Zum Hauptinhalt springen
AI & KI NachrichtenWhy AI companies are really pumping the brakes on their models(18.09.2026 um 13:00 Uhr)
AI & KI NachrichtenA.I. Safety Goes Mainstream + a ‘Hard Fork’ Exit AMA(18.09.2026 um 13:00 Uhr)
AI & KI NachrichtenWhy AI companies are really pumping the brakes on their models(18.09.2026 um 13:00 Uhr)
AI & KI NachrichtenA.I. Safety Goes Mainstream + a ‘Hard Fork’ Exit AMA(18.09.2026 um 13:00 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

Black Hat Europe 2025 | Slashing QUIC's Performance With A Hash DoS

Author: Black Hat - Bewertung: 2x - Views:16

QUIC was designed for low-latency and high-performance communication, but what if its very design enables an attack that can bring it to a crawl? In this talk, we present a remote Hash Denial-of-Service (Hash DoS) attack that exploits hash collisions in QUIC's processing of connection IDs (CID). Our survey of over 20 QUIC server implementations revealed that a third of them were vulnerable to this attack, allowing a remote attacker to trigger excessive hash table operations with minimal effort, leading to severe slowdowns or even complete stalls.

In this talk, we'll break down the attack mechanics, discuss the different hash functions used by QUIC implementations, show how to exploit them, and demonstrate the real-world impact of the attack with performance metrics and a proof-of-concept attack demonstration against a vulnerable implementation. Attendees will gain insight into why this attack emerges from QUIC's design rather than through a mere implementation flaw and why it affects 1/3 of all existing implementations of this modern, widely used protocol supported in all major browsers. We'll also present why some existing mitigations fall short and how to defend against this threat effectively. By the end, attendees will walk away with concrete techniques to identify, test for, and mitigate Hash DoS vulnerabilities in QUIC and other performance-critical protocols.

By: Paul Bottinelli | Principal Security Engineer, Cryptography, Trail of Bits

https://blackhat.com/eu-25/briefings/schedule/?#cut-to-the-quic-slashing-quics-performance-with-a-hash-dos-48330

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Black Hat Europe 2025 | Slashing QUIC's Performance With A Hash DoS

Thematisch verwandte Begriffe: Black, Europe, 2025, Slashing · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-61591 | djust provides Phoenix LiveView-style reactive server-side rendering for…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Rechts: Artikel Ziehen Links: RSS
News ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Rechts: Original Links: RSS-Ansicht
↗ Original-Quelle
Social Reaktionen Stimme abgeben (+5 Karma)
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick