This DDoS Attack... 398 million requests per second. (A demo of HTTP/2 Rapid Reset)

preview_player
Показать описание
398 Million Requests Per Second. 155 Million Requests Per Second. 201 Millions Requests Per Second. Dem packets be flyin'. In this video, I explore and demo CVE-2023-44487, the novel HTTP/2 Rapid Reset Attack zero-day. A feature rather than an inherent bug.

⏰ Timestamps:
0:00 - Introduction
0:41 - Background Information
1:38 - HTTP/2 vs HTTP/1.1
4:27 - Demo (DDoS Apache2 Web Server)
10:11 - Mitigations
11:17 - Conclusion

🔗 Links Mentioned:

🐕 Follow Me:

🤔 Have questions, concerns, comments?:

🎧 Gear:

💻 Cybersecurity PC Build Parts
Рекомендации по теме
Комментарии
Автор

what kind of packets are being sent .. ICMP packets !

mnze
Автор

Add one more thing: DDoS'er s' favorite thing is also a dark room with big headset
8:45 Why not to try running it on low powered VM ? It would use the resources which you have given to it, so the illustration might be better.

machina
Автор

This is nothing to a well structured firewall 😂

thebello