Nov. 15, 2023, 2 p.m. | Grant Collins

Grant Collins www.youtube.com

398 Million Requests Per Second. 155 Million Requests Per Second. 201 Millions Requests Per Second. Dem packets be flyin'. In this video, I explore and demo CVE-2023-44487, the novel HTTP/2 Rapid Reset Attack zero-day. A feature rather than an inherent bug.

⏰ Timestamps:
0:00 - Introduction
0:41 - Background Information
1:38 - HTTP/2 vs HTTP/1.1
4:27 - Demo (DDoS Apache2 Web Server)
10:11 - Mitigations
11:17 - Conclusion

🔗 Links Mentioned:
- Rapid Reset Client (PoC): https://github.com/secengjeff/rapidresetclient
- New 'HTTP/2 …

2 rapid reset attack bug cve cve-2023-44487 ddos ddos attack demo feature http information introduction novel packets rapid rapid reset rapid reset attack requests reset timestamps video zero-day

Security Analyst

@ Northwestern Memorial Healthcare | Chicago, IL, United States

GRC Analyst

@ Richemont | Shelton, CT, US

Security Specialist

@ Peraton | Government Site, MD, United States

Information Assurance Security Specialist (IASS)

@ OBXtek Inc. | United States

Cyber Security Technology Analyst

@ Airbus | Bengaluru (Airbus)

Vice President, Cyber Operations Engineer

@ BlackRock | LO9-London - Drapers Gardens