ื ื—ื™ืจื” ืื• ืกื•ืจื™ืงื˜ื”. ื—ืœืง 3: ื”ื’ื ื” ืขืœ ืจืฉืช ื”-Office

ะ’ ืžืืžืจ ืงื•ื“ื ืกืงืจื ื• ื›ื™ืฆื“ ืœื”ืคืขื™ืœ ืืช ื”ื’ืจืกื” ื”ื™ืฆื™ื‘ื” ืฉืœ Suricata ืขืœ ืื•ื‘ื•ื ื˜ื• 18.04 LTS. ื”ื’ื“ืจืช IDS ืขืœ ืฆื•ืžืช ื‘ื•ื“ื“ ื•ื”ืคืขืœืช ืขืจื›ื•ืช ื›ืœืœื™ื ื—ื™ื ืžื™ื•ืช ื”ื™ื ื“ื™ ืคืฉื•ื˜ื”. ื”ื™ื•ื ื ื‘ื™ืŸ ื›ื™ืฆื“ ืœื”ื’ืŸ ืขืœ ืจืฉืช ืืจื’ื•ื ื™ืช ื‘ืืžืฆืขื•ืช ืกื•ื’ื™ ื”ืชืงืคื•ืช ื”ื ืคื•ืฆื™ื ื‘ื™ื•ืชืจ ื‘ืืžืฆืขื•ืช Suricata ื”ืžื•ืชืงื ืช ืขืœ ืฉืจืช ื•ื™ืจื˜ื•ืืœื™. ืœืฉื ื›ืš, ืื ื• ื–ืงื•ืงื™ื ืœ-VDS ื‘-Linux ืขื ืฉืชื™ ืœื™ื‘ื•ืช ืžื—ืฉื•ื‘. ื›ืžื•ืช ื”-RAM ืชืœื•ื™ื” ื‘ืขื•ืžืก: 2 ื’'ื™ื’ื”-ื‘ื™ื™ื˜ ืžืกืคื™ืงื™ื ืœืžื™ืฉื”ื•, ื•ื™ื™ืชื›ืŸ ืฉื™ื™ื“ืจืฉื• 4 ืื• ืืคื™ืœื• 6 ืœืžืฉื™ืžื•ืช ืจืฆื™ื ื™ื•ืช ื™ื•ืชืจ. ื”ื™ืชืจื•ืŸ ืฉืœ ืžื›ื•ื ื” ื•ื™ืจื˜ื•ืืœื™ืช ื”ื•ื ื”ื™ื›ื•ืœืช ืœื”ืชื ืกื•ืช: ืืคืฉืจ ืœื”ืชื—ื™ืœ ื‘ืชืฆื•ืจื” ืžื™ื ื™ืžืœื™ืช ื•ืœื”ื’ื“ื™ืœ ืžืฉืื‘ื™ื ืœืคื™ ื”ืฆื•ืจืš.

ื ื—ื™ืจื” ืื• ืกื•ืจื™ืงื˜ื”. ื—ืœืง 3: ื”ื’ื ื” ืขืœ ืจืฉืช ื”-Officeืฆื™ืœื•ื: ืจื•ื™ื˜ืจืก

ื—ื™ื‘ื•ืจ ืจืฉืชื•ืช

ื”ืกืจืช IDS ืœืžื—ืฉื‘ ื•ื™ืจื˜ื•ืืœื™ ืžืœื›ืชื—ื™ืœื” ืขืฉื•ื™ื” ืœื”ื™ื•ืช ื ื—ื•ืฆื” ืœืฆื•ืจืš ื‘ื“ื™ืงื•ืช. ืื ืžืขื•ืœื ืœื ืขืกืงืชื ื‘ืคืชืจื•ื ื•ืช ื›ืืœื”, ืืœ ืชืžื”ืจื• ืœื”ื–ืžื™ืŸ ื—ื•ืžืจื” ืคื™ื–ื™ืช ื•ืœืฉื ื•ืช ืืช ืืจื›ื™ื˜ืงื˜ื•ืจืช ื”ืจืฉืช. ืขื“ื™ืฃ ืœื”ืคืขื™ืœ ืืช ื”ืžืขืจื›ืช ื‘ืฆื•ืจื” ื‘ื˜ื•ื—ื” ื•ื—ืกื›ื•ื ื™ืช ื›ื“ื™ ืœืงื‘ื•ืข ืืช ืฆืจื›ื™ ื”ืžื—ืฉื•ื‘ ืฉืœืš. ื—ืฉื•ื‘ ืœื”ื‘ื™ืŸ ืฉื›ืœ ื”ืชืขื‘ื•ืจื” ื”ืืจื’ื•ื ื™ืช ืชืฆื˜ืจืš ืœืขื‘ื•ืจ ื“ืจืš ืฆื•ืžืช ื—ื™ืฆื•ื ื™ ื™ื—ื™ื“: ื›ื“ื™ ืœื—ื‘ืจ ืจืฉืช ืžืงื•ืžื™ืช (ืื• ืžืกืคืจ ืจืฉืชื•ืช) ืœ-VDS ืขื IDS Suricata ืžื•ืชืงืŸ, ืืชื” ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ SoftEther - ืฉืจืช VPN ื—ื•ืฆื” ืคืœื˜ืคื•ืจืžื•ืช ืงืœ ืœื”ื’ื“ืจื” ื”ืžืกืคืง ื”ืฆืคื ื” ื—ื–ืงื”. ื™ื™ืชื›ืŸ ืฉืœื—ื™ื‘ื•ืจ ืื™ื ื˜ืจื ื˜ ืžืฉืจื“ื™ ืื™ืŸ IP ืืžื™ืชื™, ืื– ืขื“ื™ืฃ ืœื”ื’ื“ื™ืจ ืื•ืชื• ื‘-VPS. ืื™ืŸ ื—ื‘ื™ืœื•ืช ืžื•ื›ื ื•ืช ื‘ืžืื’ืจ ืฉืœ ืื•ื‘ื•ื ื˜ื•, ืชืฆื˜ืจืš ืœื”ื•ืจื™ื“ ืืช ื”ืชื•ื›ื ื” ืžืฉื ื™ ื”ืฆื“ื“ื™ื ืืชืจ ื”ืคืจื•ื™ืงื˜, ืื• ืžืžืื’ืจ ื—ื™ืฆื•ื ื™ ื‘ืฉื™ืจื•ืช Launchpad (ืื ืืชื” ืกื•ืžืš ืขืœื™ื•):

