BARRACUDA is inspired by the HULK (Python) tool concept by Barry Shteiman, implemented in Go with additional features and significant performance improvements. This is an independent implementation that takes inspiration from HULK's core concepts while adding modern features and optimizations.
Inspired by the HULK project concept by Barry Shteiman (
http://sectorix.com).
- Standard Attack: HTTP request flooding with optimizations
- SlowLoris Attack: Keeps connections open with partial headers (50 connections)
- HTTP Flood Attack: Multiple HTTP methods with payload variations (20 workers)
- Random Attack Pattern: Weighted random selection attack methods (15 workers)
- Multi-vector Attacks: Combination of various attack types in parallel
- Rate Limiting: Control requests per second (configurable)
- Duration Control: Attack with specific duration
- Proxy Support: Automatic proxy rotation
- Custom Headers: Header manipulation for stealth
- SSL/TLS Support: Advanced SSL configuration
- Connection Pooling: Optimized connection management
- Real-time Statistics: RPS, BPS, success rate tracking
- Target Health Monitoring: Auto-adjust based on response
- Performance Analytics: Detailed reporting and logging
- Resource Management: Advanced connection pooling
- Modern User Agents: 10+ latest browser signatures
- Request Fingerprinting: Randomized patterns to avoid detection
- IP Rotation: Proxy management and rotation
- Advanced Headers: Custom header manipulation
# Install directly from repository
go install github.com/fkr00t/barracuda@latest
# Or clone and build manually
git clone https://github.com/fkr00t/barracuda.git
cd barracuda
go build -o barracuda barracuda.go advanced_attacks.go# Compile barracuda
go build -o barracuda barracuda.go advanced_attacks.go
# Build with optimizations
go build -ldflags="-s -w" -o barracuda barracuda.go advanced_attacks.go# Standard attack
barracuda -site http://target.com
# SlowLoris attack
barracuda -site http://target.com -mode slowloris -duration 5m
# HTTP Flood with rate limiting
barracuda -site http://target.com -mode httpflood -rate 1000 -duration 10m
# Random attack pattern
barracuda -site http://target.com -mode random -duration 15m
# Multi-vector attack
barracuda -site http://target.com -mode multivector -duration 10m# With proxy support
barracuda -site http://target.com -proxy proxies.txt -proxy-rotate
# With custom headers
barracuda -site http://target.com -header "X-Custom: value" -header "Authorization: Bearer token"
# With custom payload
barracuda -site http://target.com -data "param=value" -mode httpflood
# With SSL verification disabled
barracuda -site https://target.com -ssl-verify=false
# With stealth mode
barracuda -site http://target.com -stealth -adaptive| Aspect | Original HULK | BARRACUDA |
|---|---|---|
| Attack Modes | 1 (Standard) | 5+ (Multiple vectors) |
| Rate Limiting | โ | โ Configurable |
| Monitoring | Basic | โ Advanced real-time |
| User Agents | 13 old | 10+ modern |
| Proxy Support | โ | โ Full support |
| Safety Features | โ | โ Multiple checks |
| Connection Pooling | Basic | โ Advanced (200 connections) |
| Multi-threading | Limited | โ Goroutines optimized |
- โ Status: Working perfectly
- ๐ Performance: 300+ RPS sustained
- ๐ง Features: Rate limiting, duration control, real-time monitoring
- โ Status: Working with improvements
- ๐ Performance: 300+ RPS with 20 workers
- ๐ง Features: Multiple HTTP methods, connection pooling
- โ Status: Working with enhancements
- ๐ Performance: 15 workers with 5 HTTP methods
- ๐ง Features: Random user agents, multiple methods
- โ Status: Working excellently
- ๐ Performance: 547+ RPS sustained
- ๐ง Features: 3 parallel attack vectors, payload variation
- โ Status: Enhanced implementation with connection management
- ๐ Performance: 50 connections maintained with auto-reconnection
- ๐ง Features: TCP keep-alive, proper cleanup, context-based graceful shutdown
- ๐ Note: Improved with proper connection lifecycle management
// Context-based graceful shutdown
func startAttack(ctx context.Context) {
// All attack functions now accept context
// Proper cancellation propagation
}
// Shared HTTP client with connection pooling
var (
sharedTransport *http.Transport
sharedClient *http.Client
clientInitOnce sync.Once
)
// Improved SlowLoris with proper connection management
func slowLorisAttack(ctx context.Context) {
connections := make([]net.Conn, numConnections)
connectionMu := sync.Mutex{}
// Auto-reconnection, proper cleanup
}// Enhanced HTTP Transport configuration
transport := &http.Transport{
MaxIdleConns: 200, // Increased from 100
MaxIdleConnsPerHost: 200, // Increased from 100
MaxConnsPerHost: 500, // Connection limit per host
DisableCompression: true, // Reduce CPU usage
