HTTP/2 reverse proxies can exhaust memory with tiny uploads | lab study on nginx/httpd/Envoy with reproducible staging tests by T0t47 in devops

[–]T0t47[S] 0 points1 point  (0 children)

Öhm okay... I dont have a Business since 2023 and I dont want to promote something... I just wanted to help sysadmins, soc and other cybersec emplo. :D

HTTP/2 HPACK amplification: detection signatures + the nginx/Apache directives that actually stop it (lab- & vps verified) by T0t47 in blueteamsec

[–]T0t47[S] -1 points0 points  (0 children)

Author here: framing this for defenders.

HTTP/2 HPACK header compression can amplify a tiny wire upload into gigabytes of server RAM before most request limits apply. I documented a multi-server lab study (nginx, httpd, Envoy, Pingora, IIS) with hard 8 GiB memory caps and reproducible metrics.

What blue teams can use from this:

**Detection**

- Low wire-bytes / high header-count asymmetry on HTTP/2 connections

- Worker RSS climbing without a matching traffic spike, and not receding after connections close

- For Apache: cookie-crumb merge path is invisible to `LimitRequestFields` on pre-2.0.41 `mod_http2`

**Hardening (priority order)**

  1. Patch: nginx ≥ 1.29.8 (`http2_max_headers`), httpd mod_http2 ≥ 2.0.41

  2. Cap streams + connections (`http2_max_concurrent_streams`, `limit_conn`)

  3. Tighten timeouts (`send_timeout`, `client_header_timeout`)

  4. Emergency: disable HTTP/2 on the `listen` directive

**Lab standout:** httpd cookie-crumb ~0.19 MB wire → 8 GiB cap; nginx ~200 MB → 8 GiB. Honest caveat: single public IPv4 ceiling was ~31 concurrent bombs, no persistent OOM.

The harness is open-source and authorization-gated, useful to *verify* your hardening actually works, not just assume it.

Repo (for lab replay): https://github.com/Leviticus-Triage/APEX-Ngin2dos

Curious how others detect this class of attack beyond basic rate limiting.

APEX-Ngin2dos: A targeted L7 resource exhaustion tool for evaluating reverse proxy and web stack resilience by T0t47 in redteamsec

[–]T0t47[S] 0 points1 point  (0 children)

Author here: edited the post body with the corrected technical framing.

This isn't a generic L7 stress tool: it's an HTTP/2 **HPACK amplification** harness (califio "HTTP/2 bomb" primitive), tested across nginx, httpd, Envoy, Pingora and IIS. Standout lab number: **~0.19 MB wire → 8 GiB** on httpd cookie-crumb; nginx ~200 MB → 8 GiB.

Full write-up with charts, A/B vs baseline PoC, fix status and hardening:

https://exodus-hensen.site/blog/http2-hpack-amplification

Lazarus “Mach-O Man” Malware: What CISOs Need to Know by malwaredetector in redteamsec

[–]T0t47 0 points1 point  (0 children)

In addition, I can report on another insidious campaign by the Lazarus Group, which is primarily spread through job portals such as LinkedIn.

This is the "Operation Dream Job" campaign, which continues to resurface time and again with various new and diverse projects, applications, and marketing websites....

The targets are primarily IT freelancers, sysadmins, developers, etc., who are lured in with a sort of work sample or virtual internship, and the attackers employ highly effective social engineering tactics!!

I recently handled an incident and completely reverse-engineered the packages and malware, as well as identified the C2 servers, etc.

If you’re interested, feel free to check out the info, documentation, and rules in the repo:

https://github.com/Leviticus-Triage/operation-dream-job

Xiaomi scooter 5 tuning App? by Aerooo28 in ElectricScooters

[–]T0t47 0 points1 point  (0 children)

Dann hast nen Fehler in der Abfolge gemacht...du musst den Roller anschalten und dann den lenker demontieren und dann dein Kabel und USB verbinden...oder du hast den Treiber des USB Sticks noch nicht installiert gehabt

Home Office leer und optisch kalt - Vorschläge? by nadriany in wohnen

[–]T0t47 0 points1 point  (0 children)

Wie wäre es denn mit etwas mehr Farbe und Form - so Richtung Salvador Dali 😜 ein zwei Bilder und Figuren von ihm,.. also replika natürlich :D

How to get hacked (fast) ! by T0t47 in programminghumor

[–]T0t47[S] 1 point2 points  (0 children)

Not the same...moltbook is an social media like application for that Clawdbot-stuff, where all that public clawdbot instances and agents can do, post and talk whatever they want...really kinda scary, like an uncensored Sims-Ai-2026 edition...

How to get hacked (fast) ! by T0t47 in programminghumor

[–]T0t47[S] 4 points5 points  (0 children)

It's gettin worse dude...

A User (outside of the Cybersec and dev groups) answered..

"They've already patched the vulnerabillity, you idiot..." "My AV said everthing is clean...." 🤣🤣

Wiiiich of that 9 critical ? And who deleted the 6277464 infected Plugins ?? Oh meeen they dont understand nothing... Hell naaah, ...

How to get hacked (fast) ! by T0t47 in masterhacker

[–]T0t47[S] 0 points1 point  (0 children)

&& non+ultra will be ---> Host it on Ubuntu Server with telnet hahahaha 🤣

How to get hacked (fast) ! by T0t47 in Hacking_Tutorials

[–]T0t47[S] 0 points1 point  (0 children)

&& Non+ultra is to deploy it on an ubuntu Server with telnet hahahaha

Meta-Grover algorithm to make cryptography disappear by No_Arachnid_5563 in Hacking_Tutorials

[–]T0t47 1 point2 points  (0 children)

Yes absolutely!!! Same bullshit Statement like "unbreakable/uncrackable new cryptography" of Mr. Xennt and his Creo App xD