ddos-simulation.com
All 130 Techniques Explore full Layer 3–7 attack library Network & Transport SYN flood, UDP flood, ICMP, TCP states Application & Protocols HTTP/2 Rapid Reset, Slowloris, QUIC, TLS API Gateway Resilience Kong, APISIX, Spring Cloud, Tyk, KrakenD
Compliance & Audits EU DORA Compliance Regulation 2022/2554 & TLPT stress testing NIS2 Directive Cyber resilience for essential entities PCI DSS v4.0 Testing Req 11.4 & 6.4 payment perimeter defense
Cloud & Programs AWS DDoS Testing Shield Advanced, CloudFront & ALB Azure DDoS Testing Network Protection & Front Door WAF Google Cloud Armor Adaptive Protection & Cloud CDN Cloudflare Testing WAF, rate limits & Magic Transit Periodic Testing Quarterly & continuous resilience drills White-Label Program Deliver testing under your own brand
Controlled Testing Process War room, stepped ramp-up & safety How auto-abort works 50ms health sampling & instant safety Testing Legality & RoE Rules of Engagement & authorizations
Pricing
Sign in Build a test plan
Sign in
Simulations All 130 Techniques Network & Transport (L3/L4) Application & Protocols (L7) API Gateways
Solutions & Compliance EU DORA Compliance NIS2 Directive PCI DSS v4.0 Testing AWS DDoS Testing Guide Azure DDoS Testing Guide Google Cloud Armor Guide Cloudflare Testing Guide Periodic Testing Program White-Label Partner Program
Methodology & Safety Controlled Testing Process Sub-Second Auto-Abort Testing Legality & RoE
Platform Timeline Builder Live Monitoring Pricing
Home › DDoS simulation testing › HTTP/2 MadeYouReset test

Layer 7 · Application · http2_made_you_reset

HTTP/2 MadeYouReset test

The http2_made_you_reset simulation opens HTTP/2 streams and provokes the server into resetting them — so they never count against the concurrency cap that mitigates plain Rapid Reset — against a domain you own.

Layer L7 Protocol HTTP/2 Command http2_made_you_reset Access Quote on request

On this page

  1. What MadeYouReset does
  2. How ddos-simulation.com simulates it safely
  3. What the test exercises
  4. When to run it
  5. How to run the test
  6. Reading the results
  7. Availability & limits
  8. FAQ
  9. Related simulations

What MadeYouReset does

MadeYouReset (disclosed in 2025, CVE-2025-8671 and related) is the successor to HTTP/2 Rapid Reset. Instead of the client cancelling streams — which the post-2023 mitigations cap — the client provokes the server into sending RST_STREAM with a protocol-violating frame. A server-sent reset does not count against the client’s concurrent-stream budget, so the attacker keeps opening reset-me streams without bound while the server still pays the per-stream setup and teardown cost.

How ddos-simulation.com simulates it safely

ddos-simulation.com speaks genuine HTTP/2 to a single verified domain, opens fully-formed request streams, and sends the reset-provoking frame within the domain’s rate limits. The request is fixed and non-configurable, and the verified domain must serve HTTP/2.

Authorized targets only

Every run is bound to one verified domain you have proven you own. Ownership is checked over HTTPS before anything is scheduled, and running traffic against systems you do not own or are not clearly authorized to test may be unlawful. See the Acceptable Use Policy.

What the test exercises

  • Whether your Rapid Reset mitigation also accounts for server-initiated resets
  • Per-connection stream accounting under forced resets
  • CPU cost of stream setup and teardown when the server resets
  • Proxy, load-balancer, and origin behavior
  • Recovery once the connection is closed

When to run an HTTP/2 MadeYouReset test

Run an HTTP/2 MadeYouReset test when you need to check whether server-initiated resets can slip past your rapid-reset mitigation.

  • You mitigated CVE-2023-44487 with a client-reset cap and want to confirm server-sent resets don't bypass it (CVE-2025-8671 class).
  • You run HTTP/2 origins or proxies and want evidence the concurrency accounting holds under provoked resets.
  • You're validating a recent HTTP/2 patch against a subtler reset pattern than classic rapid reset.

How to run an HTTP/2 MadeYouReset test

  1. Verify your domain. Prove ownership over HTTPS — it is self-service and takes minutes.
  2. Add the http2_made_you_reset command to a timeline in the portal and set the rate, duration, and any concurrency limit.
  3. Set health thresholds. Choose the error-rate, latency, or status-code limits at which the test should abort itself.
  4. Run and watch. Bounded workers are provisioned minutes before start and torn down the moment the last task ends, while metrics stream live.
  5. Read the results. Review the recorded latency, status codes, and worker timeline to find where your service starts to bend.

Configure an HTTP/2 MadeYouReset test in the portal →

Reading the results

Resilient: Provoked resets are counted against the same limits, CPU stays bounded, and the server keeps servicing legitimate streams.

Under strain: Work keeps piling up despite the concurrency cap, CPU climbs, and the connection degrades — the mitigation is only counting client resets.

Availability & limits

MadeYouReset is priced per engagement — request a quote. Verify your domain before it runs.

Frequently asked questions

What is MadeYouReset?

A 2025 HTTP/2 denial-of-service (CVE-2025-8671 class) that revives Rapid Reset by making the server reset streams, sidestepping the concurrent-stream limit that mitigated CVE-2023-44487.

I patched Rapid Reset — am I safe?

Not necessarily. MadeYouReset specifically targets mitigations that only count client-initiated resets. This test shows whether server-initiated resets are also bounded.

Related simulations

HTTP/2 Rapid Reset test Open and instantly cancel HTTP/2 streams to confirm you are patched against CVE-2023-44487. HTTP/2 CONTINUATION flood test Stream endless CONTINUATION frames to force unbounded header buffering. HTTPS flood test Run an authorized HTTPS flood test against a domain you own.

Rehearse an HTTP/2 MadeYouReset test against infrastructure you own — bounded, monitored, and stopped the instant you have your answer.

Build a test plan
← All DDoS simulations
ddos-simulation.com

Authorized, bounded resilience testing for infrastructure you own.

Product

Simulations Timeline builder Live monitoring Periodic testing White-label program

Guides

Controlled Testing Process How Auto-Abort Works AWS DDoS Testing Guide Azure DDoS Testing Guide Google Cloud Armor Guide Cloudflare Testing Guide 130 Attack Techniques

Portal

Sign in Create account Build a test plan

Compliance

EU DORA Compliance NIS2 Directive Compliance PCI DSS v4.0 Testing Testing Legality & RoE

Legal

Terms of Service Acceptable Use Privacy Policy Data Processing Addendum Contact
© 2026 ddos-simulation.com · Authorized testing only. DORA · PCI DSS · Terms · Privacy · Acceptable use · DPA