en
Feedback
xtawb

xtawb

Open in Telegram

🚩 Channel was restricted by Telegram

Show more
No data
Subscribers
-324 hours
-197 days
-2430 days
Posts Archive
>> 8
>> 8

>> 6
>> 6

>> 5
>> 5

>> 4
>> 4

>> 3
>> 3

>> 2
>> 2

>> 1
>> 1

🔍 اليوم سأبدأ سلسلة "أدوات Bug Bounty" مع فئة مهمة: Subdomain Enumeration! في هذه الحلقة الأولى، سأشارك معكم أفضل الأدوات والتقنيات لاكتشاف النطاقات الفرعية، وهي خطوة أساسية في عمليات الـ Bug Bounty. تعلموا كيفية استخدام هذه الأدوات لتحسين فرص اكتشاف الثغرات وتعزيز أمان تطبيقاتكم. ترقبوا المزيد من التحديثات والأدوات! 💻 --- 🔍 Today I'm starting the "Bug Bounty Tools" series with an important category: Subdomain Enumeration! In this first episode, I'll share the best tools and techniques for discovering subdomains, a crucial step in Bug Bounty operations. Learn how to use these tools to enhance your chances of finding vulnerabilities and securing your applications. Stay tuned for more updates and tools! 💻✨

بداية سأبدأ سلسلة جديدة على صفحتي بعنوان "أدوات Bug Bounty"! في هذه السلسلة، سأشارك معكم أدوات وتقنيات مفيدة لمطوري البرامج ومختبري الأمان في مجال الـ Bug Bounty. ترقبوا المزيد من المعرفة والموارد المفيدة لمساعدتكم في رحلتكم لاكتشاف الثغرات وتحسين أمان تطبيقاتكم! Starting today, I will begin a new series on my page titled "Bug Bounty Tools"! In this series, I'll be sharing useful tools and techniques for developers and security testers in the Bug Bounty field. Stay tuned for more knowledge and valuable resources to help you in your journey to discover vulnerabilities and enhance the security of your applications!

- XXEinjector        "Tool for XML External Entity Injection"  XXEinjector is a powerful tool used for exploiting XML External Entity (XXE) vulnerabilities in web applications. XXE vulnerabilities occur when an application parses XML input from an untrusted source and allows the inclusion of external entities. This can lead to sensitive information disclosure, server-side request forgery (SSRF), and other security risks. ˣᵗᵃʷᵇ$$ Features: - Exploitation: XXEinjector automates the process of exploiting XXE vulnerabilities by generating payloads and sending them to the target server. - Payloads: It supports various types of payloads, including file read/write operations, SSRF, and remote code execution. - Customization: Users can customize payloads and tailor them to the specific target environment. ˣᵗᵃʷᵇ$$ Usage: 1. Installation: XXEinjector can be installed on Kali Linux using the following commands:    
   git clone https://github.com/enjoiz/XXEinjector.git
   cd XXEinjector
   chmod +x XXEinjector.rb
   
2. Running: After installation, run the tool with:    
   ruby XXEinjector.rb
   
3. Exploitation: Follow the prompts to specify the target URL, the type of payload, and other necessary information. ˣᵗᵃʷᵇ$$ Downloading on Termux: Unfortunately, XXEinjector is not directly available for Termux. However, you can manually download and run it by following these steps: 1. Installation:    
   pkg install git ruby
   git clone https://github.com/enjoiz/XXEinjector.git
   cd XXEinjector
   chmod +x XXEinjector.rb
   
