{"id":114790,"date":"2024-04-04T18:25:42","date_gmt":"2024-04-04T16:25:42","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/ataka-continuation-flood-privodyashhaya-k-problemam-na-serverah-ispolzuyushhih-http-2-0"},"modified":"2024-04-04T18:25:42","modified_gmt":"2024-04-04T16:25:42","slug":"ataka-continuation-flood-privodyashhaya-k-problemam-na-serverah-ispolzuyushhih-http-2-0","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/ataka-continuation-flood-privodyashhaya-k-problemam-na-serverah-ispolzuyushhih-http-2-0","title":{"rendered":"El ataque de Continuation flood est\u00e1 causando problemas en los servidores que utilizan HTTP\/2.0","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Se han revelado detalles sobre el m\u00e9todo de ataque \u00abContinuation flood\u00bb, que afecta a varias implementaciones del protocolo HTTP\/2, incluyendo Apache httpd, Apache Traffic Server, Node.js, oghttp, Go net\/http2, Envoy, oghttp y nghttp2. La vulnerabilidad puede ser utilizada para llevar a cabo ataques en servidores que soportan HTTP\/2.0 y, dependiendo de la implementaci\u00f3n, puede conducir a un agotamiento de memoria (interrupci\u00f3n del procesamiento de solicitudes o finalizaci\u00f3n inesperada de procesos) o a una alta carga en la CPU (retraso en el procesamiento de solicitudes). Seg\u00fan el investigador que descubri\u00f3 la vulnerabilidad, el problema identificado es m\u00e1s peligroso que la vulnerabilidad \u00abRapid Reset\u00bb encontrada el a\u00f1o pasado, la cual fue utilizada para llevar a cabo algunos de los ataques DDoS m\u00e1s grandes en ese momento.    <\/p>\n<p>El alto nivel de peligrosidad se explica por el hecho de que para interrumpir el funcionamiento <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/es\/server\/dts-los-angeles\/\"   title=\"servidores\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"3609\">servidores<\/a>, causar una finalizaci\u00f3n anormal o una disminuci\u00f3n grave del rendimiento, es suficiente con generar un flujo de solicitudes espec\u00edficamente dise\u00f1adas desde una computadora com\u00fan. En ciertos casos, incluso una sola conexi\u00f3n TCP puede ser suficiente para llevar a cabo el ataque. Adem\u00e1s, el tr\u00e1fico relacionado con el ataque no se distingue en los registros del tr\u00e1fico regular de los usuarios.      <\/p>\n<p>La vulnerabilidad se debe a caracter\u00edsticas en el procesamiento de los marcos HEADERS y CONTINUATION en las solicitudes del protocolo HTTP\/2. Los marcos HEADERS se utilizan en HTTP\/2 para transmitir encabezados HTTP, y los marcos CONTINUATION permiten dividir el env\u00edo de encabezados HTTP en varias etapas (por ejemplo, cuando los encabezados no caben en un \u00fanico marco o cuando en un principio se deben enviar encabezados que se pueden completar en el estado actual, y luego enviar los encabezados cuyos valores a\u00fan son indeterminados). Cuando se transmiten encabezados en m\u00faltiples etapas, inicialmente se env\u00eda un marco HEADERS sin la bandera END_HEADERS, seguido de varios marcos CONTINUATION con encabezados adicionales, y la lista se cierra con un marco CONTINUATION con la bandera END_HEADERS.      <\/p>\n<p>El m\u00e9todo de ataque consiste en enviar un flujo ininterrumpido de marcos CONTINUATION sin establecer la bandera END_HEADERS. Esta actividad resulta en la transmisi\u00f3n de <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/es\/server\/\"   title=\"servidor\" data-wpil-keyword-link=\"linked\">servidor<\/a> un gran n\u00famero de encabezados que el servidor mantiene en la memoria RAM hasta que se agote la memoria disponible para el proceso. Para generar una alta carga en la CPU, adem\u00e1s de agotar la memoria, un atacante puede aprovechar la compresi\u00f3n del contenido de los frames de CONTINUATION utilizando el formato HPACK, cuyo an\u00e1lisis requiere c\u00e1lculos. En las implementaciones del protocolo HTTP\/1.1 se aplic\u00f3 un l\u00edmite en el tama\u00f1o de los encabezados y un tiempo de espera para el env\u00edo de la conexi\u00f3n como protecci\u00f3n contra inundaciones de encabezados. Para HTTP\/2, debido a la complejidad del protocolo, muchas implementaciones no previeron tales m\u00e9todos de protecci\u00f3n contra el env\u00edo infinito de encabezados.      <\/p>\n<p>La vulnerabilidad representa un mayor peligro para los usuarios de Node.js (CVE-2024-27983), ya que esta implementaci\u00f3n permite provocar un fallo enviando solo algunos cuadros al servidor. Debido a una condici\u00f3n de carrera en Node.js, para activar un cierre inesperado mediante un error de verificaci\u00f3n Assert, basta con cerrar las conexiones mientras se env\u00eda un flujo de encabezados incompleto (se produce un fallo si durante el cierre de las conexiones a\u00fan no se ha recibido un cuadro CONTINUATION con la bandera END_HEADERS). La vulnerabilidad ha sido solucionada en Node.js 18.20.1, 21.7.2 y 20.12.1, as\u00ed como en las versiones recientes de las bibliotecas llhttp y undici. En las nuevas versiones de Node.js tambi\u00e9n se ha solucionado una vulnerabilidad menos peligrosa (CVE-2024-27982) de la clase \u00abrequest smuggling\u00bb, que permite inmiscuirse en el contenido de las solicitudes de otros usuarios, que se procesan en el mismo flujo entre el frontend y el backend mediante la manipulaci\u00f3n del valor de \u00abContent Length\u00bb.     <\/p>\n<p>Vulnerabilidades relacionadas con el manejo de CONTINUATION en otras implementaciones de HTTP\/2.0:    <\/p>\n<ul>\n<li class=\"l\"> oghttp (CVE-2024-27919) \u2014 consumo de memoria no limitado.\n<li class=\"l\"> Tempesta FW (CVE-2024-2758) \u2014 eludir restricciones.\n<li class=\"l\"> Biblioteca PHP amphp\/http, amphp\/http-client y amphp\/http-server (CVE-2024-2653) \u2014 consumo de memoria no limitado, hasta el agotamiento total de la memoria disponible.\n<li class=\"l\"> Paquete Go net\/http (CVE-2023-45288) \u2014 generaci\u00f3n de alta carga en la CPU.\n<li class=\"l\"> Biblioteca nghttp2 (CVE-2024-28182) \u2014 invocaci\u00f3n de denegaci\u00f3n de servicio.\n<li class=\"l\"> Apache Httpd (CVE-2024-27316) \u2014 consumo excesivo de memoria y carga en la CPU.\n<li class=\"l\"> Apache Traffic Server (CVE-2024-31309) \u2014 consumo excesivo de recursos.\n<li class=\"l\"> Envoy (CVE-2024-30255) \u2014 generaci\u00f3n de alta carga en la CPU (se requiere un flujo de 300Mbit\/s para la carga completa de un n\u00facleo de CPU).  <\/ul>\n<p>Fuente: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=60924\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u044b \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e\u0431 \u043c\u0435\u0442\u043e\u0434\u0435 \u0430\u0442\u0430\u043a\u0438 &#171;Continuation flood&#187;, \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u044e\u0449\u0435\u043c \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0435 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430 HTTP\/2, \u0441\u0440\u0435\u0434\u0438 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 Apache httpd, Apache Traffic Server, Node.js, oghttp, Go net\/http2, Envoy, oghttp \u0438 nghttp2. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043c\u043e\u0436\u0435\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u0434\u043b\u044f \u0441\u043e\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u044f \u0430\u0442\u0430\u043a \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u044b \u0441 \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u043e\u0439 HTTP\/2.0 \u0438 \u0432 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0438 \u043e\u0442 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043f\u0440\u0438\u0432\u043e\u0434\u0438\u0442 \u043a \u0438\u0441\u0447\u0435\u0440\u043f\u0430\u043d\u0438\u044e \u043f\u0430\u043c\u044f\u0442\u0438 (\u043f\u0440\u0435\u043a\u0440\u0430\u0449\u0435\u043d\u0438\u0435 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u0437\u0430\u043f\u0440\u043e\u0441\u043e\u0432 \u0438\u043b\u0438 \u0430\u0432\u0430\u0440\u0438\u0439\u043d\u043e\u0435 \u0437\u0430\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u0435 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432) \u0438\u043b\u0438 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-114790","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u044b \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e\u0431 \u043c\u0435\u0442\u043e\u0434\u0435 \u0430\u0442\u0430\u043a\u0438 &quot;Continuation flood&quot;, \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u044e\u0449\u0435\u043c \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0435 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430 HTTP\/2, \u0441\u0440\u0435\u0434\u0438 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 Apache httpd, Apache Traffic Server, Node.js, oghttp, Go net\/http2, Envoy, oghttp \u0438 nghttp2.