Sunday, 9 November 2025
29.2 C
Singapore
26.9 C
Thailand
21 C
Indonesia
28.2 C
Philippines

New DDOS vulnerability threatens almost all websites

Discover the HTTP/2 Rapid Reset DDOS vulnerability that endangers nearly all websites, and learn about the urgent measures to protect against this severe threat.

A recent discovery of a DDOS vulnerability showcases a significant threat to nearly every website, sparking urgent actions from server software companies to devise patches for protection.

Understanding the HTTP/2 Rapid Reset vulnerability

This particular vulnerability exploits the HTTP/2 and HTTP/3 network protocols, which facilitate multiple data streams between a server and a browser. A browser can request numerous resources from a server and receive them all simultaneously instead of waiting for each resource to download sequentially.

The exploit, HTTP/2 Rapid Reset, was publicly shared by Cloudflare, Amazon Web Services (AWS), and Google. Many modern web servers operate on the HTTP/2 network protocol, and the lack of a software patch currently leaves virtually every server at risk. This new and unmitigated exploit is referred to as a zero-day exploit. However, on a brighter note, server software companies are actively developing patches to rectify the HTTP/2 security loophole.

How severe is the HTTP/2 Rapid Reset exploit?

The HTTP/2 network protocol has a server setting that limits the number of requests at any given moment, denying requests beyond this number. Another feature allows a request to be cancelled, removing that data stream from the preset request limit and freeing up the server to process another data stream.

The alarming part is that attackers can send millions of requests and cancellations to a server, completely overwhelming it. The HTTP/2 Rapid Reset exploit elevates the severity as servers currently have no defence against it. Cloudflare reported blocking a DDOS attack 300% larger than any previous DDOS attack, with Google reporting a DDOS attack exceeding 398 million requests per second (RPS).

This exploit’s sinister aspect is the trivial amount of resources required to launch an attack. Unlike traditional DDOS attacks requiring a substantial network of infected computers (a botnet), the HTTP/2 Rapid Reset exploit necessitates as few as 20,000 infected computers to initiate attacks three times larger than the most significant DDOS attacks ever recorded. This substantially lowers the bar for hackers to conduct devastating DDOS attacks.

How to safeguard against HTTP/2 Rapid Reset?

While patches are under development to address the HTTP/2 exploit, Cloudflare customers are already protected. As a temporary measure, in dire circumstances where a server is under attack and defenceless, Cloudflare suggests that server administrators could downgrade the HTTP network protocol to HTTP/1.1. Although this action may slow down server performance, it’s a preferable alternative to being offline.

Hot this week

Devialet: How Phantom Ultimate reflects the future of compact high-end sound

Devialet’s Phantom Ultimate shows how innovation, software, sustainability, and design are shaping the next era of compact high-end audio.

Crunchyroll Game Vault marks second anniversary with new game titles

Crunchyroll Game Vault celebrates its second anniversary with new titles, expanded features, and over 500 hours of ad-free gameplay.

Evotrex unveils hybrid RV trailer powered by battery and petrol engine

Former Anker employees launch Evotrex, a hybrid RV startup combining battery and petrol power to extend off-grid travel adventures.

Tenity concludes SingHacks 2025, Asia’s first fintech-focused agentic AI hackathon

Tenity concludes SingHacks 2025, Asia’s first fintech-focused agentic AI hackathon, ahead of its grand finals at Singapore FinTech Festival.

eight Telecom expands beyond mobile with 10Gbps home internet service

eight Telecom launches 10Gbps home broadband in Singapore, expanding beyond mobile with fast, reliable, and affordable connectivity.

Workato launches AI Lab in Singapore to drive applied AI innovation and workforce development

Workato opens its AI Lab in Singapore to accelerate applied AI innovation, create skilled jobs, and strengthen industry-academia collaboration.

Synology marks 25 years with launch of next-generation enterprise solutions

Synology celebrates its 25th anniversary with new AI-powered enterprise storage and cybersecurity solutions for digital transformation.

Meta introduces a quick connect shortcut for smart glasses

Meta’s new quick connect feature lets smart glasses users call or text with one touch, reducing reliance on “hey Meta” voice commands.

Square Enix cuts UK and US jobs as it shifts focus back to Japan

Square Enix lays off UK and US developers as it consolidates operations in Japan and expands its use of AI in game development.

Related Articles

Popular Categories