{"id":140668,"date":"2025-08-14T11:12:07","date_gmt":"2025-08-14T09:12:07","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-realizacziyah-protokola-http-2-uproshhayushhaya-provedenie-dos-atak"},"modified":"2025-08-14T11:12:07","modified_gmt":"2025-08-14T09:12:07","slug":"uyazvimost-v-realizacziyah-protokola-http-2-uproshhayushhaya-provedenie-dos-atak","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-v-realizacziyah-protokola-http-2-uproshhayushhaya-provedenie-dos-atak","title":{"rendered":"Vulnerabilit\u00e0 nelle implementazioni del protocollo HTTP\/2, che facilita l'esecuzione di attacchi DoS.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>\u00c8 stata presentata una nuova tecnica di attacco alle implementazioni del protocollo HTTP\/2, che semplifica l'esecuzione di attacchi di denial of service attraverso l'esaurimento delle risorse del server. La vulnerabilit\u00e0 ha ricevuto il nome in codice MadeYouReset e consente, tramite manipolazioni dei frame di controllo HTTP\/2, di inondare il server con un numero elevato di richieste bypassando i vincoli impostati.     <\/p>\n<p>Il problema principale \u00e8 che il client pu\u00f2 creare un numero molto elevato di stream elaborati contemporaneamente, indipendentemente dal limite SETTINGS_MAX_CONCURRENT_STREAMS, resettando ogni stream nelle fasi iniziali. Un tale reset si traduce nel fatto che, per inviare una nuova richiesta nella connessione HTTP\/2 stabilita, il client non \u00e8 tenuto ad attendere una risposta da <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/it\/server\/dts-los-angeles\/\"   title=\"server\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"3975\">server<\/a> e pu\u00f2 immediatamente inviare un grande flusso continuo di richieste, per quanto consentito dalla larghezza di banda della connessione.       <\/p>\n<p>Il client smette di dipendere dai ritardi tra l'invio della richiesta e il ricevimento della risposta (RTT, round-trip time) e pu\u00f2 effettuare l'attacco con costi minimi, mentre il server continua a utilizzare risorse per elaborare le richieste in arrivo. Ad esempio, il server deve allocare strutture dati per i nuovi stream, analizzare la richiesta, decomprimere l'intestazione e mappare l'URL con le risorse. In caso di attacco a proxy inversi, l'attacco pu\u00f2 propagarsi verso i backend a cui il proxy riesce a reindirizzare la richiesta prima del suo reset.    <\/p>\n<p>La vulnerabilit\u00e0 ricorda un problema noto in precedenza, Rapid Reset (CVE-2023-44487), ed \u00e8 causata da discrepanze nella logica di reset degli stream definita nella specifica del protocollo HTTP\/2 e quella attuata nei prodotti finali. Nella specifica \u00e8 prevista la possibilit\u00e0 di reset da parte del client e del server in qualsiasi momento, ma in molte implementazioni di HTTP\/2,<a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/it\/server\/\"   title=\"server\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"1779\">server<\/a> dopo tale reset, la richiesta continua a essere elaborata. La principale distinzione del nuovo attacco \u00e8 che il reset dell'elaborazione della richiesta avviene su iniziativa del server, piuttosto che tramite l'invio da parte del client di un frame con il flag RST_STREAM.     <\/p>\n<p>Il ripristino su iniziativa del server avviene quando si ricevono richieste non valide, ma tali richieste vengono scartate immediatamente senza nessun inizio di elaborazione completa e senza essere inviate al backend. Per completare il ciclo di elaborazione della richiesta, l'attaccante pu\u00f2 inizialmente inviare una richiesta HTTP valida, seguita da una sequenza non valida di frame di controllo HTTP\/2. Tale attivit\u00e0 porter\u00e0 il server a elaborare completamente la richiesta, ma poi, a causa di un errore nella gestione dei frame successivi, resetter\u00e0 il flusso (portando il flusso con la richiesta valida nello stato RST_STREAM).    <center><img decoding=\"async\" alt=\"Vulnerabilit\u00e0 nelle implementazioni del protocollo HTTP\/2, che facilita l&#039;esecuzione di attacchi DoS.\" src=\"\/wp-content\/uploads\/2025\/08\/3d278bdbd71f2845b0b29436ab30e8fb.png\" style=\"display:block;margin: 0 auto;\" \/><\/center>    <\/p>\n<p>Il problema \u00e8 stato confermato nei server HTTP Apache Tomcat, Netty, Eclipse Jetty, Fastly, Varnish, Lighttpd e Zephyr RTOS. Il problema si manifesta anche sui siti e servizi server di Mozilla. Apache httpd, Apache Traffic Server, Node.js, LiteSpeed e HAProxy non sono affetti dal problema. Non \u00e8 stata definita la presenza di vulnerabilit\u00e0 in Nginx.<br \/>\n<br \/>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=63726\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u0430 \u043d\u043e\u0432\u0430\u044f \u0442\u0435\u0445\u043d\u0438\u043a\u0430 \u0430\u0442\u0430\u043a\u0438 \u043d\u0430 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430 HTTP\/2, \u0443\u043f\u0440\u043e\u0449\u0430\u044e\u0449\u0430\u044f \u043f\u0440\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u0435 \u0430\u0442\u0430\u043a \u0434\u043b\u044f \u0432\u044b\u0437\u043e\u0432\u0430 \u043e\u0442\u043a\u0430\u0437\u0430 \u0432 \u043e\u0431\u0441\u043b\u0443\u0436\u0438\u0432\u0430\u043d\u0438\u0438 \u0447\u0435\u0440\u0435\u0437 \u0438\u0441\u0447\u0435\u0440\u043f\u0430\u043d\u0438\u0435 \u0440\u0435\u0441\u0443\u0440\u0441\u043e\u0432 \u0441\u0435\u0440\u0432\u0435\u0440\u0430. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043f\u043e\u043b\u0443\u0447\u0438\u043b\u0430 \u043a\u043e\u0434\u043e\u0432\u043e\u0435 \u0438\u043c\u044f MadeYouReset \u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0447\u0435\u0440\u0435\u0437 \u043c\u0430\u043d\u0438\u043f\u0443\u043b\u044f\u0446\u0438\u0438 \u0443\u043f\u0440\u0430\u0432\u043b\u044f\u044e\u0449\u0438\u043c\u0438 \u043a\u0430\u0434\u0440\u0430\u043c\u0438 HTTP\/2 \u043d\u0430\u0432\u043e\u0434\u043d\u0438\u0442\u044c \u0441\u0435\u0440\u0432\u0435\u0440 \u0431\u043e\u043b\u044c\u0448\u0438\u043c \u043a\u043e\u043b\u0438\u0447\u0435\u0441\u0442\u0432\u043e\u043c \u0437\u0430\u043f\u0440\u043e\u0441\u043e\u0432 \u0432 \u043e\u0431\u0445\u043e\u0434 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u0438\u0439. \u0421\u0443\u0442\u044c \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u0432 \u0442\u043e\u043c, \u0447\u0442\u043e \u043a\u043b\u0438\u0435\u043d\u0442 \u043c\u043e\u0436\u0435\u0442 \u0441\u043e\u0437\u0434\u0430\u0442\u044c \u043e\u0447\u0435\u043d\u044c \u0431\u043e\u043b\u044c\u0448\u043e\u0435 \u0447\u0438\u0441\u043b\u043e \u043e\u0434\u043d\u043e\u0432\u0440\u0435\u043c\u0435\u043d\u043d\u043e \u043e\u0431\u0440\u0430\u0431\u0430\u0442\u044b\u0432\u0430\u0435\u043c\u044b\u0445 \u043f\u043e\u0442\u043e\u043a\u043e\u0432, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":140669,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-140668","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u0430 \u043d\u043e\u0432\u0430\u044f \u0442\u0435\u0445\u043d\u0438\u043a\u0430 \u0430\u0442\u0430\u043a\u0438 \u043d\u0430 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430 HTTP\/2, \u0443\u043f\u0440\u043e\u0449\u0430\u044e\u0449\u0430\u044f \u043f\u0440\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u0435 \u0430\u0442\u0430\u043a \u0434\u043b\u044f \u0432\u044b\u0437\u043e\u0432\u0430 \u043e\u0442\u043a\u0430\u0437\u0430 \u0432 \u043e\u0431\u0441\u043b\u0443\u0436\u0438\u0432\u0430\u043d\u0438\u0438 \u0447\u0435\u0440\u0435\u0437 \u0438\u0441\u0447\u0435\u0440\u043f\u0430\u043d\u0438\u0435 \u0440\u0435\u0441\u0443\u0440\u0441\u043e\u0432 \u0441\u0435\u0440\u0432\u0435\u0440\u0430.