
PoC for CVE-2023-44487 ( HTTP/2 Rapid Reset Attack ) Concept
CVE-2023-44487 (HTTP/2 Rapid Reset)
There are some examples in this repo which are not tested completely to analyse the impact, but I just wanted to perform the concept of this attack (starting many streams and immediately sending RST_STREAM frame to avoid reaching MAX_CONCURRENT_STREAMS).
I use H2SpaceX low level HTTP/2 library which I created for exploiting Single Packet Attack
Sending 100000 POST requests (with single packet attack technique) which causes server to wait for last byte, and then sending RESET STREAM frame after each request
This tool also uses threading to open more H2 connections.
just run python CVE-2023-44487-dos-poc.py and the tool will ask you for the host enter it and done dos PoC running