CDN Cannon: Exploiting CDN Back-to-Origin Strategies for Amplification Attacks
Black Hat Asia 2025 · Day 2 · Briefings
Overview
This talk, "CDN Cannon: Exploiting CDN Back-to-Origin Strategies for Amplification Attacks," presented by Julie from the National University of Singapore and Zu from Singapore Management University, unveils a novel class of amplification attacks that leverage Content Delivery Networks (CDNs) against their own protected origin servers. The research exposes fundamental vulnerabilities arising from seemingly innocuous CDN "back-to-origin" strategies, which are designed to optimize performance and improve user experience. Instead of being a defensive shield, CDNs can be weaponized to generate massive amounts of traffic towards a victim's origin server, effectively bypassing the CDN's own Distributed Denial of Service (DDoS) defenses.

Key moments
- 0:00 Introduction to CDNs and their key benefits
- 2:15 How CDNs work and mitigate traditional DDoS attacks
- 4:20 Attackers shift focus to exploiting CDN vulnerabilities
- 6:00 Introducing the novel BTO amp amplification attack
- 6:30 First attack vector: Image optimization strategies
- 9:00 Detailed explanation of image cropping amplification attack
CDN Cannon: Exploiting CDN Back-to-Origin Strategies for Amplification Attacks
Speakers: Julie, National University of Singapore; Zu, Singapore Management University
Conference: Black Hat Asia
YouTube: https://www.youtube.com/watch?v=ZEz9_vVspoo
Overview
This talk, "CDN Cannon: Exploiting CDN Back-to-Origin Strategies for Amplification Attacks," presented by Julie from the National University of Singapore and Zu from Singapore Management University, unveils a novel class of amplification attacks that leverage Content Delivery Networks (CDNs) against their own protected origin servers. The research exposes fundamental vulnerabilities arising from seemingly innocuous CDN "back-to-origin" strategies, which are designed to optimize performance and improve user experience. Instead of being a defensive shield, CDNs can be weaponized to generate massive amounts of traffic towards a victim's origin server, effectively bypassing the CDN's own Distributed Denial of Service (DDoS) defenses.
The core of the problem lies in the significant bandwidth disparity between a CDN's global infrastructure and a typical origin server, coupled with specific optimization mechanisms that introduce asymmetric traffic patterns. Attackers can exploit these mechanisms to trigger large responses from the origin server with minimal input, transforming the CDN into a powerful amplifier. This research is critical as CDNs are an indispensable part of the modern internet, hosting approximately 60% of the Alexa top 10,000 websites, and their inherent design choices, when not rigorously secured, can be turned against the very entities they are meant to protect.
Background
▶ Watch: Introduction to CDNs and their key benefits (0:00)
Content Delivery Networks (CDNs) have become the backbone of modern web infrastructure, dramatically improving website load times, reducing bandwidth costs, and providing crucial DDoS defense. By caching content closer to end-users and acting as a proxy, CDNs hide the origin server's real IP address and absorb massive volumes of traffic. This capability has largely rendered traditional DDoS attacks, which rely on resource-intensive botnets to flood a target server, ineffective against CDN-protected assets. CDNs, with their globally distributed servers and intelligent load balancing, are specifically designed to mitigate such large-scale malicious traffic.
However, this strong defense has forced attackers to reconsider their strategies. Instead of attempting to overwhelm the CDN itself, the focus has shifted to exploiting vulnerabilities within the CDN infrastructure to launch attacks that bypass its DDoS defenses and target the origin server directly. A significant source of these vulnerabilities stems from back-to-origin strategies, which are mechanisms CDNs employ to optimize performance and compatibility. These strategies broadly fall into two categories: improving cache rates to reduce origin server burden (e.g., caching content) and modifying HTTP requests or responses to enhance client traffic efficiency or compatibility (e.g., image optimization, request headers). While beneficial for legitimate traffic, these optimizations, if not carefully implemented with security in mind, introduce new attack surfaces that can be abused for amplification.
Key Findings
▶ Watch: Attackers shift focus to exploiting CDN vulnerabilities (4:20)
The primary finding of this research is the identification and categorization of a novel class of amplification attacks termed BTO amp (Back-to-Origin Amplification). These attacks specifically exploit various back-to-origin strategies implemented by CDNs. The researchers discovered four distinct types of BTO amp attacks:
- Image Optimization Attack: Exploits lenient parameter handling in image compression and cropping services.
- Request Modification Attack: Leverages the ability to append large, attacker-controlled data to HTTP headers or URLs during request forwarding.
- Meta Conversion Strategy Attack: Abuses the proactive conversion of HEAD requests into GET requests by CDNs when a resource is not cached.
- Connection Decoupling Attack: Revives an older attack vector by using specific HTTP headers (
Transfer-Encoding: chunked) to force the CDN to fully fetch content from the origin even after the client disconnects.
A critical common requirement for all these attacks is cache bypassing. If a CDN serves content from its cache, the origin server is not hit, and the amplification fails. The researchers identified seven techniques, including URL modifications and specific HTTP headers, to reliably bypass CDN caching mechanisms, ensuring that every malicious request reaches the origin. Through real-world experiments, they demonstrated significant amplification factors, where kilobits of input traffic from the attacker resulted in gigabits of output traffic from the origin server. Furthermore, the findings were impactful, with 11 out of 14 tested CDN vendors confirming the vulnerabilities, and 5 having already patched them.
Technical Deep Dive
▶ Watch: Introducing the novel BTO amp amplification attack (6:00)
The core of the CDN Cannon attack lies in turning the CDN's performance-enhancing features into attack vectors. Each of the four identified attack types exploits a specific back-to-origin strategy:
1. Image Optimization Attack
Modern web pages heavily rely on high-resolution images, leading to significant bandwidth consumption. CDNs implement image optimization techniques like image compression (e.g., converting PNG to WebP based on client request parameters like format=webp) and image cropping (e.g., crop=100,100 for a 100x100 pixel image). The vulnerability arises when CDNs do not enforce strict limitations on these parameters.
Exploitation: An attacker crafts a request to the CDN asking it to crop a large original image down to a single pixel (e.g., C=1,1). The CDN, upon receiving this request, removes the cropping parameter, fetches the full-sized original image from the origin server, processes it by cropping it to 1x1 pixel, and then delivers the tiny result to the attacker. This creates a massive traffic imbalance: the attacker receives a minimal response, but the origin server is forced to send the entire high-resolution image to the CDN for every such request, overwhelming its bandwidth.
2. Request Modification Attack
CDNs often modify HTTP requests before forwarding them to the origin for various business needs, such as adding an X-Forwarded-For header to pass the client's real IP address or performing URL rewriting when file storage locations change. The vulnerability here is the lack of strict limitations on the size of these modified HTTP requests.
Exploitation: The attacker first registers a victim's website behind a CDN using a free trial account. They then configure the CDN's request modification strategy to append an arbitrarily large number of oversized HTTP headers or rewrite the original URL into an excessively long one (e.g., appending hundreds of 'A' characters to the path). When the attacker sends small POST requests to the CDN, the CDN, following its configuration, transforms each small request into a significantly larger one by adding the configured oversized headers and long URL before forwarding it to the origin. This amplifies the traffic directed at the origin server, quickly consuming its bandwidth.
3. Meta Conversion Strategy Attack
CDNs employ a meta conversion strategy to improve user experience and caching efficiency. When a client sends a HEAD request (to check for resource updates) and the resource is not cached, the CDN proactively converts it into a GET request. It then fetches the entire resource from the origin, caches it, and only returns the headers to the client. The rationale is that the client will likely request the full content soon, so pre-fetching improves subsequent access.
Exploitation: The attacker continuously sends a massive number of HEAD requests, ensuring each request bypasses the CDN's cache. Because the resource is not cached, the CDN converts each HEAD request into a full GET request to the origin. The origin server then sends the entire content body back to the CDN, even though the client only receives the headers. This creates a severe asymmetric traffic pattern, where small HEAD requests from the attacker trigger large full-body responses from the origin, leading to amplification.
