meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, October 11th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 11 October 2023

⏱️ 8 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Rapid Reset; Microsoft Patch Tuesday

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Wednesday, October 11, 2020,

0:04.3

edition of the Sansanet Storm Center's Stormcast.

0:08.5

My name is Johannes Ulrich, and the time I'm recording from Jacksonville, Florida.

0:14.0

Well, it's Patch Tuesday, but for a change, I won't start, at least not directly,

0:19.1

with the Microsoft Patch Tuesday content.

0:21.7

Instead, I'll first talk a little bit about the HDP2 Rapid Reset Denial of Service

0:27.6

attack that was discussed in a Cloudflare blog today.

0:32.6

Cloudflare AWS, Google, they all saw these attacks in late August being launched to basically send an

0:40.4

enormous amount of HTTP requests to their servers.

0:46.0

And, well, the attack itself is tricky because it really abuses a feature in HAP2.

0:53.2

So first, very briefly, what's so special and different about HGP2, the real difference when

1:00.6

it comes to HP2 is that a client in a server are able to efficiently use a single TCP connection.

1:09.0

In HP 1.1, it can happen that, for example, a resource that's

1:14.5

slow-to-load, sort of holds back all the other responses. Well, this cannot happen in HP2

1:21.0

because the server is able to define multiple streams for multiple responses, and that way, if one particular response

1:30.8

currently doesn't have anything to send, that bandwidth can be used by another response.

1:36.5

In some ways, I always describe it, and it may be a little bit oversimplified, but like HP2 is

1:42.3

sort of trying to re-implement TCP on the application layer.

1:47.4

And well, with that, we also have the ability to reset connections.

1:52.7

So normally if, let's say, you are loading a page and while you're starting to read the page,

1:59.6

you decide to click on a link before the page is fully loaded in HP1.1,

2:04.5

well, the TCP connection would basically be stopped with TCP reset,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.