‘Rapid Reset’ DDoS Attack Hits HTTP/2 Web Servers

A vulnerability in the HTTP/2 protocol dubbed “Rapid Reset” has led to record DDoS attacks on web servers in recent months. Google, AWS and Cloudflare jointly revealed the attacks and vulnerability today, but noted that every modern web server remains vulnerable to the attack technique. Web server vendors and projects also announced mitigation measures and […]

The post ‘Rapid Reset’ DDoS Attack Hits HTTP/2 Web Servers appeared first on eSecurity Planet.

October 10, 2023
Read More >>

ChopChop – Web Security Testing Tool

ChopChop is a command-line tool for dynamic application security testing on web applications, initially written by the Michelin CERT. Its goal is to scan several endpoints and identify exposition of services/files/folders through the webroot. Checks/Signatures are declared in a config file (by default: chopchop.yml), fully configurable, and especially by developers. “Chop chop” is a phrase rooted in […]

October 10, 2023
Read More >>