Looking at thc-ssl-dos, it only affects SSL enabled web sites with renegotiations enabled.
I have been checking a few servers and have the following questions;
First; renegotiations are disabled by default on my Apache installations, so in what scenarios would I enable it?
Secondly; I have a dev box with a few vhosts on it, how can I enabled it (for the default site only) so I can test the effectiveness of this attack? I'm running apache2 on Debian squeeze.
Thank you.