
HTTP/2 Last Frame Synchronization (also known as Single Packet Attack) low Level Library / Tool based on Scapy + Exploit Timing Attacks
H2SpaceXHTTP/2 low level library based on Scapy which can be used for Single Packet Attack (Race Condition on H2)
I wrote an article and published it at InfoSec Write-ups:
1.2.2
pyproject.toml and removed setup.py
[options] sections so package discovery is defined correctlydev extra (twine) that the old setup.py typo had droppedcheck_headers_lowercase=False (consistent with other request methods)tests/ (unit tests for header utilities) and CONTRIBUTING.md (build & release guide)1.2.1
Some following statements are just ideas and not tested or implemented.
H2SpaceX works with Python 3 (preferred: >=3.8.8)
pip install h2spacex
if you get errors of scapy:
pip install --upgrade scapy
You can import the HTTP/2 TLS Connection and set up the connection. After setting up the connection, you can do other things:
from h2spacex import H2OnTlsConnection
h2_conn = H2OnTlsConnection(
hostname='http2.github.io',
port_number=443,
ssl_log_file_path="PATH_TO_SSL_KEYS.log" # optional (if you want to log ssl keys to read the http/2 traffic in wireshark)
)
h2_conn.setup_connection()
...
see more examples in Wiki Page
See examples which contain some Portswigger race condition examples.
James Kettle introduced an improved version of Single Packet Attack in Black Hat 2024 for timing attacks:

You can implement this method easily using send_ping_frame() method.
See this Wiki and Parse Response (Threaded) + Response Times for Timing Attacks part:
Improved Version of SPA Sample Exploit
I also got some ideas from a previous developed library h2tinker.
Finally, thanks again to James Kettle for directly helping and pointing some other techniques.