You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于Nginx防御Slow HTTP Post攻击的技术问询

Does My Nginx Frontend Setup Effectively Block Slow HTTP Post Attacks (Per Qualys' 120s Threshold)?

Great question—let’s break this down clearly, since Slow HTTP Post attacks exploit server resources by dragging out request sends, and Qualys flags any server letting connections stay open over 120s as vulnerable.

First: The Critical Nginx Directives That Stop This Attack

To mitigate Slow HTTP Post, you need these key settings in your Nginx config (either in the main nginx.conf or your site-specific server block):

  • client_body_timeout: This is the core defense against Slow Post. It defines how long Nginx will wait for the client to finish sending the entire request body. If the client takes longer than this value (e.g., sending 1 byte every minute), Nginx closes the connection immediately.
    Example config line:
    client_body_timeout 60s;
    
  • client_header_timeout: While this targets request headers (not the body), it’s part of a layered defense—stops attackers from dragging out header sends to hold connections open.
    Example:
    client_header_timeout 10s;
    
  • keepalive_timeout: Limits how long idle keepalive connections stay open after a request finishes, preventing attackers from hoarding unused connections.
    Example:
    keepalive_timeout 60s;
    

Does This Meet Qualys' 120s Standard?

If you’ve set client_body_timeout to any value less than 120 seconds (like the 60s example above), Nginx will terminate the connection long before Qualys’ vulnerability threshold is hit. This directly fixes the issue Qualys flagged—your server won’t let connections hang open for 120+ seconds while waiting for a partial POST body.

How to Test if It’s Actually Working

You can simulate a Slow Post attack with curl to verify your setup:

curl -X POST -H "Content-Type: application/x-www-form-urlencoded" --limit-rate 100b -d "large_payload=$(printf 'x%.0s' {1..100000})" http://your-server-domain

If Nginx closes the connection after your configured client_body_timeout (e.g., 60s) instead of letting it drag on past 120s, your defense is active and effective.

Extra Tips for Hardening

  • Add client_max_body_size to limit the maximum size of POST payloads—prevents attackers from sending absurdly large bodies slowly to tie up resources:
    client_max_body_size 10M;
    
  • Enable tcp_nopush and tcp_nodelay to optimize TCP connection handling, helping Nginx detect and close stale connections faster.

内容的提问来源于stack exchange,提问作者Puratchi Selvan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 08:44:31