New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
Mass Exploits of HTTP/1.1 Start Wednesday
raindog308
Administrator, Veteran
in General
Or so a security researcher claims/threatens. HTTP/1.1 still powers about 1/3 of the Internet.
The issue is the request smuggling attack, which HTTP/1.1 is vulnerable to.

Comments
Wow that's bad. I am hearing first time about this.
What are the known affected servers though...
Aehh... what does that mean? Maybe that about 1/3 of the http servers out there only support HTTP/1.1 (and not anything newer)? I'd argue that almost 100% of http servers support HTTP/1.1. So why not use that figure then? Would sound even more alarming then.
Why would a http server supporting HTTP/2.0 not be affected when it has to handle a HTTP/1.1 request? And are all HTTP/1.1-only web servers behind a reverse proxy? (otherwise, there won't be any request smuggling anyway)
So what's going to happen? Interesting to see 1/3 internet blackout, let's go out and enjoy life!
I recommend to read - and understand - @raindog308's linked LEB article (plus maybe Ted Unangst's article).
Why? Because I feel that this OP's title is somewhat misleading. Actually it's about a combination of at least 3 factors:
So, only a not so widespread constellation of factors allows that attack vector.