2 ms·
If anyone is curios, Nginx is vulnerable to this https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products https://www.nginx.com/blog/ht
by vdfs 3y ago
If anyone is curios, Nginx is vulnerable to this
https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products https://www.nginx.com/blog/http-2-rapid-reset-attack-impacti...
- obituary_latte 3y agoIF configured away from the defaults: By relying on the default keepalive limit, NGINX prevents this type of attack. Creating additional connections to circumvent this limit exposes bad actors via standard layer 4 monitoring and alerting tools. However, if NGINX is configured with a keepalive that is substantially higher than the default and recommended setting, the attack may deplete system resources.