{"id":140668,"date":"2025-08-14T11:12:07","date_gmt":"2025-08-14T09:12:07","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-realizacziyah-protokola-http-2-uproshhayushhaya-provedenie-dos-atak"},"modified":"2025-08-14T11:12:07","modified_gmt":"2025-08-14T09:12:07","slug":"uyazvimost-v-realizacziyah-protokola-http-2-uproshhayushhaya-provedenie-dos-atak","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-realizacziyah-protokola-http-2-uproshhayushhaya-provedenie-dos-atak","title":{"rendered":"O vulnerabilitate \u00een implement\u0103rile protocolului HTTP\/2, care faciliteaz\u0103 desf\u0103\u0219urarea atacurilor DoS","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>A fost prezentat\u0103 o nou\u0103 tehnic\u0103 de atac asupra implement\u0103rilor protocolului HTTP\/2, care simplific\u0103 efectuarea atacurilor de tip denial-of-service prin epuizarea resurselor serverului. Vulnerabilitatea a primit numele de cod MadeYouReset \u0219i permite, prin manipularea cadrelor de control HTTP\/2, inundarea serverului cu un num\u0103r mare de cereri, ocolind limitele stabilite.     <\/p>\n<p>Esentialul problemei este c\u0103 un client poate crea un num\u0103r foarte mare de fluxuri procesate simultan, indiferent de limita SETTINGS_MAX_CONCURRENT_STREAMS, reset\u00e2nd fiecare flux la \u00eenceput. O astfel de resetare face ca pentru a trimite o nou\u0103 cerere \u00een conexiunea HTTP\/2 stabilit\u0103, clientul s\u0103 nu fie necesar s\u0103 a\u0219tepte r\u0103spunsul de la <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/ro\/server\/dts-los-angeles\/\"   title=\"server\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"3975\">server<\/a> \u0219i poate direc\u021biona imediat un mare flux continuu de cereri, c\u00e2t permite l\u0103\u021bimea de band\u0103 a canalului de comunica\u021bie.       <\/p>\n<p>Clientul \u00eenceteaz\u0103 s\u0103 depind\u0103 de \u00eent\u00e2rzierile dintre trimiterea cererii \u0219i primirea r\u0103spunsului (RTT, round-trip time) \u0219i poate lansa un atac cu costuri minime, pe c\u00e2nd serverul continu\u0103 s\u0103 cheltuie resurse pentru procesarea cererilor primite. De exemplu, serverul aloc\u0103 structuri de date pentru noi fluxuri, analizeaz\u0103 cererea, decompune antetul \u0219i potrivi URL-ul cu resursa. \u00cen cazul unui atac asupra proxy-urilor inverse, atacul se poate extinde la backend-urile c\u0103tre care proxy-ul reu\u0219e\u0219te s\u0103 redirec\u021bioneze cererea \u00eenainte de resetare.    <\/p>\n<p>Vulnerabilitatea este similar\u0103 cu problema cunoscut\u0103 anterior, Rapid Reset (CVE-2023-44487) \u0219i este cauzat\u0103 de discrepan\u021ba \u00eentre logica resett\u0103rii fluxurilor, definit\u0103 \u00een specifica\u021bia protocolului HTTP\/2 \u0219i implementat\u0103 \u00een produsele finale. \u00cen specifica\u021bie este prev\u0103zut\u0103 posibilitatea reset\u0103rii fluxului de c\u0103tre client \u0219i server \u00een orice moment, dar \u00een multe implement\u0103ri HTTP\/2,<a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/ro\/server\/\"   title=\"servere\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"1779\">servere<\/a> dup\u0103 o astfel de resetare, cererea continu\u0103 s\u0103 fie procesat\u0103. Principalul aspect care distinge noul atac este c\u0103 resetarea proces\u0103rii cererii se realizeaz\u0103 la ini\u021biativa serverului, \u0219i nu prin trimiterea de c\u0103tre client a unui cadru cu flag-ul RST_STREAM.     <\/p>\n<p>Resetting by the server's initiative occurs when incorrect requests are received, but such requests are discarded immediately without initiating their full processing and without passing them to the backend. In order to achieve a complete request processing cycle, the attacker may first send a correct HTTP request, but then follow it up with an incorrect sequence of control frames in HTTP\/2. Such activity will cause the server to start processing the request properly, but then, due to an error in processing the following frames, it will reset the stream (change the stream state with the correct request to RST_STREAM).    <center><img decoding=\"async\" alt=\"O vulnerabilitate \u00een implement\u0103rile protocolului HTTP\/2, care faciliteaz\u0103 desf\u0103\u0219urarea atacurilor DoS\" src=\"\/wp-content\/uploads\/2025\/08\/3d278bdbd71f2845b0b29436ab30e8fb.png\" style=\"display:block;margin: 0 auto;\" \/><\/center>    <\/p>\n<p>The presence of the problem has been confirmed in HTTP servers like Apache Tomcat, Netty, Eclipse Jetty, Fastly, Varnish, Lighttpd, and Zephyr RTOS. The issue also manifests on websites and server services operated by Mozilla. Apache httpd, Apache Traffic Server, Node.js, LiteSpeed, and HAProxy are not vulnerable to this problem. The vulnerability status in Nginx remains undetermined.<br \/>\n<br \/>Sursa: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=63726\">opennet.ro<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u0430 \u043d\u043e\u0432\u0430\u044f \u0442\u0435\u0445\u043d\u0438\u043a\u0430 \u0430\u0442\u0430\u043a\u0438 \u043d\u0430 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430 HTTP\/2, \u0443\u043f\u0440\u043e\u0449\u0430\u044e\u0449\u0430\u044f \u043f\u0440\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u0435 \u0430\u0442\u0430\u043a \u0434\u043b\u044f \u0432\u044b\u0437\u043e\u0432\u0430 \u043e\u0442\u043a\u0430\u0437\u0430 \u0432 \u043e\u0431\u0441\u043b\u0443\u0436\u0438\u0432\u0430\u043d\u0438\u0438 \u0447\u0435\u0440\u0435\u0437 \u0438\u0441\u0447\u0435\u0440\u043f\u0430\u043d\u0438\u0435 \u0440\u0435\u0441\u0443\u0440\u0441\u043e\u0432 \u0441\u0435\u0440\u0432\u0435\u0440\u0430. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043f\u043e\u043b\u0443\u0447\u0438\u043b\u0430 \u043a\u043e\u0434\u043e\u0432\u043e\u0435 \u0438\u043c\u044f MadeYouReset \u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0447\u0435\u0440\u0435\u0437 \u043c\u0430\u043d\u0438\u043f\u0443\u043b\u044f\u0446\u0438\u0438 \u0443\u043f\u0440\u0430\u0432\u043b\u044f\u044e\u0449\u0438\u043c\u0438 \u043a\u0430\u0434\u0440\u0430\u043c\u0438 HTTP\/2 \u043d\u0430\u0432\u043e\u0434\u043d\u0438\u0442\u044c \u0441\u0435\u0440\u0432\u0435\u0440 \u0431\u043e\u043b\u044c\u0448\u0438\u043c \u043a\u043e\u043b\u0438\u0447\u0435\u0441\u0442\u0432\u043e\u043c \u0437\u0430\u043f\u0440\u043e\u0441\u043e\u0432 \u0432 \u043e\u0431\u0445\u043e\u0434 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u0438\u0439. \u0421\u0443\u0442\u044c \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u0432 \u0442\u043e\u043c, \u0447\u0442\u043e \u043a\u043b\u0438\u0435\u043d\u0442 \u043c\u043e\u0436\u0435\u0442 \u0441\u043e\u0437\u0434\u0430\u0442\u044c \u043e\u0447\u0435\u043d\u044c \u0431\u043e\u043b\u044c\u0448\u043e\u0435 \u0447\u0438\u0441\u043b\u043e \u043e\u0434\u043d\u043e\u0432\u0440\u0435\u043c\u0435\u043d\u043d\u043e \u043e\u0431\u0440\u0430\u0431\u0430\u0442\u044b\u0432\u0430\u0435\u043c\u044b\u0445 \u043f\u043e\u0442\u043e\u043a\u043e\u0432, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":140669,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-140668","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u0430 \u043d\u043e\u0432\u0430\u044f \u0442\u0435\u0445\u043d\u0438\u043a\u0430 \u0430\u0442\u0430\u043a\u0438 \u043d\u0430 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430 HTTP\/2, \u0443\u043f\u0440\u043e\u0449\u0430\u044e\u0449\u0430\u044f \u043f\u0440\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u0435 \u0430\u0442\u0430\u043a \u0434\u043b\u044f \u0432\u044b\u0437\u043e\u0432\u0430 \u043e\u0442\u043a\u0430\u0437\u0430 \u0432 \u043e\u0431\u0441\u043b\u0443\u0436\u0438\u0432\u0430\u043d\u0438\u0438 \u0447\u0435\u0440\u0435\u0437 \u0438\u0441\u0447\u0435\u0440\u043f\u0430\u043d\u0438\u0435 \u0440\u0435\u0441\u0443\u0440\u0441\u043e\u0432 \u0441\u0435\u0440\u0432\u0435\u0440\u0430.