无数据
订阅者
-324 小时
-197 天
-2430 天
帖子存档
1. Cybrary:
- Features: Cybrary offers a wide range of free and paid educational courses in the field of cybersecurity. These courses cover topics such as penetration testing, network analysis, security management, and encryption.
- Hands-On Training: Cybrary provides practical training that allows learners to apply the concepts they have learned through practical challenges and projects.
- Recognized Certifications: Some courses on Cybrary prepare learners to obtain recognized certifications in the field of cybersecurity.
2. Coursera:
- Features: Coursera offers high-quality courses in cybersecurity from recognized universities worldwide. These topics include cyber attacks, network security, and digital data analysis.
- Academic Delivery: Educational materials are delivered through video lectures, reading materials, and practical assignments to enhance understanding of concepts.
- Recognized Certifications: Learners on Coursera can earn recognized certifications from universities upon successful completion of the course.
3. Udemy:
- Features: Udemy offers a wide range of educational courses in cybersecurity at affordable prices. Topics range from penetration testing and security management to digital data analysis.
- Self-Paced Learning: The Udemy platform allows students to learn at their own pace according to their personal schedule.
- Practical Application: Some courses on Udemy include hands-on projects to apply the taught concepts in a real-world environment.
4. Hack The Box (HTB):
- Features: HTB is a website that provides an interactive learning environment for developing cybersecurity skills through challenges and community participation. It offers realistic challenges and vulnerable machines that allow participants to apply the concepts they have learned in a real-world environment.
- Diverse Challenges: HTB includes a variety of challenges covering hacking, network analysis, encryption, and other cybersecurity-related topics.
- Community and Interaction: HTB provides forums and communication channels for participants to interact and exchange knowledge and experiences, contributing to learning and skill development.
5. OverTheWire:
- Features: OverTheWire offers free training challenges focusing on various aspects of cybersecurity. These challenges include penetration testing, network analysis, and encryption, providing a safe environment for beginners to apply fundamental concepts.
- Progressive Advancement: OverTheWire provides progressive challenges that allow participants to gradually progress from basic to advanced levels in cybersecurity.
6. SANS Cyber Aces Online:
- Features: SANS Cyber Aces Online offers free educational materials and interactive challenges covering a variety of cybersecurity concepts. These courses include hacking attacks, network security, and security management.
- Sequential Progression: SANS Cyber Aces Online provides educational materials that help beginners understand the basics and gradually progress towards advanced concepts and techniques in cybersecurity.
7. SecurityTube:
- Features: SecurityTube offers a range of videos and educational courses in various cybersecurity domains, including malware analysis, network analysis, and penetration testing.
- Comprehensive Educational Materials: SecurityTube provides educational materials covering most aspects of cybersecurity, allowing participants to delve into topics they are interested in.
-----
1. Cybrary:
- الميزات: يقدم Cybrary مجموعة كبيرة من الدورات التعليمية المجانية والمدفوعة في مجال الأمن السيبراني. تشمل هذه الدورات مواضيع مثل اختبار الاختراق، وتحليل الشبكات، وإدارة الأمن، والتشفير.
- التدريب العملي: يوفر Cybrary تدريبًا عمليًا يسمح للمتعلمين بتطبيق المفاهيم التي تعلموها من خلال تحديات ومشاريع عملية.
- الشهادات المعترف بها: بعض الدورات في Cybrary تستعد المتعلمين لاجتياز شهادات معترف بها في مجال الأمن السيبراني.
2. انسخ مستودع Dumpzilla من GitHub باستخدام الأمر التالي:
git clone https://github.com/Busindre/Dumpzilla.git
3. انتقل إلى دليل Dumpzilla:
cd Dumpzilla
4. اجعل النص الرئيسي قابلًا للتنفيذ:
chmod +x dumpzilla.py
5. أنت الآن جاهز! يمكنك الآن تشغيل Dumpzilla عن طريق تنفيذ النص:
./dumpzilla.py
استخدام Dumpzilla على Termux:
نعم، يمكنك استخدام Dumpzilla على Termux، المحاكي المحمول للطرفية على نظام Android. إليك كيفية تنزيل Dumpzilla على Termux:
1. افتح تطبيق Termux على جهاز Android الخاص بك.
