Slowloris DoS Attack: How Partial HTTP Requests Exhaust Server Resources
Which DoS attack exploits the HTTP protocol by sending partial HTTP requests to keep connections open, exhausting server resources?
Quick Answer
The answer is Slowloris. This Denial of Service attack exploits the HTTP protocol by sending partial HTTP requests—specifically, incomplete HTTP headers—to a web server, then maintaining those connections open indefinitely by periodically sending additional header fragments. Because the server waits for the request to complete before releasing the thread, each partial request consumes a server thread, and when enough connections are opened simultaneously, the server exhausts its thread pool and becomes unable to respond to legitimate traffic. On the Certified Ethical Hacker CEH exam, this question tests your understanding of application-layer DoS attacks versus network-layer floods; a common trap is confusing Slowloris with a SYN flood, but remember that Slowloris operates at Layer 7 using HTTP keep-alive mechanics. A useful memory tip: think of a slow-moving lizard—Slowloris sends headers slowly, one byte at a time, to keep the server waiting.
⚠ Common exam trap
EC-Council often tests the distinction between network-layer attacks (SYN flood, UDP flood) and application-layer attacks (Slowloris), so candidates mistakenly choose SYN flood because they associate 'partial requests' with TCP handshake manipulation rather than HTTP header manipulation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Slowloris
Slowloris is a DoS attack that exploits HTTP by opening multiple connections to the target web server and sending partial HTTP requests (e.g., incomplete headers) while never completing them. The server keeps each connection open, waiting for the rest of the request, eventually exhausting its connection pool and denying service to legitimate users.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SYN flood
Why it's wrong here
SYN flood exhausts the TCP backlog with half-open handshakes, not HTTP-layer partial requests. It is tempting because it also holds connections open, and it is genuinely correct against any TCP service, but Slowloris-style attacks complete TCP and stall at the HTTP request stage.
- ✓
Slowloris
Why this is correct
Slowloris opens many connections to the target web server and sends partial HTTP headers repeatedly, never completing requests. This holds sockets open, exhausting the server's connection pool and denying legitimate clients, matching the stem's partial-request, resource-exhaustion constraint.
- ✗
Ping of Death
Why it's wrong here
Ping of Death sends oversized ICMP packets to crash a target's IP stack, unrelated to HTTP connection handling. It is tempting because it is a classic resource-exhaustion attack, and it is genuinely correct against unpatched ICMP implementations, but it never opens TCP sessions or partial HTTP requests.
- ✗
UDP flood
Why it's wrong here
UDP flood saturates bandwidth with connectionless datagrams, never opening or holding HTTP connections. It is tempting because it is a volumetric DoS, and it is genuinely correct against UDP-based services such as DNS or streaming, but it does not exploit HTTP request handling.
Go deeper
Related to this question
About these practice questions
This CEH question is part of Courseiva's 913-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CEH
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO of the following are examples of protocol-based DoS attacks? (Choose two.)
medium- ✓ A.Smurf attack
- ✓ B.SYN flood
- C.HTTP flood
- D.Slowloris
- E.UDP flood
Why A: A Smurf attack (A) is a protocol-based DoS attack because it abuses ICMP by sending echo requests to a network's broadcast address with a spoofed source IP, causing every host to reply to the victim and amplifying traffic. A SYN flood (B) is protocol-based because it exploits the TCP three-way handshake: the attacker sends many SYN packets with spoofed source addresses, filling the victim's half-open connection table so legitimate connections cannot complete. HTTP flood (C) and Slowloris (D) are application-layer (Layer 7) attacks that target web services rather than exploiting a network protocol's mechanics, and UDP flood (E) is a volumetric attack that simply overwhelms bandwidth with generic UDP datagrams rather than abusing a specific protocol behavior.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.