⫷⫷ 𝙉𝙤𝙤B 𝘿𝙚𝙫𝙡𝙤𝙥𝙚𝙧 ⫸⫸
Closed channel
1 393
Subscribers
No data24 hours
No data7 days
-930 days
Data loading in progress...
Attracting Subscribers
April '25
April '25
+144
in 7 channels
March '250
in 0 channels
Get PRO
February '250
in 0 channels
Get PRO
January '250
in 0 channels
Get PRO
December '240
in 0 channels
Get PRO
November '24
+3
in 0 channels
Get PRO
October '24
+3
in 0 channels
Get PRO
September '24
+422
in 13 channels
Get PRO
August '24
+1 575
in 31 channels
Get PRO
July '24
+1 877
in 9 channels
| Date | Subscriber Growth | Mentions | Channels | |
| 10 April | +4 | |||
| 09 April | +10 | |||
| 08 April | +10 | |||
| 07 April | +20 |
Channel Posts
- UNIX Variant: Linux
- Linux kernel version: 2.6.10
- Distribution: Mandrake ("mdk")
- Architecture: Intel 686
😈 لما الموضوع يقلب خطر: SNMP وكتابة الإعدادات!
كل المعلومات اللي بتطلع من SNMP مفيدة جدا للمهاجم، بس اللي أخطر من كده بكتير هو لو الجهاز بيشتغل بـ write community string افتراضي زي:
private
في الحالة دي، الهاكر مش بس هيشوف المعلومات... ده يقدر يغير في إعدادات الجهاز نفسه 😳
يعني مثلا ممكن يوقف خدمة، يغير إعداد أمني، أو حتى يعمل نوع من أنواع Denial of Service!
💥 SNMP و أجهزة الشبكة
لو جهاز زي Cisco أو غيره كان بيشتغل بـ SNMP، ومعاه write community string معروف، المهاجم يقدر يسحب منه الإعدادات، وده يفتحله باب لمعرفة الباسوردات، أو حتى يشن هجوم brute-force لو الحماية أقوى.
لكن دلوقتي بدل الأدوات القديمة، بنستخدم حاجات أقوى بكتير زي:
- الـ Metasploit SNMP modules: تقدر من خلالها تعمل استكشاف، وتسريب معلومات، واستغلال لأي Misconfiguration على SNMP.
- الـ Nmap + NSE Scripts: عندك سكربتات زي snmp-info, snmp-interfaces, snmp-brute، بتديك كل حاجة عن الجهاز من غير ما تكتب سطرين.
مثال سريع:
nmap -sU -p 161 --script=snmp-info <target>
🔍 أدوات سكان لـ SNMP
🪟 على Windows و Linux:
استخدم الأدوات دي:
اداة Nmap - فحص شامل للبورتات و SNMP Enumeration باستخدام الـ NSE
اداة snmpwalk / snmpget - جمع معلومات محددة أو كاملة من الـ MIB
اداة SNMP-Check - أداة بتلخصلك كل بيانات SNMP بشكل منظم وسهل القراءة
اداة CrackMapExec - لو بتفحص بيئة Active Directory، يقدر يدمج SNMP مع باقي أدوات التقييم
🛡 طرق الحماية والمضادات من استكشاف SNMPدلوقتي بقى خلينا نرجع للطرف التاني من القصة… إزاي تحمي نفسك من اللي شرحناه فوق 👀 ❌ أبسط حل؟ امسح SNMP من على الأجهزة (عجبك الحل اكيد 😂) لو انت مش محتاج SNMP فعلا، اقفله وخلاص. كده تكون ضربت العصفور بالحجر من غير ما تتعب. 🔒 مش هتقدر تقفله؟ يبقى لازم تأمنه لو لازم تستخدم SNMP لأي سبب إداري، فـ: - ابعد عن الباسوردات التقليدية زي public و private 😐 - حط Community Strings صعبة التخمين، وغيرها كل فترة. - اقفل البورتات 161/UDP و 161/TCP على الفايروول بتاع الشبكة، خصوصا عند الـ perimeter devices (اللي بتحمي حدود الشبكة). 🎯 قصر الوصول لـ SNMP مثال: SNMP Agent في Windows تقدر تخليه يرد بس على أجهزة معينة (IP addresses محددة)، زي أجهزة الإدارة بس. 🔐 استخدم SNMP Version 3 الـ SNMP v3 هو الإصدار اللي فعلا يستاهل يتقال عليه آمن، لأنه بيوفر: - تشفير قوي 🔐 - توثيق حقيقي ✅ - وبيمنع التنصت أو التلاعب في الداتا ✋ 🧬 لو بتشتغل على Windows NT Family في خطوات كمان تقدر تعملها لحماية SNMP من خلال الـ Registry: 1. افتح regedt32 وروح على:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SNMP\Parameters\ValidCommunitiesوبعد كده غير صلاحيات الدخول (Permissions) علشان تقصرها على اليوزرات اللي انت مأمنهم بس. 2. بعد كده، روح على:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SNMP\Parameters\ExtensionAgents
- احذف أي قيمة فيها LANManagerMIB2Agent
- رتب القيم اللي بعدها من أول وجديد (يعني لو حذفت الرقم 1، خليه يبدأ من 1 لحد العدد الحالي من غير فراغات في الترتيب).