2. قم بتثبيت Git عن طريق تشغيل الأمر التالي:
pkg install git
3. انسخ مستودع Dumpzilla من GitHub:
git clone https://github.com/Busindre/Dumpzilla.git
4. انتقل إلى دليل Dumpzilla:
cd Dumpzilla
5. اجعل النص الرئيسي قابلًا للتنفيذ:
chmod +x dumpzilla.py
6. أنت الآن جاهز لاستخدام Dumpzilla! قم بتشغيل النص:
./dumpzilla.py
الختام:
إن Dumpzilla هي أداة لا غنى عنها للمحققين والمحللين الرقميين الذين يسعون لاستخراج وتحليل أدلة متصفح Firefox. بفضل واجهتها السهلة الاستخدام ووظائفها القوية، تُسهِّل Dumpzilla عملية استخراج المعلومات القيمة، مما يجعلها إضافة أساسية لأي مجموعة أدوات تحليل رقمي. سواء كنت تستخدم نظام Kali Linux أو Termux على جهاز Android الخاص بك، توفر Dumpzilla حلاً سلسًا وفعّالًا لتحليل متصفح Firefox.Introducing Dumpzilla
"A Powerful Forensic Tool"
Are you looking for a comprehensive forensic tool to extract valuable information from Firefox browser profiles? Look no further than Dumpzilla! Dumpzilla is a robust and versatile tool designed specifically for forensic analysis of Firefox browser artifacts. In this post, we'll delve into the features of Dumpzilla, its usage, and how to download it on a Kali Linux system using terminal commands.
What is Dumpzilla?
Dumpzilla is a Python-based forensic tool primarily used for extracting detailed information from Firefox browser profiles. It enables investigators to retrieve a wide range of data including browsing history, bookmarks, cookies, downloads, and much more from Firefox profiles.
How to Use Dumpzilla:
Using Dumpzilla is straightforward and efficient. Once installed, simply run the tool and provide the path to the Firefox profile directory you want to analyze. Dumpzilla will then parse through the profile and generate a comprehensive report containing all relevant information extracted from the browser artifacts.
Downloading Dumpzilla on Kali Linux:
To download Dumpzilla on Kali Linux, follow these steps:
1. Open a terminal window.
2. Clone the Dumpzilla repository from GitHub using the following command:
git clone https://github.com/Busindre/Dumpzilla.git
3. Navigate to the Dumpzilla directory:
cd Dumpzilla
4. Make the main script executable:
chmod +x dumpzilla.py
5. You're all set! Now you can run Dumpzilla by executing the script:
./dumpzilla.py
Using Dumpzilla on Termux:
Yes, you can use Dumpzilla on Termux, the terminal emulator for Android. Here's how to download Dumpzilla on Termux:
1. Open the Termux app on your Android device.
2. Install git by running:
pkg install git
3. Clone the Dumpzilla repository from GitHub:
git clone https://github.com/Busindre/Dumpzilla.git
4. Navigate to the Dumpzilla directory:
cd Dumpzilla
5. Make the main script executable:
chmod +x dumpzilla.py
6. You're ready to use Dumpzilla! Run the script:
./dumpzilla.py
Conclusion:
Dumpzilla is an indispensable tool for forensic investigators and analysts seeking to extract and analyze Firefox browser artifacts. With its user-friendly interface and powerful functionality, Dumpzilla streamlines the process of extracting valuable information, making it an essential addition to any forensic toolkit. Whether you're using Kali Linux or Termux on your Android device, Dumpzilla provides a seamless and efficient solution for Firefox browser analysis.
----BY : @xtawb -----
تعريف بأداة Dumpzilla
"أداة تحليل متقدمة للأدلة الرقمية"
هل تبحث عن أداة تحليل رقمية شاملة لاستخراج المعلومات القيمة من ملفات تعريف المتصفح Firefox؟ لا داعي للبحث بعيدًا، فإن Dumpzilla هي الأداة المثالية! إن Dumpzilla هي أداة قوية ومتعددة الاستخدامات مصممة خصيصًا لتحليل الأدلة الرقمية من متصفح Firefox. في هذا المنشور، سنتناول ميزات Dumpzilla، وطريقة استخدامها، وكيفية تنزيلها على نظام Kali Linux باستخدام أوامر الطرفية.
