
HTTP/2 attack simulation & defense lab - Slowloris, Rapid Reset (CVE-2023-44487), HPACK Bomb attacks with 5 layered defenses. Built in pure Python with raw sockets and h2 library.
A from-scratch HTTP/2 attack simulation and defense lab built in pure Python.
Simulates 3 real-world HTTP/2 attacks against a vulnerable server, then demonstrates 5 defense layers blocking all 3 on a hardened server.
| Attack | Technique | Impact |
|---|---|---|
| Slowloris | Open stream, never send END_STREAM | RAM exhaustion |
| Rapid Reset | RST_STREAM flood (CVE-2023-44487) | CPU exhaustion |
| HPACK Bomb | 300+ headers per request | Memory allocation attack |
| Defense | Method |
|---|---|
| Slowloris Watchdog | Background thread kills idle connections |
| Rapid Reset Ban | IP permanently banned after 10 RSTs |
| Header Flood Block | Stream reset if headers > 25 |
| Rate Limiter | IP banned after 60 req/min |
| Stream Cap | MAX_CONCURRENT_STREAMS = 20 |
Basic Server → 0/3 blocked (0%) Hardened Server → 3/3 blocked (99%)
pip install h2
# Terminal 1
python3 basic_server.py
# Terminal 2
python3 hardened_server.py
# Terminal 3
python3 compare.py