ForceAttemptHTTP2: false, // Use HTTP/1.1 for compatibility
IdleConnTimeout: 90 * time.Second,
DisableKeepAlives: !config.KeepAlive,
}// Three parallel attack vectors with context support
func multiVectorAttack(ctx context.Context) {
var wg sync.WaitGroup
// Vector 1: Standard HTTP flood
// Vector 2: POST data flood with payloads
// Vector 3: Header manipulation attacks
// All with proper context cancellation
wg.Wait()
}type Config struct {
// Basic options
Site, Data, AttackMode string
Duration time.Duration
RateLimit int
// Advanced features
ProxyRotation bool
MultiVector bool
StealthMode bool
AdaptiveRate bool
}- Connection Pooling: 50 concurrent connections
- Auto-reconnection: Automatic recovery from dropped connections
- Partial Headers: Sends incomplete HTTP headers to keep connections alive
- Random Patterns: Varies header content to avoid detection
- TCP Keep-Alive: Maintains stable connections
- Graceful Shutdown: Proper cleanup on context cancellation
- Worker Pool Architecture: Dynamic worker pool based on rate limit
- Method Variation: GET, POST, HEAD, PUT, DELETE
- User Agent Rotation: 5 modern browser signatures
- Connection Reuse: Optimized connection pooling
- Context Support: Proper cancellation handling
- Weighted Selection: Different attack methods with weights
- Dynamic Payloads: Various data formats (JSON, XML, form data)
- Header Manipulation: Custom headers for evasion
- Rate Variation: Different timing patterns
- Parallel Execution: 3 attack vectors running simultaneously
- Vector 1: Standard HTTP GET flood
- Vector 2: POST data flood with multiple payload types
- Vector 3: Header manipulation attacks
- Coordinated Timing: Synchronized attack patterns
- Proper Synchronization: WaitGroup for clean shutdown
- Enhanced Pooling: 200 idle connections per host
- Connection Limits: 500 max connections per host
- Compression Disabled: Reduces CPU overhead
- HTTP/1.1 Focus: Better compatibility and control
- Shared Client: Singleton pattern for efficiency
- Division by Zero Prevention: Safe calculations in stats
- Resource Cleanup: Proper body closing and connection management
- Context Cancellation: Graceful shutdown on interrupt
- Rate Limiting: Configurable per-second request limits
| Attack Mode | RPS | Success Rate | Duration | Status |
|---|---|---|---|---|
| Standard | 300+ | 100% | Configurable | โ Working |
| HTTP Flood | 300+ | 100% | Configurable | โ Working |
| Random | Variable | 100% | Configurable | โ Working |
| Multi-vector | 547+ | 100% | Configurable | โ Working |
| SlowLoris | Variable | 100% | Configurable | โ Enhanced |
- Memory: Efficient connection pooling reduces memory usage
- CPU: Disabled compression and optimized algorithms
- Network: Connection reuse and keep-alive optimization
- Threading: Goroutines for better concurrency
- Graceful Shutdown: Proper cleanup prevents resource leaks
- Advanced attack modes (Standard, HTTP Flood, Random, Multi-vector)
- Rate limiting and duration control
- Enhanced real-time monitoring
- Connection pooling optimization
- Multi-threading with goroutines
- Context-based graceful shutdown
- Improved SlowLoris connection management
- Error handling and safety improvements
- SlowLoris attack implementation
- Multi-vector attack system
- Advanced configuration options
- Proxy rotation system
- Advanced payload generation
- Distributed attack simulation
- Machine learning integration
- Advanced evasion techniques
- Web interface for monitoring
- Automated target analysis
This tool is ONLY for:
- Testing security of your own systems
- Research and education
- Legitimate penetration testing
- Load testing with authorization
DO NOT use for:
- Attacking other people's systems
- Illegal activities
- Disrupting public services
- Cybercrime
Unauthorized use of this tool is illegal and unethical. Users are solely responsible for their actions.
barracuda/
โโโ barracuda.go # Main BARRACUDA implementation
โโโ advanced_attacks.go # Advanced attack modes
โโโ go.mod # Go module definition
โโโ README.md # Complete documentation
โโโ LICENSE # GPLv3 License
โโโ barracuda # Compiled binary
- Proxy Support: Framework ready but not fully implemented
- Memory Management: Long-running attacks may need memory optimization
- Advanced Features: Some configuration options not yet fully integrated
- โ Enhanced SlowLoris: Better connection management and monitoring
- โ Graceful Shutdown: Context-based cancellation
- โ Resource Leaks Fixed: Proper cleanup and error handling
- โ Race Conditions: Improved synchronization
- โ Division by Zero: Safe calculations
BARRACUDA is licensed under GPLv3. See LICENSE file for details.
Original HULK utility by Barry Shteiman (http://sectorix.com)