Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cve-2023-44487-demo — Demo for detection and mitigation of HTTP/2 Rapid Reset vulnerability (CVE-2023-44487) | Kitploit
Tools/GitHubGitHub/zanks08/cve-2023-44487-demo
Vulnerability AnalysisExploitationWeb SecurityNetwork SecurityPenetration TestingIntrusion DetectionLearning & EducationLabs & Practice
GitHubzanks08/cve-2023-44487-demo

cve-2023-44487-demo

Demo for detection and mitigation of HTTP/2 Rapid Reset vulnerability (CVE-2023-44487)

View Repository
1191 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

⚡ CVE-2023-44487 Demo – HTTP/2 Rapid Reset Attack

This project demonstrates the HTTP/2 "Rapid Reset" vulnerability (CVE-2023-44487) that allows attackers to overwhelm servers using RST_STREAM frames, causing denial-of-service (DoS). It includes:

  • ✅ Exploit test using Golang-based tool
  • ✅ Vulnerable Apache HTTP/2 setup via Docker
  • ✅ Real-time monitoring with Webmin
  • ✅ Firewall-based mitigation with IPTables

📁 Folder Structure

  • Setup/setup_guide.md – Environment setup (attacker & victim)
  • Detection/webmin_monitoring.md – Monitoring with Webmin
  • Mitigation/iptables.md – Firewall rule to stop the attack
  • Images/
    • webmin_spike.png
    • webmin_cpu.png
    • apache_log.png
  • README.md

⚙️ Setup Instructions

📄 View full setup guide here:
Setup/setup_guide.md

It includes:

  • Cloning the original exploit repo
  • Building the Golang tool
  • Running the vulnerable Apache HTTP/2 container
  • Installing and accessing Webmin

🕵️ Detection (Webmin Monitoring)

📝 Guide: Detection/webmin_monitoring.md

📸 Screenshots

Images/webmin_spike.png ← CPU spike during attack
Images/webmin_cpu.png ← Webmin CPU monitor
Images/apache_log.png ← Apache access logs

These visuals confirm that the exploit successfully triggers load and logs corresponding request activity.


🛡️ Mitigation (IPTables Firewall Rules)

📄 See: Mitigation/iptables.md

Highlights:

  • Uses hashlimit to rate-limit connections per IP
  • Drops excess HTTP/2 requests
  • Protects the server from resource exhaustion

Credits

This demo is based on PatrickTulskie's reset-rabbit, extended with:

  • 🛠️ Step-by-step setup & detection documentation
  • 📊 Visual proof of DoS using Webmin
  • 🔐 Custom IPTables rules to mitigate the attack

Created for educational use under controlled lab conditions.


📚 References

  • CVE-2023-44487 – NVD
  • Google Cloud – Rapid Reset Blog
  • Cloudflare: HTTP/2 vs HTTP/1.1
  • Vicarius Security Blog. (2024)

Created by Harshitha Sha ❤️

Download Tool