
CVE-2023-44487, HTTP/2 Rapid Reset भेद्यता के लिए एक व्यापक Python परीक्षण उपकरण। यह उन्नत संस्करण परीक्षण मापदंडों पर विस्तृत नियंत्रण, कई आक्रमण पैटर्न और उन्नत निगरानी क्षमताएँ प्रदान करता है।
CVE-2023-44487, यानी HTTP/2 रैपिड रीसेट भेद्यता के लिए एक व्यापक Python परीक्षण उपकरण। इस रिपॉजिटरी में आक्रमण परीक्षण और सत्यापन-केंद्रित दोनों प्रकार के उपकरण शामिल हैं।
यह उपकरण केवल शैक्षिक और अधिकृत परीक्षण उद्देश्यों के लिए है!
CVE-2023-44487, जिसे "HTTP/2 रैपिड रीसेट" के नाम से भी जाना जाता है, HTTP/2 प्रोटोकॉल में एक गंभीर भेद्यता है जो हमलावरों को निम्नलिखित की अनुमति देती है:
CVSS स्कोर: 7.5 (उच्च)
प्रभाव: सेवा से वंचित करना (Denial of Service), संसाधन क्षरण (Resource Exhaustion)
h2 लाइब्रेरी: pip install h2git clone https://github.com/madhusudhan-in/CVE_2023_44487-Rapid_Reset.git
cd CVE_2023_44487-Rapid_Reset
pip install h2
chmod +x *.py
python3 --version # Should be 3.7+
cve_2023_44487_verifier_enhanced.pyउद्देश्य: पैच-पश्चात सत्यापन और अनुपालन जाँच के लिए प्रवर्तन-संकेत पहचान
# Basic verification
python3 cve_2023_44487_verifier_enhanced.py target.com
# Multiple concurrent connections
python3 cve_2023_44487_verifier_enhanced.py target.com -c 5 -s 500
# Verbose output with debugging
python3 cve_2023_44487_verifier_enhanced.py target.com -v -c 3 -s 1000
# Baseline test only (normal requests)
python3 cve_2023_44487_verifier_enhanced.py target.com --baseline-only
| विकल्प | विवरण | डिफ़ॉल्ट |
|---|---|---|
host | लक्ष्य होस्टनाम (आवश्यक) | - |
-p, --port | लक्ष्य पोर्ट | 443 |
--no-ssl | SSL/TLS अक्षम करें | False (SSL सक्षम) |
-s, --streams | प्रति कनेक्शन स्ट्रीम की संख्या | 1000 |
-d, --delay | स्ट्रीम संचालनों के बीच विलंब (सेकंड) | 0.001 |
-c, --connections | समवर्ती कनेक्शनों की संख्या | 1 |
--baseline-only | केवल बेसलाइन परीक्षण करें (आक्रमण नहीं) | False |
-v, --verbose | विस्तृत/डीबग आउटपुट | False |
स्क्रिप्ट RFC 9113-अनुरूप प्रवर्तन संकेतों के आधार पर एक बुद्धिमान निर्णय प्रदान करती है:
Server sends GOAWAY with ENHANCE_YOUR_CALM (0xb) error code
Classification: NOT VULNERABLE — protocol-layer enforcement is active
Meaning: HTTP/2 implementation has proper rate-limiting controls
50%+ of connections terminated via TCP reset
Classification: LIKELY PROTECTED — verify with edge/infrastructure team
Meaning: Edge appliance or DDoS protection engaged at transport layer
Per-second reset rate drops significantly over time (late buckets <60% of early)
Classification: PARTIAL PROTECTION — confirm with infrastructure team
Meaning: Server or edge slowing the attack adaptively
Server sends REFUSED_STREAM (0x7) responses
Classification: PARTIAL PROTECTION — review rate limits
Meaning: Some stream-level rate-limiting in place
No ENHANCE_YOUR_CALM GOAWAY, no TCP resets, no throttling detected
Classification: VECTOR EXERCISABLE — exploitability unconfirmed
Important: This doesn't prove DoS exploitability. Edge volumetric/behavioral
protections (Akamai, CloudFlare) may engage at higher scales
============================================================
ENFORCEMENT SIGNAL ANALYSIS
============================================================
Server SETTINGS (initial frame):
HEADER_TABLE_SIZE = 4096
ENABLE_PUSH = True
MAX_CONCURRENT_STREAMS = 128
INITIAL_WINDOW_SIZE = 65535
MAX_FRAME_SIZE = 16384
→ MAX_CONCURRENT_STREAMS=128 is conservative (good post-CVE default)
GOAWAY breakdown across connections:
ENHANCE_YOUR_CALM (0xb): 3/5
Other GOAWAY codes: 1/5
No GOAWAY received: 1/5
TCP reset (RST at transport): 0/5
Total RST_STREAM frames from server: 2
REFUSED_STREAM frames from server: 0
Connections showing adaptive throttling: 1/5
============================================================
VERDICT
============================================================
✅ ENFORCEMENT CONFIRMED
3/5 connection(s) received GOAWAY with ENHANCE_YOUR_CALM (0xb).
This is the canonical signal that the CVE-2023-44487 mitigation is active.
Classification: NOT VULNERABLE — protocol-layer enforcement is engaged.
# Verify patch deployment with 10 connections, 500 streams each
python3 cve_2023_44487_verifier_enhanced.py prod-api.example.com \
-c 10 \
-s 500 \
-d 0.0001 \
-v
# Test non-standard HTTPS port
python3 cve_2023_44487_verifier_enhanced.py example.com \
-p 8443 \
-c 5 \
-s 1000
# Minimal load compliance test
python3 cve_2023_44487_verifier_enhanced.py example.com \
-c 3 \
-s 200 \
--baseline-only
ENHANCE_YOUR_CALM (त्रुटि कोड 0xb):
REFUSED_STREAM (त्रुटि कोड 0x7):
प्रति-सेकंड रीसेट दर विश्लेषण:
ट्रांसपोर्ट परत पर TCP RST: