Threat:
The web application is possibly vulnerable to a "slow HTTP POST" Denial of Service (DoS) attack. This is an application-level DoS that consumes server resources by maintaining open connections for an extended period of time by slowly sending traffic to the server. If the server maintains too many connections open at once, then it may not be able to respond to new, legitimate connections. Unlike bandwidth-consumption DoS attacks, the "slow" attack does not require a large amount of traffic to be sent to the server – only that the client is able to maintain open connections for several minutes at a time.
The attack holds server connections open by sending properly crafted HTTP POST headers that contain a Content-Length header with a large value to inform the web server how much of data to expect. After the HTTP POST headers are fully sent, the HTTP POST message body is sent at slow speeds to prolong the completion of the connection and lock up server resources. By waiting for the complete request body, the server is helping clients with slow or intermittent connections to complete requests, but is also exposing itself to abuse.
Impact:
All other services remain intact but the web server itself becomes inaccessible.
Solution:
The security vulnerability can be fixed by updating the Limits settings for the web site. For some customers, they have some web applications installed on the same web site, Flexera cannot update the settings for the whole web site. Please follow the below instructions to limit the size of the acceptable request to User Console to remediate the Slow HTTP Post vulnerability.
Steps:
- Open IIS settings
- Browse to the web site where User Console is installed to, the default is "Default Web Site"
- On the Actions panel, click "Limits"
- Set Connection time-out to 30
- Check "Limit number of connections" and set the value to 1024.
- Click OK
- Run iisreset.exe to restart IIS service and take effect.
Related Articles
User Console Configuration Wizard Fails at “Configure Flexera User Console” Step 7Number of Views Disable HTTP for Flexera Data Platform and User Console UI 6Number of Views Not supported special characters for Flexera Data Platfrom and User Console and Database Server 8Number of Views CVE-2024-9389: Data Platform User Console Command Execution Vulnerability 6Number of Views How to increase the Online timeout for User Console startup time 12Number of Views
Hi, I am Reva - Ask me anything.
No new updates
Thanks for the feedback!
Your feedback has been saved.Rate this response:
Add Additional feedback ( Optional )
Are you sure you want to cancel
the case creation?
Are you sure you want to cancel the case creation?
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
Revenera Assistant
Case id: 00001065
Activity: Status change: 2 hours ago