⚖️ Charte Éthique Apache
Yo, Apache membre ! Voici Apache Ears, par Platon-y pour pctamalou.fr. Ce tuto construit un intercepteur radio DIY pour démontrer le cassage de chiffrement AES-256 en lab éthique. Lab uniquement – interdiction d’intercepter des réseaux réels (ex. article 226-15 Code pénal : 6 mois prison, 30 000 € amende). Sensibilisation à la sécurité, pas d’usage illégal ! Hackez propre !
Apache Ears 📡💾
Exclusivité membres : construisez un intercepteur radio DIY avec Raspberry Pi et HackRF pour démontrer le cassage de chiffrement radio (AES-256) en lab éthique. Simulation d’un réseau sécurisé, attaques side-channel, et sensibilisation. 100% éthique ! ⚡️
1️⃣ Introduction à Apache Ears 📡
Apache Ears est un projet DIY pour construire un intercepteur radio avec SDR (Software Defined Radio) et démontrer comment casser des communications chiffrées (AES-256) dans un lab éthique. On simule un réseau radio sécurisé pour tester des attaques (interception, side-channel, failles d’implémentation). Lab-only, pas d’interception de réseaux réels.
Objectifs
- Construire un intercepteur SDR sur Raspberry Pi.
- Simuler un réseau radio chiffré AES-256.
- Démontrer interception et attaques.
- Sensibiliser à la sécurité radio.
- Design nomade robuste.
2️⃣ Matériel 🛠️
Liste des composants (usage lab-only, certains illégaux hors lab).
| Composant | Description | Prix (approx.) |
|---|---|---|
| Raspberry Pi 4 (4GB) | Base de calcul | 60 € |
| HackRF One | SDR émetteur/récepteur (1 MHz–6 GHz) | 300 € |
| Antenne 400-470 MHz | Pour PMR446/ISM | 20 € |
| Batterie LiPo 5000mAh | Autonomie 12h+ | 25 € |
| Micro/écouteurs | Entrée/sortie audio | 15 € |
| Écran OLED 0.96" | Interface minimaliste | 10 € |
| FPGA (Altera Cyclone V) | Side-channel | 100 € |
| Boîtier ABS | Robust nomade | 10 € |
| Oscilloscope USB | Analyse puissance | 50 € |
3️⃣ Setup Hardware 🔧
Assemblez le dispositif.
+-----------------------------------+
| [Apache Ears] |
| Raspberry Pi 4 ----> HackRF One |
| | ^ USB |
| | Antenne 400-470 MHz |
| | Micro/Écouteurs |
| | OLED 0.96" |
| | LiPo 5000mAh |
| | FPGA (Cyclone V) |
| | Oscilloscope USB |
| [Boîtier ABS] |
+-----------------------------------+
Étapes
# 1. Connecter HackRF
sudo apt update
sudo apt install hackrf
hackrf_info
# 2. Antenne
# Branchez sur port ANT1 (SMA)
# 3. Micro/écouteurs
# Jack USB
arecord -f cd test.wav
aplay test.wav
# 4. OLED (I2C)
sudo pip3 install adafruit-circuitpython-ssd1306
sudo i2cdetect -y 1
# 5. Batterie
# Régulateur 5V
# 6. FPGA
sudo apt install quartus
# Configurer via JTAG
# 7. Oscilloscope
sudo apt install sigrok-cli
sigrok-cli --driver fx2lafw --scan
4️⃣ Setup Logiciel 💻
Installez Kali Linux, GNU Radio, et dépendances.
# Kali 2024.4
sudo apt install -y gnuradio gqrx-sdr python3-pip libhackrf-dev
pip3 install pycryptodome numpy scipy matplotlib
# Test HackRF
hackrf_sweep -f 400:470 -w 100000
# GNU Radio
gnuradio-companion
5️⃣ Simulation Réseau Chiffré 🔐
Simulez un réseau radio chiffré AES-256 sur PMR446.
Émetteur (Python)
# aes_encrypt.py
from Crypto.Cipher import AES
from Crypto.Random import get_random_bytes
import numpy as np
import sounddevice as sd
import scipy.io.wavfile as wavfile
def encrypt_audio():
key = get_random_bytes(32) # AES-256
cipher = AES.new(key, AES.MODE_GCM)
audio_data = sd.rec(int(5 * 44100), samplerate=44100, channels=1)
sd.wait()
audio_bytes = audio_data.tobytes()
nonce = cipher.nonce
ciphertext, tag = cipher.encrypt_and_digest(audio_bytes)
with open('/tmp/encrypted_signal.bin', 'wb') as f:
f.write(nonce + tag + ciphertext)
with open('/tmp/aes_key.bin', 'wb') as f:
f.write(key)
# Save raw audio for reference
wavfile.write('/tmp/raw_audio.wav', 44100, audio_data)
encrypt_audio()
Émettre Signal (GNU Radio)
# emit_signal.grc (exporter depuis gnuradio-companion)
# Flowgraph:
# - File Source: /tmp/encrypted_signal.bin
# - Modulation: QPSK
# - Frequency: 446.00625 MHz (PMR446 canal 1)
# - Bandwidth: 12.5 kHz
# - Sink: HackRF Sink
python3 emit_signal.py
6️⃣ Interception Signal 📶
Capturez le signal avec HackRF.