📌 خلاصة:
- الـ SNMP ممكن يبقى سلاح قاتل في إيد الهاكرز لو فضل شغال بإعداداته الافتراضية.
- امسحه أو أأمنه كويس.
- ولو عايز تقرأ أكتر؟ دور على RFCs الخاصة بـ SNMP على موقع: rfc-editor.org| 2 | 🛰 استكشاف SNMP - UDP 161 🔍
بص يا سيدي، بروتوكول SNMP (أو Simple Network Management Protocol) اتعمل علشان يراقب ويدير الشبكات ، يعني يديك معلومات مفصلة عن الأجهزة اللي شغالة 💻، والبرامج، والسيستمات نفسها. وبسبب كمية المعلومات اللي بيكشفها، هو هدف مغري جدا لأي حد ناوي يخترق الشبكة 💥.
بس المصيبة إنه مافيهوش حماية قوية 🛡، لدرجة إن بعض الناس بتسميه "Security Not My Problem" على سبيل التريقة 😅
البيانات في SNMP بتتحمي بحاجة بسيطة جدا… مجرد "باسورد" 🔑. بس للأسف في باسوردات كتير جدا مشهورة ومعروفة بتتستخدم بشكل افتراضي في إعداداته 🤦♂️. أشهرهم هو الباسورد بتاع القراءة بس، أو اللي بنسميه "read community string"، واللي غالبا بيكون ببساطة:
public 📣
الهاكرز أول حاجة بيجربوها لما يلاقوا البورت 161 مفتوح 🚪، إنهم يجربوا الباسورد ده، أو حتى يستخدموا أدوات تحليل ترافيك زي Wireshark 🧪 علشان يلقطوا الباسورد ده من الشبكة 🧲.
اللي أسوأ من كده؟ 🥺 إن كل شركة بتضيف حاجات خاصة بيها على SNMP، الحاجات دي بنسميها MIBs (Management Information Bases)، ودي عبارة عن قواعد بيانات بتوضح معلومات إضافية عن الأجهزة 🗃📈.
يعني مثلا، مايكروسوفت عندها MIB فيها أسامي يوزرات الويندوز 🧑💼. فحتى لو انت مأمن بورتات زي 139 أو 445 🔐، ممكن تلاقي جهاز شغال SNMP وبيفضح نفس المعلومات دي بسبب إنه لسه بيشتغل بالإعدادات الافتراضية (آه، يعني الباسورد: public تاني 😐).
🧾 طيب نجيب الكلام من الآخر...
لو عايز تعدي على يوزرات الويندوز اللي على جهاز بيشغل SNMP 🕵️، تقدر تعمل كده بسهولة جدا باستخدام أداة زي snmpwalk 🛠، والأمر هيكون شبه كده:
snmpwalk -v2c -c public 192.168.202.33 1.3.6.1.4.1.77.1.2.25
هتلاقي الرد جايبلك يوزرات زي:
Value = Guest
Value = Administrator
الرقم الطويل في الآخر ده اسمه OID (Object Identifier) 🧬، وده بيمثل الفرع بتاع الـ MIB اللي فيه بيانات معينة 🌲. كل ما تطلع لفوق في الـ OID (يعني تستخدم رقم أقل تحديدا)، كل ما تطلعلك معلومات أكتر وأكتر 📤📚.
