advanced
Rapid Proxy Rotation explained
TL;DR
Rapid Proxy Rotation is an effective DDoS attack technique that bypasses traditional rate-based detection and mitigation mechanisms.
The use of Proxies in Layer-7-DDoS
HTTP/2 Continuation Flood (and POC)
Intro
In early April 2024, Bartek Nowotarski disclosed a new DDoS attack technique named "HTTP/2 Continuation Flood", which exploits vulnerabilities in various
Fuzzing Smugglers / A dive into attacking WAFs
Utilizing a blend of header smuggling and header fuzzing, sophisticated HTTP attack techniques can effectively deliver DDoS payloads, either by evading detection by Web Application Firewalls (WAFs) or by targeting the WAF-encoders themselves
HTTP/2 attacks measured (Floods and RapidReset)
a comparison of HTTP/2 RapidReset vector-potential vs established vectors: IoT/HTTP/2 Multiplexing