A group of researchers has released a tool that they say implements a denial-of-service attack against SSL servers by triggering a huge number of SSL renegotiations. The tool exploits a widely known issue with the way that SSL connections work. The attack tool, released by a group called The Hacker s Choice, is meant to exploit the fact that it takes a lot of server resources to handle SSL handshakes at the beginning of a session. The authors of the tool say that the attack will work on servers without SSL renegotiation enabled, but with some modifications.
Source: https://threatpost.com/attack-tool-released-exploit-ssl-dos-issue-102411/75795/