🔎 طب إزاي نكتشف الـ OIDs كلها؟ 🤔
لو مش عارف تبدأ منين، أو عايز تستكشف الشجرة كلها وتشوف إيه الـ OIDs اللي الجهاز بيعرضها، يبقى تعمل حاجة اسمها SNMP Walk 🎯
ودي ببساطة بتخليك تمشي على كل فروع الشجرة وتشوف كل البيانات المتاحة.
🧪 الأمر الأساسي:
snmpwalk -v2c -c public 192.168.1.100
🔹 كده انت بتقوله: "هاتلي كل اللي عندك من أول الشجرة لحد آخرها" 🌳
ولو عايز تبدأ من نقطة معينة:
snmpwalk -v2c -c public 192.168.1.100 1.3.6.1.2.1
وده يجيبلك معلومات عن الجهاز (الـ system info).
📌 بعض الـ OIDs المشهورة:
معلومات عن الجهاز - 1.3.6.1.2.1.1
كروت الشبكة (interfaces) - 1.3.6.1.2.1.2
TCP info - 1.3.6.1.2.1.6
يوزرات الويندوز (M$ only) - 1.3.6.1.4.1.77.1.2.25
🔠 بدل ما تحفظ أرقام الـ OID... استخدم النصوص البسيطة!
افتكر أرقام بالشكل ده: 1.3.6.1.4.1.77.1.2.25؟ 🤯
أكيد لا! عشان كده، الهاكرز دايما بيفضلوا يستخدموا التمثيل النصي بدل الأرقام، ودي أمثلة لبعض أجزاء الـ MIB اللي بتحتوي على معلومات مهمة:
SNMP MIB (Append this to .iso.org.dod.internet.private.enterprises.lanmanager.lanmgr2)
.server.svSvcTable.svSvcEntry.svSvcName Running services
.server.svShareTable.svShareEntry.svShareName Share names
.server.svShareTable.svShareEntry.svSharePath Share paths
.server.svShareTable.svShareEntry.svShareComment Comments on shares
.server.svUserTable.svUserEntry.svUserName Usernames
.domain.domPrimaryDomain Domain name
🔧 أدوات تانية ممكن تستخدمها:
لو شغال على UNIX أو Linux، ممكن تستخدم أداة snmpget من ضمن مجموعة أدوات net-snmp:
[root] # snmpget –c public –v 2c 192.168.1.60 system.sysName.0
الرد هيكون مثل:
system.sysName.0 = wave
بس بالرغم من إن snmpget مفيد، فهو بيرجع قيمة واحدة بس كل مرة. لكن لو عايز تلم كل البيانات مرة واحدة وبسرعة ⚡️، يبقى snmpwalk (برضو بتنزل علي لينكس) هو سلاحك المفضل:
[root]# snmpwalk –c public –v 2c 192.168.1.60
ممكن تشوف رد زي:
system.sysDescr.0 = Linux wave 2.6.10 mdk #1 Sun Apr 15 2008 i686
system.sysObjectID.0 = OID: enterprises.ucdavis.ucdSnmpAgent.linux
system.sysUpTime.0 = Timeticks: (25701) 0:04:17.01
system.sysContact.0 = Root <root@localhost> (configure /etc/snmp/snmp.conf)
system.sysName.0 = wave
system.sysLocation.0 = Unknown (configure /etc/snmp/snmp.conf)
system.sysORLastChange.0 = Timeticks: (0)
[output truncated for brevity]
🎯 وشوف قد إيه المعلومات اللي رجعت: | 1 |
| 3 | Now that we know everything you said, how do we protect the API from being hacked?
Do you have to protect the API, Mustafa?
Ion and very necessary as well.. Ok, how?
Of course, the first thing we will use is API Keys to restrict access.
We will activate OAuth 2.0 for authentication.
We will encrypt data via HTTPS protocol.
It is necessary to set Rate Limits to prevent attacks that could cause damage to the API.
It is very important and necessary to verify the users' permissions in each request.
