#http2 — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #http2, aggregated by home.social.
-
Google's HTTP/2 codec slows Envoy
https://apoxy.dev/blog/oghttp2-vs-nghttp2
Comments: https://news.ycombinator.com/item?id=49182586
#HackerNews #Google #HTTP2 #Envoy #Codec #Performance #TechNews
-
Google's HTTP/2 codec slows Envoy
https://apoxy.dev/blog/oghttp2-vs-nghttp2
Comments: https://news.ycombinator.com/item?id=49182586
#HackerNews #Google #HTTP2 #Envoy #Codec #Performance #TechNews
-
Following some discussions during #IETF last week (in the hallway and on various mailing lists), the awesome #IPvFoo extension now shows in Mozilla #FireFox if connections used H1, H2, or H3, not just IPv4-vs-IPv6! This is helpful for seeing how that angle of Happy Eyeballs works.
(It would work in the Chrome version as well but the interface for getting at this info is broken and always returns H1.)
Note that if the connection starts with H2 but then switches to H3 for later objects on the hostname (eg, if you have an Alt-Svc record) then it will show H3 rather than H2.
-
Following some discussions during #IETF last week (in the hallway and on various mailing lists), the awesome #IPvFoo extension now shows in Mozilla #FireFox if connections used H1, H2, or H3, not just IPv4-vs-IPv6! This is helpful for seeing how that angle of Happy Eyeballs works.
(It would work in the Chrome version as well but the interface for getting at this info is broken and always returns H1.)
Note that if the connection starts with H2 but then switches to H3 for later objects on the hostname (eg, if you have an Alt-Svc record) then it will show H3 rather than H2.
-
Bandwidth амплификация с коэффициентом x783, вызванная трансляцией HTTP/2 → HTTP/1.1 в Cloudflare
За счёт трансляции HTTP/2 в HTTP/1.1 при проксировании запроса через Cloudflare можно достичь увеличения объёма полезной нагрузки в 783 раза. Это коэффициент payload-to-payload, без учёта накладных расходов на сетевом, транспортном уровне и уровне представления, а так же без учёта расхода трафика на инициализацию HTTP/2 соединения (отправка client preface, settings, ack и первого прогревочного запроса).
-
По обе стороны антибота: как я имитирую Chrome при скрейпинге и ловлю ботов по тем же сигналам
Я собираю афишу города в одну карту из пяти источников. Два из них — Яндекс.Афиша и afisha.ru — собирать себя не хотят. И режут не так, как ждешь: ни логина, ни капчи на входе, ни «подтвердите, что вы не робот». Мой requests.get(...) ловит 403 — даже когда заголовки скопированы из Chrome один в один . Первая мысль была дурацкая: где-то не хватает куки или очередного sec-ch-ua . Оказалось — проблема раньше. К тому моменту, когда сервер читает мой браузерный User-Agent , он уже успел посмотреть, как именно клиент открыл защищенное соединение . Питоновский клиент палится ровно тем, как он здоровается.
https://habr.com/ru/articles/1063180/
#TLS_fingerprint #JA3 #JA4 #curl_cffi #антибот #парсинг #BoringSSL #fraud_score #bot_detection #http2
-
Как изменилась жизнь интернет-безопасников с приходом QUIC? IDS и threat analysing в реалиях HTTP/3
Обзорный анализ “нового” протокола HTTP/3 и подходов к анализу трафика и защите информационных систем построенных на его основе. Фингерпринтинг выступает одной из больших тем статьи, ему уделено отдельное внимание. Читать
-
А мой веб-сервер точно нормально работает?
У меня есть сервер в интернете, который работает с HTTP/2, HTTP/3, с IPv4 и IPv6… Как всё это хозяйство протестировать? Я не нашёл решение и прибёг к помощи ИИ, который мне навайбкодил нужный мне сервис. Всё это хорошо. Но, может быть из этой идеи можно слепить годный продукт или просто доработать этот? Если у вас те же проблемы с тестированием своего сайта, добро пожаловать под кат. Там я расскажу, с какой проблемой я лично столкнулся. И как, временно, решил этот вопрос.
