OpenAI Codex Aids HTTP/2 Web Server Exploit Discovery
TL;DR. Security researchers discovered a new HTTP/2 Bomb exploit, aided by OpenAI's Codex, capable of knocking major web servers offline in seconds. - The exploit chains known denial-of-service techniques, including a compression bomb and a Slowloris-style hold. - Over 880,000 websites running default NGINX, Apache HTTPD, Microsoft IIS, Envoy, or Cloudflare Pingora are potentially affected. - A single home computer with a 100 Mbps connection can launch the attack, rendering servers unavailable rapidly.
- A new HTTP/2 Bomb exploit combines a compression bomb (HPACK Bomb) with a Slowloris-style hold.
- OpenAI's Codex assisted Calif security researchers in discovering this attack chain.
- The exploit can take down major web servers like NGINX, Apache, and Microsoft IIS within seconds.
- Many modern web servers use HTTP/2 by default, making a vast number of sites vulnerable.
Sources
- ‘HTTP/2 Bomb’ Exploit Knocks Web Servers Offline in Seconds — securityweek.com
- bleepingcomputer.com — bleepingcomputer.com