Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 3426918
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 18, 20262026-05-18T06:46:25+00:00 2026-05-18T06:46:25+00:00

Problem: I found that certain sessions are sending a heavy burst of requests to

  • 0

Problem:

I found that certain sessions are sending a heavy burst of requests to some of my .aspx pages. Some of them are sending requests to my login page also. I tried to find out if this is a dictionary attack but on checking the IIS logs found that the csBytes is not varying for large number of requests. So, a dictionary attack is less likely. I then checked if somebody is trying a Denial of Service but that also seems unlikely since the burst subsides after a short duration (usually after a minute or so).

Some of the patterns that emerged while I was doing the investigation are:

  1. Some sessions are hitting my login page but in very small bursts. The peak hits/min. (including javascripts, images etc. and not just the page hits) went as high as 2k for some sessions but the total hits for that session may be 4-5K which means that something caused the spike but then the activity went back to normal. From these sessions some users also successfully logged in but they did nothing unusual and some of them are trusted users. I don’t suspect them to do anything weird. I have a hunch that this might be caused by a bug in the browser or in our application.
  2. Some sessions are hitting the login page big time — around 2.5k hits/min — but all these are GET requests which is weird. This could be a DoS attempt. The total hits have reached 20k for some of the sessions but there are other sessions where peak has touched .5K but avg activity/min could be as low as 20 requests. Most of these are coming from Firefox 3.6.x. I’m currently checking whether there’s any known issue in FF which may explain this because in this case our app is not even doing anything.

Technical Details:

  • Application was developed in ASP.NET 2.0
  • Deployed on
    IIS 7
  • Browsers causing issues:
    Firefox 3.6.x (sending huge amount of
    GET), IE 7/8 (POST requests to
    different pages)

I’ve given a bare-bone intro on the issue. Let me know if you require more information to dig further.

Update:
When I said that 20 requests/min from a session are normal I meant all requests including associated javascripts/images.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-18T06:46:25+00:00Added an answer on May 18, 2026 at 6:46 am

    You tagged this with ‘Security’, so I’m not 100% sure if you are really looking for possible errors in the application itself which could cause this, but anyway…

    Those rates are definitely not ‘natural’ – no normal, physical user would even (re)load a page a ‘mere’ 20-times per minute, much less the other times you have shown.

    I would first look at the payload of the requests in-depth and make sure there is nothing malicious there. You have a lot of log entries which seem to bear looking into more, to see if you are experiencing dictionary-type attacks, or perhaps even something else, like probing for XSS or SQL Injection vulnerabilities. Many of your ‘spurts’ seem to suggest some simple vulnerability probing, perhaps as opposed to dictionary attacks.

    But the methodology (and indeed, any tools/processes you would use) for mitigating attacks is very different from what you would be doing for potential application bugs causing unintended requests.


    For that, I would cross-reference the frequently-loaded URLs with the referer information in the logs for those requests, and verify that the referers are capable of producing such URLs; perhaps dynamically, or even client-side, via Ajax. Mis-used Ajax updates could actually be the cause, in fact. But if all the referer values on those hits are ‘incorrect’ or invalid, this is likely some sort of attack or probe, perhaps rather than an app bug.

    But if the referer info does lead to a valid page, you then at least have someplace to look.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I have found that I have no problem using require to load something like
I've found that there seems to be a problem using css transitions properties when
i have problem with libhid . i found that there 2 way 4 accessing
I am using a NamedParameterJdbcTemplate, but found that this problem is in the underlying
Searched a lot about this problem but never found a answer, that solved it.
Basically my problem is that i've adapted a piece of code found here http://social.msdn.microsoft.com/Forums/en-US/vemapcontroldev/thread/62e70670-f306-4bb7-8684-549979af91c1
I'm working on a problem that uses pointer arithmetic and I have found this
I have found that certain inputs cause the iteration over the matches to have
Using MVC2 Have a master-page that needs to hide certain menus if currently logged
I've run into the same problem as found in this question . However, I

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.