{"id":39289,"date":"2019-10-31T22:29:21","date_gmt":"2019-10-31T19:29:21","guid":{"rendered":"https:\/\/prohoster.info\/blog\/ataka-cpdos-pozvolyayushhaya-sdelat-nedostupnymi-stranitsy-otdavaemye-cherez-cdn\/"},"modified":"2019-10-31T22:29:21","modified_gmt":"2019-10-31T19:29:21","slug":"ataka-cpdos-pozvolyayushhaya-sdelat-nedostupnymi-stranitsy-otdavaemye-cherez-cdn","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/ataka-cpdos-pozvolyayushhaya-sdelat-nedostupnymi-stranitsy-otdavaemye-cherez-cdn","title":{"rendered":"Attacco CPDoS che consente di rendere non disponibili le pagine servite tramite CDN","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Ricercatori delle universit\u00e0 di Amburgo e Colonia<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/cpdos.org\/\">hanno sviluppato<\/a><\/noindex> nuove tecniche di attacco alle reti di distribuzione dei contenuti e proxy di caching \u2014 <noindex><a rel=\"nofollow\" href=\"https:\/\/cpdos.org\/paper\/Your_Cache_Has_Fallen__Cache_Poisoned_Denial_of_Service_Attack__Preprint_.pdf\">CPDoS<\/a><\/noindex> (Cache-Poisoned Denial-of-Service). L'attacco consente di ottenere un'interruzione dell'accesso a una pagina attraverso l'avvelenamento della cache. <\/p>\n<p>Il problema \u00e8 legato al fatto che i CDN memorizzano nella cache non solo le richieste eseguite con successo, ma anche le situazioni in cui il server HTTP restituisce un errore. In genere, in caso di problemi nella formulazione delle richieste, il server restituisce un errore 400 (Bad Request), eccezione fatta per IIS, che restituisce un errore 404 (Not Found) per intestazioni troppo grandi. Lo standard consente di memorizzare nella cache solo gli errori con codici 404 (Not Found), 405 (Method Not Allowed), 410 (Gone) e 501 (Not Implemented), ma alcuni CDN memorizzano anche le risposte con codice 400 (Bad Request), che dipende dalla richiesta inviata. <\/p>\n<p>Gli attaccanti possono causare un errore di ritorno &#171;400 Bad Request&#187; sul sito originale inviando una richiesta con intestazioni HTTP formattate in modo specifico. Queste intestazioni non vengono considerate dalla CDN, quindi verranno memorizzate nella cache informazioni sull'impossibilit\u00e0 di accedere alla pagina e tutte le altre richieste valide degli utenti fino alla scadenza del timeout possono portare a visualizzare un errore, anche se il sito originale restituisce contenuti senza problemi. <\/p>\n<p>Per forzare il server HTTP a restituire un errore, sono proposte tre varianti di attacco:  <\/p>\n<ul>\n<li class=\"l\"> HMO (HTTP Method Override) \u2014 l'attaccante pu\u00f2 sovrascrivere il metodo originale della richiesta tramite le intestazioni &#171;X-HTTP-Method-Override&#187;, &#171;X-HTTP-Method&#187; o &#171;X-Method-Override&#187;, supportate da alcuni server ma non considerate dalla CDN. Ad esempio, \u00e8 possibile cambiare il metodo originale &#171;GET&#187; in un metodo &#171;DELETE&#187; vietato sul server o in un metodo &#171;POST&#187; non applicabile per la statica;\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/cpdos.org\/img\/HMO.png\"><img decoding=\"async\" alt=\"Attacco CPDoS che consente di rendere non disponibili le pagine servite tramite CDN\" src=\"\/wp-content\/uploads\/2019\/10\/6449e613e38cfb3cb1f2f185921214e9.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<li class=\"l\"> HHO (HTTP Header Oversize) \u2014 l'attaccante pu\u00f2 scegliere una dimensione dell'intestazione tale da superare il limite del server originale, ma non rientrare nei limiti della CDN. Ad esempio, Apache httpd limita la dimensione dell'intestazione a 8 KB, mentre la CDN Amazon Cloudfront consente intestazioni fino a 20 KB;<br \/>\n<center><noindex><a rel=\"nofollow\" href=\"https:\/\/cpdos.org\/img\/HHO.png\"><img decoding=\"async\" alt=\"Attacco CPDoS che consente di rendere non disponibili le pagine servite tramite CDN\" src=\"\/wp-content\/uploads\/2019\/10\/2bbefaff1f9b5b1b4e568801cd7ac7cd.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<li class=\"l\"> HMC (HTTP Meta Character) \u2014 l'attaccante pu\u00f2 inserire caratteri speciali nella richiesta (&#092;n, &#092;r, &#092;a), che sono considerati non validi sul server originale, ma ignorati nella CDN.