{"id":39289,"date":"2019-10-31T22:29:21","date_gmt":"2019-10-31T19:29:21","guid":{"rendered":"https:\/\/prohoster.info\/blog\/ataka-cpdos-pozvolyayushhaya-sdelat-nedostupnymi-stranitsy-otdavaemye-cherez-cdn\/"},"modified":"2019-10-31T22:29:21","modified_gmt":"2019-10-31T19:29:21","slug":"ataka-cpdos-pozvolyayushhaya-sdelat-nedostupnymi-stranitsy-otdavaemye-cherez-cdn","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/ataka-cpdos-pozvolyayushhaya-sdelat-nedostupnymi-stranitsy-otdavaemye-cherez-cdn","title":{"rendered":"Attacco CPDoS, che rende inaccessibili le pagine erogate tramite CDN","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>I ricercatori delle universit\u00e0 di Amburgo e Colonia<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/cpdos.org\/\">hanno sviluppato<\/a><\/noindex> nuove tecniche di attacco alle reti di distribuzione dei contenuti e ai proxy di caching \u2014 <noindex><a rel=\"nofollow\" href=\"https:\/\/cpdos.org\/paper\/Your_Cache_Has_Fallen__Cache_Poisoned_Denial_of_Service_Attack__Preprint_.pdf\">CPDoS<\/a><\/noindex> (Cache-Poisoned Denial-of-Service). L'attacco consente di ottenere un'interruzione dell'accesso alla pagina tramite l'avvelenamento della cache. <\/p>\n<p>Il problema \u00e8 legato al fatto che i CDN memorizzano nella cache non solo le richieste riuscite, ma anche le situazioni in cui il server HTTP restituisce un errore. In generale, quando ci sono problemi nella formazione delle richieste, il server restituisce un errore 400 (Bad Request), fatta eccezione per IIS, che restituisce un errore 404 (Not Found) per intestazioni troppo grandi. Lo standard consente di memorizzare nella cache solo gli errori con i codici 404 (Not Found), 405 (Method Not Allowed), 410 (Gone) e 501 (Not Implemented), ma alcuni CDN memorizzano anche le risposte con codice 400 (Bad Request), che dipende dalla richiesta inviata. <\/p>\n<p>Gli aggressori possono causare il ritorno dell'errore sul sito originale \"400 Bad Request\" inviando una richiesta con intestazioni HTTP formattate in un certo modo. Queste intestazioni non vengono considerate dal CDN, quindi nel cache verranno memorizzate informazioni sull'impossibilit\u00e0 di accedere alla pagina e tutte le altre richieste corrette degli utenti fino alla scadenza del timeout potrebbero generare un errore, anche se il sito originale restituisce correttamente il contenuto. <\/p>\n<p>Per costringere il server HTTP a restituire un errore sono stati proposti tre tipi di attacco:  <\/p>\n<ul>\n<li class=\"l\"> HMO (HTTP Method Override) \u2014 l'aggressore pu\u00f2 sovrascrivere il metodo di richiesta originale tramite intestazioni \"X-HTTP-Method-Override\", \"X-HTTP-Method\" o \"X-Method-Override\", supportate da alcuni server ma non considerate dal CDN. Ad esempio, \u00e8 possibile cambiare il metodo originale \"GET\" in un metodo \"DELETE\" vietato dal server o in un metodo \"POST\" non applicabile per contenuti statici;\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/cpdos.org\/img\/HMO.png\"><img decoding=\"async\" alt=\"Attacco CPDoS, che rende inaccessibili le pagine erogate tramite CDN\" src=\"\/wp-content\/uploads\/2019\/10\/6449e613e38cfb3cb1f2f185921214e9.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<li class=\"l\"> HHO (HTTP Header Oversize) \u2014 l'aggressore pu\u00f2 scegliere la dimensione dell'intestazione in modo tale che superi il limite del server originale, ma non rientri nei limiti del CDN. Ad esempio, Apache httpd limita la dimensione dell'intestazione a 8 KB, mentre il CDN Amazon Cloudfront consente intestazioni fino a 20 KB;<br \/>\n<center><noindex><a rel=\"nofollow\" href=\"https:\/\/cpdos.org\/img\/HHO.png\"><img decoding=\"async\" alt=\"Attacco CPDoS, che rende inaccessibili le pagine erogate tramite CDN\" src=\"\/wp-content\/uploads\/2019\/10\/2bbefaff1f9b5b1b4e568801cd7ac7cd.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<li class=\"l\"> HMC (HTTP Meta Character) \u2014 l'aggressore pu\u00f2 inserire nella richiesta caratteri speciali (\n, \r, \n), che sono considerati non validi sul server originale, ma vengono ignorati nel CDN.\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/cpdos.org\/img\/HMC.png\"><img decoding=\"async\" alt=\"Attacco CPDoS, che rende inaccessibili le pagine erogate tramite CDN\" src=\"\/wp-content\/uploads\/2019\/10\/5e8426e93a48735796b600db00a5c99d.