DDOS
https://github.com/jgamblin/Mirai-Source-Code/blob/master/ForumPost.md
分工
使用的技術
攻擊者
- Attack Script
- 找最新 Attack 技術
防禦
Env (For 實驗)
攻擊點
Bandwidth
Image Not Showing
Possible Reasons
- The image file may be corrupted
- The server hosting the image is unavailable
- The image path is incorrect
- The image format is not supported
Learn More →
有papaer -> 可以到 1.7TB/s 的檔案傳輸
Memory
low orbit ion cannon
https://github.com/NewEraCracker/LOIC
Linux
mono(require)
https://www.monodevelop.com/download/#fndtn-download-lin
hping3
ICMP flooding
-> Attack bandwidth
Image Not Showing
Possible Reasons
- The image file may be corrupted
- The server hosting the image is unavailable
- The image path is incorrect
- The image format is not supported
Learn More →
Image Not Showing
Possible Reasons
- The image file may be corrupted
- The server hosting the image is unavailable
- The image path is incorrect
- The image format is not supported
Learn More →
Wire Shark
Image Not Showing
Possible Reasons
- The image file may be corrupted
- The server hosting the image is unavailable
- The image path is incorrect
- The image format is not supported
Learn More →
Defense -> ICMP disable
SYN flooding
192.168.86.181
D -> 200 byte
Image Not Showing
Possible Reasons
- The image file may be corrupted
- The server hosting the image is unavailable
- The image path is incorrect
- The image format is not supported
Learn More →
Image Not Showing
Possible Reasons
- The image file may be corrupted
- The server hosting the image is unavailable
- The image path is incorrect
- The image format is not supported
Learn More →
Image Not Showing
Possible Reasons
- The image file may be corrupted
- The server hosting the image is unavailable
- The image path is incorrect
- The image format is not supported
Learn More →
defend -> firewall
Saphyra
Http Get
繞過Firewall 使用不同 userAgent(http header) 來造成混洨
http Get -> request traget host
Script
https://github.com/IkzCx/ProgramsForDDos/blob/master/Saphyra.py
Image Not Showing
Possible Reasons
- The image file may be corrupted
- The server hosting the image is unavailable
- The image path is incorrect
- The image format is not supported
Learn More →
nload
使用方法
C2 server
byob
byob
DOC
https://github.com/malwaredllc/byob/wiki
LinuxEnv setup
video1
video2
video3
https://github.com/malwaredllc/byob/wiki/Installing-Requirements-on-Linux
Run setup.py
Armitage
https://github.com/Intek13x/armitage

Creating a Listener in Armitage

Reverse shell


IEEE paper
Analysis Hping3 攻擊行為

iptables
Linux Firewall
flag
Filter Table
Add New Rules

Delete Rules
刪掉第一個Rules

Output chain (out bound 出站)
ping 192.168.203.151
PING 192.168.203.151 (192.168.203.151) 56(84) bytes of data.
64 bytes from 192.168.203.151: icmp_seq=1 ttl=64 time=5.23 ms
64 bytes from 192.168.203.151: icmp_seq=2 ttl=64 time=1.02 ms
root@ubuntu:/home/user# ping 192.168.203.151PING 192.168.203.151 (192.168.203.151) 56(84) bytes of data.
ping: sendmsg: Operation not permitted
ping: sendmsg: Operation not permitted
ping: sendmsg: Operation not permitted
ping: sendmsg: Operation not permitted
Mac filter (MAC 過濾)
(有效)
Nat Table (NAT 設定)
show
Nat Table 會有4個chain
- PreRouting(Before Routing)
改 destination IP or Address
可以進行轉發
改 Source IP or Address
Prevent SYN