article thumbnail

The Anatomy of Broken Apache Struts 2: A Technical Deep Dive into CVE-2024-53677

Dynatrace

Introduction Apache Struts 2 is a widely used Java framework for web applications, valued for its flexibility and Model-View-Controller (MVC) architecture. According to a 2017 article, attackers exploited an unpatched Apache Struts vulnerability ( CVE-2017-5638 ) to expose the sensitive information of over 145 million people.

Servers 214
article thumbnail

AWS EC2 Virtualization 2017: Introducing Nitro

Brendan Gregg

Xen AWS 2017 In 2015, AWS launched c4, which used hardware virtualization for EBS volumes. This finally came to storage-optimized instance types in 2017 with the [i3 instance type], which used SR-IOV and the nvme storage driver. With a solution in hand for network performance, the next target was storage. ## 6. 0% performance overhead.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

5 key areas for tech leaders to watch in 2020

O'Reilly

Software architecture, infrastructure, and operations are each changing rapidly. The shift to cloud native design is transforming both software architecture and infrastructure and operations. Up until 2017, the ML+AI topic had been amongst the fastest growing topics on the platform. Coincidence?

article thumbnail

Evolving Container Security With Linux User Namespaces

The Netflix TechBlog

Titus internally employs a cellular bulkhead architecture for scalability, so the fleet is composed of multiple cells. Many bulkhead architectures partition their cells on tenants, where a tenant is defined as a team and their collection of applications. Road to Implementation We began work to enable user namespaces in early 2017.

Media 295
article thumbnail

What is cloud application security?

Dynatrace

Microservices-based architecture Applications built using microservices-based architecture can operate and interact across different cloud platforms. Recent examples include the Heartbleed vulnerability in 2014, the attacks on Apache Struts in 2017, and Log4Shell in 2021. Read report now!

Cloud 245
article thumbnail

Working at Netflix 2017

Brendan Gregg

You might imagine that at some point we had a major scaling crises, where it looked like we'd fail due to an architectural bottleneck, and engineers worked long nights and weekends to save Netflix from certain disaster. html [The PMCs of EC2]: /blog/2017-05-04/the-pmcs-of-ec2.html That'd make a great story, but it didn't happen.

Java 75
article thumbnail

The Show Must Go On: Securing Netflix Studios At Scale

The Netflix TechBlog

Written by Jose Fernandez , Arthur Gonigberg , Julia Knecht , and Patrick Thomas In 2017, Netflix Studios was hitting an inflection point from a period of merely rapid growth to the sort of explosive growth that throws “how do we scale?” into every conversation.

Internet 227