2. Running:    
   ruby XXEinjector.rb
   
ˣᵗᵃʷᵇ$$ Can it be used in Termux? Yes, XXEinjector can be used in Termux on Android devices, but it requires Ruby and Git to be installed. ˣᵗᵃʷᵇ$$ Usage in Termux: You can follow the same installation and usage instructions as on Kali Linux.                ----------//------------ - XXEinjector         "أداة لاختراق ثغرات XML External Entity"  XXEinjector هي أداة قوية تستخدم لاستغلال ثغرات XML External Entity (XXE) في تطبيقات الويب. تحدث ثغرات XXE عندما يقوم التطبيق بتحليل مدخلات XML من مصدر غير موثوق به ويسمح بتضمين كيانات خارجية. يمكن أن يؤدي ذلك إلى كشف معلومات حساسة وتزوير طلبات على الخادم (SSRF) ومخاطر أمنية أخرى. $$ الميزات: - استغلال: تقوم XXEinjector بتأتيمن عملية استغلال ثغرات XXE عن طريق إنشاء أحمال وإرسالها إلى خادم الهدف. - الأحمال: تدعم أنواع مختلفة من الأحمال ، بما في ذلك عمليات قراءة/كتابة الملفات و SSRF وتنفيذ الأوامر عن بعد. - التخصيص: يمكن للمستخدمين تخصيص الأحمال وضبطها لبيئة الهدف المحددة. $$ الاستخدام: 1. التثبيت: يمكن تثبيت XXEinjector على Kali Linux باستخدام الأوامر التالية:    
   git clone https://github.com/enjoiz/XXEinjector.git
   cd XXEinjector
   chmod +x XXEinjector.rb
   
2. التشغيل: بعد التثبيت ، قم بتشغيل الأداة باستخدام:    
   ruby XXEinjector.rb
   
3. الاستغلال: اتبع الإرشادات لتحديد عنوان URL الهدف ونوع الحمولة وغيرها من المعلومات الضرورية. $$ التنزيل على تيرمكس: للأسف ، لا يتوفر XXEinjector مباشرة لـ Termux. ومع ذلك ، يمكنك تنزيله وتشغيله يدويًا عن طريق اتباع هذه الخطوات: 1. التثبيت:    
   pkg install git ruby
   git clone https://github.com/enjoiz/XXEinjector.git
   cd XXEinjector
   chmod +x XXEinjector.rb
   
2. التشغيل:    
   ruby XXEinjector.rb
   
#### هل يمكن استخدامها في تيرمكس؟ نعم ، يمكن استخدام XXEinjector في Termux على أجهزة Android ، ولكن يتطلب ذلك تثبيت Ruby و Git.

photo content

photo content

photo content

photo content

- CRLF Injection "The Invisible Threat" - Introduction: CRLF Injection attacks represent a hidden threat that websites and online applications may face. The vulnerability lies in the ability to inject command sequences and control the server's behavior, ultimately leading to attacks that compromise the website or steal user data. In the case of a CRLF Injection vulnerability, attackers can input unauthorized control into the text sent to the server. Typically used in HTTP messages, attackers can use CRLF sequences (Carriage Return and Line Feed) to insert unwanted commands such as changing the request header or even inserting malicious content. The main issue lies in the attacker's ability to shape the response returned from the server, opening the door to various attacks such as redirection, forwarding, and spoofing. - Usage: - Tools like Burp Suite or OWASP ZAP can be used to discover and exploit CRLF Injection vulnerabilities. - They can be used to manipulate HTTP request headers to execute various attacks. ˣᵗᵃʷᵇ$$ Tool Installation: CRLF Injection tools can be downloaded using the package manager in Kali Linux, for example:
sudo apt-get update
sudo apt-get install crlf-injection-tool
ˣᵗᵃʷᵇ$$ Can it be used in Termux on a phone? Yes, CRLF Injection tools can be used in the Termux application on a smartphone. - Tool Installation on Termux: - CRLF Injection tools can be downloaded on Termux using the following command:
pkg update
pkg install crlf-injection-tool
------------ - CRLF Injection "هجمات CRLF Injection" - مقدمة: تعتبر هجمات CRLF Injection واحدة من التهديدات الخفية التي قد تواجه المواقع والتطبيقات على الإنترنت. تكمن الثغرة في القدرة على حقن تسلسلات الأوامر والتحكم في سلوك الخادم، مما يؤدي في النهاية إلى هجمات تعرض الموقع للخطر أو سرقة بيانات المستخدمين. في حالة ثغرة CRLF Injection، يمكن للمهاجمين إدخال تحكم غير مصرح به في النص المرسل إلى الخادم. عادةً ما تُستخدم في رسائل HTTP، حيث يمكن للمهاجم استخدام تسلسلات CRLF (Carriage Return و Line Feed) لإدخال أوامر غير مرغوب فيها مثل تغيير رأس الطلب أو حتى إدراج محتوى ضار. المشكلة الرئيسية تكمن في قدرة المهاجم على تشكيل الرد الذي يتم إرجاعه من الخادم، مما يفتح الباب أمام العديد من الهجمات مثل التوجيه والتحويل والاحتيال. - طريقة الاستخدام: - يمكن استخدام أدوات مثل Burp Suite أو OWASP ZAP لاكتشاف واستغلال ثغرات CRLF Injection. - يمكن استخدامها لتلاعب في رؤوس طلبات HTTP لتنفيذ هجمات مختلفة. - تثبيت الأداة: يمكن تحميل أدوات CRLF Injection باستخدام مدير الحزم في نظام Kali Linux، على سبيل المثال:
sudo apt-get update
sudo apt-get install crlf-injection-tool
$$ هل يمكن استخدامها في تطبيق Termux على الهاتف؟ نعم، يمكن استخدام أدوات CRLF Injection في تطبيق Termux على الهاتف الذكي. - تثبيت الأداة على Termux: - يمكن تحميل أدوات CRLF Injection على Termux باستخدام الأمر التالي:
pkg update
pkg install crlf-injection-tool