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-v-realizacziyah-protokola-http-2-uproshhayushhaya-provedenie-dos-atak\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f\u0445 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430 HTTP\/2, \u0443\u043f\u0440\u043e\u0449\u0430\u044e\u0449\u0430\u044f \u043f\u0440\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u0435 DoS-\u0430\u0442\u0430\u043a | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u0430 \u043d\u043e\u0432\u0430\u044f \u0442\u0435\u0445\u043d\u0438\u043a\u0430 \u0430\u0442\u0430\u043a\u0438 \u043d\u0430 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430 HTTP\/2, \u0443\u043f\u0440\u043e\u0449\u0430\u044e\u0449\u0430\u044f \u043f\u0440\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u0435 \u0430\u0442\u0430\u043a \u0434\u043b\u044f \u0432\u044b\u0437\u043e\u0432\u0430 \u043e\u0442\u043a\u0430\u0437\u0430 \u0432 \u043e\u0431\u0441\u043b\u0443\u0436\u0438\u0432\u0430\u043d\u0438\u0438 \u0447\u0435\u0440\u0435\u0437 \u0438\u0441\u0447\u0435\u0440\u043f\u0430\u043d\u0438\u0435 \u0440\u0435\u0441\u0443\u0440\u0441\u043e\u0432 \u0441\u0435\u0440\u0432\u0435\u0440\u0430.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-v-realizacziyah-protokola-http-2-uproshhayushhaya-provedenie-dos-atak\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2025-08-14T09:12:07+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2025-08-14T09:12:07+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilit\u00e0 nelle implementazioni del protocollo HTTP\/2, che semplifica l'esecuzione di attacchi DoS | ProHoster","description":"\u00c8 stata presentata una nuova tecnica di attacco alle implementazioni del protocollo HTTP\/2, che semplifica l'esecuzione di attacchi per provocare un'interruzione del servizio attraverso l'esaurimento delle risorse del server.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-v-realizacziyah-protokola-http-2-uproshhayushhaya-provedenie-dos-atak","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f\u0445 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430 HTTP\/2, \u0443\u043f\u0440\u043e\u0449\u0430\u044e\u0449\u0430\u044f \u043f\u0440\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u0435 DoS-\u0430\u0442\u0430\u043a | ProHoster","og:description":"\u041f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u0430 \u043d\u043e\u0432\u0430\u044f \u0442\u0435\u0445\u043d\u0438\u043a\u0430 \u0430\u0442\u0430\u043a\u0438 \u043d\u0430 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430 HTTP\/2, \u0443\u043f\u0440\u043e\u0449\u0430\u044e\u0449\u0430\u044f \u043f\u0440\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u0435 \u0430\u0442\u0430\u043a \u0434\u043b\u044f \u0432\u044b\u0437\u043e\u0432\u0430 \u043e\u0442\u043a\u0430\u0437\u0430 \u0432 \u043e\u0431\u0441\u043b\u0443\u0436\u0438\u0432\u0430\u043d\u0438\u0438 \u0447\u0435\u0440\u0435\u0437 \u0438\u0441\u0447\u0435\u0440\u043f\u0430\u043d\u0438\u0435 \u0440\u0435\u0441\u0443\u0440\u0441\u043e\u0432 \u0441\u0435\u0440\u0432\u0435\u0440\u0430.","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-v-realizacziyah-protokola-http-2-uproshhayushhaya-provedenie-dos-atak","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2025-08-14T09:12:07+00:00","article:modified_time":"2025-08-14T09:12:07+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"140668","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-02-22 15:52:24","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-23 14:15:21","updated":"2026-02-22 15:52:24","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/140668","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=140668"}],"version-history":[{"count":2,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/140668\/revisions"}],"predecessor-version":[{"id":162504,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/140668\/revisions\/162504"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media\/140669"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=140668"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=140668"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=140668"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}