\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/cpdos.org\/img\/HMC.png\"><img decoding=\"async\" alt=\"Attacco CPDoS che consente di rendere non disponibili le pagine servite tramite CDN\" src=\"\/wp-content\/uploads\/2019\/10\/5e8426e93a48735796b600db00a5c99d.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<\/ul>\n<p>Il CDN CloudFront, utilizzato in Amazon Web Services (AWS), \u00e8 stato il pi\u00f9 vulnerabile all'attacco. Attualmente, Amazon ha gi\u00e0 risolto il problema vietando la memorizzazione nella cache degli errori, ma agli esperti sono servuti oltre tre mesi per ottenere l'aggiunta di misure di protezione. Il problema ha riguardato anche Cloudflare, Varnish, Akamai, CDN77 e<br \/>\nFastly, ma l'attacco attraverso di essi \u00e8 limitato ai server target che utilizzano IIS, ASP.NET, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/pallets\/flask\">Flask<\/a><\/noindex> e <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/playframework\/play1\/issues\/1300\">Play 1<\/a><\/noindex>. <noindex><a rel=\"nofollow\" href=\"https:\/\/cpdos.org\/paper\/Your_Cache_Has_Fallen__Cache_Poisoned_Denial_of_Service_Attack__Preprint_.pdf\">Osservato<\/a><\/noindex>, il che significa che circa l'11% dei domini del Ministero della Difesa degli Stati Uniti, il 16% degli URL del database HTTP Archive e circa il 30% dei 500 siti web pi\u00f9 grandi secondo il rating di Alexa sono potenzialmente vulnerabili all'attacco.<\/p>\n<p>Come metodo alternativo per bloccare gli attacchi sul lato del sito, si pu\u00f2 utilizzare l'intestazione &#171;Cache-Control: no-store&#187;, che vieta la memorizzazione nella cache delle risposte. In alcune CDN, ad esempio, in<br \/>\n CloudFront e Akamai consentono di disattivare la cache degli errori a livello delle impostazioni del profilo. Per la protezione, \u00e8 possibile utilizzare anche i firewall per applicazioni web (WAF, Web Application Firewall), che devono per\u00f2 essere implementati sul lato CDN prima degli host che effettuano la cache.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fonte: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51753\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u0413\u0430\u043c\u0431\u0443\u0440\u0433\u0441\u043a\u043e\u0433\u043e \u0438 \u041a\u0451\u043b\u044c\u043d\u0441\u043a\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u043e\u0432 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u043b\u0438 \u043d\u043e\u0432\u0443\u044e \u0442\u0435\u0445\u043d\u0438\u043a\u0443 \u0430\u0442\u0430\u043a \u043d\u0430 \u0441\u0435\u0442\u0438 \u0434\u043e\u0441\u0442\u0430\u0432\u043a\u0438 \u043a\u043e\u043d\u0442\u0435\u043d\u0442\u0430 \u0438 \u043a\u044d\u0448\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u043f\u0440\u043e\u043a\u0441\u0438 &#8212; CPDoS (Cache-Poisoned Denial-of-Service). \u0410\u0442\u0430\u043a\u0430 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u043e\u0442\u043a\u0430\u0437\u0430 \u0434\u043e\u0441\u0442\u0443\u043f\u0430 \u043a \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u0435 \u0447\u0435\u0440\u0435\u0437 \u043e\u0442\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0435 \u043a\u044d\u0448\u0430. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0441\u0432\u044f\u0437\u0430\u043d\u0430 \u0441 \u0442\u0435\u043c, \u0447\u0442\u043e CDN \u043a\u044d\u0448\u0438\u0440\u0443\u044e\u0442 \u043d\u0435 \u0442\u043e\u043b\u044c\u043a\u043e \u0443\u0441\u043f\u0435\u0448\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u043d\u044b\u0435 \u0437\u0430\u043f\u0440\u043e\u0441\u044b, \u043d\u043e \u0438 \u0441\u0438\u0442\u0443\u0430\u0446\u0438\u0438, \u043a\u043e\u0433\u0434\u0430 http-\u0441\u0435\u0440\u0432\u0435\u0440 \u0432\u043e\u0437\u0432\u0440\u0430\u0449\u0430\u0435\u0442 \u043e\u0448\u0438\u0431\u043a\u0443. \u041a\u0430\u043a \u043f\u0440\u0430\u0432\u0438\u043b\u043e, \u043f\u0440\u0438 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430\u0445 \u0441 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":39290,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-39289","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-novosti-interneta"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u0413\u0430\u043c\u0431\u0443\u0440\u0433\u0441\u043a\u043e\u0433\u043e \u0438 \u041a\u0451\u043b\u044c\u043d\u0441\u043a\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u043e\u0432 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u043b\u0438 \u043d\u043e\u0432\u0443\u044e \u0442\u0435\u0445\u043d\u0438\u043a\u0443 \u0430\u0442\u0430\u043a \u043d\u0430 \u0441\u0435\u0442\u0438 \u0434\u043e\u0441\u0442\u0430\u0432\u043a\u0438 \u043a\u043e\u043d\u0442\u0435\u043d\u0442\u0430 \u0438 \u043a\u044d\u0448\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u043f\u0440\u043e\u043a\u0441\u0438 -\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/ataka-cpdos-pozvolyayushhaya-sdelat-nedostupnymi-stranitsy-otdavaemye-cherez-cdn\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0410\u0442\u0430\u043a\u0430 CPDoS, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0441\u0434\u0435\u043b\u0430\u0442\u044c \u043d\u0435\u0434\u043e\u0441\u0442\u0443\u043f\u043d\u044b\u043c\u0438 \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u044b, \u043e\u0442\u0434\u0430\u0432\u0430\u0435\u043c\u044b\u0435 \u0447\u0435\u0440\u0435\u0437 CDN | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u0413\u0430\u043c\u0431\u0443\u0440\u0433\u0441\u043a\u043e\u0433\u043e \u0438 \u041a\u0451\u043b\u044c\u043d\u0441\u043a\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u043e\u0432 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u043b\u0438 \u043d\u043e\u0432\u0443\u044e \u0442\u0435\u0445\u043d\u0438\u043a\u0443 \u0430\u0442\u0430\u043a \u043d\u0430 \u0441\u0435\u0442\u0438 \u0434\u043e\u0441\u0442\u0430\u0432\u043a\u0438 \u043a\u043e\u043d\u0442\u0435\u043d\u0442\u0430 \u0438 \u043a\u044d\u0448\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u043f\u0440\u043e\u043a\u0441\u0438 -\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/ataka-cpdos-pozvolyayushhaya-sdelat-nedostupnymi-stranitsy-otdavaemye-cherez-cdn\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:29:21+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:29:21+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Attacco CPDoS, che rende indisponibili le pagine servite tramite CDN | ProHoster","description":"I ricercatori dell'Universit\u00e0 di Amburgo e di Colonia hanno sviluppato una nuova tecnica di attacco alle reti di distribuzione dei contenuti e ai proxy di caching -","canonical_url":"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/ataka-cpdos-pozvolyayushhaya-sdelat-nedostupnymi-stranitsy-otdavaemye-cherez-cdn","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0410\u0442\u0430\u043a\u0430 CPDoS, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0441\u0434\u0435\u043b\u0430\u0442\u044c \u043d\u0435\u0434\u043e\u0441\u0442\u0443\u043f\u043d\u044b\u043c\u0438 \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u044b, \u043e\u0442\u0434\u0430\u0432\u0430\u0435\u043c\u044b\u0435 \u0447\u0435\u0440\u0435\u0437 CDN | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u0413\u0430\u043c\u0431\u0443\u0440\u0433\u0441\u043a\u043e\u0433\u043e \u0438 \u041a\u0451\u043b\u044c\u043d\u0441\u043a\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u043e\u0432 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u043b\u0438 \u043d\u043e\u0432\u0443\u044e \u0442\u0435\u0445\u043d\u0438\u043a\u0443 \u0430\u0442\u0430\u043a \u043d\u0430 \u0441\u0435\u0442\u0438 \u0434\u043e\u0441\u0442\u0430\u0432\u043a\u0438 \u043a\u043e\u043d\u0442\u0435\u043d\u0442\u0430 \u0438 \u043a\u044d\u0448\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u043f\u0440\u043e\u043a\u0441\u0438 -","og:url":"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/ataka-cpdos-pozvolyayushhaya-sdelat-nedostupnymi-stranitsy-otdavaemye-cherez-cdn","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:29:21+00:00","article:modified_time":"2019-10-31T19:29:21+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"39289","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 01:34:21","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 00:52:27","updated":"2026-01-24 01:34:21","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/39289","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=39289"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/39289\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media\/39290"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=39289"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=39289"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=39289"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}