Skip to content

Comment on Codex Discovered a Hidden HTTP/2 Bomb

Comments

After reading the article, I can conclude that Codex discovered nothing new.

This is already something that is known, and if you're able to be targeted by this (which is not the majority of users) configure your httpd differently.

Apache and nginx maintainers implemented fixes one or two days after the author reported, so how do you mean this was known already?

AFIAK, it was already being actively exploited in DDoS attacks.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.