{"id":82929,"date":"2020-05-26T19:42:01","date_gmt":"2020-05-26T17:42:01","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/rangeamp-seriya-atak-na-cdn-manipuliruyushhaya-http-zagolovkom-range"},"modified":"2020-05-26T19:42:01","modified_gmt":"2020-05-26T17:42:01","slug":"rangeamp-seriya-atak-na-cdn-manipuliruyushhaya-http-zagolovkom-range","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/rangeamp-seriya-atak-na-cdn-manipuliruyushhaya-http-zagolovkom-range","title":{"rendered":"RangeAmp \u2014 a series of attacks on CDN that manipulates the HTTP Range header","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>A group of researchers from Peking University, Tsinghua University, and the University of Texas at Dallas <noindex><a rel=\"nofollow\" href=\"https:\/\/www.liubaojun.org\/uploads\/1\/1\/8\/3\/118316462\/dsn_2020.pdf\">has identified<\/a><\/noindex> A new class of DoS attacks \u2014 RangeAmp, based on the use of the HTTP header <noindex><a rel=\"nofollow\" href=\"https:\/\/tools.ietf.org\/html\/rfc7233\">Range<\/a><\/noindex> to organize traffic amplification through content delivery networks (CDN). The essence of the method is that due to the way Range headers are processed in many CDNs, the attacker can request a single byte from a large file through the CDN, but the CDN will load the entire file or a significantly larger block of data from the target server for caching. The traffic amplification factor for such an attack, depending on the CDN, ranges from 724 to 43,330 times, which can be used to overwhelm the incoming traffic to the CDN or reduce the bandwidth of the communication channel to the victim's site.<\/p>\n<p><center><img decoding=\"async\" alt=\"RangeAmp - a series of attacks on CDNs that manipulate the HTTP Range header.\" src=\"\/wp-content\/uploads\/2020\/05\/45a7b48e01885f8ae50c3549e3293b12.png\" style=\"display:block;margin: 0 auto;\" \/><\/center><\/p>\n<p>The Range header allows the client to specify which byte ranges of a file to download instead of receiving the entire file. For example, the client can specify \"Range: bytes=0-1023\" and the server will only send the first 1024 bytes of data. This feature is useful for downloading large files \u2014 users can pause and then resume the download from where it was interrupted. Specifying \"bytes=0-0\" directs the server to send the first byte of the file, \"bytes=-1\" \u2014 the last byte, \"bytes=1-\" \u2014 from the first byte to the end of the file. Multiple ranges can be sent in a single header, e.g., \"Range: bytes=0-1023,8192-10240\".<\/p>\n<p>An additional second variant of the attack has been proposed, aimed at increasing network load by routing traffic through another CDN used as a proxy (for example, when Cloudflare acts as the front-end (FCDN) and Akamai as the back-end (BCDN)). This method resembles the first attack but is localized within CDN networks and allows for traffic amplification when accessed through other CDNs, increasing load on infrastructure and degrading service quality.  <\/p>\n<p>The idea is that the attacker sends Range requests to the CDN for multiple ranges, such as \"bytes=0-,0-,0-...\", \"bytes=1-,0-,0-...\" or \"bytes=-1024,0-,0-...\". These requests contain a large number of \"0-\" ranges, implying a request for the file from the starting position to its end. Due to incorrect implementation in the range parsing when the first CDN queries the second, each \"0-\" range returns the full file (the ranges are not aggregated but processed sequentially) if there is duplication and overlap in the ranges present in the initially sent attack request. The amplification factor in such an attack ranges from 53 to 7432 times.<\/p>\n<p><center><img decoding=\"async\" alt=\"RangeAmp - a series of attacks on CDNs that manipulate the HTTP Range header.\" src=\"\/wp-content\/uploads\/2020\/05\/981161394221a0548a04ec5961081c27.png\" style=\"display:block;margin: 0 auto;\" \/><\/center><\/p>\n<p>During the research, the behavior of 13 CDNs was studied \u2014<br \/>\nAkamai, Alibaba Cloud, Azure, CDN77, CDNsun, Cloudflare, CloudFront, Fastly, G-Core Labs, Huawei Cloud, KeyCDN, StackPath, and Tencent Cloud. All the reviewed CDNs were vulnerable to the first type of attack on the end server. The second type of attack on the CDN affected 6 services, of which four could act as a frontend in the attack (CDN77, CDNsun, Cloudflare, and StackPath) and three as a backend (Akamai, Azure, and StackPath). The highest amplification was achieved in Akamai and StackPath, which allow specifying more than 10,000 ranges in the Range header. CDN owners were notified of the vulnerabilities about 7 months ago, and by the time of public disclosure, 12 out of 13 CDNs had either fixed the identified issues or expressed willingness to do so (only StackPath did not respond).