
Demo for detection and mitigation of HTTP/2 Rapid Reset vulnerability (CVE-2023-44487)
This project demonstrates the HTTP/2 "Rapid Reset" vulnerability (CVE-2023-44487) that allows attackers to overwhelm servers using RST_STREAM frames, causing denial-of-service (DoS). It includes:
Setup/setup_guide.md – Environment setup (attacker & victim)Detection/webmin_monitoring.md – Monitoring with WebminMitigation/iptables.md – Firewall rule to stop the attackImages/
webmin_spike.pngwebmin_cpu.pngapache_log.pngREADME.md📄 View full setup guide here:
Setup/setup_guide.md
It includes:
📝 Guide: Detection/webmin_monitoring.md
Images/webmin_spike.png ← CPU spike during attack
Images/webmin_cpu.png ← Webmin CPU monitor
Images/apache_log.png ← Apache access logs
These visuals confirm that the exploit successfully triggers load and logs corresponding request activity.
📄 See: Mitigation/iptables.md
Highlights:
hashlimit to rate-limit connections per IPThis demo is based on PatrickTulskie's reset-rabbit, extended with:
Created for educational use under controlled lab conditions.
Created by Harshitha Sha ❤️