For your information, there are very, very, very heavy companies that do not know this and they suffer from disasters due to a lack of sufficient awareness of protection.
Ok, are there any tools that can let me test the API myself easily?
In Postman it is used to test and explore the API.
In RapidAPI, you can search for free APIs.
Insomnia is an alternative to Postman for API testing.
Ok, what if you want to try a real API?
We have several things
Like OpenWeather API to retrieve weather data
And in Twitter API to publish tweets automatically
And of course, the ChatGPT API to add ChatGPT to the program
And that's it, we're done
I hope to God that I was successful in explaining
If anything is not clear, let me know.
Don't forget our brothers in Palestine in your prayers 🙏🏼 ❤️
May God grant you all the best, God willing ❤️ | 1 |
| 4 | May the peace, blessings, and mercy of God be upon you
God willing, today we will talk together about something that is indispensable in our field, especially if you are a programmer, which is the API . God willing, we will explain together almost everything about it and say what it is, how it works, what we use it for, what its types are, what its protocols are, how we protect our API, and if we want to try it, where and how we should try it.
First of all, what is API?
Listen, dear, API is short for Application Programming Interface.
Simply put, the API is the translator that allows systems and programs to understand each other.
I feel like you're lost and don't understand, or you haven't arrived yet, right?
Okay, look, sir
Imagine that you entered a restaurant, called the waiter, gave him your order, and then he took it to the kitchen and brought you back the food.
Here we have to say that
You = the program
Kitchen = Server
Waiter = API
It's almost clear now
To summarize what I told you, dear, the API takes your request, which is the Request, and transfers it to the server, and then returns to you the result, which is the Response.
Ok, how does the API work?
As we said, the API has a Request and a Response.
Let's explain them together in an easier way.
First, the program sends a request to the server.
The server processes the request and sends a response in the format required by the program.
Most requests are made over HTTP and the results are in JSON or XML format
What does that mean?
For example, this means an API request to access user data
GET https://api.example.com/users/123
The response that will bring us back will be as follows:
{
user(id: "123") {
Name: Mohammed
Email: mo@gmail.com
}
}
This way the application can display data without storing it internally.
Ok, where is the API located or what do we use it for?
I don't know how to bring it to you, but the API is everywhere without you noticing.
How, Uncle Mustafa? Come on, let's see together.
For example, when you request an Uber while you are going to your fiancée’s house and you don’t ask me why you are going to your fiancée’s house, you will find the application connecting to the Maps API + Payment API + Drivers API in Uber
I forgot that you are not engaged and a miserable single. I am sorry. I will tell you the same thing again.
When you log in with your Google account to a website, it is done through the Google Authentication API.
For example, if you want to buy something online, the site pulls shipping and payment data via the payment API.
The last example we have is that even Facebook, for example, uses an API for every like, comment, or share you make.
And add to that everything
What are the types of API?
Do they have different types, Mustafa?
Yes, engineer, there are types of them, and they are not all the same. There are different types depending on the use.
How?
We will say them together now
1- Open API
This type is open to the public.
Like Google Maps and OpenWeather (which brings weather data that we have never opened and found to be correct)
2- Private API
This type is private within the company.
For example, they create an API for banks to access customer data.
3- Partner API
This type is common among specific entities.
For example, such as PayPal or Apple Pay payment API, etc.
4- Composite API
This type combines several APIs into one request.
For example, a single request brings user data and requests at the same time.
What are the API protocols?
1- REST API (this is the most used protocol)
This depends on HTTP.
It uses GET, POST, PUT, and DELETE
2- SOAP API (this is old and heavy)
This depends on XML.
So that one can tell the truth as well
This is safer but more complicated.
3- GraphQL API (latest and smooth)
This allows you to request only the data you need.
