Courseiva

Slowloris DoS Attack: How Partial HTTP Requests Exhaust Server Resources

Which DoS attack exploits the HTTP protocol by sending partial HTTP requests to keep connections open, exhausting server resources?

Quick Answer

The answer is Slowloris. This Denial of Service attack exploits the HTTP protocol by sending partial HTTP requests—specifically, incomplete HTTP headers—to a web server, then maintaining those connections open indefinitely by periodically sending additional header fragments. Because the server waits for the request to complete before releasing the thread, each partial request consumes a server thread, and when enough connections are opened simultaneously, the server exhausts its thread pool and becomes unable to respond to legitimate traffic. On the Certified Ethical Hacker CEH exam, this question tests your understanding of application-layer DoS attacks versus network-layer floods; a common trap is confusing Slowloris with a SYN flood, but remember that Slowloris operates at Layer 7 using HTTP keep-alive mechanics. A useful memory tip: think of a slow-moving lizard—Slowloris sends headers slowly, one byte at a time, to keep the server waiting.

⚠ Common exam trap

EC-Council often tests the distinction between network-layer attacks (SYN flood, UDP flood) and application-layer attacks (Slowloris), so candidates mistakenly choose SYN flood because they associate 'partial requests' with TCP handshake manipulation rather than HTTP header manipulation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Slowloris

Slowloris is a DoS attack that exploits HTTP by opening multiple connections to the target web server and sending partial HTTP requests (e.g., incomplete headers) while never completing them. The server keeps each connection open, waiting for the rest of the request, eventually exhausting its connection pool and denying service to legitimate users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SYN flood

    Why it's wrong here

    SYN flood exhausts the TCP backlog with half-open handshakes, not HTTP-layer partial requests. It is tempting because it also holds connections open, and it is genuinely correct against any TCP service, but Slowloris-style attacks complete TCP and stall at the HTTP request stage.

  • ✓

    Slowloris

    Why this is correct

    Slowloris opens many connections to the target web server and sends partial HTTP headers repeatedly, never completing requests. This holds sockets open, exhausting the server's connection pool and denying legitimate clients, matching the stem's partial-request, resource-exhaustion constraint.

  • ✗

    Ping of Death

    Why it's wrong here

    Ping of Death sends oversized ICMP packets to crash a target's IP stack, unrelated to HTTP connection handling. It is tempting because it is a classic resource-exhaustion attack, and it is genuinely correct against unpatched ICMP implementations, but it never opens TCP sessions or partial HTTP requests.

  • ✗

    UDP flood

    Why it's wrong here

    UDP flood saturates bandwidth with connectionless datagrams, never opening or holding HTTP connections. It is tempting because it is a volumetric DoS, and it is genuinely correct against UDP-based services such as DNS or streaming, but it does not exploit HTTP request handling.

About these practice questions

This CEH question is part of Courseiva's 913-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CEH

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO of the following are examples of protocol-based DoS attacks? (Choose two.)

medium
  • ✓ A.Smurf attack
  • ✓ B.SYN flood
  • C.HTTP flood
  • D.Slowloris
  • E.UDP flood

Why A: A Smurf attack (A) is a protocol-based DoS attack because it abuses ICMP by sending echo requests to a network's broadcast address with a spoofed source IP, causing every host to reply to the victim and amplifying traffic. A SYN flood (B) is protocol-based because it exploits the TCP three-way handshake: the attacker sends many SYN packets with spoofed source addresses, filling the victim's half-open connection table so legitimate connections cannot complete. HTTP flood (C) and Slowloris (D) are application-layer (Layer 7) attacks that target web services rather than exploiting a network protocol's mechanics, and UDP flood (E) is a volumetric attack that simply overwhelms bandwidth with generic UDP datagrams rather than abusing a specific protocol behavior.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.