Home

Protecting the
Important Bits

News

Mitigate Microsoft's MS15-034 DoS

Denial of Service (DoS) exploits are widely available to exploit CVE-2015-1635/MS15-034, a vulnerability in HTTP.sys, affecting Microsoft Internet Information Server (IIS). For applications using Ishlangu Load Balancer ADC, the following uControl Script rule mitigates the vulnerability.

Based on initial reports on this vulnerability, the exploit is caused by using high values in the Range header of HTTP requests. The problem stems from HTTP.sys not safely handling the Range Header in a HTTP request; this mechanism is used to fetch part of a file from a server, which is sometimes handy for resuming downloads. If you set the range way too large, it causes the Windows kernel to crash.

The following uControl Script code can be added as a request rule for HTTP based proxies of Ishlangu Load Balancer ADC. The rule will check for high values of the Range header in a request and remove it if it exceeds a certain threshold.

Lastest news

Load Balance with TCP Fast Open

HTTP/2 Load Balancer

Mitigate Microsoft's MS15-034 DoS

What we do

  • Load Balancer
  • Firewall
  • Web Acceleration
  • Web Security
  • Application Scalability
  • Application Delivery

Get in touch

  • Elgar Drive
    Witham Essex
    CM8 1QD
    United Kingdom
  • +44 203 397 2168
  • shakatechs