HTTP/2 desync attacks | Techzone

General News

Summary

Researcher James Kettle recently published a set of HTTP/2 desynchronization attacks against proxies transforming HTTP/2 to HTTP/1.1 [1]. By crafting special HTTP/2 requests an attacker can bypass critical security controls of WAFs like authorization checks. Airlock Gateway supports HTTP/2 to HTTP/1.1 transformation by default (see Virtual Host setting Enable HTTP/2). Most attack types were blocked by the web listener (Apache HTTP Server) of Airlock Gateway before they hit the core engine (Gatekeeper). These attack types were blocked by the core engine of Airlock Gateway in the default configuration.

Classifications

industries
Telecommunications
applications
Business Planning / Continuity

AskAI Classifications

Labels
Software Development SaaS Standard Software

Linked Companies

Ergon Informatik AG
$10M to $25M