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<\/ul>\n<p>Il CDN CloudFront, utilizzato in Amazon Web Services (AWS), \u00e8 stato particolarmente vulnerabile all'attacco. Attualmente, l'azienda Amazon ha gi\u00e0 risolto il problema vietando la memorizzazione nella cache degli errori, ma gli esperti hanno impiegato oltre tre mesi per ottenere l'implementazione della protezione. Il problema ha colpito anche Cloudflare, Varnish, Akamai, CDN77 e<br \/>\nFastly, ma l'attacco attraverso di loro \u00e8 limitato ai server target che utilizzano IIS, ASP.NET, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/pallets\/flask\">Flask<\/a><\/noindex> e <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/playframework\/play1\/issues\/1300\">Play 1<\/a><\/noindex>. <noindex><a rel=\"nofollow\" href=\"https:\/\/cpdos.org\/paper\/Your_Cache_Has_Fallen__Cache_Poisoned_Denial_of_Service_Attack__Preprint_.pdf\">Si segnala<\/a><\/noindex>, con il potenziale per colpire l'11% dei domini del Ministero della Difesa degli Stati Uniti, il 16% degli URL del database HTTP Archive e circa il 30% dei 500 siti web principali secondo la classifica di Alexa.<\/p>\n<p>Come metodo di bypass per bloccare l'attacco dal lato del sito, si pu\u00f2 utilizzare l'intestazione \"Cache-Control: no-store\", che vieta la cachizzazione delle risposte. In alcuni CDN, ad esempio, in<br \/>\n CloudFront e Akamai, \u00e8 possibile disattivare la memorizzazione nella cache degli errori a livello di impostazioni del profilo. Per la protezione \u00e8 possibile utilizzare anche firewall per applicazioni web (WAF, Web Application Firewall), ma devono essere implementati sul lato CDN prima degli host che effettuano la memorizzazione nella cache.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fonte: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51753\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u0413\u0430\u043c\u0431\u0443\u0440\u0433\u0441\u043a\u043e\u0433\u043e \u0438 \u041a\u0451\u043b\u044c\u043d\u0441\u043a\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u043e\u0432 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u043b\u0438 \u043d\u043e\u0432\u0443\u044e \u0442\u0435\u0445\u043d\u0438\u043a\u0443 \u0430\u0442\u0430\u043a \u043d\u0430 \u0441\u0435\u0442\u0438 \u0434\u043e\u0441\u0442\u0430\u0432\u043a\u0438 \u043a\u043e\u043d\u0442\u0435\u043d\u0442\u0430 \u0438 \u043a\u044d\u0448\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u043f\u0440\u043e\u043a\u0441\u0438 &#8212; CPDoS (Cache-Poisoned Denial-of-Service). \u0410\u0442\u0430\u043a\u0430 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u043e\u0442\u043a\u0430\u0437\u0430 \u0434\u043e\u0441\u0442\u0443\u043f\u0430 \u043a \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u0435 \u0447\u0435\u0440\u0435\u0437 \u043e\u0442\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0435 \u043a\u044d\u0448\u0430. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0441\u0432\u044f\u0437\u0430\u043d\u0430 \u0441 \u0442\u0435\u043c, \u0447\u0442\u043e CDN \u043a\u044d\u0448\u0438\u0440\u0443\u044e\u0442 \u043d\u0435 \u0442\u043e\u043b\u044c\u043a\u043e \u0443\u0441\u043f\u0435\u0448\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u043d\u044b\u0435 \u0437\u0430\u043f\u0440\u043e\u0441\u044b, \u043d\u043e \u0438 \u0441\u0438\u0442\u0443\u0430\u0446\u0438\u0438, \u043a\u043e\u0433\u0434\u0430 http-\u0441\u0435\u0440\u0432\u0435\u0440 \u0432\u043e\u0437\u0432\u0440\u0430\u0449\u0430\u0435\u0442 \u043e\u0448\u0438\u0431\u043a\u0443. \u041a\u0430\u043a \u043f\u0440\u0430\u0432\u0438\u043b\u043e, \u043f\u0440\u0438 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430\u0445 \u0441 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":39290,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-39289","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u0413\u0430\u043c\u0431\u0443\u0440\u0433\u0441\u043a\u043e\u0433\u043e \u0438 \u041a\u0451\u043b\u044c\u043d\u0441\u043a\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u043e\u0432 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u043b\u0438 \u043d\u043e\u0432\u0443\u044e \u0442\u0435\u0445\u043d\u0438\u043a\u0443 \u0430\u0442\u0430\u043a \u043d\u0430 \u0441\u0435\u0442\u0438 \u0434\u043e\u0441\u0442\u0430\u0432\u043a\u0438 \u043a\u043e\u043d\u0442\u0435\u043d\u0442\u0430 \u0438 \u043a\u044d\u0448\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u043f\u0440\u043e\u043a\u0441\u0438 -\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/ataka-cpdos-pozvolyayushhaya-sdelat-nedostupnymi-stranitsy-otdavaemye-cherez-cdn\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0410\u0442\u0430\u043a\u0430 CPDoS, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0441\u0434\u0435\u043b\u0430\u0442\u044c \u043d\u0435\u0434\u043e\u0441\u0442\u0443\u043f\u043d\u044b\u043c\u0438 \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u044b, \u043e\u0442\u0434\u0430\u0432\u0430\u0435\u043c\u044b\u0435 \u0447\u0435\u0440\u0435\u0437 CDN | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u0413\u0430\u043c\u0431\u0443\u0440\u0433\u0441\u043a\u043e\u0433\u043e \u0438 \u041a\u0451\u043b\u044c\u043d\u0441\u043a\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u043e\u0432 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u043b\u0438 \u043d\u043e\u0432\u0443\u044e \u0442\u0435\u0445\u043d\u0438\u043a\u0443 \u0430\u0442\u0430\u043a \u043d\u0430 \u0441\u0435\u0442\u0438 \u0434\u043e\u0441\u0442\u0430\u0432\u043a\u0438 \u043a\u043e\u043d\u0442\u0435\u043d\u0442\u0430 \u0438 \u043a\u044d\u0448\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u043f\u0440\u043e\u043a\u0441\u0438 -\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/ataka-cpdos-pozvolyayushhaya-sdelat-nedostupnymi-stranitsy-otdavaemye-cherez-cdn\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:29:21+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:29:21+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Attacco CPDoS, che rende indisponibili le pagine servite tramite CDN | ProHoster","description":"I ricercatori delle universit\u00e0 di Amburgo e Colonia hanno sviluppato una nuova tecnica di attacco alle reti di distribuzione dei contenuti e ai proxy di caching -","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/ataka-cpdos-pozvolyayushhaya-sdelat-nedostupnymi-stranitsy-otdavaemye-cherez-cdn","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0410\u0442\u0430\u043a\u0430 CPDoS, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0441\u0434\u0435\u043b\u0430\u0442\u044c \u043d\u0435\u0434\u043e\u0441\u0442\u0443\u043f\u043d\u044b\u043c\u0438 \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u044b, \u043e\u0442\u0434\u0430\u0432\u0430\u0435\u043c\u044b\u0435 \u0447\u0435\u0440\u0435\u0437 CDN | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u0413\u0430\u043c\u0431\u0443\u0440\u0433\u0441\u043a\u043e\u0433\u043e \u0438 \u041a\u0451\u043b\u044c\u043d\u0441\u043a\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u043e\u0432 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u043b\u0438 \u043d\u043e\u0432\u0443\u044e \u0442\u0435\u0445\u043d\u0438\u043a\u0443 \u0430\u0442\u0430\u043a \u043d\u0430 \u0441\u0435\u0442\u0438 \u0434\u043e\u0441\u0442\u0430\u0432\u043a\u0438 \u043a\u043e\u043d\u0442\u0435\u043d\u0442\u0430 \u0438 \u043a\u044d\u0448\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u043f\u0440\u043e\u043a\u0441\u0438 -","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/ataka-cpdos-pozvolyayushhaya-sdelat-nedostupnymi-stranitsy-otdavaemye-cherez-cdn","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:29:21+00:00","article:modified_time":"2019-10-31T19:29:21+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"39289","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 01:34:21","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 00:52:27","updated":"2026-01-24 01:34:21","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/39289","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=39289"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/39289\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media\/39290"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=39289"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=39289"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=39289"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}