¹¹¡¢ÈëÇÖ¼ì²âÓë·À»¤
ij²ÆË°ÁìÓòÖªÃûIT·þÎñÉÌ Web°²È«²âÊÔ
ÆÕÈð¿Ë˹ web°²È«Éè¼Æ¡¢²âÊÔÓëÓÅ»¯
±±¾©ºÍÀûʱ ÐÔÄܺͰ²È«ÐÔ²âÊÔ