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-realizacziyah-protokola-http-2-uproshhayushhaya-provedenie-dos-atak\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f\u0445 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430 HTTP\/2, \u0443\u043f\u0440\u043e\u0449\u0430\u044e\u0449\u0430\u044f \u043f\u0440\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u0435 DoS-\u0430\u0442\u0430\u043a | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u0430 \u043d\u043e\u0432\u0430\u044f \u0442\u0435\u0445\u043d\u0438\u043a\u0430 \u0430\u0442\u0430\u043a\u0438 \u043d\u0430 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430 HTTP\/2, \u0443\u043f\u0440\u043e\u0449\u0430\u044e\u0449\u0430\u044f \u043f\u0440\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u0435 \u0430\u0442\u0430\u043a \u0434\u043b\u044f \u0432\u044b\u0437\u043e\u0432\u0430 \u043e\u0442\u043a\u0430\u0437\u0430 \u0432 \u043e\u0431\u0441\u043b\u0443\u0436\u0438\u0432\u0430\u043d\u0438\u0438 \u0447\u0435\u0440\u0435\u0437 \u0438\u0441\u0447\u0435\u0440\u043f\u0430\u043d\u0438\u0435 \u0440\u0435\u0441\u0443\u0440\u0441\u043e\u0432 \u0441\u0435\u0440\u0432\u0435\u0440\u0430.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-realizacziyah-protokola-http-2-uproshhayushhaya-provedenie-dos-atak\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2025-08-14T09:12:07+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2025-08-14T09:12:07+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerability in HTTP\/2 protocol implementations, simplifying the execution of DoS attacks | ProHoster","description":"A new attack technique has been introduced for implementations of the HTTP\/2 protocol, simplifying the execution of denial-of-service attacks through server resource exhaustion.","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-realizacziyah-protokola-http-2-uproshhayushhaya-provedenie-dos-atak","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f\u0445 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430 HTTP\/2, \u0443\u043f\u0440\u043e\u0449\u0430\u044e\u0449\u0430\u044f \u043f\u0440\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u0435 DoS-\u0430\u0442\u0430\u043a | ProHoster","og:description":"\u041f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u0430 \u043d\u043e\u0432\u0430\u044f \u0442\u0435\u0445\u043d\u0438\u043a\u0430 \u0430\u0442\u0430\u043a\u0438 \u043d\u0430 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430 HTTP\/2, \u0443\u043f\u0440\u043e\u0449\u0430\u044e\u0449\u0430\u044f \u043f\u0440\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u0435 \u0430\u0442\u0430\u043a \u0434\u043b\u044f \u0432\u044b\u0437\u043e\u0432\u0430 \u043e\u0442\u043a\u0430\u0437\u0430 \u0432 \u043e\u0431\u0441\u043b\u0443\u0436\u0438\u0432\u0430\u043d\u0438\u0438 \u0447\u0435\u0440\u0435\u0437 \u0438\u0441\u0447\u0435\u0440\u043f\u0430\u043d\u0438\u0435 \u0440\u0435\u0441\u0443\u0440\u0441\u043e\u0432 \u0441\u0435\u0440\u0432\u0435\u0440\u0430.","og:url":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-realizacziyah-protokola-http-2-uproshhayushhaya-provedenie-dos-atak","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2025-08-14T09:12:07+00:00","article:modified_time":"2025-08-14T09:12:07+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"140668","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-02-22 15:52:24","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-23 14:15:21","updated":"2026-02-22 15:52:24","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/140668","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=140668"}],"version-history":[{"count":2,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/140668\/revisions"}],"predecessor-version":[{"id":162504,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/140668\/revisions\/162504"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media\/140669"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=140668"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=140668"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=140668"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}