4- WebSockets API (for real-time updates)
We use it in chat programs such as WhatsApp, Messenger, and online games. | 1 |
| 5 | +8 🔖SEC530: Defensible Security Architecture and Engineering
Part-1 | 32 |
| 6 | Join our backup Chanel
https://t.me/+f7YSMNPMArQxYTI1 | 50 |
| 7 | +1 By: @darkcsc | 46 |
| 8 | https://zerotomastery.io/courses/introduction-to-web3/ | 43 |
| 9 | Web3.0.pdf | 37 |
| 10 | Mastering Web 3 en.pdf | 37 |
| 11 | 💻𝗘𝗫𝗧𝗥𝗘𝗠𝗘 𝗗𝗔𝗡𝗚𝗘𝗥 𝗗𝗜𝗦𝗖𝗟𝗔𝗜𝗠𝗘𝗥 💻
📌 𝗪𝗔𝗥𝗡𝗜𝗡𝗚: 𝗧𝗛𝗜𝗦 𝗜𝗦 𝗡𝗢𝗧 𝗔 𝗚𝗔𝗠𝗘📌
This channel contains information related to 𝗘𝗧𝗛𝗜𝗖𝗔𝗟 𝗛𝗔𝗖𝗞𝗜𝗡𝗚 & 𝗖𝗬𝗕𝗘𝗥𝗦𝗘𝗖𝗨𝗥𝗜𝗧𝗬 for 𝗘𝗗𝗨𝗖𝗔𝗧𝗜𝗢𝗡𝗔𝗟 𝗣𝗨𝗥𝗣𝗢𝗦𝗘𝗦 𝗢𝗡𝗟𝗬.
⚠️ 𝗨𝗡𝗔𝗨𝗧𝗛𝗢𝗥𝗜𝗭𝗘𝗗 𝗨𝗦𝗘 = 𝗖𝗬𝗕𝗘𝗥 𝗖𝗥𝗜𝗠𝗘 ⚠️
If you use this knowledge to:
❌ Hack systems without permission
❌ Steal, leak, or damage data
❌ Violate any law, privacy, or security
Then remember this:
⛔ 𝗬𝗢𝗨 𝗔𝗥𝗘 𝗢𝗡 𝗔 𝗗𝗔𝗥𝗞 𝗣𝗔𝗧𝗛 ⛔
☠️ 𝗚𝗢𝗩𝗘𝗥𝗡𝗠𝗘𝗡𝗧 𝗖𝗬𝗕𝗘𝗥 𝗟𝗔𝗪𝗦 𝗪𝗜𝗟𝗟 𝗛𝗨𝗡𝗧 𝗬𝗢𝗨 ☠️
𝗙𝗜𝗡𝗘𝗦
𝗝𝗔𝗜𝗟
𝗣𝗘𝗥𝗠𝗔𝗡𝗘𝗡𝗧 𝗕𝗔𝗡𝗦
𝗗𝗘𝗦𝗧𝗥𝗢𝗬𝗘𝗗 𝗙𝗨𝗧𝗨𝗥𝗘
𝗪𝗘 𝗔𝗥𝗘 𝗡𝗢𝗧 𝗥𝗘𝗦𝗣𝗢𝗡𝗦𝗜𝗕𝗟𝗘 𝗙𝗢𝗥 𝗔𝗡𝗬 𝗠𝗜𝗦𝗨𝗦𝗘.
If you ignore this warning—𝗬𝗢𝗨 𝗔𝗟𝗢𝗡𝗘 𝗪𝗜𝗟𝗟 𝗙𝗔𝗖𝗘 𝗧𝗛𝗘 𝗖𝗢𝗡𝗦𝗘𝗤𝗨𝗘𝗡𝗖𝗘𝗦.
⚠️ 𝗧𝗛𝗜𝗡𝗞 𝗧𝗪𝗜𝗖𝗘 𝗕𝗘𝗙𝗢𝗥𝗘 𝗔𝗖𝗧𝗜𝗡𝗚 ⚠️
– 𝗢𝗪𝗡𝗘𝗥 | 50 |
| 12 | 22. 00x10 Fully simulated pentest.zip | 60 |
| 13 | 21. 00x09 Pentesting checklists.zip | 59 |
| 14 | 20. 008 The OWASP top 10's.zip | 61 |
| 15 | 19. 007. Vulnerability scanners & tools.zip | 61 |
| 16 | 18. 006. Methodologies.zip | 59 |
| 17 | 17. 005 Web exploits part 2.zip | 56 |
| 18 | 16. 00x04 Web app exploits.zip | 51 |
| 19 | 15. 004.3 CSRF.zip | 50 |
| 20 | 14. 004.2 burp suite.zip | 51 |