4. Connection Decoupling Attack
Connection decoupling is a CDN strategy where the CDN maintains its connection to the origin server even if the client's connection to the CDN is unstable or drops. This prevents the origin from being burdened by client network issues and allows the CDN to cache the resource for faster delivery upon client reconnection. While beneficial, a similar attack vector was identified as early as 2009, where attackers could force CDNs to fetch full resources even after disconnection. Many CDNs subsequently mitigated this by promptly closing the CDN-to-origin connection if the client disconnects.
Exploitation: The researchers discovered that by including the Transfer-Encoding: chunked header in their requests, attackers could bypass these modern mitigations. Even if the client disconnects immediately after sending the initial request, the presence of this header in the request forces the CDN to maintain its connection to the origin and continue fetching the full resource. This revives the connection decoupling attack, allowing attackers to trigger full resource fetches from the origin without needing to receive the entire response themselves, thus amplifying traffic.
Cache Bypassing Techniques
All BTO amp attacks critically depend on cache bypassing. If a CDN serves a resource from its cache, the origin server is not contacted, rendering the amplification attack ineffective. The researchers identified and summarized seven techniques to bypass CDN caching mechanisms. A common method involves randomizing URI parameters. For instance, requesting a.png?s=123 is treated as a distinct cache key from a.png?s=234, even if the base path is the same. By frequently changing such parameters, attackers can ensure that each request is treated as unique, forcing the CDN to forward it to the origin server every time. This ensures the continuous consumption of origin resources, making the attacks effective.
Demo / Proof of Concept
▶ Watch: First attack vector: Image optimization strategies (6:30)
To validate the efficacy of the CDN Cannon attacks in a real-world environment, the researchers conducted controlled experiments, carefully avoiding any third-party targets. Their test setup involved:
- Victim Origin Server: A cloud server located in Silicon Valley, configured with an HTTP service, running on a 1 Gigabit per second (Gbps) network connection.
- Attacker: A low-bandwidth Virtual Private Server (VPS) located in Singapore, with a modest 30 Megabits per second (Mbps) network connection.
For the Request Modification Attack specifically, the demonstration proceeded as follows:
- The HTTP service on the Silicon Valley server was set up as the origin.
- The victim's website was deployed behind a CDN, with the CDN configured to use the origin server.
- The CDN's configuration was then modified to instruct it to append a large number of oversized HTTP headers during the request forwarding process to the origin. This replicated the attacker's malicious configuration.
- Finally, the attacker (from the Singapore VPS) sent numerous small POST requests to the CDN.
The results were striking and clearly demonstrated the amplification effect: merely kilobits of input traffic generated by the attacker on the client side resulted in gigabits of traffic being generated from the origin server. This significant discrepancy highlighted the practical effectiveness and potential devastation of these amplification attacks, confirming that CDNs could indeed be weaponized to overwhelm origin servers with minimal attacker resources. The experiment underscored the critical need for robust mitigations against these newly identified vulnerabilities.
Defensive Implications
▶ Watch: Detailed explanation of image cropping amplification attack (9:00)
The CDN Cannon research provides crucial insights for both CDN vendors and website operators on how to defend against these sophisticated amplification attacks. The proposed mitigation strategies focus on addressing the root causes of the vulnerabilities:
- Limit Parameters in Back-to-Origin Strategies: CDN vendors must enforce strict limitations on the parameters used in back-to-origin optimization strategies, such as image optimization and URL rewriting. This includes setting maximum values for cropping dimensions, header sizes, and URL lengths. By preventing extreme parameter values, CDNs can eliminate the traffic consumption gap between the client-CDN and CDN-origin connections, thus neutralizing amplification.
- Validate Ownership of Customer-Supplied Origin Configurations: To prevent CDNs from being abused to attack arbitrary third-party targets, CDN providers should implement rigorous validation processes for customer-supplied origin configurations. This ensures that a customer can only configure a CDN to point to an origin server that they genuinely own or are authorized to configure. While this won't prevent attacks against a website legitimately hosted on the CDN, it significantly reduces the potential for collateral damage to unrelated entities.