photo content

- OSSEC "An Overview" OSSEC is an open-source tool for intrusion detection, log management, and security analysis of various operating systems. OSSEC monitors system events and analyzes system logs to detect attack patterns and security threats, helping to protect systems and networks from intrusions. ˣᵗᵃʷᵇ$$ Features: - Intrusion detection and security threat detection. - Log management and analysis. - Immediate alerts for unwanted events. - Monitoring attack patterns and security threats. ˣᵗᵃʷᵇ$$ How to Use: OSSEC can be downloaded on Kali Linux using the following commands:
wget -q -O - https://updates.atomicorp.com/installers/atomic | bash
yum install ossec-hids -y
ˣᵗᵃʷᵇ$$ Compatibility: OSSEC can be used on the Termux app on Android smartphones, but the user needs to install it from third-party sources. --- $$ OSSEC "نظرة عامة" OSSEC هي أداة مفتوحة المصدر للكشف عن الاختراقات وإدارة السجلات والتحليل الأمني لأنظمة التشغيل المختلفة. تقوم OSSEC برصد أحداث النظام وتحليل سجلات النظام للكشف عن أنماط الهجمات والتهديدات الأمنية، مما يساعد في حماية الأنظمة والشبكات من الاختراقات. $$ الميزات: - كشف الاختراقات والهجمات الأمنية. - إدارة وتحليل سجلات النظام. - تنبيهات فورية عن الأحداث غير المرغوب فيها. - رصد أنماط الهجمات والتهديدات الأمنية. $$ كيفية الاستخدام: يمكن تحميل OSSEC على نظام Kali Linux باستخدام الأوامر التالية:
wget -q -O - https://updates.atomicorp.com/installers/atomic | bash
yum install ossec-hids -y
$$ التوافق: يمكن استخدام OSSEC على تطبيق Termux على الهواتف الذكية التي تعمل بنظام Android، ولكن يحتاج المستخدم إلى تثبيتها من مصادر ثالثة.