ما هو Dumpzilla؟
Dumpzilla هي أداة تحليل رقمية تعتمد على لغة Python يُستخدمها بشكل أساسي لاستخراج المعلومات التفصيلية من ملفات تعريف المتصفح Firefox. تُمكِّن هذه الأداة المحققين من استرجاع مجموعة واسعة من البيانات بما في ذلك سجل التصفح، والإشارات المرجعية، والكوكيز، والتنزيلات، والمزيد من ملفات تعريف Firefox.
كيفية استخدام Dumpzilla:
استخدام Dumpzilla بسيط وفعال. بمجرد تثبيتها، قم بتشغيل الأداة وقدم مسارًا إلى دليل ملفات تعريف Firefox الذي ترغب في تحليله. ستقوم Dumpzilla بمراجعة الملفات وإنشاء تقرير شامل يحتوي على جميع المعلومات ذات الصلة المستخرجة من أدلة المتصفح.
تنزيل Dumpzilla على Kali Linux:
لتنزيل Dumpzilla على نظام Kali Linux، اتبع الخطوات التالية:
1. افتح نافذة الطرفية.-- Whois tool
English:
About Whois Tool:
Whois tool is one of the essential network tools used to search for information about the owner of a specific domain on the internet. This tool can be used to retrieve information about domains such as owner ID, expiration date, and contact details.
How to Use Whois:
To use the Whois tool in Kali Linux, simply open a terminal and use the following command:
whois domain.com
Where "domain.com" represents the domain you want to search for information about.
Installation Guide:
The installation of the Whois tool comes pre-installed with the Kali Linux distribution. However, if you need to update it, you can use the following commands in the Kali Linux terminal:
sudo apt-get update
sudo apt-get install whois
Using Whois in Termux App:
For the Termux app on your phone, you can use the Whois tool in the same manner. You can install it using the following command:
pkg install whois
-----BY : @xtawb ------
-- Whois tool
Arabic:
تُعد أداة Whois أحد أدوات الشبكات الهامة التي تُستخدم للبحث عن معلومات المالك لنطاق معين على الإنترنت. يمكن استخدام هذه الأداة لاستعراض معلومات حول النطاقات مثل معرف المالك، تاريخ انتهاء الاشتراك، وبيانات الاتصال.
طريقة استخدام Whois:
لاستخدام أداة Whois في نظام Kali Linux، يمكنك ببساطة فتح ترمينال واستخدام الأمر التالي:
whois domain.com
حيث "domain.com" يمثل النطاق الذي ترغب في البحث عن معلوماته.
طريقة التحميل:
يأتي تثبيت أداة Whois مُضمنًا في توزيعة Kali Linux. ولكن إذا كنت بحاجة لتحديثها، يمكنك استخدام الأمر التالي في ترمينال Kali Linux:
sudo apt-get update
sudo apt-get install whois
استخدام Whois في تطبيق Termux:
بالنسبة لتطبيق Termux على الهاتف، يمكن استخدام أداة Whois بنفس الطريقة. يمكنك تثبيتها باستخدام الأمر التالي:
pkg install whois$Kismet Wireless$
"The Ultimate Tool for Wireless Network Monitoring"
$$$ Introduction:
Kismet Wireless is a powerful tool used for wireless network detection, packet sniffing, and network traffic analysis. Whether you're a security professional, a network administrator, or a curious enthusiast, Kismet provides comprehensive insights into nearby wireless networks.
$$$ مقدمة:
اداة Kismet Wireless هي أداة قوية تستخدم لاكتشاف الشبكات اللاسلكية واستقبال الحزم وتحليل حركة المرور على الشبكة. سواء كنت محترفًا في الأمان، أو مسؤول شبكة، أو هاوي فضولي، فإن Kismet توفر رؤى شاملة حول الشبكات اللاسلكية القريبة.
$$$ Features:
- Passive Monitoring: Kismet operates passively, meaning it doesn't generate any traffic, making it stealthy and ideal for monitoring without detection.
