¥¦¥§¥Ö¥µ¡¼¥Ð¡¼¤ò¿ôÉÃ°ÊÆâ¤Ë¥À¥¦¥ó¤µ¤»¤ë¡ÖHTTP/2 Bomb¡×¹¶·â¤¬OpenAI¤ÎCodex¤ò»È¤Ã¤ÆÈ¯¸«¤µ¤ì¤ë

ÉáÄ̤βÈÄíÍÑPC¤Ç¿ôÉÃ°ÊÆâ¤Ë¥µ¡¼¥Ð¡¼¤ò¥À¥¦¥ó¤µ¤»¤é¤ì¤ëDoS¹¶·â¼êË¡¤ò¥»¥¥å¥ê¥Æ¥£¸¦µæ¼Ô¤¬È¯¸«¤·¤Þ¤·¤¿¡£
Codex Discovered a Hidden HTTP/2 Bomb - Calif
https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb
New 'HTTP/2 Bomb' DoS attack crashes web servers in under a minute
º£²óȯ¸«¤µ¤ì¤¿¹¶·â¤Ï¡¢¤³¤ì¤Þ¤ÇÃΤé¤ì¤Æ¤¤¤¿¹¶·â¡ÖHPACK°µ½ÌÁýÉý¡×¤È¡¢HTTP/2¤Î¥Õ¥í¡¼À©¸æÄä»ß¤Ë¤è¤ëSlowloris·¿¤Î¥ê¥½¡¼¥¹ÊÝ»ý¤òÁȤ߹ç¤ï¤»¤¿¼êË¡¤Ç¤¹¡£nginx¡¢Apache HTTP Server¡¢Microsoft IIS¡¢Envoy¡¢Cloudflare Pingora¤Ê¤É¤Î¼çÍפʥ¦¥§¥Ö¥µ¡¼¥Ð¡¼¤Î¥Ç¥Õ¥©¥ë¥È¹½À®¤È¤Ê¤Ã¤Æ¤¤¤ëHTTP/2ÀßÄê¤Çµ¡Ç½¤·¤Þ¤¹¡£
HPACK°µ½ÌÁýÉý¹¶·â¤Ï¡¢HPACKưŪ¥Æ¡¼¥Ö¥ë¤Ë¥Ø¥Ã¥À¡¼¤òÁÞÆþ¤·¡¢¤½¤Î¸å1¥Ð¥¤¥ÈÄøÅÙ¤ÎÂ礤µ¤·¤«¤Ê¤¤¥³¥ó¥Ñ¥¯¥È¤Ê¥¤¥ó¥Ç¥Ã¥¯¥¹É½¸½¤òÍѤ¤¤Æ¤½¤Î¥Ø¥Ã¥À¡¼¤ò·«¤êÊÖ¤·»²¾È¤¹¤ë¤â¤Î¤Ç¤¹¡£¤½¤Î·ë²Ì¡¢¹¶·â¼Ô¤¬Á÷¿®¤·¤¿1¥Ð¥¤¥È¤¬¥µ¡¼¥Ð¡¼Â¦¤Ç¿ôÀé¥Ð¥¤¥È¤Î¥á¥â¥ê³ä¤êÅö¤Æ¤ò°ú¤µ¯¤³¤·¤Þ¤¹¡£
¹¶·â¤ÎÂè2Ãʳ¬¤Ç¡¢¥¼¥í¥Ð¥¤¥È¤Î¥Õ¥í¡¼À©¸æ¥¦¥£¥ó¥É¥¦¤òÄÌÃΤ·¡¢¥µ¡¼¥Ð¡¼¤¬±þÅú¤ÎÁ÷¿®¤ò´°Î»¤Ç¤¤Ê¤¤¤è¤¦¤Ë¤·¤Þ¤¹¡£¤³¤Î¾õ¶·¤Ç¤Ï¡¢¥ê¥¯¥¨¥¹¥È¤Ï´°Á´¤Ë´°Î»¤¹¤ë¤³¤È¤¬¤Ê¤¯¡¢³ä¤êÅö¤Æ¤é¤ì¤¿¥á¥â¥ê¤Ï²òÊü¤µ¤ì¤Ê¤¤¤Þ¤ÞÁý¤¨Â³¤±¤Þ¤¹¡£
¸¦µæ¼Ô¤Ï¡Ö100MbpsÀܳ¤Î²ÈÄíÍÑPC¤Ç¤â¡¢Àȼå(¤¼¤¤¤¸¤ã¤¯)¤Ê¥µ¡¼¥Ð¡¼¤ò¿ôÉÃ°ÊÆâ¤ËÍøÍÑÉÔǽ¤Ë¤Ç¤¤Þ¤¹¡£Apache httpd¤ª¤è¤ÓEnvoy¤ËÂФ·¤Æ¤Ï¡¢Ã±°ì¥¯¥é¥¤¥¢¥ó¥È¤¬Ìó20ÉäÇ32GB¤Î¥µ¡¼¥Ð¡¼¥á¥â¥ê¤ò¾ÃÈñ¤·¡¢¤½¤ì¤òÊÝ»ý¤Ç¤¤Þ¤¹¡×¤È½Ò¤Ù¤Þ¤·¤¿¡£

