Many Websites mix secure and insecure content on the same page, like
Facebook. This makes it possible to steal all the data entered on such a
page easily, using Moxie Marlinspike's SSLstrip tool. I will explain and
demonstrate this attack.
Slowloris is a very new layer 7 denial-of-service attack created by RSnake
that stops Apache web servers completely with very low bandwidth--one packet
every 2 seconds. The Apache developers were notified of this vulnerability
and decided it was unimportant and not worth patching. I will explain and
demonstrate this attack, and discuss various ways to protect your Apache
servers.
O'Reilly Media
Sam Bowne