-
Microsoft corrige 200 vulnerabilidades en el Patch Tuesday de junio 2026
La actualización mensual de seguridad incluye casi 40 fallas críticas en Windows, Azure, Office, Outlook y Exchange, y suma 360 correcciones adicionales en componentes de terceros. Tres vulnerabilidades ya habían sido divulgadas públicamente antes de ser parcheadas (Fuente Microsoft).
El Patch Tuesday de junio 2026 de Microsoft es uno de los más voluminosos del año. Las actualizaciones de seguridad de junio de 2026 corrigen aproximadamente 200 vulnerabilidades descubiertas en los productos de la compañía. Ninguna parece haber sido explotada en el mundo real, pero tres problemas fueron divulgados públicamente antes de que Microsoft los parcheara.
Las tres vulnerabilidades previamente expuestas concentran la atención de los investigadores. La primera es CVE-2026-49160, un problema de denegación de servicio (DoS) en Windows relacionado con HTTP2/Bomb, una técnica de ataque capaz de dejar fuera de línea servidores web en segundos y que podría afectar a cientos de miles de sitios. La segunda es CVE-2026-50507, un bypass de seguridad en Windows BitLocker que permite a un atacante con acceso físico al sistema acceder a datos cifrados. La falla podría estar relacionada con YellowKey, uno de los exploits filtrados por un investigador conocido como Chaotic Eclipse y Nightmare Eclipse tras una disputa con Microsoft, cuyas filtraciones previas ya fueron aprovechadas en ataques reales. La tercera es CVE-2026-45586, un bug en Windows Collaborative Translation Framework que permite elevar privilegios al nivel System, reportado por un investigador anónimo. Las tres recibieron la calificación de «explotación más probable» por parte de Microsoft.
En el panorama general del parche, casi 40 de las aproximadamente 200 vulnerabilidades tienen calificación crítica. Afectan a Windows, Azure, Office, Outlook, Exchange y herramientas de IA, y su explotación puede derivar en ejecución remota de código, escalada de privilegios y divulgación de información. A ese número se suma un volumen adicional significativo: Microsoft publicó avisos de seguridad para 360 problemas adicionales que afectan a componentes de terceros utilizados por su software.
En paralelo, Adobe también lanzó sus actualizaciones de Patch Tuesday de junio, corrigiendo más de 120 vulnerabilidades. Para los equipos de seguridad IT, la primera semana de junio implica una carga de trabajo considerable. La recomendación es clara: aplicar las actualizaciones cuanto antes, especialmente en entornos con BitLocker activo o servidores web expuestos.
#Actualizacion #adobe #azure #BitLocker #ciberseguridad #CVE #exchange #HTTP2 #microsoft #office #PatchTuesday #PORTADA #SeguridadInformatica #vulnerabilidades #windows -
[Перевод] Создаём HTTP/2-сервер на C++ и хостим на нём свой сайт
Что будет, если написать HTTP/2-сервер на C++23 с нуля, собрать для него минимальный контейнер и выставить всё это в интернет? Я проверил проект на реальном трафике, усилил защиту бинарника и контейнера, столкнулся с ограничениями Cloudflare, bunny.net и Cloud Run, а заодно поймал утечку памяти в OpenSSL. Получился практический разбор того, где заканчивается учебный эксперимент и начинается эксплуатация системного кода. Заглянуть под капот
https://habr.com/ru/companies/otus/articles/1044058/
#C++ #http2 #c++23 #вебсервер #системное_программирование #контейнеризация #tls #безопасность_контейнеров #управление_памятью #OpenSSL
-
This Week in Security: Messing with AI, 7Zip and Notepad++ Vulnerabilities, HTTP2 Bomb, and More
-
This Week in Security: Messing with AI, 7Zip and Notepad++ Vulnerabilities, HTTP2 Bomb, and More
-
📰 New 'HTTP/2 Bomb' Exploit Can Crash NGINX, Apache, and Other Major Web Servers in Seconds
💣 A new 'HTTP/2 Bomb' exploit can knock major web servers (NGINX, Apache, IIS) offline in seconds. The attack chains known bugs to create a potent DoS threat. 880,000+ sites potentially at risk. #DoS #Vulnerability #HTTP2
🌐 cyber[.]netsecops[.]io
-
💣 HTTP/2 Bomb : une "nouvelle" vulnérabilité DoS permet à un seul client d'épuiser la mémoire d'un serveur web en quelques secondes.