¸¦µæ¼Ô¤¬¥Æ¥¹¥È¤·¤¿¤È¤³¤í¡¢Envoy 1.37.2¤ÏÌó10ÉäÇ32GB¤ÎRAM¤¬¸Ï³é¤·¡¢Apache httpd 2.4.67¤ÏÌó18ÉäÇ32GB¡¢nginx 1.29.7¤ÏÌó45ÉäÇ32GB¤ÎRAM¡¢IIS(Windows Server 2025)¤ÏÌó45ÉäÇ64GB¤ÎRAM¤¬¸Ï³é¤·¤¿¤È¤Î¤³¤È¤Ç¤¹¡£
¸¦µæ¼Ô¤é¤Ï¡¢¤³¤ì¤é¤Î¹¶·â¤ò¹½À®¤¹¤ë¤½¤ì¤¾¤ì¤ÎÍ×ÁÇ¤ÏÆÃ¤Ë¿·¤·¤¤¤â¤Î¤Ç¤Ï¤Ê¤¤¤â¤Î¤Î¡¢Î¾¼Ô¤òÁȤ߹ç¤ï¤»¤ë¤³¤È¤ÇÈó¾ï¤ËÂ礤ʱƶÁ¤¬À¸¤¸¤ë¤È¶¯Ä´¤·¤Æ¤¤¤Þ¤¹¡£¸¦µæ¼Ô¤é¤ÏOpenAI¤Î¥³¡¼¥Ç¥£¥ó¥°¥¨¡¼¥¸¥§¥ó¥È¡ÖCodex¡×¤òÍѤ¤¤ÆÁȤ߹ç¤ï¤»¤ò¸«¤Ä¤±¤Þ¤·¤¿¡£

¸¦µæ¼Ô¤é¤Ï¥µ¡¼¥Ð¡¼¤ò´ÉÍý¤¹¤ë´ë¶È¤ËÌäÂê¤òÊó¹ð¤·¤Æ¤ª¤ê¡¢nginx¤ÈApache¡¢Envoy¤Ï½¤ÀµºÑ¤ß¤È¤Î¤³¤È¡£Microsoft IIS¡¢Pingora¸þ¤±¤Î¥Ñ¥Ã¥Á¤Ï̤Äê¤Ç¤¹¡£
¤³¤ì¤é¤Î¥¦¥§¥Ö¥µ¡¼¥Ð¡¼¤Ç¤Ï¡¢²Äǽ¤Ç¤¢¤ì¤ÐHTTP/2¤ò̵¸ú²½¤·¡¢¸·³Ê¤Ê¥Ø¥Ã¥À¡¼¿ôÀ©¸Â¤òŬÍѤ¹¤ë¥×¥í¥¥·¤ä¥Õ¥¡¥¤¥¢¥¦¥©¡¼¥ë¤òÁ°ÃʤËÇÛÃÖ¤¹¤ë¤³¤È¤¬¿ä¾©¤µ¤ì¤Æ¤¤¤Þ¤¹¡£
