目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1310

100%

CVE-2023-44487 PoC — Apache HTTP/2 资源管理错误漏洞

来源
关联漏洞
标题:Apache HTTP/2 资源管理错误漏洞 (CVE-2023-44487)
Description:HTTP/2是超文本传输协议的第二版,主要用于保证客户机与服务器之间的通信。 Apache HTTP/2存在安全漏洞。攻击者利用该漏洞导致系统拒绝服务。以下产品和版本受到影响:.NET 6.0,ASP.NET Core 6.0,.NET 7.0,Microsoft Visual Studio 2022 version 17.2,Microsoft Visual Studio 2022 version 17.4,Microsoft Visual Studio 2022 version 17.6,Micros
Description
A python based exploit to test out rapid reset attack (CVE-2023-44487)
介绍
# HTTP2 Rapid Reset Attack: CVE-2023-44487
Quick exploit to test out rapid reset attack (CVE-2023-44487). Note: For education purpose only

# Exploit: 
Quick exploit to test out rapid reset attack (CVE-2023-44487). Note: For education purpose only

## Table of Contents

- [Installation](#installation)
- [Usage](#usage)

## Installation

Clone the repository to your local machine using Git, install poetry, and run the program:

   ```bash
   git clone https://github.com/studiogangster/CVE-2023-44487.git

   cd CVE-2023-44487

    # install Poetry, if you haven't already:
    curl -sSL https://install.python-poetry.org | python -
    
    # poetry install
    poetry install

    # Activate the virtual environment created by Poetry:
    poetry shell

    # Run Help
    python main.py

   ## Example:
   python main.py --host example.com --path /api --headers "Authorization: Basic dummy-token ; Custom-Header:Custom-Header-Value" --port 443 --requests_count 100  --max_streams 20 --parallel_connections 2
```

## Usage
Usage: main.py [OPTIONS]
```bash
Options:
  --host TEXT                     Host URL  [required]
  --path TEXT                     Path on the host  [required]
  --headers TEXT                  Headers (comma-separated)  [required]
  --port INTEGER                  Port number  [required]
  --requests_count INTEGER        Number of requests to be sent  [required]
  --max_streams INTEGER           Maximum streams to be opened in parallel
                                  [required]
  --parallel_connections INTEGER  Number of parallel connections to be made
                                  with the server. (TCP connection)
                                  [required]
  --help                          Show this message and exit.

```





文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →