Apache HTTP Server 2.4.58 (CVE fixes)
downloads.apache.org
downloads.apache.org
HTTP/2 Rapid Reset: deconstructing the record-breaking attack - https://news.ycombinator.com/item?id=37831004 - Oct 2023 (23 comments)
HTTP/2 zero-day vulnerability results in record-breaking DDoS attacks - https://news.ycombinator.com/item?id=37830998 - Oct 2023 (71 comments)
The novel HTTP/2 'Rapid Reset' DDoS attack - https://news.ycombinator.com/item?id=37830987 - Oct 2023 (106 comments)
From the README of the apache_1.3.0 distribution (April 1998) https://archive.apache.org/dist/httpd/
Love this project. It changed the world and it still goes strong. The closest to "forever software"?
HTTP/2 Rapid Reset and Apache
https://github.com/icing/blog/blob/main/h2-rapid-reset.md
Apache httpd 2.4.58
core: Updated conf/mime.types:
- .js moved from 'application/javascript' to 'text/javascript'
That’s probably going to break something for somebody.This attack is just about failing to enforce the negotiated parameters during the start phase of the connection.
It doesn’t strike me as odd to question its fit for people who have more experience with containers. If there’s a reverse proxy in the front, one may just need business logic in the back.
I'm trying to imagine what that haircut would look like