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/ataka-continuation-flood-privodyashhaya-k-problemam-na-serverah-ispolzuyushhih-http-2-0\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0410\u0442\u0430\u043a\u0430 Continuation flood, \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u043a \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430\u043c \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0430\u0445, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e\u0449\u0438\u0445 HTTP\/2.0 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u044b \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e\u0431 \u043c\u0435\u0442\u043e\u0434\u0435 \u0430\u0442\u0430\u043a\u0438 &quot;Continuation flood&quot;, \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u044e\u0449\u0435\u043c \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0435 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430 HTTP\/2, \u0441\u0440\u0435\u0434\u0438 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 Apache httpd, Apache Traffic Server, Node.js, oghttp, Go net\/http2, Envoy, oghttp \u0438 nghttp2.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/ataka-continuation-flood-privodyashhaya-k-problemam-na-serverah-ispolzuyushhih-http-2-0\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2024-04-04T16:25:42+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2024-04-04T16:25:42+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Ataque Continuation flood, que causa problemas en servidores que utilizan HTTP\/2.0 | ProHoster","description":"Se han revelado detalles sobre el m\u00e9todo de ataque \"Continuation flood\", que afecta a varias implementaciones del protocolo HTTP\/2, incluyendo Apache httpd, Apache Traffic Server, Node.js, oghttp, Go net\/http2, Envoy, oghttp y nghttp2.","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/ataka-continuation-flood-privodyashhaya-k-problemam-na-serverah-ispolzuyushhih-http-2-0","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0410\u0442\u0430\u043a\u0430 Continuation flood, \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u043a \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430\u043c \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0430\u0445, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e\u0449\u0438\u0445 HTTP\/2.0 | ProHoster","og:description":"\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u044b \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e\u0431 \u043c\u0435\u0442\u043e\u0434\u0435 \u0430\u0442\u0430\u043a\u0438 &quot;Continuation flood&quot;, \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u044e\u0449\u0435\u043c \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0435 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430 HTTP\/2, \u0441\u0440\u0435\u0434\u0438 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 Apache httpd, Apache Traffic Server, Node.js, oghttp, Go net\/http2, Envoy, oghttp \u0438 nghttp2.","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/ataka-continuation-flood-privodyashhaya-k-problemam-na-serverah-ispolzuyushhih-http-2-0","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2024-04-04T16:25:42+00:00","article:modified_time":"2024-04-04T16:25:42+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"114790","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-02-22 15:41:47","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-22 21:24:22","updated":"2026-02-22 15:41:47","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/114790","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=114790"}],"version-history":[{"count":2,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/114790\/revisions"}],"predecessor-version":[{"id":172815,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/114790\/revisions\/172815"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=114790"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=114790"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=114790"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}