sudo add-apt-repository ppa:paskal-07/softethervpn
sudo apt-get update

ืืชื” ื™ื›ื•ืœ ืœื”ืฆื™ื’ ืืช ืจืฉื™ืžืช ื”ื—ื‘ื™ืœื•ืช ื”ื–ืžื™ื ื•ืช ืขื ื”ืคืงื•ื“ื” ื”ื‘ืื”:

apt-cache search softether

ื ื—ื™ืจื” ืื• ืกื•ืจื™ืงื˜ื”. ื—ืœืง 3: ื”ื’ื ื” ืขืœ ืจืฉืช ื”-Office

ื ืฆื˜ืจืš softether-vpnserver (ื”ืฉืจืช ื‘ืชืฆื•ืจืช ื”ื‘ื“ื™ืงื” ืคื•ืขืœ ืขืœ VDS), ื›ืžื• ื’ื softether-vpncmd - ื›ืœื™ ืขื–ืจ ืฉืœ ืฉื•ืจืช ื”ืคืงื•ื“ื” ืœื”ื’ื“ืจืชื•.

sudo apt-get install softether-vpnserver softether-vpncmd

ื›ืœื™ ืฉื•ืจืช ืคืงื•ื“ื” ืžื™ื•ื—ื“ ืžืฉืžืฉ ื›ื“ื™ ืœื”ื’ื“ื™ืจ ืืช ื”ืฉืจืช:

sudo vpncmd

ื ื—ื™ืจื” ืื• ืกื•ืจื™ืงื˜ื”. ื—ืœืง 3: ื”ื’ื ื” ืขืœ ืจืฉืช ื”-Office

ืœื ื ื“ื‘ืจ ื‘ืคื™ืจื•ื˜ ืขืœ ื”ื”ื’ื“ืจื”: ื”ื”ืœื™ืš ื“ื™ ืคืฉื•ื˜, ื”ื•ื ืžืชื•ืืจ ื”ื™ื˜ื‘ ื‘ืคืจืกื•ืžื™ื ืจื‘ื™ื ื•ืื™ื ื• ืžืชื™ื™ื—ืก ื™ืฉื™ืจื•ืช ืœื ื•ืฉื ื”ืžืืžืจ. ื‘ืงื™ืฆื•ืจ, ืœืื—ืจ ื”ืคืขืœืช vpncmd, ืืชื” ืฆืจื™ืš ืœื‘ื—ื•ืจ ืคืจื™ื˜ 1 ื›ื“ื™ ืœืขื‘ื•ืจ ืœืžืกื•ืฃ ื ื™ื”ื•ืœ ื”ืฉืจืช. ืœืฉื ื›ืš, ืขืœื™ืš ืœื”ื–ื™ืŸ ืืช ื”ืฉื localhost ื•ืœืœื—ื•ืฅ ืขืœ enter ื‘ืžืงื•ื ืœื”ื–ื™ืŸ ืืช ืฉื ื”ืจื›ื–ืช. ืกื™ืกืžืช ื”ืžื ื”ืœ ื ืงื‘ืขืช ื‘ืงื•ื ืกื•ืœื” ืขื ื”ืคืงื•ื“ื” serverpasswordset, ื”ืจื›ื–ืช ื”ื•ื™ืจื˜ื•ืืœื™ืช DEFAULT ื ืžื—ืงืช (ืคืงื•ื“ื” hubdelete) ื•ื ื•ืฆืจืช ื—ื“ืฉื” ื‘ืฉื Suricata_VPN, ื•ื’ื ื”ืกื™ืกืžื” ืฉืœื” ืžื•ื’ื“ืจืช (ืคืงื•ื“ื” hubcreate). ืœืื—ืจ ืžื›ืŸ, ืขืœื™ืš ืœืขื‘ื•ืจ ืœืžืกื•ืฃ ื”ื ื™ื”ื•ืœ ืฉืœ ื”ืจื›ื–ืช ื”ื—ื“ืฉื” ื‘ืืžืฆืขื•ืช ื”ืคืงื•ื“ื” hub Suricata_VPN ื›ื“ื™ ืœื™ืฆื•ืจ ืงื‘ื•ืฆื” ื•ืžืฉืชืžืฉ ื‘ืืžืฆืขื•ืช ื”ืคืงื•ื“ื•ืช groupcreate ื•-usercreate. ืกื™ืกืžืช ื”ืžืฉืชืžืฉ ืžื•ื’ื“ืจืช ื‘ืืžืฆืขื•ืช userpasswordset.

SoftEther ืชื•ืžืš ื‘ืฉื ื™ ืžืฆื‘ื™ ื”ืขื‘ืจืช ืชืขื‘ื•ืจื”: SecureNAT ื•ื’ืฉืจ ืžืงื•ืžื™. ื”ืจืืฉื•ืŸ ื”ื•ื ื˜ื›ื ื•ืœื•ื’ื™ื” ืงื ื™ื™ื ื™ืช ืœื‘ื ื™ื™ืช ืจืฉืช ืคืจื˜ื™ืช ื•ื™ืจื˜ื•ืืœื™ืช ืขื NAT ื•-DHCP ืžืฉืœื”. SecureNAT ืื™ื ื• ื“ื•ืจืฉ TUN/TAP ืื• Netfilter ืื• ื”ื’ื“ืจื•ืช ื—ื•ืžืช ืืฉ ืื—ืจื•ืช. ื ื™ืชื•ื‘ ืื™ื ื• ืžืฉืคื™ืข ืขืœ ืœื™ื‘ืช ื”ืžืขืจื›ืช, ื•ื›ืœ ื”ืชื”ืœื™ื›ื™ื ืžื‘ื•ืฆืขื™ื ื•ื™ืจื˜ื•ืืœื™ื™ื ื•ืขื•ื‘ื“ื™ื ืขืœ ื›ืœ VPS / VDS, ืœืœื ืงืฉืจ ืœ-hypervisor ื‘ืฉื™ืžื•ืฉ. ื–ื” ืžื‘ื™ื ืœืขื•ืžืก ืžืขื‘ื“ ืžื•ื’ื‘ืจ ื•ืžื”ื™ืจื•ืช ืื™ื˜ื™ืช ื™ื•ืชืจ ื‘ื”ืฉื•ื•ืื” ืœืžืฆื‘ Local Bridge, ื”ืžื—ื‘ืจ ืืช ื”ืจื›ื–ืช ื”ื•ื™ืจื˜ื•ืืœื™ืช ืฉืœ SoftEther ืœืžืชืื ืจืฉืช ืคื™ื–ื™ ืื• ื”ืชืงืŸ TAP.

ื”ืชืฆื•ืจื” ื‘ืžืงืจื” ื–ื” ื”ื•ืคื›ืช ืžืกื•ื‘ื›ืช ื™ื•ืชืจ, ืžื›ื™ื•ื•ืŸ ืฉื”ื ื™ืชื•ื‘ ืžืชืจื—ืฉ ื‘ืจืžืช ื”ืงืจื ืœ ื‘ืืžืฆืขื•ืช Netfilter. ื”-VDS ืฉืœื ื• ื‘ื ื•ื™ื™ื ืขืœ Hyper-V, ืื– ื‘ืฉืœื‘ ื”ืื—ืจื•ืŸ ืื ื—ื ื• ื™ื•ืฆืจื™ื ื’ืฉืจ ืžืงื•ืžื™ ื•ืžืคืขื™ืœื™ื ืืช ื”ืชืงืŸ TAP ืขื ื”ืคืงื•ื“ื” bridgecreate Suricate_VPN -device:suricate_vpn -tap:yes. ืœืื—ืจ ื™ืฆื™ืื” ืžืžืกื•ืฃ ื ื™ื”ื•ืœ ื”ืจื›ื–ื•ืช, ื ืจืื” ืžืžืฉืง ืจืฉืช ื—ื“ืฉ ื‘ืžืขืจื›ืช ืฉื˜ืจื ื”ื•ืงืฆื” ืœื• IP:

ifconfig

ื ื—ื™ืจื” ืื• ืกื•ืจื™ืงื˜ื”. ื—ืœืง 3: ื”ื’ื ื” ืขืœ ืจืฉืช ื”-Office

ืœืื—ืจ ืžื›ืŸ, ืชืฆื˜ืจืš ืœืืคืฉืจ ื ื™ืชื•ื‘ ืžื ื•ืช ื‘ื™ืŸ ืžืžืฉืงื™ื (ip forward), ืื ื”ื•ื ืœื ืคืขื™ืœ:

sudo nano /etc/sysctl.conf

ื‘ื˜ืœ ืืช ื”ื”ืขืจื” ืœืฉื•ืจื” ื”ื‘ืื”:

net.ipv4.ip_forward = 1

ืฉืžื•ืจ ืืช ื”ืฉื™ื ื•ื™ื™ื ื‘ืงื•ื‘ืฅ, ืฆื ืžื”ืขื•ืจืš ื•ื”ื—ืœ ืื•ืชื ื‘ืคืงื•ื“ื” ื”ื‘ืื”:

sudo sysctl -p

ืœืื—ืจ ืžื›ืŸ, ืขืœื™ื ื• ืœื”ื’ื“ื™ืจ ืชืช-ืจืฉืช ืœืจืฉืช ื”ื•ื™ืจื˜ื•ืืœื™ืช ืขื ื›ืชื•ื‘ื•ืช IP ืคื™ืงื˜ื™ื‘ื™ื•ืช (ืœื“ื•ื’ืžื”, 10.0.10.0/24) ื•ืœื”ืงืฆื•ืช ื›ืชื•ื‘ืช ืœืžืžืฉืง:

sudo ifconfig tap_suricata_vp 10.0.10.1/24

ืื– ืืชื” ืฆืจื™ืš ืœื›ืชื•ื‘ ื—ื•ืงื™ Netfilter.

