Skip to content
KitploitKITPLOIT
HerramientasExploitsBlog
Log in
Enviar
HerramientasExploitsBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

FeedsContactoPrivacidad© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
h2spacex — Sincronización del último frame de HTTP/2 (también conocida como Single Packet Attack) biblioteca/herramienta de bajo nivel basada en Scapy + Exploit Timing Attacks | Kitploit
Herramientas/GitHubGitHub/nxenon/h2spacex
Sniffing y Análisis de PaquetesExplotaciónExplotación de Aplicaciones WebSeguridad WebFuzzingSeguridad de RedesPruebas de PenetraciónUtilidades y FrameworksPapers e Investigación
GitHubnxenon/h2spacex

h2spacex

Sincronización del último frame de HTTP/2 (también conocida como Single Packet Attack) biblioteca/herramienta de bajo nivel basada en Scapy + Exploit Timing Attacks

229194hace 3 mesesRevisado por Kitploit
Ver RepositorioSitio web

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

H2SpaceX   H2SpaceX

pypi: 1.2.2 Python: 3.8.8 License: GPL v3

Librería de bajo nivel HTTP/2 basada en Scapy que puede utilizarse para Single Packet Attack (Race Condition en H2)

  • Esta librería formó parte de una investigación académica con el título de QUIC-er Races: HTTP/3 won’t save you from TOCTOU vulnerabilities.

Sumérgete en el artículo de Single Packet Attack

Escribí un artículo y lo publiqué en InfoSec Write-ups:

  • Dive into Single Packet Attack

TODO

  • Single Packet Attack - POST
    • implement
  • Single Packet Attack - GET
    • Content-Length: 1 Method
    • POST Request with x-override-method: GET header
  • Response Parsing
    • implement
    • implement threaded response parser
    • add response times in nano seconds for timing attacks
    • Body Decompression
      • gzip
      • br
      • deflate
  • Proxy
    • Socks5 Proxy

Change Log & Beta Versions

  • 1.2.2

    • packaging: consolidated build config into pyproject.toml and removed setup.py
      • fixed invalid [options] sections so package discovery is defined correctly
      • exposed the dev extra (twine) that the old setup.py typo had dropped
    • code cleanup
      • removed unused import and a redundant header-normalization call in GET request builder
      • GET requests now respect check_headers_lowercase=False (consistent with other request methods)
    • added tests/ (unit tests for header utilities) and CONTRIBUTING.md (build & release guide)
  • 1.2.1

    • merged PR-6
      • implement setup_connection for H2Connection (no TLS)
    • merged PR-7
      • normalize HTTP header names using Parser instead of regex
    • fixed Issue 8
      • parsing issue with raw data frames (packets)

Más investigación

Algunas de las siguientes afirmaciones son solo ideas y no están probadas ni implementadas.

  • Más peticiones en un solo paquete
    • Aumentar MSS (Idea de James Kettle)
    • Paquetes TCP fuera de orden (Idea de James Kettle)
    • Fragmentación IP
  • Proxy de la petición de un solo paquete a través de SOCKS
  • Single Packet Attack en peticiones GET
    • Content-Length: 1 Method (Idea de James Kettle)
    • x-override-method: GET Method (Idea de James Kettle)
    • Indexar cabeceras HPACK para hacer las peticiones GET más pequeñas
    • Trama HEADERS sin el flag END_HEADER
    • Trama HEADERS sin algunas pseudo cabeceras

Instalación

H2SpaceX funciona con Python 3 (preferiblemente: >=3.8.8)

pip install h2spacex

Error en la instalación

si obtienes errores de scapy:

pip install --upgrade scapy

Inicio rápido

Puedes importar la conexión HTTP/2 TLS y configurar la conexión. Después de configurar la conexión, puedes hacer otras cosas:

from h2spacex import H2OnTlsConnection

h2_conn = H2OnTlsConnection(
    hostname='http2.github.io',
    port_number=443,
    ssl_log_file_path="PATH_TO_SSL_KEYS.log"  # optional (if you want to log ssl keys to read the http/2 traffic in wireshark)
)

h2_conn.setup_connection()
...

ver más ejemplos en la Wiki Page

Ejemplos

Ver ejemplos que contienen algunos ejemplos de race condition de Portswigger.

Examples Page

Método mejorado de Single Packet Attack (Black Hat 2024) para ataques de temporización

James Kettle presentó una versión mejorada de Single Packet Attack en Black Hat 2024 para ataques de temporización:

Impvoved Version Image

Puedes implementar este método fácilmente usando el método send_ping_frame().

Ver esta Wiki y la parte Parse Response (Threaded) + Response Times for Timing Attacks:

  • New Method README (WIKI)

Improved Version of SPA Sample Exploit

Referencia del método mejorado:

  • Listen to the whispers: web timing attacks that actually work

Referencias y recursos

  • James Kettle DEF CON 31 Presentation
  • Portswigger Research Page
  • HTTP/2 in Action Book

También obtuve algunas ideas de una librería desarrollada previamente h2tinker.

Finalmente, gracias de nuevo a James Kettle por ayudar directamente y señalar algunas otras técnicas.

Descargar herramienta