- Slow Read. You may have heard of the Slowloris DDos attack on major credit processors in 2010. As it turns out, a variation of the attack that involves a malicious client very slowly reading responses has been found on virtually all of the most popular web servers.
- HPACK Bomb. Similar to a zip bomb or decompression bomb, an HPACK bomb is a compression layer attack that essentially involves sending a message that appears to be small, but unpacks to be gigabytes worth of data. All that information takes up all the available server memory resources and either slows it down or causes it to crash outright.
- Dependency Cycle Attack. By taking advantage of HTTP/2’s control mechanisms for network optimization, it’s possible for hackers to use special requests to create an infinite loop that can be used in a DoS attack.
- Stream Multiplexing. This another DoS attack vector that involves crashing a server by taking advantage of the stream multiplexing functionality.
Free, practical, and specific to regulated environments. We will email it to you.
No spam. Unsubscribe anytime.