Toggle light / dark theme

New HTTP/2 ‘MadeYouReset’ Vulnerability Enables Large-Scale DoS Attacks

This attack is notable not least because it obviates the need for an attacker to send an RST_STREAM frame, thereby completely bypassing Rapid Reset mitigations, and also achieves the same impact as the latter.

In an advisory, the CERT Coordination Center (CERT/CC) said MadeYouReset exploits a mismatch caused by stream resets between HTTP/2 specifications and the internal architectures of many real-world web servers, resulting in resource exhaustion — something an attacker can exploit to induce a DoS attack.

New antidote for cobra bites discovered by Liverpool and Sydney researchers

Cobras kill thousands of people a year worldwide and perhaps a hundred thousand more are seriously maimed by necrosis – the death of body tissue and cells – caused by the venom, which can lead to amputation.

Current antivenom treatment is expensive and does not effectively treat the necrosis of the flesh where the bite occurs.

“Our discovery could drastically reduce the terrible injuries from necrosis caused by cobra bites – and it might also slow the venom, which could improve survival rates,” said Professor Greg Neely, a corresponding author of the study from the Charles Perkins Centre and Faculty of Science at the University of Sydney.

/* */