Skip to content
KitploitKITPLOIT
HerramientasExploitsBlog
Log in
Enviar
HerramientasExploitsBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
CVE-2023-44487 — Entorno educativo para LTAT.04.022 Tarea 4. | Kitploit
Herramientas/GitHubGitHub/hirokiii/cve-2023-44487
Seguridad de ContenedoresAnálisis de VulnerabilidadesAuditoría de ConfiguraciónSeguridad WebSeguridad de RedesAprendizaje y EducaciónLabs y Práctica
GitHubhirokiii/cve-2023-44487

CVE-2023-44487

Entorno educativo para LTAT.04.022 Tarea 4.

Ver Repositorio
60hace 4 mesesAún no revisado

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

CVE-2023-44487 — Laboratorio de pruebas de HTTP/2 Rapid Reset

Entorno educativo para la Tarea 4 de LTAT.04.022.
Cuatro contenedores te permiten escanear y comparar configuraciones vulnerables y parcheadas.


Mapa de puertos

ContenedorPuertoSoftwareEstado
nginx-vuln8441nginx 1.24Vulnerable
nginx-secure8442nginx latestParcheado
apache-vuln8443Apache 2.4.57Vulnerable
apache-secure8444Apache latestParcheado

1. Configuración

# Generate self-signed TLS certs (required by all containers)
bash gen-certs.sh

# Start all 4 containers
docker compose up -d

# Verify all are running
docker compose ps

2. Prueba básica de conectividad

# Check each container responds (ignore cert warning with -k)
curl -k --http2 -I https://localhost:8441   # nginx vulnerable
curl -k --http2 -I https://localhost:8442   # nginx secure
curl -k --http2 -I https://localhost:8443   # apache vulnerable
curl -k --http2 -I https://localhost:8444   # apache secure

Esperado: HTTP/2 200 de los cuatro.


3. Confirmar que HTTP/2 está activo

curl -k --http2 -v https://localhost:8441 2>&1 | grep -E "ALPN|HTTP/"

Busca:

* ALPN: server accepted h2
< HTTP/2 200

4. Ejecutar el escáner CVE

# Copy the scanner here first (or adjust the path)
cp ../scanner.py .

python3 scanner.py localhost 8441   # nginx vuln
python3 scanner.py localhost 8442   # nginx secure
python3 scanner.py localhost 8443   # apache vuln
python3 scanner.py localhost 8444   # apache secure

Resultados esperados:

ObjetivoHTTP/2Veredicto
8441YESLIKELY VULNERABLE
8442YESLIKELY PATCHED
8443YESLIKELY VULNERABLE
8444YESUNKWOWN

5. Comprobar los límites de flujo (diferencia clave)

Usa nghttp para inspeccionar la trama SETTINGS que envía cada servidor.
Esto muestra directamente el valor de SETTINGS_MAX_CONCURRENT_STREAMS.

# Install nghttp2 client
sudo apt install nghttp2-client   # Ubuntu/Debian
brew install nghttp2              # macOS

# Inspect SETTINGS frame
for port in 8441 8442 8443 8444; LIKELY PAdo
  streams=$(nghttp -nvy https://localhost:$port 2>&1 | grep "MAX_CONCURRENT" | tail -1 | awk -F: '{print $2}' | tr -d ']')
  echo "port $port → MAX_CONCURRENT_STREAMS: $streams"
done

# (Results)
port 8441 → MAX_CONCURRENT_STREAMS: 128
port 8442 → MAX_CONCURRENT_STREAMS: 32
port 8443 → MAX_CONCURRENT_STREAMS: 1000
port 8444 → MAX_CONCURRENT_STREAMS: 32

Servidor vulnerable: límite de flujo alto (128+)
Servidor seguro: limitado a 32


6. Simular presión de Rapid Reset (seguro, solo local)

Esto envía 50 solicitudes rápidamente en una sola conexión — no es un ataque real, pero muestra el comportamiento de manejo de RST del servidor en los registros.

# h2load is part of nghttp2-client
h2load -n 1000 -c 1 -m 50 https://localhost:8441   # vuln
h2load -n 1000 -c 1 -m 50 https://localhost:8442   # secure

Registros esperados para los ejemplos:

$ h2load -n 1000 -c 1 -m 1000 https://localhost:8441
starting benchmark...
spawning thread #0: 1 total client(s). 1000 total requests
TLS Protocol: TLSv1.3
Cipher: TLS_AES_256_GCM_SHA384
Server Temp Key: X25519 253 bits
Application protocol: h2
progress: 10% done
progress: 20% done
progress: 30% done
progress: 40% done
progress: 50% done
progress: 60% done
progress: 70% done
progress: 80% done
progress: 90% done
progress: 100% done

finished in 22.51ms, 44428.65 req/s, 5.38MB/s
requests: 1000 total, 1000 started, 1000 done, 1000 succeeded, 0 failed, 0 errored, 0 timeout
status codes: 1000 2xx, 0 3xx, 0 4xx, 0 5xx
traffic: 124.07KB (127049) total, 83.01KB (85000) headers (space savings 38.85%), 23.44KB (24000) data
                     min         max         mean         sd        +/- sd
time for request:      260us      2.98ms      2.25ms       384us    87.70%
time for connect:     2.51ms      2.51ms      2.51ms         0us   100.00%
time to 1st byte:     3.24ms      3.24ms      3.24ms         0us   100.00%
req/s           :   45059.11    45059.11    45059.11        0.00   100.00%

$ h2load -n 1000 -c 1 -m 1000 https://localhost:8442
starting benchmark...
spawning thread #0: 1 total client(s). 1000 total requests
TLS Protocol: TLSv1.3
Cipher: TLS_AES_256_GCM_SHA384
Server Temp Key: X25519 253 bits
Application protocol: h2
progress: 10% done

finished in 5.38ms, 18583.91 req/s, 2.33MB/s
requests: 1000 total, 1000 started, 167 done, 100 succeeded, 900 failed, 900 errored, 0 timeout
status codes: 100 2xx, 0 3xx, 0 4xx, 0 5xx
traffic: 12.83KB (13134) total, 8.30KB (8500) headers (space savings 38.85%), 2.25KB (2300) data
                     min         max         mean         sd        +/- sd
time for request:       83us      1.04ms       533us       256us    63.00%
time for connect:     2.96ms      2.96ms      2.96ms         0us   100.00%
time to 1st byte:     3.55ms      3.55ms      3.55ms         0us   100.00%
req/s           :   19316.22    19316.22    19316.22        0.00   100.00%

El contenedor seguro mostrará restablecimientos o rechazos de conexión cuando se alcance el límite de flujo; el vulnerable aceptará las 50 sin quejarse.


7. Comparar cabeceras del servidor

# Vulnerable servers expose version info
curl -k -I https://localhost:8441 2>/dev/null | grep -i server
curl -k -I https://localhost:8443 2>/dev/null | grep -i server

# Secure servers hide or minimize version info
curl -k -I https://localhost:8442 2>/dev/null | grep -i server
curl -k -I https://localhost:8444 2>/dev/null | grep -i server

8. Desmontaje

docker compose down

Qué cambian las configuraciones (resumen)

nginx

AjusteVulnerable (1.24)Seguro (1.25.3+)
http2_max_concurrent_streams128 (por defecto)32
keepalive_requests10000100
keepalive_timeout300s65s
Limitador de tasa RST_STREAMNingunoIntegrado en el parche

Apache

AjusteVulnerable (2.4.57)Seguro (2.4.58+)
H2MaxSessionStreams100032
ServerTokensFullProd
Parche de protección contra resetNo presenteAplicado

Referencias

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2023-44487
  • Informe de Cloudflare: https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/
  • Informe de Google: https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attack
  • Aviso de CISA: https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487
Descargar herramienta