核弹级DDOS漏洞http2-bomb

核弹级DDOS漏洞http2-bomb
核弹级DDOS漏洞http2-bomb

网站支持http2并且没套cdn的佬友们要注意了 :melting_face:这个流量不大,但是直接持续占用服务器内存,一般vps抗不了一点。

Cyber Security News – 3 Jun 26

HTTP/2 Bomb — Remote DoS Exploit Hits nginx, Apache, IIS, Envoy, and...

A newly disclosed remote denial-of-service exploit dubbed "HTTP/2 Bomb" targets the default HTTP/2 configurations of the world's most widely deployed web servers, nginx, Apache httpd, Microsoft IIS, Envoy, and Cloudflare Pingora, enabling a single...

Est. reading time: 4 minutes

Server Amplification Demo Result Envoy 1.37.2 ~5,700:1 ~32 GB in ~10s Apache httpd 2.4.67 ~4,000:1 ~32 GB in ~18s nginx 1.29.7 ~70:1 ~32 GB in ~45s Microsoft IIS (Windows Server 2025) ~68:1 ~64 GB in ~45s

实测家用带宽单机随便打死我的nginx服务器 :melting_face:

image

3 个帖子 - 3 位参与者

阅读完整话题

来源: LinuxDo 最新话题查看原文