HTTP/2 0day allows much larger DDoS attacks

A zero-day vulnerability named “HTTP/2 Rapid Reset” was used by users to initiate larger distributed denial-of-service (DDoS from distributed denial-of-service) in the history of the Internet. security 2023

One of the attacks recorded by Cloudflare it was three times larger than the record-breaking 71 million requests per second (RPS) attack reported by the company in February.

Specifically, the HTTP/2 Rapid Reset DDoS attack peaked at 201 RPS, while the observed a DDoS attack that peaked at 398 million RPS.

The new attack method uses a feature of HTTP/2 called 'stream cancellation', repeatedly sending a request and canceling it immediately.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).