
LTAT.04.022 होमवर्क 4 के लिए शैक्षिक वातावरण।
LTAT.04.022 होमवर्क 4 के लिए शैक्षिक वातावरण।
चार कंटेनर आपको कमजोर बनाम पैच किए गए कॉन्फ़िगरेशन को स्कैन और तुलना करने देते हैं।
| कंटेनर | पोर्ट | सॉफ्टवेयर | स्थिति |
|---|---|---|---|
| nginx-vuln | 8441 | nginx 1.24 | अतिसंवेदनशील |
| nginx-secure | 8442 | nginx latest | पैच किया गया |
| apache-vuln | 8443 | Apache 2.4.57 | अतिसंवेदनशील |
| apache-secure | 8444 | Apache latest | पैच किया गया |
# Generate self-signed TLS certs (required by all containers)
bash gen-certs.sh
# Start all 4 containers
docker compose up -d
# Verify all are running
docker compose ps
# Check each container responds (ignore cert warning with -k)
curl -k --http2 -I https://localhost:8441 # nginx vulnerable
curl -k --http2 -I https://localhost:8442 # nginx secure
curl -k --http2 -I https://localhost:8443 # apache vulnerable
curl -k --http2 -I https://localhost:8444 # apache secure
अपेक्षित: सभी चार से HTTP/2 200।
curl -k --http2 -v https://localhost:8441 2>&1 | grep -E "ALPN|HTTP/"
खोजें:
* ALPN: server accepted h2
< HTTP/2 200
# Copy the scanner here first (or adjust the path)
cp ../scanner.py .
python3 scanner.py localhost 8441 # nginx vuln
python3 scanner.py localhost 8442 # nginx secure
python3 scanner.py localhost 8443 # apache vuln
python3 scanner.py localhost 8444 # apache secure
अपेक्षित परिणाम:
प्रत्येक सर्वर द्वारा भेजे गए SETTINGS फ्रेम का निरीक्षण करने के लिए nghttp का उपयोग करें।
यह सीधे SETTINGS_MAX_CONCURRENT_STREAMS मान दिखाता है।
# Install nghttp2 client
sudo apt install nghttp2-client # Ubuntu/Debian
brew install nghttp2 # macOS
# Inspect SETTINGS frame
for port in 8441 8442 8443 8444; do
streams=$(nghttp -nvy https://localhost:$port 2>&1 | grep "MAX_CONCURRENT" | tail -1 | awk -F: '{print $2}' | tr -d ']')
echo "port $port → MAX_CONCURRENT_STREAMS: $streams"
done
# (Results)
port 8441 → MAX_CONCURRENT_STREAMS: 128
port 8442 → MAX_CONCURRENT_STREAMS: 32
port 8443 → MAX_CONCURRENT_STREAMS: 1000
port 8444 → MAX_CONCURRENT_STREAMS: 32
अतिसंवेदनशील सर्वर: उच्च स्ट्रीम सीमा (128+)
सुरक्षित सर्वर: 32 तक सीमित
यह एक कनेक्शन पर तेज़ी से 50 अनुरोध भेजता है — वास्तविक हमला नहीं, लेकिन लॉग में सर्वर के RST हैंडलिंग व्यवहार को दर्शाता है।
# h2load is part of nghttp2-client
h2load -n 1000 -c 1 -m 50 https://localhost:8441 # vuln
h2load -n 1000 -c 1 -m 50 https://localhost:8442 # secure
उदाहरणों के लिए अपेक्षित लॉग:
$ h2load -n 1000 -c 1 -m 1000 https://localhost:8441
starting benchmark...
spawning thread #0: 1 total client(s). 1000 total requests
TLS Protocol: TLSv1.3
Cipher: TLS_AES_256_GCM_SHA384
Server Temp Key: X25519 253 bits
Application protocol: h2
progress: 10% done
progress: 20% done
progress: 30% done
progress: 40% done
progress: 50% done
progress: 60% done
progress: 70% done
progress: 80% done
progress: 90% done
progress: 100% done
finished in 22.51ms, 44428.65 req/s, 5.38MB/s
requests: 1000 total, 1000 started, 1000 done, 1000 succeeded, 0 failed, 0 errored, 0 timeout
status codes: 1000 2xx, 0 3xx, 0 4xx, 0 5xx
traffic: 124.07KB (127049) total, 83.01KB (85000) headers (space savings 38.85%), 23.44KB (24000) data
min max mean sd +/- sd
time for request: 260us 2.98ms 2.25ms 384us 87.70%
time for connect: 2.51ms 2.51ms 2.51ms 0us 100.00%
time to 1st byte: 3.24ms 3.24ms 3.24ms 0us 100.00%
req/s : 45059.11 45059.11 45059.11 0.00 100.00%
$ h2load -n 1000 -c 1 -m 1000 https://localhost:8442
starting benchmark...
spawning thread #0: 1 total client(s). 1000 total requests
TLS Protocol: TLSv1.3
Cipher: TLS_AES_256_GCM_SHA384
Server Temp Key: X25519 253 bits
Application protocol: h2
progress: 10% done
finished in 5.38ms, 18583.91 req/s, 2.33MB/s
requests: 1000 total, 1000 started, 167 done, 100 succeeded, 900 failed, 900 errored, 0 timeout
status codes: 100 2xx, 0 3xx, 0 4xx, 0 5xx
traffic: 12.83KB (13134) total, 8.30KB (8500) headers (space savings 38.85%), 2.25KB (2300) data
min max mean sd +/- sd
time for request: 83us 1.04ms 533us 256us 63.00%
time for connect: 2.96ms 2.96ms 2.96ms 0us 100.00%
time to 1st byte: 3.55ms 3.55ms 3.55ms 0us 100.00%
req/s : 19316.22 19316.22 19316.22 0.00 100.00%
सुरक्षित कंटेनर कनेक्शन रीसेट या अस्वीकार दिखाएगा जब स्ट्रीम सीमा हिट होती है; अतिसंवेदनशील कंटेनर बिना शिकायत के सभी 50 स्वीकार करेगा।
# Vulnerable servers expose version info
curl -k -I https://localhost:8441 2>/dev/null | grep -i server
curl -k -I https://localhost:8443 2>/dev/null | grep -i server
# Secure servers hide or minimize version info
curl -k -I https://localhost:8442 2>/dev/null | grep -i server
curl -k -I https://localhost:8444 2>/dev/null | grep -i server
docker compose down
| सेटिंग | अतिसंवेदनशील (2.4.57) | सुरक्षित (2.4.58+) |
|---|---|---|
H2MaxSessionStreams | 1000 | 32 |
ServerTokens | पूर्ण |
| लक्ष्य |
|---|
| HTTP/2 |
|---|
| निर्णय |
|---|
| 8441 | YES | संभावित रूप से अतिसंवेदनशील |
| 8442 | YES | संभावित रूप से पैच किया गया |
| 8443 | YES | संभावित रूप से अतिसंवेदनशील |
| 8444 | YES | अज्ञात |
| सेटिंग | अतिसंवेदनशील (1.24) | सुरक्षित (1.25.3+) |
|---|
http2_max_concurrent_streams | 128 (default) | 32 |
keepalive_requests | 10000 | 100 |
keepalive_timeout | 300s | 65s |
| RST_STREAM दर गार्ड | कोई नहीं | पैच में निर्मित |
| प्रोड |
| रीसेट गार्ड पैच | मौजूद नहीं | लागू |