- Packet Sniffing: It captures data packets from wireless networks, allowing for detailed analysis of network traffic.
- Multiple Platform Support: Kismet is compatible with various platforms including Linux, macOS, and Windows, providing flexibility in usage.
- Real-time Updates: It continuously updates its database of detected networks, ensuring real-time monitoring and analysis.
$$$ الخصائص:
- الرصد السلبي: تعمل Kismet بشكل سلبي، مما يعني أنها لا تولد أي حركة مرور، مما يجعلها متسللة ومثالية للمراقبة دون اكتشاف.
- استقبال الحزم: يقوم بالتقاط حزم البيانات من الشبكات اللاسلكية، مما يتيح تحليلًا مفصلًا لحركة المرور على الشبكة.
- دعم عدة منصات: تتوافق Kismet مع مختلف المنصات بما في ذلك Linux وmacOS وWindows، مما يوفر مرونة في الاستخدام.
- تحديثات فورية: يقوم بتحديث قاعدة البيانات المستخدمة للشبكات المكتشفة بشكل مستمر، مما يضمن المراقبة والتحليل في الوقت الفعلي.
$$$ Installation on Kali Linux:
1. Open a terminal window.
2. Update your package lists:
sudo apt update
3. Install Kismet:
sudo apt install kismet
$$$ تثبيت على نظام كالي لينكس:
1. افتح نافذة الطرفية.
2. قم بتحديث قوائم الحزم:
sudo apt update
3. قم بتثبيت Kismet:
sudo apt install kismet
#### Usage:
1. Start Kismet by typing the following command in the terminal:
kismet
2. Configure Kismet by following the on-screen instructions.
3. Once configured, Kismet will start scanning for nearby wireless networks automatically.
$$$ الاستخدام:
1. ابدأ Kismet عن طريق كتابة الأمر التالي في الطرفية:
kismet
2. قم بتكوين Kismet باتباع التعليمات التي تظهر على الشاشة.
3. بمجرد التكوين، سيبدأ Kismet في البحث عن الشبكات اللاسلكية القريبة تلقائيًا.
$$$ Usage in Termux (Android):
Unfortunately, Kismet is not available for Termux directly. However, you can try alternative tools like Aircrack-ng for similar functionality.
$$$ الاستخدام في تيرمكس (أندرويد):
للأسف، لا تتوفر Kismet مباشرة لـ Termux. ومع ذلك، يمكنك محاولة أدوات بديلة مثل Aircrack-ng للحصول على وظائف مماثلة.
$$$ Conclusion:
Kismet Wireless is an indispensable tool for anyone involved in wireless network security or administration. Its wide range of features and ease of use make it a top choice for professionals and enthusiasts alike.
$$$ الختام:
Kismet Wireless هي أداة لا غنى عنها لأي شخص معني بأمان الشبكات اللاسلكية أو إدارتها. مجموعة ميزاتها الواسعة وسهولة استخدامها تجعلها خيارًا رائدًا للمحترفين والهواة على حد سواء.$$ الختام:
ميدوسا هي أداة قوية للفرق الأمنية لتقييم قوة كلمات المرور وتقييم أمان الأنظمة. على الرغم من تصميمها الأساسي لـ Kali Linux، يمكن باستخدام بعض الجهد استخدامها أيضًا على Termux لأغراض اختبار الأمان على الهواتف المحمولة.
ˣᵗᵃʷᵇ$ "Medusa"
"A Powerful Password Cracking Tool"
ˣᵗᵃʷᵇ$ Introduction:
Medusa is a versatile and robust password cracking tool used by security professionals and ethical hackers for testing the strength of passwords and assessing the security of systems. It supports various protocols including FTP, SSH, Telnet, HTTP, HTTPS, SMB, and more.
ˣᵗᵃʷᵇ$ Features:
- Multi-Protocol Support: Medusa supports a wide range of protocols for password authentication.
- Parallel Processing: It utilizes parallel processing to speed up the cracking process.
- Flexible and Configurable: Users can configure and customize attack options according to their needs.
- Modular Design: Its modular design allows for easy integration of new protocols and functionalities.
