7.5The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
7.4ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.
HTTP/1.1 404 Not Found
Server: Tengine
Date: Wed, 09 Apr 2025 04:22:14 GMT
Content-Type: text/html
Content-Length: 580
Connection: keep-alive
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<h1>404 Not Found</h1>
<p>The requested URL was not found on this server. Sorry for the inconvenience.<br/>
Please report this message and include the following information to us.<br/>
Thank you very much!</p>
<table>
<tr>
<td>URL:</td>
<td>http://27.155.69.7:8000/</td>
</tr>
<tr>
<td>Server:</td>
<td>merge5.l2cn1832</td>
</tr>
<tr>
<td>Date:</td>
<td>2025/04/09 12:22:14</td>
</tr>
</table>
<hr/>Powered by Tengine</body>
</html>