Les chercheurs de Calif et leurs 🤖 Codex ont démontré qu'une combinaison entre l'amplification HPACK et des techniques proches du Slowloris HTTP/2 peut provoquer une consommation mémoire massive.
⚠️ Produits concernés :
• NGINX
• Apache HTTPD
• Microsoft IIS
• Envoy
• Cloudflare Pingora
...🩹 Rémediation :
✅ NGINX
• Mettre à jour vers 1.29.8+
• Sinon désactiver HTTP/2 temporairement✅ Apache HTTPD
• Mettre à jour mod_http2 vers 2.0.41+
• Sinon revenir à HTTP/1.1:debian: https://security-tracker.debian.org/tracker/CVE-2026-49975
:opensuse: https://www.suse.com/security/cve/CVE-2026-49975.html
🛡️ Mitigations complémentaires :
• Limiter la mémoire par processus (cgroups, conteneurs, ulimit)
• Surveiller les pics de consommation mémoire des workers web
• Vérifier que les protections OOM interviennent avant l'utilisation du swap📖 Analyse :
https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb🧪 PoC :
https://github.com/califio/publications/tree/main/MADBugs/http2-bomb -
Codex Discovered a Hidden HTTP/2 Bomb
https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb
#http #http2 #http2bomb #apache #httpd #nginx #envoy #IIS #cve #cve_2026_49975
-
Codex Discovered a Hidden HTTP/2 Bomb
https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb
#http #http2 #http2bomb #apache #httpd #nginx #envoy #IIS #cve #cve_2026_49975
-
Preliminary assessment: We consider Vinyl Cache safe against the attack vector named "HTTP/2 Bomb", because it does not allow the amplification method underlying it.
#http2 #http2bomb #vinyl_cachehttps://vinyl-cache.org/lists/pipermail/vinyl-dev/2026-June/004936.html
-
Preliminary assessment: We consider Vinyl Cache safe against the attack vector named "HTTP/2 Bomb", because it does not allow the amplification method underlying it.
#http2 #http2bomb #vinyl_cachehttps://vinyl-cache.org/lists/pipermail/vinyl-dev/2026-June/004936.html
-
https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb
We’re publishing HTTP/2 Bomb, a remote denial-of-service exploit against most major web servers, including:
nginx
Apache httpd
Microsoft IIS
Envoy
Cloudflare Pingora
The vulnerable behavior exists in each server's default HTTP/2 configuration.
A home computer on a 100Mbps connection can render a vulnerable server inaccessible within seconds.#infoSec #cybersecurity #apache #nginx #http2
Thx @hexa for pointing it out
-
https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb
We’re publishing HTTP/2 Bomb, a remote denial-of-service exploit against most major web servers, including:
nginx
Apache httpd
Microsoft IIS
Envoy
Cloudflare Pingora
The vulnerable behavior exists in each server's default HTTP/2 configuration.
A home computer on a 100Mbps connection can render a vulnerable server inaccessible within seconds.#infoSec #cybersecurity #apache #nginx #http2
Thx @hexa for pointing it out
-
#Freenginx 1.31.2 has been released ( #nginx / #http / #http2 / #http3 / #httpd / #Web / #Webserver / #TLS / #TLS13 ) https://freenginx.org/
-
#Freenginx 1.31.2 has been released ( #nginx / #http / #http2 / #http3 / #httpd / #Web / #Webserver / #TLS / #TLS13 ) https://freenginx.org/
-
#nginx 1.31.1 (dev) has been released ( #http / #http2 / #http3 / #httpd / #Web / #Webserver / #TLS / #TLS13 / #CVE / #SecurityVulnerability ) https://nginx.org/
-
#nginx 1.31.1 (dev) has been released ( #http / #http2 / #http3 / #httpd / #Web / #Webserver / #TLS / #TLS13 / #CVE / #SecurityVulnerability ) https://nginx.org/
-
#nginx 1.30.2 has been released ( #http / #http2 / #http3 / #httpd / #Web / #Webserver / #TLS / #TLS13 / #CVE / #SecurityVulnerability ) https://nginx.org/
-
#nginx 1.30.2 has been released ( #http / #http2 / #http3 / #httpd / #Web / #Webserver / #TLS / #TLS13 / #CVE / #SecurityVulnerability ) https://nginx.org/
-
Oh joy, yet another article explaining how to unleash the "power" of HTTP/2 cleartext in #Go 1.24. 🚀 Because clearly, the world needed *another* way to serve data without encryption. 🙄 If exposing your data to the world was an Olympic sport, this article would take gold. 🏅
https://www.clarityboss.com/blog/go-http2-cleartext-h2c-cloud-run #HTTP2 #HTTP2Cleartext #DataSecurity #GoldMedal #HackerNews #ngated -
Oh joy, yet another article explaining how to unleash the "power" of HTTP/2 cleartext in #Go 1.24. 🚀 Because clearly, the world needed *another* way to serve data without encryption. 🙄 If exposing your data to the world was an Olympic sport, this article would take gold. 🏅
https://www.clarityboss.com/blog/go-http2-cleartext-h2c-cloud-run #HTTP2 #HTTP2Cleartext #DataSecurity #GoldMedal #HackerNews #ngated -
Using HTTP/2 Cleartext for a server in Go 1.24
https://www.clarityboss.com/blog/go-http2-cleartext-h2c-cloud-run
-
Using HTTP/2 Cleartext for a server in Go 1.24
https://www.clarityboss.com/blog/go-http2-cleartext-h2c-cloud-run
-
Apache HTTP Server Flaw Enables DoS and Potential RCE Attacks
A critical flaw in the Apache HTTP Server, known as CVE-2026-23918, can be exploited to launch devastating denial-of-service (DoS) and potential remote code execution (RCE) attacks, putting your online security at risk. This high-severity bug has been patched in Apache HTTP Server version 2.4.67, so updating is crucial to prevent…
#ApacheHttpServer #Cve202623918 #DenialOfService #RemoteCodeExecution #Http2
-
Почему на фронте нет GRPC?
Я всю жизнь писал только бэк и подкапотщину - будь это классический КРУД, хайлоад, CLI, [вставьте свое]... И для любых сетевых взаимодействий чаще всего люди думают именно прикладными вещами - GRPC, REST, Kafka, не задумываясь об этом глубже - супер удобные инструменты с защитами от дураков и прочими радостями Но тут спохватился я писать фронт - подключать свое же к себе же. И в этот момент я понял, насколько же это сложно, муторно и, главное, НЕУДОБНО взаимодействовать REST'ом ЗАЧЕМ ОН НУЖЕН?? - У нас нет удобного контракта общения (eg Proto, Avro) кроме Swagger, который нужно поддерживать с обеих сторон. Да и к тому-же, сложность взаимодействия с JSONом с ОБЕИХ СТОРОН - одна постоянно маршаллит, защищается, ищет поля, в то время другая боится резких обновлений, что строчка получения поля может превратиться в что-то в роде connect via grpc
https://habr.com/ru/articles/1019510/
#grpc #rest #GraphQL #gRPCWeb #WebTransport #tRPC #Connect_protocol #браузер #http2 #http3
-
Руководство по оптимизации производительности сайта
Если у вас есть собственный сайт — вы наверняка проверяли его работу с телефона. Открыли, полистали, остались довольны: «Всё летает». Но это не гарантия, что так же быстро сайт загрузится у ваших посетителей. Представьте: пользователь заходит на ваш сайт с iPhone (неважно, нового или трёхлетней давности) — и страница зависает, изображения грузятся по одному, скролл дёргается. Через 5–10 секунд он просто закрывает вкладку и уходит к конкурентам. Проблема не в вашем телефоне или интернете, а в скрытых особенностях браузера Safari и устройств iOS. Ниже — руководство по оптимизации, которое поможет избежать таких сценариев. Пройдитесь по чек‑листу и убедитесь, что каждый пункт выполнен. Даже если ваш сайт кажется быстрым, с большой вероятностью он теряет часть аудитории на Safari.
https://habr.com/ru/articles/1018636/
#оптимизация_сайта #скорость_загрузки #Safari #клиентская_оптимизация #http2 #lazy_loading #defer #WebP #Lighthouse #производительность_фронтенда
-
HTTP/2 и HTTP/3: настройка, достоинства и недостатки
Наверняка вы слышали о новых версиях HTTP — второй и третьей. Что за этими версиями? Зачем они были разработаны? Чем они отличаются от классического HTTP/1.1 и где могут быть полезны? Какие настройки предоставляет веб‑сервер Angie для этих протоколов? Все эти вопросы мы будем разбирать в этой статье. Начнём с краткой истории развития протокола HTTP.