photo content

- PHPSploit "An Overview" PHPSploit is a powerful tool in the realm of hacking and vulnerability testing. It is used to test vulnerabilities in web applications that are PHP-based. PHPSploit provides an easy-to-use interface and advanced features for system penetration and full control over PHP-hosted servers. ˣᵗᵃʷᵇ$$ Features: - Efficient: More than 20 plugins to automate privilege-escalation tasks. - Run commands and browse filesystem, bypassing PHP security restrictions. - Upload/Download files between client and target. - Edit remote files through local text editor. - Run SQL console on target system. - Spawn reverse TCP shells. - Stealth: The framework is made by paranoids, for paranoids. - Nearly invisible by log analysis and NIDS signature detection. - Safe-mode and common PHP security restrictions bypass. - Communications are hidden in HTTP Headers. - Loaded payloads are obfuscated to bypass NIDS. - HTTP/HTTPS/SOCKS4/SOCKS5 Proxy support. - Convenient: A robust interface with many crucial features. - Detailed help for any option (help command). - Cross-platform on both client and server. - CLI supports auto-completion & multi-command. - Session saving/loading feature & persistent history. - Multi-request support for large payloads (such as uploads). - Provides a powerful, highly configurable settings engine. - Each setting, such as user-agent, has a polymorphic mode. - Customizable environment variables for plugin interaction. - Provides a complete plugin development API. ˣᵗᵃʷᵇ$$ How to Use: PHPSploit can be downloaded on Kali Linux using the following commands:
git clone https://github.com/nil0x42/phpsploit.git
cd phpsploit
./phpsploit
ˣᵗᵃʷᵇ$$ Compatibility: PHPSploit can be used on the Termux app on Android smartphones, but the user must first install the PHP and Git environment. PHPSploit can be downloaded in the same way as described above on Termux. ------- - PHPSploit "نظرة عامة" تُعتبر أداة PHPSploit أداة قوية في مجال الاختراق واختبار الضعف. تستخدم هذه الأداة لاختبار الثغرات في تطبيقات الويب التي تعتمد على لغة PHP. توفر PHPSploit واجهة سهلة الاستخدام وميزات متقدمة لاختراق النظام والتحكم الكامل بالخوادم المستضيفة PHP. $$ المميزات: - فعالية: أكثر من 20 إضافة لتتميز بمهام تصعيد الامتياز تلقائيًا. - تشغيل الأوامر وتصفح نظام الملفات، متجاوزًا قيود أمان PHP. - تحميل/تنزيل الملفات بين العميل والهدف. - تحرير الملفات عن بُعد من خلال محرر النص المحلي. - تشغيل وحدة التحكم SQL على نظام الهدف. - إنشاء قذائف TCP عكسية. - خفية: تم تصميم الإطار من قبل المُتزمين بالأمان، لصالح المُتزمين بالأمان. - تكاد تكون غير مرئية من خلال تحليل السجلات واكتشاف توقيعات NIDS. - تجاوز وضع الأمان الآمن وقيود أمان PHP الشائعة. - يتم إخفاء الاتصالات في رؤوس HTTP. - يتم تشفير الحمولات المحملة لتجاوز اكتشافات NIDS. - دعم بروكسي HTTP/HTTPS/SOCKS4/SOCKS5. - مريحة: واجهة قوية مع العديد من الميزات الحاسمة. - توفير مساعدة مفصلة لأي خيار (أمر المساعدة). - متوافق مع مختلف الأنظمة على الجهاز والخادم. - توفير الإكمال التلقائي والأوامر المتعددة في واجهة سطر الأوامر. - ميزة حفظ/تحميل الجلسات وتاريخ الاستخدام الدائم. - دعم الطلبات المتعددة للحمولات الكبيرة (مثل التحميلات). - يوفر محرك إعدادات قوي وقابل للتكوين بشكل كبير. - كل إعداد، مثل وكيل المستخدم، لديه وضع متعدد الأشكال. - متغيرات البيئة قابلة للتخصيص لتفاعل الإضافات. $$ كيفية الاستخدام: يمكن تحميل PHPSploit على نظام Kali Linux باستخدام الأوامر التالية:
git clone https://github.com/nil0x42/phpsploit.git
cd phpsploit
./phpsploit
$$ التوافق: يمكن استخدام PHPSploit على تطبيق Termux على الهواتف الذكية التي تعمل بنظام Android، ولكن يجب على المستخدم أولاً تثبيت بيئة PHP و Git. يمكن تحميل PHPSploit بنفس الطريقة السابقة على Termux.

photo content