1. ื‘ืžื™ื“ืช ื”ืฆื•ืจืš, ืืคืฉืจ ืžื ื•ืช ื ื›ื ืกื•ืช ื‘ื™ืฆื™ืื•ืช ื”ืื–ื ื” (ื”ืคืจื•ื˜ื•ืงื•ืœ ื”ืงื ื™ื™ื ื™ ืฉืœ SoftEther ืžืฉืชืžืฉ ื‘-HTTPS ื•ื‘ื™ืฆื™ืื” 443)

sudo iptables -A INPUT -p tcp -m tcp --dport 443 -j ACCEPT
sudo iptables -A INPUT -p tcp -m tcp --dport 992 -j ACCEPT
sudo iptables -A INPUT -p tcp -m tcp --dport 1194 -j ACCEPT
sudo iptables -A INPUT -p udp -m udp --dport 1194 -j ACCEPT
sudo iptables -A INPUT -p tcp -m tcp --dport 5555 -j ACCEPT

2. ื”ื’ื“ืจ NAT ืžืจืฉืช ื”ืžืฉื ื” 10.0.10.0/24 ืœ-IP ืฉืœ ื”ืฉืจืช ื”ืจืืฉื™

sudo iptables -t nat -A POSTROUTING -s 10.0.10.0/24 -j SNAT --to-source 45.132.17.140

3. ืืคืฉืจ ืœื”ืขื‘ื™ืจ ืžื ื•ืช ืžืจืฉืช ื”ืžืฉื ื” 10.0.10.0/24

sudo iptables -A FORWARD -s 10.0.10.0/24 -j ACCEPT

4. ืืคืฉืจ ืœื”ืขื‘ื™ืจ ืžื ื•ืช ืœื—ื™ื‘ื•ืจื™ื ืฉื›ื‘ืจ ื ื•ืฆืจื•

sudo iptables -A FORWARD -p all -m state --state ESTABLISHED,RELATED -j ACCEPT

ืืช ื”ืื•ื˜ื•ืžืฆื™ื” ืฉืœ ื”ืชื”ืœื™ืš ื ืฉืื™ืจ ืœืงื•ืจืื™ื ื›ืฉื™ืขื•ืจื™ ื‘ื™ืช ืขื ื”ืคืขืœื” ืžื—ื“ืฉ ืฉืœ ื”ืžืขืจื›ืช ื‘ืืžืฆืขื•ืช ืกืงืจื™ืคื˜ื™ื ืฉืœ ืืชื—ื•ืœ.

ืื ืืชื” ืจื•ืฆื” ืœืชืช IP ืœืœืงื•ื—ื•ืช ื‘ืื•ืคืŸ ืื•ื˜ื•ืžื˜ื™, ืชืฆื˜ืจืš ื’ื ืœื”ืชืงื™ืŸ ืกื•ื’ ืฉืœ ืฉื™ืจื•ืช DHCP ืขื‘ื•ืจ ื”ื’ืฉืจ ื”ืžืงื•ืžื™. ื–ื” ืžืฉืœื™ื ืืช ื”ื’ื“ืจืช ื”ืฉืจืช ื•ืืชื” ื™ื›ื•ืœ ืœืœื›ืช ืืœ ื”ืœืงื•ื—ื•ืช. SoftEther ืชื•ืžืš ื‘ืคืจื•ื˜ื•ืงื•ืœื™ื ืจื‘ื™ื, ืฉื”ืฉื™ืžื•ืฉ ื‘ื”ื ืชืœื•ื™ ื‘ื™ื›ื•ืœื•ืช ืฉืœ ืฆื™ื•ื“ ื”-LAN.

netstat -ap |grep vpnserver

ื ื—ื™ืจื” ืื• ืกื•ืจื™ืงื˜ื”. ื—ืœืง 3: ื”ื’ื ื” ืขืœ ืจืฉืช ื”-Office

ืžื›ื™ื•ื•ืŸ ืฉื ืชื‘ ื”ื‘ื“ื™ืงื” ืฉืœื ื• ืคื•ืขืœ ื’ื ืชื—ืช ืื•ื‘ื•ื ื˜ื•, ื‘ื•ืื• ื ืชืงื™ืŸ ืืช ื”ื—ื‘ื™ืœื•ืช softether-vpnclient ื•-softether-vpncmd ืžืžืื’ืจ ื—ื™ืฆื•ื ื™ ืขืœื™ื• ื›ื“ื™ ืœื”ืฉืชืžืฉ ื‘ืคืจื•ื˜ื•ืงื•ืœ ื”ืงื ื™ื™ื ื™. ืชืฆื˜ืจืš ืœื”ืคืขื™ืœ ืืช ื”ืœืงื•ื—:

sudo vpnclient start

ื›ื“ื™ ืœื”ื’ื“ื™ืจ, ื”ืฉืชืžืฉ ื‘ื›ืœื™ ื”ืฉื™ืจื•ืช vpncmd, ื•ื‘ื—ืจ ื‘-localhost ื›ืžื—ืฉื‘ ืฉื‘ื• ืคื•ืขืœ ื”-vpnclient. ื›ืœ ื”ืคืงื•ื“ื•ืช ืžืชื‘ืฆืขื•ืช ื‘ืžืกื•ืฃ: ืชืฆื˜ืจืš ืœื™ืฆื•ืจ ืžืžืฉืง ื•ื™ืจื˜ื•ืืœื™ (NicCreate) ื•ื—ืฉื‘ื•ืŸ (AccountCreate).

ื‘ืžืงืจื™ื ืžืกื•ื™ืžื™ื, ืขืœื™ืš ืœืฆื™ื™ืŸ ืืช ืฉื™ื˜ืช ื”ืื™ืžื•ืช ื‘ืืžืฆืขื•ืช ื”ืคืงื•ื“ื•ืช AccountAnonymousSet, AccountPasswordSet, AccountCertSet ื•- AccountSecureCertSet. ืžื›ื™ื•ื•ืŸ ืฉืื™ื ื ื• ืžืฉืชืžืฉื™ื ื‘-DHCP, ื”ื›ืชื•ื‘ืช ืฉืœ ื”ืžืชืื ื”ื•ื™ืจื˜ื•ืืœื™ ืžื•ื’ื“ืจืช ื‘ืื•ืคืŸ ื™ื“ื ื™.

ื‘ื ื•ืกืฃ, ืขืœื™ื ื• ืœื”ืคืขื™ืœ ip forward (ื”ืคืจืžื˜ืจ net.ipv4.ip_forward=1 ื‘ืงื•ื‘ืฅ /etc/sysctl.conf) ื•ืœื”ื’ื“ื™ืจ ืžืกืœื•ืœื™ื ืกื˜ื˜ื™ื™ื. ื‘ืžื™ื“ืช ื”ืฆื•ืจืš, ื‘-VDS ืขื Suricata, ืชื•ื›ืœ ืœื”ื’ื“ื™ืจ ื”ืขื‘ืจืช ื™ืฆื™ืื•ืช ืœืฉื™ืžื•ืฉ ื‘ืฉื™ืจื•ืชื™ื ื”ืžื•ืชืงื ื™ื ื‘ืจืฉืช ื”ืžืงื•ืžื™ืช. ืขืœ ื–ื”, ืžื™ื–ื•ื’ ื”ืจืฉืช ื™ื›ื•ืœ ืœื”ื™ื—ืฉื‘ ื›ืžื•ืฉืœื.

ื”ืชืฆื•ืจื” ื”ืžื•ืฆืขืช ืฉืœื ื• ืชื™ืจืื” ื‘ืขืจืš ื›ืš:

ื ื—ื™ืจื” ืื• ืกื•ืจื™ืงื˜ื”. ื—ืœืง 3: ื”ื’ื ื” ืขืœ ืจืฉืช ื”-Office

ื”ื’ื“ืจืช Suricata

ะ’ ืžืืžืจ ืงื•ื“ื ื“ื™ื‘ืจื ื• ืขืœ ืฉื ื™ ืžืฆื‘ื™ ืคืขื•ืœื” ืฉืœ IDS: ื“ืจืš ืชื•ืจ NFQUEUE (ืžืฆื‘ NFQ) ื•ื“ืจืš ื”ืขืชืงื” ืืคืก (ืžืฆื‘ AF_PACKET). ื”ืฉื ื™ ื“ื•ืจืฉ ืฉื ื™ ืžืžืฉืงื™ื, ืื‘ืœ ื”ื•ื ืžื”ื™ืจ ื™ื•ืชืจ - ืื ื—ื ื• ื ืฉืชืžืฉ ื‘ื•. ื”ืคืจืžื˜ืจ ืžื•ื’ื“ืจ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ื‘- /etc/default/suricata. ืื ื—ื ื• ืฆืจื™ื›ื™ื ื’ื ืœืขืจื•ืš ืืช ืงื˜ืข vars ื‘-/etc/suricata/suricata.yaml, ืœื”ื’ื“ื™ืจ ืืช ืจืฉืช ื”ืžืฉื ื” ื”ื•ื•ื™ืจื˜ื•ืืœื™ืช ืฉื ื›ื‘ื™ืช.

ื ื—ื™ืจื” ืื• ืกื•ืจื™ืงื˜ื”. ื—ืœืง 3: ื”ื’ื ื” ืขืœ ืจืฉืช ื”-Office

ื›ื“ื™ ืœื”ืคืขื™ืœ ืžื—ื“ืฉ ืืช IDS, ื”ืฉืชืžืฉ ื‘ืคืงื•ื“ื”:

systemctl restart suricata

ื”ืคืชืจื•ืŸ ืžื•ื›ืŸ, ื›ืขืช ื™ื™ืชื›ืŸ ืฉื™ื”ื™ื” ืขืœื™ืš ืœื‘ื“ื•ืง ืืช ื”ื”ืชื ื’ื“ื•ืช ืœืคืขื•ืœื•ืช ื–ื“ื•ื ื™ื•ืช.

ื”ื“ืžื™ื™ืช ื”ืชืงืคื•ืช

ื™ื›ื•ืœื™ื ืœื”ื™ื•ืช ืžืกืคืจ ืชืจื—ื™ืฉื™ื ืœืฉื™ืžื•ืฉ ืงืจื‘ื™ ื‘ืฉื™ืจื•ืช IDS ื—ื™ืฆื•ื ื™:

ื”ื’ื ื” ืžืคื ื™ ื”ืชืงืคื•ืช DDoS (ืžื˜ืจื” ืจืืฉื™ืช)

ืงืฉื” ืœื™ื™ืฉื ืืคืฉืจื•ืช ื›ื–ื• ื‘ืชื•ืš ื”ืจืฉืช ื”ืืจื’ื•ื ื™ืช, ืฉื›ืŸ ื”ื—ื‘ื™ืœื•ืช ืœื ื™ืชื•ื— ื—ื™ื™ื‘ื•ืช ืœื”ื’ื™ืข ืœืžืžืฉืง ื”ืžืขืจื›ืช ืฉืžืกืชื›ืœ ืขืœ ื”ืื™ื ื˜ืจื ื˜. ื’ื ืื ื”-IDS ื—ื•ืกื ืื•ืชื, ืชืขื‘ื•ืจื” ืžื–ื•ื™ืคืช ืขืœื•ืœื” ืœื”ืคื™ืœ ืืช ืงื™ืฉื•ืจ ื”ื ืชื•ื ื™ื. ื›ื“ื™ ืœื”ื™ืžื ืข ืžื›ืš, ืขืœื™ืš ืœื”ื–ืžื™ืŸ VPS ืขื ื—ื™ื‘ื•ืจ ืื™ื ื˜ืจื ื˜ ืคืจื•ื“ื•ืงื˜ื™ื‘ื™ ืžืกืคื™ืง ืฉื™ื›ื•ืœ ืœื”ืขื‘ื™ืจ ืืช ื›ืœ ืชืขื‘ื•ืจืช ื”ืจืฉืช ื”ืžืงื•ืžื™ืช ื•ื›ืœ ื”ืชืขื‘ื•ืจื” ื”ื—ื™ืฆื•ื ื™ืช. ืœืจื•ื‘ ืงืœ ื•ื–ื•ืœ ื™ื•ืชืจ ืœืขืฉื•ืช ื–ืืช ืžืืฉืจ ืœื”ืจื—ื™ื‘ ืืช ืขืจื•ืฅ ื”ืžืฉืจื“. ื›ื—ืœื•ืคื”, ืจืื•ื™ ืœื”ื–ื›ื™ืจ ืฉื™ืจื•ืชื™ื ืžื™ื•ื—ื“ื™ื ืœื”ื’ื ื” ืžืคื ื™ DDoS. ืขืœื•ืช ื”ืฉื™ืจื•ืชื™ื ืฉืœื”ื ื“ื•ืžื” ืœืขืœื•ืช ืฉืœ ืฉืจืช ื•ื™ืจื˜ื•ืืœื™, ื•ื”ื™ื ืื™ื ื” ื“ื•ืจืฉืช ืชืฆื•ืจื” ืฉื’ื•ื–ืœืช ื–ืžืŸ, ืื‘ืœ ื™ืฉ ื’ื ื—ืกืจื•ื ื•ืช - ื”ืœืงื•ื— ืžืงื‘ืœ ืจืง ื”ื’ื ืช DDoS ืขื‘ื•ืจ ื›ืกืคื•, ื‘ืขื•ื“ ืฉื”-IDS ืฉืœื• ื™ื›ื•ืœ ืœื”ื™ื•ืช ืžื•ื’ื“ืจ ื›ืžื•ืš ื›ืžื•.

ื”ื’ื ื” ืžืคื ื™ ื”ืชืงืคื•ืช ื—ื™ืฆื•ื ื™ื•ืช ืžืกื•ื’ื™ื ืื—ืจื™ื

Suricata ืžืกื•ื’ืœืช ืœื”ืชืžื•ื“ื“ ืขื ื ื™ืกื™ื•ื ื•ืช ืœื ืฆืœ ืคื’ื™ืขื•ื™ื•ืช ืฉื•ื ื•ืช ื‘ืฉื™ืจื•ืชื™ ืจืฉืช ืืจื’ื•ื ื™ื™ื ื”ื ื’ื™ืฉื™ื ืžื”ืื™ื ื˜ืจื ื˜ (ืฉืจืช ื“ื•ืืจ, ืฉืจืช ืื™ื ื˜ืจื ื˜ ื•ื™ื™ืฉื•ืžื™ ืื™ื ื˜ืจื ื˜ ื•ื›ื•'). ื‘ื“ืจืš ื›ืœืœ, ื‘ืฉื‘ื™ืœ ื–ื”, IDS ืžื•ืชืงืŸ ื‘ืชื•ืš ื”-LAN ืื—ืจื™ ื”ืชืงื ื™ ื”ื’ื‘ื•ืœ, ืื‘ืœ ืœืงื—ืช ืื•ืชื• ื”ื—ื•ืฆื” ื™ืฉ ื–ื›ื•ืช ืงื™ื•ื.