# capture_signal.grc
# Flowgraph:
# - Source: HackRF Source
# - Frequency: 446.00625 MHz
# - Sample Rate: 2 MS/s
# - Demodulation: QPSK
# - Sink: File Sink (/tmp/captured_signal.bin)
python3 capture_signal.py
# Visualiser
gqrx --freq 446006250
7️⃣ Attaques 🔓
Side-Channel (Analyse Puissance)
Simulez une attaque via consommation électrique (FPGA + oscilloscope).
# power_analysis.py
import numpy as np
import matplotlib.pyplot as plt
def simulate_side_channel():
traces = np.random.rand(1000, 1000) # 1000 traces
key_guess = np.zeros(32)
for byte in range(32):
for guess in range(256):
correlation = np.corrcoef(traces[:, byte], guess)[0,1]
if correlation > 0.5:
key_guess[byte] = guess
np.save('/tmp/key_guess.npy', key_guess)
plt.plot(traces[0])
plt.savefig('/tmp/power_trace.png')
simulate_side_channel()
# Oscilloscope
sigrok-cli --driver fx2lafw --config samplerate=1M --continuous -o /tmp/power.sr
Faille d’Implémentation
Simuler une mauvaise gestion de clés.
# vuln_key.py
def vulnerable_key_gen():
# Faible entropie
seed = 12345
return bytes([seed % 256 for _ in range(32)])
key = vulnerable_key_gen()
with open('/tmp/vuln_key.bin', 'wb') as f:
f.write(key)
Brute-Force (Théorique)
Démontrer complexité AES-256.
# brute_force.py
from Crypto.Cipher import AES
def brute_force_attempt():
# Simuler (impossible en pratique)
for i in range(2**32): # Sous-ensemble
key = i.to_bytes(32, 'big')
cipher = AES.new(key, AES.MODE_GCM, nonce=b'1234567890123456')
try:
cipher.decrypt_and_verify(b'ciphertext', b'tag')
return key
except:
pass
return None
8️⃣ Décryptage Démo 🔍
Déchiffrez avec une clé compromise.
# decrypt_audio.py
from Crypto.Cipher import AES
import numpy as np
import sounddevice as sd
import scipy.io.wavfile as wavfile
def decrypt_audio():
with open('/tmp/vuln_key.bin', 'rb') as f:
key = f.read()
with open('/tmp/captured_signal.bin', 'rb') as f:
data = f.read()
nonce, tag, ciphertext = data[:16], data[16:32], data[32:]
cipher = AES.new(key, AES.MODE_GCM, nonce=nonce)
try:
audio_bytes = cipher.decrypt_and_verify(ciphertext, tag)
audio_data = np.frombuffer(audio_bytes, dtype=np.float32)
sd.play(audio_data, samplerate=44100)
sd.wait()
wavfile.write('/tmp/decrypted_audio.wav', 44100, audio_data)
except Exception as e:
print(f"Erreur: {e}")
decrypt_audio()
9️⃣ Boîtier DIY 🛠️
Construisez un boîtier nomade.
- Matériaux: ABS, vis inox.
- Design: Compartiments pour Pi, HackRF, batterie, OLED, FPGA.
- LED: Verte (actif), rouge (attaque).
- Connecteurs: USB-C, SMA antenne.
+--------------------+
| [Apache Ears] |
| [LED Verte/Rouge] |
| [OLED 0.96"] |
| [Antenne SMA] |
| [USB-C / Batterie] |
| [Boîtier ABS] |
+--------------------+
🔟 Tests Lab 🧪
Scénarios éthiques.
- Émission: Émettre signal chiffré.
- Interception: Capturer signal.
- Attaque: Side-channel, clé vulnérable.
- Déchiffrement: Vérifier audio.
# Test
python3 aes_encrypt.py
python3 emit_signal.py &
sleep 5
python3 capture_signal.py
python3 power_analysis.py
python3 decrypt_audio.py
❓ FAQ Apache 🔥
Q: Puis-je viser des réseaux réels ?
A: Non, illégal (article 226-15). Lab-only.
Q: Pourquoi simuler ?
A: Sensibilisation sans risques.
Q: HackRF détectable ?
A: Réception passive = indétectable.
Q: Et si la clé est sûre ?
A: AES-256 quasi-incassable sans failles.