Actualiser ICS.py
This commit is contained in:
@@ -1,27 +1,35 @@
|
|||||||
from scapy.all import sniff, ICMP, IP, TCP
|
from scapy.all import sniff, ICMP, IP, TCP
|
||||||
|
|
||||||
|
## On crée la fonction detect_os.
|
||||||
|
## On se base sur les retours ICMP pour trouver l'OS de la machine
|
||||||
|
## Puis on print avec l'IP source et l'OS type.
|
||||||
|
|
||||||
def detect_os(pkt):
|
def detect_os(pkt):
|
||||||
if pkt.haslayer(ICMP):
|
if pkt.haslayer(ICMP):
|
||||||
ip_src = pkt[IP].src
|
ip_src = pkt[IP].src
|
||||||
icmp_type = pkt[ICMP].type
|
icmp_type = pkt[ICMP].type
|
||||||
|
|
||||||
if icmp_type == 0: # Echo Reply
|
if icmp_type == 0:
|
||||||
user_agent = pkt[IP].options if hasattr(pkt[IP], 'options') else ""
|
user_agent = pkt[IP].options if hasattr(pkt[IP], 'options') else ""
|
||||||
if "Microsoft" in str(user_agent):
|
if "Microsoft" in str(user_agent):
|
||||||
os_type = "Windows"
|
os_type = "Windows"
|
||||||
|
elif "Linux" in str(user_agent):
|
||||||
|
os_type = "Linux"
|
||||||
else:
|
else:
|
||||||
os_type = "Linux or Other"
|
os_type = "Ne contient pas Windows ou Linux dans son user_agent"
|
||||||
|
|
||||||
print(f"Alerte : paquet ICMP reçu de {ip_src} ({os_type})")
|
print(f"Alerte : paquet ICMP reçu de {ip_src} ({os_type})")
|
||||||
|
|
||||||
|
## On crée la fonction detect_ftp qui va vérifié si une tentative de connexion à lieu sur le port 21 avec l'USER root.
|
||||||
|
|
||||||
def detect_ftp(pkt):
|
def detect_ftp(pkt):
|
||||||
if pkt.haslayer(TCP) and pkt[TCP].dport == 21: # Port FTP
|
if pkt.haslayer(TCP) and pkt[TCP].dport == 21:
|
||||||
payload = str(pkt[TCP].payload)
|
payload = str(pkt[TCP].payload)
|
||||||
if "USER root" in payload or "PASS root" in payload:
|
if "USER root" in payload:
|
||||||
ip_src = pkt[IP].src
|
ip_src = pkt[IP].src
|
||||||
print(f"Alerte : tentative de connexion FTP avec 'root' de {ip_src}")
|
print(f"Alerte : tentative de connexion FTP avec 'root' de {ip_src}")
|
||||||
|
|
||||||
|
## Puis on créer la fonction start_sniffing qui va sniffer sur l'ICMP ou sur le port 21 en TCP
|
||||||
|
|
||||||
def start_sniffing():
|
def start_sniffing():
|
||||||
print("Démarrage de l'analyse du réseau... Appuyez sur Ctrl+C pour arrêter.")
|
print("Démarrage de l'analyse du réseau... Appuyez sur Ctrl+C pour arrêter.")
|
||||||
|
|||||||
Reference in New Issue
Block a user