
RapidResetClient
Rapid Reset Client is a tool for testing mitigations and exposure to CVE-2023-44487 (rapid reset DDoS attack vector). It implements a minimal HTTP/2 client that opens a single TCP socket, negotiates TLS, ignores the certificate, and exchanges SETTINGS frames. The client then sends rapid HEADERS frames followed by RST_STREAM frames. It monitors (but does not handle) server frames after the initial setup, in addition to sending them to standard output.
The compiled script cve.bat for Windows and the file cve_python.bat prepared for execution on other systems via Python are located.
If the attacked system is properly protected, the program execution will close and display nothing.
Otherwise, if it is clearly seen that RST frames are being sent, it means the Server is vulnerable to this CVE.
One of the fastest ways to mitigate the risk of this vulnerability is to temporarily disable HTTP/2 on Apache, at least until a more complete patch is released. This can reduce your exposure to attacks, but it is only a temporary solution.
Step 1: Disable the HTTP/2 module in Apache:
sudo a2dismod http2
Step 2: Restart Apache to apply the changes:
sudo systemctl restart apache2
With this, the server will stop accepting HTTP/2 connections, and connections will be made via HTTP/1.1, which mitigates the attack based on CVE-2023-44487.
This project is licensed under the Apache License - see the LICENSE file for details
This work is based on the initial analysis of CVE-2023-44487 by Juho Snellman and Daniele Iamartino at Google.