<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53026\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0413\u0440\u0443\u043f\u043f\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438\u0437 \u041f\u0435\u043a\u0438\u043d\u0441\u043a\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430, \u0423\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 \u0426\u0438\u043d\u0445\u0443\u0430 \u0438 \u0422\u0435\u0445\u0430\u0441\u0441\u043a\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 \u0432 \u0414\u0430\u043b\u043b\u0430\u0441\u0435 \u0432\u044b\u044f\u0432\u0438\u043b\u0430 \u043d\u043e\u0432\u044b\u0439 \u043a\u043b\u0430\u0441\u0441 DoS-\u0430\u0442\u0430\u043a &#8212; RangeAmp, \u043e\u0441\u043d\u043e\u0432\u0430\u043d\u043d\u044b\u0439 \u043d\u0430 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0438 HTTP-\u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043a\u0430 Range \u0434\u043b\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0443\u0441\u0438\u043b\u0435\u043d\u0438\u044f \u0442\u0440\u0430\u0444\u0438\u043a\u0430 \u0447\u0435\u0440\u0435\u0437 \u0441\u0435\u0442\u0438 \u0434\u043e\u0441\u0442\u0430\u0432\u043a\u0438 \u043a\u043e\u043d\u0442\u0435\u043d\u0442\u0430 (CDN). \u0421\u0443\u0442\u044c \u043c\u0435\u0442\u043e\u0434\u0430 \u0432 \u0442\u043e\u043c, \u0447\u0442\u043e \u0438\u0437-\u0437\u0430 \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 Range-\u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043a\u043e\u0432 \u0432\u043e \u043c\u043d\u043e\u0433\u0438\u0445 CDN \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0439 \u043c\u043e\u0436\u0435\u0442 \u0437\u0430\u043f\u0440\u043e\u0441\u0438\u0442\u044c \u0447\u0435\u0440\u0435\u0437 CDN \u043e\u0434\u0438\u043d \u0431\u0430\u0439\u0442 \u0438\u0437 \u0431\u043e\u043b\u044c\u0448\u043e\u0433\u043e \u0444\u0430\u0439\u043b\u0430, \u043d\u043e [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":82930,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-82929","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0413\u0440\u0443\u043f\u043f\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438\u0437 \u041f\u0435\u043a\u0438\u043d\u0441\u043a\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430, \u0423\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 \u0426\u0438\u043d\u0445\u0443\u0430 \u0438 \u0422\u0435\u0445\u0430\u0441\u0441\u043a\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 \u0432 \u0414\u0430\u043b\u043b\u0430\u0441\u0435\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/rangeamp-seriya-atak-na-cdn-manipuliruyushhaya-http-zagolovkom-range\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47RangeAmp \u2014 \u0441\u0435\u0440\u0438\u044f \u0430\u0442\u0430\u043a \u043d\u0430 CDN, \u043c\u0430\u043d\u0438\u043f\u0443\u043b\u0438\u0440\u0443\u044e\u0449\u0430\u044f HTTP-\u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043a\u043e\u043c Range | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0413\u0440\u0443\u043f\u043f\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438\u0437 \u041f\u0435\u043a\u0438\u043d\u0441\u043a\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430, \u0423\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 \u0426\u0438\u043d\u0445\u0443\u0430 \u0438 \u0422\u0435\u0445\u0430\u0441\u0441\u043a\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 \u0432 \u0414\u0430\u043b\u043b\u0430\u0441\u0435\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/rangeamp-seriya-atak-na-cdn-manipuliruyushhaya-http-zagolovkom-range\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-05-26T17:42:01+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-05-26T17:42:01+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47RangeAmp \u2014 a series of attacks on CDNs that manipulate the HTTP Range header | ProHoster","description":"A group of researchers from Peking University, Tsinghua University, and the University of Texas at Dallas.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/rangeamp-seriya-atak-na-cdn-manipuliruyushhaya-http-zagolovkom-range","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47RangeAmp \u2014 \u0441\u0435\u0440\u0438\u044f \u0430\u0442\u0430\u043a \u043d\u0430 CDN, \u043c\u0430\u043d\u0438\u043f\u0443\u043b\u0438\u0440\u0443\u044e\u0449\u0430\u044f HTTP-\u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043a\u043e\u043c Range | ProHoster","og:description":"\u0413\u0440\u0443\u043f\u043f\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438\u0437 \u041f\u0435\u043a\u0438\u043d\u0441\u043a\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430, \u0423\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 \u0426\u0438\u043d\u0445\u0443\u0430 \u0438 \u0422\u0435\u0445\u0430\u0441\u0441\u043a\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 \u0432 \u0414\u0430\u043b\u043b\u0430\u0441\u0435","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/rangeamp-seriya-atak-na-cdn-manipuliruyushhaya-http-zagolovkom-range","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-05-26T17:42:01+00:00","article:modified_time":"2020-05-26T17:42:01+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"82929","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 15:28:37","updated":"2022-10-02 22:54:20","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/82929","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=82929"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/82929\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/82930"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=82929"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=82929"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=82929"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}