2 ืคื’ื™ืขื•ื™ื•ืช DoS ื–ื•ื”ื• ื‘ื™ื™ืฉื•ืžื™ื ืฉื•ื ื™ื ืฉืœ ืคืจื•ื˜ื•ืงื•ืœ HTTP/8

ื—ื•ืงืจื™ื ืžื ื˜ืคืœื™ืงืก ื•ื’ื•ื’ืœ ื’ื™ืœื” ืงื™ื™ืžื•ืช ืฉืžื•ื ื” ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ื”ื˜ืžืขื•ืช ืฉื•ื ื•ืช ืฉืœ ืคืจื•ื˜ื•ืงื•ืœ HTTP/2 ืฉืขืœื•ืœื•ืช ืœื’ืจื•ื ืœืžื ื™ืขืช ืฉื™ืจื•ืช ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ื–ืจื ืฉืœ ื‘ืงืฉื•ืช ืจืฉืช ื‘ืฆื•ืจื” ืžืกื•ื™ืžืช. ื”ื‘ืขื™ื” ืžืฉืคื™ืขื” ื‘ืžื™ื“ื” ืžืกื•ื™ืžืช ืขืœ ืจื•ื‘ ืฉืจืชื™ ื”-HTTP ืขื ืชืžื™ื›ื” ื‘-HTTP/2 ื•ื’ื•ืจืžืช ืœื›ืš ืฉื”ื–ื™ื›ืจื•ืŸ ืื•ื–ืœ ืœืขื•ื‘ื“ ืื• ืœื™ืฆื•ืจ ืขื•ืžืก ืจื‘ ืžื“ื™ ื‘ืžืขื‘ื“. ืขื“ื›ื•ื ื™ื ืฉืžื‘ื˜ืœื™ื ืคื’ื™ืขื•ื™ื•ืช ื›ื‘ืจ ืžื•ืฆื’ื™ื ื‘ nginx 1.16.1/1.17.3 ะธ H2O 2.2.6, ืื‘ืœ ื›ืจื’ืข ืื™ื ื• ื–ืžื™ืŸ ืขื‘ื•ืจ Apache httpd ื• ืžื•ืฆืจื™ื ืื—ืจื™ื.

ื”ื‘ืขื™ื•ืช ื ื‘ืขื• ืžืกื™ื‘ื•ื›ื™ื ืฉื”ื•ื›ื ืกื• ืœืคืจื•ื˜ื•ืงื•ืœ HTTP/2 ื”ืงืฉื•ืจื™ื ืœืฉื™ืžื•ืฉ ื‘ืžื‘ื ื™ื ื‘ื™ื ืืจื™ื™ื, ืžืขืจื›ืช ืœื”ื’ื‘ืœืช ื–ืจื™ืžื•ืช ื ืชื•ื ื™ื ื‘ืชื•ืš ื—ื™ื‘ื•ืจื™ื, ืžื ื’ื ื•ืŸ ืชืขื“ื•ืฃ ื–ืจื™ืžื”, ื•ื ื•ื›ื—ื•ืช ืฉืœ ื”ื•ื“ืขื•ืช ื‘ืงืจื” ื“ืžื•ื™ื•ืช ICMP ื”ืคื•ืขืœื•ืช ื‘ื—ื™ื‘ื•ืจ HTTP/2 ืจืžื” (ืœื“ื•ื’ืžื”, ื”ื’ื“ืจื•ืช ืคื™ื ื’, ืื™ืคื•ืก ื•ื–ืจื™ืžื”). ื™ื™ืฉื•ืžื™ื ืจื‘ื™ื ืœื ื”ื’ื‘ื™ืœื• ื›ืจืื•ื™ ืืช ื–ืจื™ืžืช ื”ื•ื“ืขื•ืช ื”ื‘ืงืจื”, ืœื ื ื™ื”ืœื• ื‘ื™ืขื™ืœื•ืช ืืช ืชื•ืจ ื”ืขื“ื™ืคื•ืช ื‘ืขืช ืขื™ื‘ื•ื“ ื‘ืงืฉื•ืช, ืื• ื”ืฉืชืžืฉื• ื‘ื™ื™ืฉื•ืžื™ื ืœื ืื•ืคื˜ื™ืžืœื™ื™ื ืฉืœ ืืœื’ื•ืจื™ืชืžื™ ื‘ืงืจืช ื–ืจื™ืžื”.

