HTTP/2 desync attacks | Techzone
Summary
Researcher James Kettle recently published a set of HTTP/2 desynchronization attacks against proxies transforming HTTP/2 to HTTP/1.1 [1]. By crafting special HTTP/2 requests an attacker can bypass critical security controls of WAFs like authorization checks. Airlock Gateway supports HTTP/2 to HTTP/1.1 transformation by default (see Virtual Host setting Enable HTTP/2). Most attack types were blocked by the web listener (Apache HTTP Server) of Airlock Gateway before they hit the core engine (Gatekeeper). These attack types were blocked by the core engine of Airlock Gateway in the default configuration.
Classifications
industries
Telecommunications
applications
Business Planning / Continuity
AskAI Classifications
Labels
Software Development
SaaS
Standard Software
Linked Companies
Ergon Informatik AG
$10M to $25M