ˣᵗᵃʷᵇ$ Usage:
1. Installation:
- Medusa can be installed on Kali Linux using the following command:
sudo apt-get install medusa
2. Basic Syntax:
- The basic syntax to use Medusa is:
medusa -h [target] -U [username file] -P [password file] -M [protocol]
3. Example:
- To perform a brute-force attack on SSH with a list of usernames and passwords:
medusa -h [target] -U [usernames.txt] -P [passwords.txt] -M ssh
ˣᵗᵃʷᵇ$ Can it be used on Termux?
Unfortunately, Medusa is not available in the default Termux repositories. However, it is possible to compile and install it manually on Termux, although this process might be challenging due to dependencies and compatibility issues.
ˣᵗᵃʷᵇ$ Installation on Termux (if feasible):
1. Install necessary dependencies:
pkg install clang make openssl-dev
2. Download Medusa source code:
git clone https://github.com/jmk-foofus/medusa.git
3. Compile and install:
cd medusa
./configure
make
make install
ˣᵗᵃʷᵇ$Conclusion:
Medusa is a powerful tool for security professionals to assess the strength of passwords and evaluate the security posture of systems. While primarily designed for Kali Linux, with some effort, it can also be used on Termux for mobile security testing purposes.
-----------BY : @xtawb -----------
$$ "ميدوسا"
"أداة قوية لكسر كلمات المرور"
$$ المقدمة:
ميدوسا هي أداة قوية ومتعددة الاستخدامات تستخدمها الفرق الأمنية والهاكرز الأخلاقيين لاختبار قوة كلمات المرور وتقييم أمان الأنظمة. تدعم ميدوسا مجموعة متنوعة من البروتوكولات بما في ذلك FTP و SSH و Telnet و HTTP و HTTPS و SMB وغيرها.
$$ الميزات:
- دعم متعدد البروتوكولات: تدعم ميدوسا مجموعة واسعة من البروتوكولات لمصادقة كلمات المرور.
- معالجة متوازية: يستخدم ميدوسا معالجة متوازية لتسريع عملية كسر كلمات المرور.
- مرنة وقابلة للتكوين: يمكن للمستخدمين تكوين وتخصيص خيارات الهجوم حسب احتياجاتهم.
- تصميم موديولار: يسمح التصميم الموديولار بتكامل سهل لبروتوكولات ووظائف جديدة.
$$ الاستخدام:
1. التثبيت:
- يمكن تثبيت ميدوسا على Kali Linux باستخدام الأمر التالي:
sudo apt-get install medusa
2. الصيغة الأساسية:
- الصيغة الأساسية لاستخدام ميدوسا هي:
medusa -h [الهدف] -U [ملف الاسماء] -P [ملف كلمات المرور] -M [البروتوكول]
3. مثال:
- لتنفيذ هجوم بروتوكول SSH مع قائمة من اسماء المستخدمين وكلمات المرور:
medusa -h [الهدف] -U [usernames.txt] -P [passwords.txt] -M ssh
$$ هل يمكن استخدامه على Termux؟
للأسف، ميدوسا غير متوفر في مستودعات Termux الافتراضية. ومع ذلك، من الممكن تركيبه يدويًا على Termux، على الرغم من أن هذه العملية قد تكون تحديًا بسبب التبعيات ومشكلات التوافق.
$$ التثبيت على Termux (إذا كان ذلك ممكنًا):
1. تثبيت التبعيات الضرورية:
pkg install clang make openssl-dev
2. تنزيل مصدر كود ميدوسا:
git clone https://github.com/jmk-foofus/medusa.git
3. تجميع وتثبيت:
cd medusa
./configure
make
make installEnglish:
1. CAESAR CIPHER: It's a type of simple encryption where letters are shifted by a certain number in the alphabet. For example, with a shift of 3, the letter A becomes D, B becomes E, and so on.
2. KEYSTROKE LOGGER: It's a software or device that records keystrokes on a keyboard without the user's knowledge, often used in hacking to steal sensitive information like passwords.
3. HASH FUNCTION: A function that converts text data into a fixed-length string of numbers or characters. It's used in various applications such as securely storing passwords.
4. PACKET SNIFFING: The process of intercepting and analyzing data packets passing through a computer network, used to understand and monitor data traffic.