ืจื•ื‘ ืฉื™ื˜ื•ืช ื”ื”ืชืงืคื” ืฉื–ื•ื”ื• ืžืกืชื›ืžื•ืช ื‘ืฉืœื™ื—ืช ื‘ืงืฉื•ืช ืžืกื•ื™ืžื•ืช ืœืฉืจืช, ืžื” ืฉืžื•ื‘ื™ืœ ืœื™ืฆื™ืจืช ืžืกืคืจ ืจื‘ ืฉืœ ืชื’ื•ื‘ื•ืช. ืื ื”ืœืงื•ื— ืœื ืงื•ืจื ื ืชื•ื ื™ื ืžื”ืฉืงืข ื•ืœื ืกื•ื’ืจ ืืช ื”ื—ื™ื‘ื•ืจ, ืชื•ืจ ื—ืฆื™ืฆืช ื”ืชื’ื•ื‘ื” ื‘ืฆื“ ื”ืฉืจืช ืžืชืžืœื ืœืœื ื”ืจืฃ. ื”ืชื ื”ื’ื•ืช ื–ื• ื™ื•ืฆืจืช ืขื•ืžืก ืขืœ ืžืขืจื›ืช ื ื™ื”ื•ืœ ื”ืชื•ืจื™ื ืœืขื™ื‘ื•ื“ ื—ื™ื‘ื•ืจื™ ืจืฉืช, ื•ื‘ื”ืชืื ืœืชื›ื•ื ื•ืช ื”ื™ื™ืฉื•ื, ืžื•ื‘ื™ืœื” ืœืžื™ืฆื•ื™ ื”ื–ื™ื›ืจื•ืŸ ื”ื–ืžื™ื ื™ื ืื• ืžืฉืื‘ื™ ื”ืžืขื‘ื“.

ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืฉื–ื•ื”ื•:

  • CVE-2019-9511 (Data Dribble) - ืชื•ืงืฃ ืžื‘ืงืฉ ื›ืžื•ืช ื’ื“ื•ืœื” ืฉืœ ื ืชื•ื ื™ื ืœืชื•ืš ืฉืจืฉื•ืจื™ื ืžืจื•ื‘ื™ื ืขืœ ื™ื“ื™ ืžื ื™ืคื•ืœืฆื™ื” ืฉืœ ื’ื•ื“ืœ ื”ื—ืœื•ืŸ ื”ื”ื–ื–ื” ื•ืงื“ื™ืžื•ืช ื”ืฉืจืฉื•ืจ, ืžื” ืฉืžืืœืฅ ืืช ื”ืฉืจืช ืœืขืžื•ื“ ื‘ืชื•ืจ ืืช ื”ื ืชื•ื ื™ื ื‘ื‘ืœื•ืงื™ื ืฉืœ 1 ื‘ืชื™ื;
  • CVE-2019-9512 (Ping Flood) - ืชื•ืงืฃ ืžืจืขื™ืœ ืœืœื ื”ืจืฃ ื”ื•ื“ืขื•ืช ืคื™ื ื’ ื‘ื—ื™ื‘ื•ืจ HTTP/2, ืžื” ืฉื’ื•ืจื ืœืชื•ืจ ื”ืคื ื™ืžื™ ืฉืœ ืชื’ื•ื‘ื•ืช ืฉื ืฉืœื—ื• ืœื”ืฆื™ืฃ ื‘ืฆื“ ื”ืฉื ื™;
  • CVE-2019-9513 (ืœื•ืœืืช ืžืฉืื‘ื™ื) - ืชื•ืงืฃ ื™ื•ืฆืจ ืฉืจืฉื•ืจื™ ื‘ืงืฉื•ืช ืžืจื•ื‘ื™ื ื•ืžืฉื ื” ืœืœื ื”ืจืฃ ืืช ื”ืขื“ื™ืคื•ืช ืฉืœ ื”ืฉืจืฉื•ืจื™ื, ืžื” ืฉื’ื•ืจื ืœืขืฅ ื”ืขื“ื™ืคื•ืช ืœืขืจื‘ื•ื‘;
  • CVE-2019-9514 (ืื™ืคื•ืก ื”ืฆืคื”) - ืชื•ืงืฃ ื™ื•ืฆืจ ืฉืจืฉื•ืจื™ื ืžืจื•ื‘ื™ื
    ื•ืฉื•ืœื— ื‘ืงืฉื” ืœื ื—ื•ืงื™ืช ื“ืจืš ื›ืœ ืฉืจืฉื•ืจ, ืžื” ืฉื’ื•ืจื ืœืฉืจืช ืœืฉืœื•ื— ืžืกื’ืจื•ืช RST_STREAM, ืืš ืื™ื ื• ืžืงื‘ืœ ืื•ืชืŸ ื›ื“ื™ ืœืžืœื ืืช ืชื•ืจ ื”ืชื’ื•ื‘ื•ืช;

