DDOS

188 views
Skip to first unread message

Batiste Blactot

unread,
Mar 15, 2022, 5:17:48 AM3/15/22
to OWASP ZAP User Group
Hello,

Another subject, is it possible to make a scan to check if my site can be attacked in DDOS? Because my current site has suffered DDOS attacks but I do not see where I would like if possible to launch a scan that can scan that to check if my site may be vulnerable to attacks

Cheers 

Batiste

Simon Bennetts

unread,
Mar 15, 2022, 5:58:24 AM3/15/22
to OWASP ZAP User Group
Hi Batiste,

We do not have a specific DDOS attack, especially as ZAP is not distributed.
However a ZAP active scan can put a significant strain on websites so if your site struggles with just one ZAP instance attacking it then it will _really_ struggle under a DDOS attack.
You could always launch multiple ZAP instances to attack the same site, but you would be constrained by the system they are running on unless you launched them on different systems.
We do not have explicit support for that but ZAP is designed to be easy to automate so there will be lots of 3rd party tools which can do this for you.

Cheers,

Simon

kingthorin+owaspzap

unread,
Mar 15, 2022, 10:05:50 AM3/15/22
to OWASP ZAP User Group
There is no point testing for DDoS. Whoever has more resources wins. You should just assume you're vulnerable to DDoS and take steps to protect yourself.
Reply all
Reply to author
Forward
0 new messages