5. SQL INJECTION: A type of attack where attackers exploit vulnerabilities in database applications to inject malicious SQL commands to access or manipulate data.
6. IMAGE ENCRYPTION: The process of encrypting an image so that it cannot be understood or accessed except by a specific person or using a secret key.
7. CREDIT CARD FRAUD DETECTION: The use of modern techniques, such as artificial intelligence, to detect and prevent fraud using credit cards.
8. CAPTCHA IMAGES: Images containing unreadable text or codes that users must identify to verify that they are human and not bots.
9. INTERNET BORDER PATROL: Refers to a set of policies and technologies used to monitor and control data flow across national internet borders, which can be used for national security purposes or communication regulation.
----
Arabic :
1. CAESAR CIPHER: هو نوع من أنواع التشفير البسيطة تستخدم فيها تحويل الحروف بواسطة تحريكها بعدد معين في الأبجدية. على سبيل المثال، إذا كان الإزاحة هي 3، يتم تحويل الحرف A إلى D، والحرف B إلى E، وهكذا.
2. KEYSTROKE LOGGER: هو برنامج أو جهاز يسجل الضغطات على لوحة المفاتيح دون معرفة المستخدم، ويستخدم غالباً في الاختراق لسرقة معلومات حساسة مثل كلمات المرور.
3. HASH FUNCTION: وظيفة تقوم بتحويل البيانات النصية إلى سلسلة من الأرقام أو الحروف بطول ثابت. تستخدم في العديد من التطبيقات مثل تخزين كلمات المرور بشكل آمن.
4. PACKET SNIFFING: هو عملية استرجاع وتحليل حزم البيانات (باكيتات) التي تمر عبر شبكة الإنترنت، ويمكن استخدامها لفهم ومراقبة حركة البيانات.
5. SQL INJECTION: هو نوع من أنواع الاختراق يستخدم فيه المهاجمون ثغرات في تطبيقات قواعد البيانات لحقن أوامر SQL ضارة للوصول إلى المعلومات أو تدميرها.
6. IMAGE ENCRYPTION: هو عملية تشفير الصورة بحيث لا يمكن فهمها أو الوصول إليها إلا بواسطة شخص معين أو بواسطة مفتاح سري.
7. CREDIT CARD FRAUD DETECTION: هو عملية استخدام التقنيات الحديثة مثل الذكاء الاصطناعي لاكتشاف ومنع الاحتيال باستخدام بطاقات الائتمان.
8. CAPTCHA IMAGES: هي صور تحتوي على نص أو رموز غير مقروءة يجب على المستخدمين تحديدها للتحقق من أنهم بشر وليسوا برامج أو بوتات.
9. INTERNET BORDER PATROL: تشير إلى مجموعة من السياسات والتقنيات المستخدمة لمراقبة وتحكم في حركة البيانات عبر الحدود الإنترنتية للدولة، ويمكن استخدامها لأغراض الأمن القومي أو تنظيم الاتصالات.
1. Download and Install SigPloit Tool:
- You can download the SigPloit tool from GitHub or use the following commands:
git clone https://web.archive.org/web/20201203032412/https://github.com/SigPloiter/SigPloit
cd SigPloit
sudo pip2 install -r requirements.txt
python sigsloit.py
2. Select SS7 Module and Configure Options:
- Choose the SS7 module and configure the required options such as server IP address, port, and target phone number.
3. Capture and Analyze Packets:
- Capture packets using a tool like Wireshark to eavesdrop on text messages and phone calls.
4. Gather Information Using HackRF one Device:
- The HackRF one device is used to analyze radio waves and is essential for executing SS7 attacks.
$$-- Targeting Specific Applications:
- WhatsApp Hacking:
- SS7 vulnerability attacks target popular applications like WhatsApp, which rely on phone number verification.
- SS7 vulnerabilities are exploited to obtain verification codes and thus steal WhatsApp accounts.
- Targeting Other Applications:
- Many other applications like Facebook and Telegram also rely on phone number verification, making them susceptible to SS7 attacks.
By using tools like SigPloit and HackRF one, attackers can exploit SS7 vulnerabilities to gain unauthorized access to social media accounts and other applications that rely on phone number verification.