Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-44487-HTTP2-DoS-Rapid-Reset-Exploit — Advanced CVE-2023-44487 HTTP/2 Rapid Reset vulnerability exploitation framework. Features multi-connection concurrent attacks, adaptive rate control, stealth mode with randomized headers, real-time metrics, and risk assessment reporting. For authorized penetration testing only. By Sudeepa Wanigarathna | Kitploit
Tools/GitHubGitHub/cerberusmrxi/cve-2023-44487-http2-dos-rapid-reset-exploit
Exploit FrameworksVulnerability AnalysisExploitationWeb SecurityPenetration TestingRed TeamingAdversarial Attack
GitHubcerberusmrxi/cve-2023-44487-http2-dos-rapid-reset-exploit

CVE-2023-44487-HTTP2-DoS-Rapid-Reset-Exploit

View Repository
1172 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →

About

Advanced CVE-2023-44487 HTTP/2 Rapid Reset vulnerability exploitation framework. Features multi-connection concurrent attacks, adaptive rate control, stealth mode with randomized headers, real-time metrics, and risk assessment reporting. For authorized penetration testing only. By Sudeepa Wanigarathna

Share

CVE-2023-44487 HTTP/2 DoS Rapid Reset Exploit

Professional Edition v1.0.1 | Author: Sudeepa Wanigarathna

Python Version License Version CVSS


Table of Contents

  • Overview
  • Vulnerability Details
  • Features
  • Requirements
  • Installation
  • Quick Start
  • Usage Guide
  • Configuration Options
  • Docker Support
  • Examples
  • Understanding Results
  • Security Recommendations
  • Legal Disclaimer
  • Author
  • Changelog

Overview

A professional-grade assessment framework for CVE-2023-44487, the HTTP/2 Rapid Reset vulnerability. This tool helps security professionals test and validate systems against one of the most impactful HTTP/2 DoS conditions disclosed in recent years.

It demonstrates how rapidly creating and resetting HTTP/2 streams can exhaust server resources and lead to Denial of Service (DoS) conditions.

Key Features at a Glance

  • Multi-Connection Attack Engine — Concurrent HTTP/2 connections
  • Adaptive Rate Control — Dynamic adjustment for maximum effectiveness
  • Stealth Mode — Randomized headers and connection rotation
  • Comprehensive Reporting — JSON/CSV with risk assessment
  • Docker Support — Containerized deployment
  • Real-time Monitoring — Live attack metrics and progress
  • Professional Logging — Colored console output with file logging
UsageResults

Vulnerability Details

CVE-2023-44487: HTTP/2 Rapid Reset Attack

AttributeValue
CVE IDCVE-2023-44487
CVSS Score7.5 (High)
Attack VectorNetwork
Attack ComplexityLow
ImpactDenial of Service (Resource Exhaustion)
Affected ProtocolsHTTP/2
Disclosure DateOctober 2023

Technical Overview

The vulnerability exploits the HTTP/2 protocol's stream management mechanism:

  1. Stream Creation — Client sends a HEADERS frame to create a new stream
  2. Immediate Reset — Client immediately sends an RST_STREAM frame
  3. Server Processing — Server must process both frames, consuming resources
  4. Resource Exhaustion — Repeated cycles overwhelm server resources

Impact

  • Resource exhaustion on HTTP/2 servers
  • Potential Denial of Service (DoS)
  • Can affect load balancers, proxies, and CDNs
  • No authentication or special privileges required

Features

Core Features

FeatureDescription
HTTP/2 SupportFull HTTP/2 protocol implementation using the h2 library
Multi-ConnectionConcurrent attack across multiple connections
SSL/TLSHTTPS support with certificate verification options
Adaptive Rate ControlDynamically adjusts attack rate based on server response
Stealth ModeRandomized headers and connection rotation
Real-time MonitoringLive metrics display during the run
Comprehensive ReportsJSON/CSV output with risk assessment
Docker SupportContainerized deployment for easy testing

Advanced Capabilities

  • Proxy Support — Extensible proxy configuration
  • Connection Pooling — Efficient connection management
  • Error Recovery — Graceful handling of connection failures
  • Performance Tuning — Configurable settings for different scenarios
  • CI/CD Integration — Suitable for automated security testing

Requirements

System Requirements

ComponentMinimumRecommended
OSLinux / macOS / WindowsLinux or macOS
Python3.7+3.11+
CPU2 cores4+ cores
RAM2GB4GB+
Network100Mbps1Gbps+

Dependencies

h2>=4.1.0,<5.0.0
aiohttp>=3.8.0,<4.0.0

Installation

1. Quick Install

# Clone the repository
git clone https://github.com/CerberusMrXi/CVE-2023-44487-HTTP2-DoS-Rapid-Reset-Exploit
cd CVE-2023-44487-HTTP2-DoS-Rapid-Reset-Exploit

# Install dependencies
pip install -r requirements.txt

# Verify installation
python3 cve-2023-44487-exploit.py --help

2. Virtual Environment (Recommended)

# Create virtual environment
python3 -m venv venv

# Activate virtual environment
# On Linux/macOS:
source venv/bin/activate
# On Windows:
venv\Scripts\activate

# Install dependencies
pip install -r requirements.txt

3. Docker Installation

# Build Docker image
docker build -t cve-2023-44487-exploit .

# Run with Docker
docker run --rm cve-2023-44487-exploit target.com

4. Manual Installation

# Install without requirements.txt
pip install "h2>=4.1.0,<5.0.0" "aiohttp>=3.8.0,<4.0.0"

# Download the exploit
wget https://raw.githubusercontent.com/CerberusMrXi/CVE-2023-44487-HTTP2-DoS-Rapid-Reset-Exploit/main/cve-2023-44487-exploit.py

# Make executable
chmod +x cve-2023-44487-exploit.py

Quick Start

Basic Usage

# Simple run with default settings
python3 cve-2023-44487-exploit.py example.com

# Test HTTPS on port 443
python3 cve-2023-44487-exploit.py target.com -p 443 --no-verify

# Test HTTP on port 80
python3 cve-2023-44487-exploit.py target.com -p 80 --no-ssl

Quick Test (5 seconds)

python3 cve-2023-44487-exploit.py target.com -c 10 -s 100 -d 5 --no-verify

Full Assessment (60 seconds)

python3 cve-2023-44487-exploit.py target.com -c 100 -s 2000 -d 60 --stealth --no-verify

Usage Guide

Command Line Options

Target Configuration

OptionDescriptionDefault
hostTarget hostname or IPRequired
-p, --portTarget port443
--no-sslDisable SSL/TLSFalse
--no-verifySkip SSL verificationFalse

Attack Configuration

OptionDescriptionDefault
-c, --connectionsNumber of concurrent connections50
-s, --streamsStreams per connection1000
-d, --durationDuration in seconds30
--max-streamsMaximum total streams100000
--delayBase delay between operations0.0001s

Advanced Options

OptionDescriptionDefault
--adaptiveAdaptive rate controlTrue
--target-rpsTarget requests per second10000
--stealthStealth mode (random headers)False
--skip-validationSkip target validationFalse
--forceSkip legal disclaimer promptFalse

Reporting

OptionDescriptionDefault
-o, --outputOutput file nameexploit_results.json
--formatOutput format (json / csv / console)json
-v, --verboseVerbose loggingFalse

Configuration Options

Download Tool