Burp Suite User Forum

Create new post

Slow Loris Test in BURP?

IAKOVENKO | Last updated: Aug 06, 2020 03:55PM UTC

Hello, Do you think you will add a Slow Loris Test feature ? Regards

Uthman, PortSwigger Agent | Last updated: Aug 07, 2020 10:06AM UTC

Can you provide more information on this? Is it used to test DoS attacks?

Zarkones | Last updated: Aug 20, 2020 12:48PM UTC

@Uthman, you're right. If I'm not mistaken the tool opens as much connections as it can, and sends a bit of data right before the timeout. That way it's denying the service to other users.

Uthman, PortSwigger Agent | Last updated: Aug 20, 2020 01:35PM UTC

Thanks. It looks like there are dedicated tools to look for this issue so I am not sure how helpful it would be to add it into Burp. - https://nmap.org/nsedoc/scripts/http-slowloris-check.html - https://tools.kali.org/stress-testing/slowhttptest Burp Scanner is generally interested in common web application vulnerabilities. I have raised a feature request for you.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.