Thursday, 1 May 2025
26.7 C
Singapore
30 C
Thailand
21 C
Indonesia
28.6 C
Philippines

New DDOS vulnerability threatens almost all websites

Discover the HTTP/2 Rapid Reset DDOS vulnerability that endangers nearly all websites, and learn about the urgent measures to protect against this severe threat.

A recent discovery of a DDOS vulnerability showcases a significant threat to nearly every website, sparking urgent actions from server software companies to devise patches for protection.

Understanding the HTTP/2 Rapid Reset vulnerability

This particular vulnerability exploits the HTTP/2 and HTTP/3 network protocols, which facilitate multiple data streams between a server and a browser. A browser can request numerous resources from a server and receive them all simultaneously instead of waiting for each resource to download sequentially.

The exploit, HTTP/2 Rapid Reset, was publicly shared by Cloudflare, Amazon Web Services (AWS), and Google. Many modern web servers operate on the HTTP/2 network protocol, and the lack of a software patch currently leaves virtually every server at risk. This new and unmitigated exploit is referred to as a zero-day exploit. However, on a brighter note, server software companies are actively developing patches to rectify the HTTP/2 security loophole.

How severe is the HTTP/2 Rapid Reset exploit?

The HTTP/2 network protocol has a server setting that limits the number of requests at any given moment, denying requests beyond this number. Another feature allows a request to be cancelled, removing that data stream from the preset request limit and freeing up the server to process another data stream.

The alarming part is that attackers can send millions of requests and cancellations to a server, completely overwhelming it. The HTTP/2 Rapid Reset exploit elevates the severity as servers currently have no defence against it. Cloudflare reported blocking a DDOS attack 300% larger than any previous DDOS attack, with Google reporting a DDOS attack exceeding 398 million requests per second (RPS).

This exploit’s sinister aspect is the trivial amount of resources required to launch an attack. Unlike traditional DDOS attacks requiring a substantial network of infected computers (a botnet), the HTTP/2 Rapid Reset exploit necessitates as few as 20,000 infected computers to initiate attacks three times larger than the most significant DDOS attacks ever recorded. This substantially lowers the bar for hackers to conduct devastating DDOS attacks.

How to safeguard against HTTP/2 Rapid Reset?

While patches are under development to address the HTTP/2 exploit, Cloudflare customers are already protected. As a temporary measure, in dire circumstances where a server is under attack and defenceless, Cloudflare suggests that server administrators could downgrade the HTTP network protocol to HTTP/1.1. Although this action may slow down server performance, it’s a preferable alternative to being offline.

Hot this week

Step inside Brooklyn’s cardboard coworking space for AI chatbots

Step inside Chat Haus, a clever cardboard coworking space for AI chatbots in Brooklyn. It offers a playful take on the future of creativity.

Google to end support for early Nest thermostats on October 25

Google will stop supporting first—and second-generation Nest thermostats on October 25 and end new Nest launches in Europe.

Content moderators around the world join forces to demand better conditions

Content moderators form a global alliance to demand better working conditions and mental health support from Big Tech companies.

Veeam report reveals nearly 70% of organisations still targeted by ransomware

Nearly 70% of organisations were hit by ransomware last year, says Veeam, urging stronger recovery strategies and proactive resilience.

Bowers & Wilkins unveil updated headphones and McLaren-themed earbuds in Singapore

Bowers & Wilkins launches Px7 S3 headphones and Pi8 McLaren earbuds in Singapore. These headphones blend high-quality sound with comfort and stylish design.

You can get DOOM: The Dark Ages free with select Nvidia graphics cards

Get DOOM: The Dark Ages Premium Edition free with select Nvidia RTX 50 GPUs until May 21, including in-game extras and early access.

Xiaomi enters China’s AI race with new model to power smart devices

Xiaomi joins China’s AI race with its new MiMo model, aiming to power devices with smarter tech and compete with big tech firms.

Samsung chip profits fall sharply due to US export controls and price drops

Samsung chip profits dropped 40% due to US export rules and price cuts as the company raced to catch up in AI memory production.

Chinese AI and robotics start-ups back Xi’s push for technological self-reliance

Chinese AI and robotics start-ups vow self-reliance after Xi visits Shanghai, showcasing innovation and commitment to homegrown tech.

Related Articles

Popular Categories