- Strict Adherence to RFC Standards for Request Forwarding: In the case of the meta conversion strategy, CDNs should strictly follow RFC standards for HTTP request forwarding. This means that a HEAD request should be directly forwarded as a HEAD request to the origin, and should not be proactively converted into a GET request unless there is a clear, explicitly configured, and security-reviewed reason to do so. This prevents the unnecessary fetching of full content bodies from the origin.
- Synchronize Client-to-CDN and CDN-to-Origin Connections: For connection decoupling attacks, CDNs need to implement robust synchronization mechanisms between the client-facing connection and the origin-facing connection. If the client disconnects from the CDN, the CDN should promptly terminate its connection to the origin and cease fetching the resource. A short grace period might be acceptable for unstable client connections, but prolonged fetching after client disconnect must be prevented to avoid amplification. The
Transfer-Encoding: chunkedheader bypass found in this research specifically highlights the need for advanced parsing and connection management.
The researchers engaged with 14 CDN vendors, and their findings were significant: 12 vendors acknowledged the reports, 11 confirmed the existence of the vulnerabilities, and 5 have already deployed patches. This demonstrates the widespread nature of these vulnerabilities and the industry's recognition of their severity. Website operators should inquire with their CDN providers about the status of these patches and ensure their configurations are not inadvertently enabling these attack vectors.
Key Takeaways
- CDNs as Amplifiers: Back-to-origin strategies, designed for performance, introduce critical vulnerabilities that allow CDNs to be weaponized as powerful traffic amplifiers against their own protected origin servers.
- Asymmetric Traffic Exploitation: The core of CDN Cannon attacks lies in exploiting asymmetric traffic patterns, where minimal input from an attacker triggers massive data transfers from the origin server via the CDN.
- Bypassing CDN Defenses: These attacks bypass traditional CDN DDoS defenses by turning the CDN into an unwitting participant, targeting the origin server directly rather than overwhelming the CDN's edge infrastructure.
- Cache Bypassing is Critical: Effective execution of BTO amp attacks relies heavily on various cache bypassing techniques to ensure that every malicious request hits the origin server.
- Design Flaws in Optimization: The fundamental cause of these vulnerabilities is often a trade-off where CDNs prioritize speed and flexibility over strict security in the implementation of certain specifications, leading to exploitable resource consumption gaps.
- Industry-Wide Impact: The widespread confirmation of these vulnerabilities across multiple major CDN vendors underscores the need for a re-evaluation of CDN design specifications and implementation practices across the industry.
About the Speaker(s)
The research presented in this talk was a collaborative effort between Julie from the National University of Singapore and Zu from Singapore Management University. Both researchers are actively involved in cybersecurity research, focusing on uncovering vulnerabilities and improving the security posture of critical internet infrastructure. Their work demonstrates a deep understanding of network protocols and CDN architectures, contributing valuable insights to the security community.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
This is a critical piece of research, exposing a novel class of amplification attacks that weaponize CDNs against their own origin servers. The 'CDN Cannon' isn't just a clever name; it's a stark reminder that performance optimizations often create gaping security holes. The speakers have delivered deep technical insights into how seemingly innocuous back-to-origin strategies, combined with cache-bypassing techniques, can turn a defender's shield into an attacker's amplifier. This isn't theoretical fluff; 11 major CDN vendors confirmed the vulnerabilities, demonstrating the widespread and immediate impact of this work. Any CISO or infrastructure engineer relying on CDNs needs to pay…
Heather Calloway (CISO) — STRONG ACCEPT
This research on 'CDN Cannon' is a critical examination of how foundational internet infrastructure can be turned into an attack vector. It clearly demonstrates that CDNs, often considered a primary line of DDoS defense, can be weaponized against their own origin servers due to inherent design choices and configuration vulnerabilities. The findings offer actionable insights for CISOs and security leaders, underscoring the immediate need to re-evaluate vendor dependencies and internal configurations to mitigate significant business exposure.