Thursday, 19 December 2024
28.1 C
Singapore

New DDOS vulnerability threatens almost all websites

Discover the HTTP/2 Rapid Reset DDOS vulnerability that endangers nearly all websites, and learn about the urgent measures to protect against this severe threat.

A recent discovery of a DDOS vulnerability showcases a significant threat to nearly every , sparking urgent actions from server software companies to devise patches for protection.

Understanding the HTTP/2 Rapid Reset vulnerability

This particular vulnerability exploits the HTTP/2 and HTTP/3 network protocols, which facilitate multiple data streams between a server and a browser. A browser can request numerous resources from a server and receive them all simultaneously instead of waiting for each resource to download sequentially.

The exploit, HTTP/2 Rapid Reset, was publicly shared by Cloudflare, Amazon Web Services (AWS), and Google. Many modern web servers operate on the HTTP/2 network protocol, and the lack of a software patch currently leaves virtually every server at risk. This new and unmitigated exploit is referred to as a zero-day exploit. However, on a brighter note, server software companies are actively developing patches to rectify the HTTP/2 loophole.

How severe is the HTTP/2 Rapid Reset exploit?

The HTTP/2 network protocol has a server setting that limits the number of requests at any given moment, denying requests beyond this number. Another feature allows a request to be cancelled, removing that data stream from the preset request limit and freeing up the server to process another data stream.

The alarming part is that attackers can send millions of requests and cancellations to a server, completely overwhelming it. The HTTP/2 Rapid Reset exploit elevates the severity as servers currently have no defence against it. Cloudflare reported blocking a DDOS attack 300% larger than any previous DDOS attack, with Google reporting a DDOS attack exceeding 398 million requests per second (RPS).

This exploit’s sinister aspect is the trivial amount of resources required to launch an attack. Unlike traditional DDOS attacks requiring a substantial network of infected computers (a botnet), the HTTP/2 Rapid Reset exploit necessitates as few as 20,000 infected computers to initiate attacks three times larger than the most significant DDOS attacks ever recorded. This substantially lowers the bar for hackers to conduct devastating DDOS attacks.

How to safeguard against HTTP/2 Rapid Reset?

While patches are under development to address the HTTP/2 exploit, Cloudflare customers are already protected. As a temporary measure, in dire circumstances where a server is under attack and defenceless, Cloudflare suggests that server administrators could downgrade the HTTP network protocol to HTTP/1.1. Although this action may slow down server performance, it’s a preferable alternative to being offline.

Hot this week

Twilio leads in the 2024-2025 IDC MarketScape for B2C customer data platforms

Discover why Twilio Segment leads in the IDC MarketScape for B2C Customer Data Platforms, featuring innovative AI and data management solutions.

Apple’s AI mishap sparks concerns after BBC headline blunder

Apple faces backlash after its AI notification feature falsely claims a BBC shooting suspect shot himself, prompting calls for urgent fixes.

YouTube partners with CAA to help creators combat AI copies of their likeness

YouTube collaborates with CAA to develop tools that help creators and celebrities track and remove AI-generated copies of their likenesses.

ChatGPT’s AI search engine is now available for all users

ChatGPT’s AI search engine is now available to all users, with mobile upgrades, faster searches, and exclusive features for paid subscribers.

Apple’s next AirTag could track items over longer distances

Apple’s next AirTag is expected to triple its tracking range with a new UWB chip, offering improved Precision Finding for locating items.

YouTuber reveals possible first look at Nintendo Switch 2 with new magnetic Joy-Cons

YouTuber NerdNest reveals a possible dummy model of the Nintendo Switch 2, showcasing magnetic Joy-Cons, larger screen size, and new features.

PlayStation and AMD collaborate to revolutionise gaming with AI

Sony and AMD partner to bring AI-powered gaming innovations, enhancing graphics and gameplay on PlayStation, PCs, and cloud platforms.

Intel outlines fixes to improve Arrow Lake CPU performance

Intel rolls out fixes for Arrow Lake CPU performance issues, addressing Windows updates, gaming optimisation, and future improvements at CES.

Sandisk unveils bold new rebrand

Sandisk unveils a bold rebrand with a modern logo inspired by data and collaboration, setting the stage for its spinoff from Western Digital.

Related Articles

Popular Categories