  • CVE-2019-9515 (Settings Flood) - ื”ืชื•ืงืฃ ืฉื•ืœื— ื–ืจื ืฉืœ ืžืกื’ืจื•ืช "SETTINGS" ืจื™ืงื•ืช, ื‘ืชื’ื•ื‘ื” ืขืœ ื”ืฉืจืช ืœืืฉืจ ืงื‘ืœื” ืฉืœ ื›ืœ ื‘ืงืฉื”;
  • CVE-2019-9516 (0-Length Headers Leak) - ืชื•ืงืฃ ืฉื•ืœื— ื–ืจื ืฉืœ ื›ื•ืชืจื•ืช ืขื ืฉื null ื•ืขืจืš null, ื•ื”ืฉืจืช ืžืงืฆื” ืžืื’ืจ ื‘ื–ื™ื›ืจื•ืŸ ืœืื—ืกื•ืŸ ื›ืœ ื›ื•ืชืจืช ื•ืœื ืžืฉื—ืจืจ ืื•ืชื• ืขื“ ืฉื”ื”ืคืขืœื” ืžืกืชื™ื™ืžืช ;
  • CVE-2019-9517 (Buffering Internal Data) - ื”ืชื•ืงืฃ ื ืคืชื—
    ื—ืœื•ืŸ ื”ื–ื–ื” ืฉืœ HTTP/2 ืขื‘ื•ืจ ื”ืฉืจืช ืœืฉืœื™ื—ืช ื ืชื•ื ื™ื ืœืœื ื”ื’ื‘ืœื•ืช, ืืš ืฉื•ืžืจ ืขืœ ื—ืœื•ืŸ ื”-TCP ืกื’ื•ืจ, ื•ืžื•ื ืข ืžื”ื ืชื•ื ื™ื ืœื”ื™ื›ืชื‘ ื‘ืคื•ืขืœ ืœืฉืงืข. ืœืื—ืจ ืžื›ืŸ, ื”ืชื•ืงืฃ ืฉื•ืœื— ื‘ืงืฉื•ืช ื”ื“ื•ืจืฉื•ืช ืชื’ื•ื‘ื” ื’ื“ื•ืœื”;

  • CVE-2019-9518 (Empty Frames Flood) - ืชื•ืงืฃ ืฉื•ืœื— ื–ืจื ืฉืœ ืคืจื™ื™ืžื™ื ืžืกื•ื’ DATA, HEADERS, CONTINUATION ืื• PUSH_PROMISE, ืืš ืขื ืžื˜ืขืŸ ืจื™ืง ื•ืœืœื ื“ื’ืœ ืกื™ื•ื ื–ืจื™ืžื”. ื”ืฉืจืช ืžื‘ืœื” ื–ืžืŸ ื‘ืขื™ื‘ื•ื“ ื›ืœ ืคืจื™ื™ื, ืœื ืคืจื•ืคื•ืจืฆื™ื•ื ืœื™ ืœืจื•ื—ื‘ ื”ืคืก ืฉืฆื•ืจืš ื”ืชื•ืงืฃ.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”