New DoS tool from THC: Another overhyped threat | InfoWorld That's what THC-SSL-DoS does: It initiates an SSL session, then rejects it, leaving the server to try again. The developers claim that the tool is even effective against server farms

THC•SSL•DOS - THC-SSL-DOS is a tool to verify the performance of SSL. Establishing a secure SSL connection requires 15x more processing power on the server than on the client.

The THC-SSL-DOS tool allows a single computer with a modest internet connection to crash a much more powerful server with vastly more bandwidth, but only when the server supports what’s known as SSL renegotiation, Monday’s postings claimed. Renegotiation is used to establish a new secret key securing communications after an encrypted

THC SSL Renegotiation DoS Tool for SMTP STARTTLS | alpacapowered The so called Secure Client-Initiated Renegotiation function of SSL/TLS suffers from a possible DoS danger because it burdens the server's CPU orders of magnitude more than the client's, who initiates it.

THC-SSL DOS was developed by a hacking group called The Hacker’s Choice (THC), as a proof-of-concept to encourage vendors to patch a serious SSL vulnerability. THC-SSL-DOS, as with other “low and slow” attacks, requires only a small number of packets to cause denial-of-service for a fairly large server. It works by initiating a regular