Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
http2-security-lab — HTTP/2 attack simulation & defense lab - Slowloris, Rapid Reset (CVE-2023-44487), HPACK Bomb attacks with 5 layered defenses. Built in pure Python with raw sockets and h2 library. | Kitploit
Tools/GitHubGitHub/madhantr0/http2-security-lab
Defensive ToolsVulnerability AnalysisWeb SecurityNetwork SecurityPenetration TestingLearning & EducationLabs & Practice
GitHubmadhantr0/http2-security-lab

http2-security-lab

HTTP/2 attack simulation & defense lab - Slowloris, Rapid Reset (CVE-2023-44487), HPACK Bomb attacks with 5 layered defenses. Built in pure Python with raw sockets and h2 library.

View Repository
173 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🦣 TuskMads HTTP/2 Security Lab

A from-scratch HTTP/2 attack simulation and defense lab built in pure Python.

What This Does

Simulates 3 real-world HTTP/2 attacks against a vulnerable server, then demonstrates 5 defense layers blocking all 3 on a hardened server.

Attacks Implemented

AttackTechniqueImpact
SlowlorisOpen stream, never send END_STREAMRAM exhaustion
Rapid ResetRST_STREAM flood (CVE-2023-44487)CPU exhaustion
HPACK Bomb300+ headers per requestMemory allocation attack

Defenses Implemented

DefenseMethod
Slowloris WatchdogBackground thread kills idle connections
Rapid Reset BanIP permanently banned after 10 RSTs
Header Flood BlockStream reset if headers > 25
Rate LimiterIP banned after 60 req/min
Stream CapMAX_CONCURRENT_STREAMS = 20

Result

Basic Server → 0/3 blocked (0%) Hardened Server → 3/3 blocked (99%)

Run It

pip install h2

# Terminal 1
python3 basic_server.py

# Terminal 2
python3 hardened_server.py

# Terminal 3
python3 compare.py
Download Tool