-
@ant0inet: Merci für den Hinweis auf das unter #CreativeCommons stehende High Performance
Browser Networking Buch aus dem #OReillyVerlag unter https://hpbn.co/! -
@ant0inet: Merci für den Hinweis auf das unter #CreativeCommons stehende High Performance
Browser Networking Buch aus dem #OReillyVerlag unter https://hpbn.co/! -
🪧 HTTP/2 From Scratch: Part 4: More HPACK and using http.Request and http.Response
https://kmcd.dev/posts/http2-from-scratch-part-4/
#Go #Http2 #Protocols #Networking -
🪧 HTTP/2 From Scratch: Part 4: More HPACK and using http.Request and http.Response
https://kmcd.dev/posts/http2-from-scratch-part-4/
#Go #Http2 #Protocols #Networking -
🪧 HTTP/2 From Scratch: Part 3: Decoding HPACK and the evolution of the HTTP header
https://kmcd.dev/posts/http2-from-scratch-part-3/
#Go #Http2 #Protocols #Networking -
🪧 HTTP/2 From Scratch: Part 3: Decoding HPACK and the evolution of the HTTP header
https://kmcd.dev/posts/http2-from-scratch-part-3/
#Go #Http2 #Protocols #Networking -
Weekend Reads
* Peering market evolution
https://blog.lacnic.net/en/peering-market-at-a-glance/
* BGP path security with ASPA
https://blog.cloudflare.com/aspa-secure-internet/
* HTTP/2 from scratch part 2
https://kmcd.dev/posts/http2-from-scratch-part-2/
* First subsea optic cable removal
https://www.wired.com/story/say-goodbye-to-the-undersea-cable-that-made-the-global-internet-possible/
* Password managers comparative analysis
https://eprint.iacr.org/2026/058.pdf -
🪧 HTTP/2 From Scratch: Part 2: Diving into the binary framing layer and byte-shifting in Go
https://kmcd.dev/posts/http2-from-scratch-part-2/
#Go #Http2 #Protocols #Networking -
🪧 HTTP/2 From Scratch: Part 2: Diving into the binary framing layer and byte-shifting in Go
https://kmcd.dev/posts/http2-from-scratch-part-2/
#Go #Http2 #Protocols #Networking -
🪧 HTTP/2 From Scratch: Part 1: Re-building the web in Go to learn more about it
https://kmcd.dev/posts/http2-from-scratch-part-1/
#Go #Http2 #Protocols #Networking -
🪧 HTTP/2 From Scratch: Part 1: Re-building the web in Go to learn more about it
https://kmcd.dev/posts/http2-from-scratch-part-1/
#Go #Http2 #Protocols #Networking -
Ever wonder how Node handles HTTP‑2 while your code just sees familiar APIs? This piece walks through how Node “speaks” HTTP‑2 without you noticing.
-
After months (yes, months, because I have a life beyond open source) I finally finished the draft PR I had to add HTTP/2 support to on-finished, also thanks to the help of my Express teammates. Feel free to review it, any help is welcome.
https://github.com/jshttp/on-finished/pull/87
#nodejs #expressjs #webdev #http2 #javaScript #programming -
🚀 gRPC es el framework de Google que acelera la comunicación entre servicios. Usa HTTP/2 y Protocol Buffers para máximo rendimiento. ¡Conoce cómo funciona! 💻
Lee más 👉 https://www.soloingenieria.org/ingenieria-en-sistemas/grpc/
#gRPC #Microservicios #IngenieríaDeSistemas #DesarrolloBackend #ProtocolBuffers #HTTP2