ื”ื’ื ื” ืžืคื ื™ ื’ื•ืจืžื™ื ืคื ื™ืžื™ื™ื

ืœืžืจื•ืช ืžืืžืฆื™ื• ื”ื˜ื•ื‘ื™ื ื‘ื™ื•ืชืจ ืฉืœ ืžื ื”ืœ ื”ืžืขืจื›ืช, ืžื—ืฉื‘ื™ื ื‘ืจืฉืช ื”ืืจื’ื•ื ื™ืช ืขืœื•ืœื™ื ืœื”ื™ื“ื‘ืง ื‘ืชื•ื›ื ื” ื–ื“ื•ื ื™ืช. ื‘ื ื•ืกืฃ, ืœืคืขืžื™ื ืžื•ืคื™ืขื™ื ื‘ืกื‘ื™ื‘ื” ื—ื•ืœื™ื’ื ื™ื, ืฉืžื ืกื™ื ืœื‘ืฆืข ื›ืžื” ืคืขื•ืœื•ืช ืœื ื—ื•ืงื™ื•ืช. Suricata ื™ื›ื•ืœื” ืœืขื–ื•ืจ ืœื—ืกื•ื ื ื™ืกื™ื•ื ื•ืช ื›ืืœื”, ืื ื›ื™ ื›ื“ื™ ืœื”ื’ืŸ ืขืœ ื”ืจืฉืช ื”ืคื ื™ืžื™ืช ืขื“ื™ืฃ ืœื”ืชืงื™ืŸ ืื•ืชื” ื‘ืชื•ืš ื”ื”ื™ืงืฃ ื•ืœื”ืฉืชืžืฉ ื‘ื” ื‘ืžืงื‘ื™ืœ ืœืžืชื’ ืžื ื•ื”ืœ ืฉื™ื›ื•ืœ ืœืฉืงืฃ ืชืขื‘ื•ืจื” ืœื™ืฆื™ืื” ืื—ืช. ื’ื IDS ื—ื™ืฆื•ื ื™ ืื™ื ื• ื—ืกืจ ืชื•ืขืœืช ื‘ืžืงืจื” ื–ื” - ืœืคื—ื•ืช ื”ื•ื ื™ื•ื›ืœ ืœืชืคื•ืก ื ื™ืกื™ื•ื ื•ืช ืฉืœ ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช ืฉื—ื™ื•ืช ืขืœ ื”-LAN ืœื™ืฆื•ืจ ืงืฉืจ ืขื ืฉืจืช ื—ื™ืฆื•ื ื™.

ืžืœื›ืชื—ื™ืœื”, ื ื™ืฆื•ืจ ื‘ื“ื™ืงื” ื ื•ืกืคืช ืฉืชื•ืงืคืช VPS, ื•ื‘ื ืชื‘ ื”ืจืฉืช ื”ืžืงื•ืžื™ืช ื ืขืœื” ืืช Apache ืขื ืชืฆื•ืจืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ, ื•ืœืื—ืจ ืžื›ืŸ ื ืขื‘ื™ืจ ืืœื™ื• ืืช ื”ืคื•ืจื˜ ื”-80 ืžืฉืจืช ื”-IDS. ืœืื—ืจ ืžื›ืŸ, ื ื“ืžื” ืžืชืงืคืช DDoS ืžืžืืจื— โ€‹โ€‹ืชื•ืงืฃ. ื›ื“ื™ ืœืขืฉื•ืช ื–ืืช, ื”ื•ืจื“ ืž-GitHub, ืงื•ืžืคืœ ื•ื”ืคืขื™ืœ ืชื•ื›ื ื™ืช xerxes ืงื˜ื ื” ืขืœ ื”ืฆื•ืžืช ื”ืชื•ืงืฃ (ื™ื™ืชื›ืŸ ืฉืชืฆื˜ืจืš ืœื”ืชืงื™ืŸ ืืช ื—ื‘ื™ืœืช gcc):

git clone https://github.com/Soldie/xerxes-DDos-zanyarjamal-C.git
cd xerxes-DDos-zanyarjamal-C/
gcc xerxes.c -o xerxes 
./xerxes 45.132.17.140 80

ื”ืชื•ืฆืื” ืฉืœ ืขื‘ื•ื“ืชื” ื”ื™ื™ืชื” ื›ื“ืœืงืžืŸ:

ื ื—ื™ืจื” ืื• ืกื•ืจื™ืงื˜ื”. ื—ืœืง 3: ื”ื’ื ื” ืขืœ ืจืฉืช ื”-Office

ืกื•ืจื™ืงื˜ื” ืžื ืชืงืช ืืช ื”ื ื‘ืœ, ื•ืขืžื•ื“ ื”ืืคืืฆ'ื™ ื ืคืชื— ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ืœืžืจื•ืช ื”ืžืชืงืคื” ื”ืžืื•ืœืชืจืช ืฉืœื ื• ื•ื”ืขืจื•ืฅ ื”ื“ื™ ืžืช ืฉืœ ืจืฉืช ื”"ืžืฉืจื“" (ื‘ืขืฆื ื”ื‘ื™ืชื™ืช). ืขื‘ื•ืจ ืžืฉื™ืžื•ืช ืจืฆื™ื ื™ื•ืช ื™ื•ืชืจ, ื›ื“ืื™ ืœื”ืฉืชืžืฉ ืžืกื’ืจืช Metasploit. ื”ื•ื ืžื™ื•ืขื“ ืœื‘ื“ื™ืงื•ืช ื—ื“ื™ืจื” ื•ืžืืคืฉืจ ืœืš ืœื“ืžื•ืช ืžื’ื•ื•ืŸ ื”ืชืงืคื•ืช. ื”ื•ืจืื•ืช ื”ืชืงื ื” ื–ืžื™ืŸ ื‘ืืชืจ ื”ืคืจื•ื™ืงื˜. ืœืื—ืจ ื”ื”ืชืงื ื”, ื ื“ืจืฉ ืขื“ื›ื•ืŸ:

sudo msfupdate

ืœื‘ื“ื™ืงื”, ื”ืคืขืœ ืืช msfconsole.

ื ื—ื™ืจื” ืื• ืกื•ืจื™ืงื˜ื”. ื—ืœืง 3: ื”ื’ื ื” ืขืœ ืจืฉืช ื”-Office

ืœืžืจื‘ื” ื”ืฆืขืจ, ื”ื’ืจืกืื•ืช ื”ืื—ืจื•ื ื•ืช ืฉืœ ื”ืžืกื’ืจืช ื—ืกืจื•ืช ืืช ื”ื™ื›ื•ืœืช ืœืคืฆื— ืื•ื˜ื•ืžื˜ื™ืช, ื•ืœื›ืŸ ื ื™ืฆื•ืœ ื™ืฆื˜ืจื›ื• ืœื”ื™ื•ืช ืžืžื•ื™ืŸ ื‘ืื•ืคืŸ ื™ื“ื ื™ ื•ืœื”ืคืขื™ืœ ื‘ืืžืฆืขื•ืช ืคืงื•ื“ืช use. ืžืœื›ืชื—ื™ืœื”, ื›ื“ืื™ ืœืงื‘ื•ืข ืืช ื”ืคื•ืจื˜ื™ื ื”ืคืชื•ื—ื™ื ื‘ืžื—ืฉื‘ ื”ืžื•ืชืงืฃ, ืœืžืฉืœ, ื‘ืืžืฆืขื•ืช nmap (ื‘ืžืงืจื” ืฉืœื ื•, ื”ื•ื ื™ื•ื—ืœืฃ ืœื—ืœื•ื˜ื™ืŸ ืขืœ ื™ื“ื™ netstat ืขืœ ื”ืžืืจื— ื”ืžื•ืชืงืฃ), ื•ืœืื—ืจ ืžื›ืŸ ืœื‘ื—ื•ืจ ื•ืœื”ืฉืชืžืฉ ื‘ ืžื•ื“ื•ืœื™ื ืฉืœ Metasploit

ื™ืฉื ื ืืžืฆืขื™ื ืื—ืจื™ื ืœื‘ื—ื•ืŸ ืืช ื”ืขืžื™ื“ื•ืช ืฉืœ IDS โ€‹โ€‹ื ื’ื“ ื”ืชืงืคื•ืช, ื›ื•ืœืœ ืฉื™ืจื•ืชื™ื ืžืงื•ื•ื ื™ื. ืœืžืขืŸ ื”ืกืงืจื ื•ืช, ื ื™ืชืŸ ืœืืจื’ืŸ ื‘ื“ื™ืงื•ืช ืžืืžืฅ ื‘ืืžืฆืขื•ืช ื’ืจืกืช ื”ื ื™ืกื™ื•ืŸ ืžื“ื’ื™ืฉ IP. ื›ื“ื™ ืœื‘ื“ื•ืง ืืช ื”ืชื’ื•ื‘ื” ืœืคืขื•ืœื•ืช ืฉืœ ืคื•ืœืฉื™ื ืคื ื™ืžื™ื™ื, ื›ื“ืื™ ืœื”ืชืงื™ืŸ ื›ืœื™ื ืžื™ื•ื—ื“ื™ื ืขืœ ืื—ืช ื”ืžื›ื•ื ื•ืช ื‘ืจืฉืช ื”ืžืงื•ืžื™ืช. ื™ืฉ ื”ืจื‘ื” ืืคืฉืจื•ื™ื•ืช ื•ืžื“ื™ ืคืขื ื™ืฉ ืœื™ื™ืฉื ืื•ืชืŸ ืœื ืจืง ื‘ืืชืจ ื”ื ื™ืกื•ื™, ืืœื ื’ื ืขืœ ืžืขืจื›ื•ืช ืขื•ื‘ื“ื•ืช, ืจืง ืฉื–ื” ืกื™ืคื•ืจ ืื—ืจ ืœื’ืžืจื™.

ื ื—ื™ืจื” ืื• ืกื•ืจื™ืงื˜ื”. ื—ืœืง 3: ื”ื’ื ื” ืขืœ ืจืฉืช ื”-Office

ื ื—ื™ืจื” ืื• ืกื•ืจื™ืงื˜ื”. ื—ืœืง 3: ื”ื’ื ื” ืขืœ ืจืฉืช ื”-Office

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”