Collected research
Security Risks in Asynchronous Web Servers: When Performance Optimizations Amplify the Impact of Data-Oriented Attacks
Asynchronous web servers like Nginx serve every client from one long-lived process, so a single memory bug reaches all of them. The paper traces memory to locate configuration structures, beats ASLR with a Heartbleed-style linear heap leak, then uses arbitrary writes to repoint the config pointer table at faux structures, disabling logging and security headers and leaking the private key.
Record
- Researcher
- Micah Morton, Jan Werner, Panagiotis Kintis, Kevin Snow, Manos Antonakakis, Michalis Polychronakis and Fabian Monrose
- Published by
- fabianmonrose.github.io
- Format
- Whitepaper
- Topic
- Server
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Micah Morton, Jan Werner, Panagiotis Kintis, Kevin Snow, Manos Antonakakis, Michalis Polychronakis and Fabian Monrose, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .