xtawb
Ir al canal en Telegram
Sin datos
Suscriptores
-324 horas
-197 días
-2430 días
Archivo de publicaciones
اللغة العربية:
تُعد أدوات الـ Phishing أدوات شائعة ومُستخدمة بكثرة في عمليات الاحتيال الإلكتروني. تهدف هذه الأدوات إلى استخدام تقنيات تصيد الهوية والاستيلاء على معلومات شخصية حساسة من ضحاياها. ومن بين هذه الأدوات المعروفة تأتي أداة AdvPhishing.
تُعد AdvPhishing أداة قوية وشاملة تتيح للمستخدمين إنشاء صفحات Phishing ذات مظهر احترافي بطريقة سهلة وسريعة. تعتمد هذه الأداة على تقنيات الهندسة الاجتماعية لإغراء الضحايا وجعلهم يدخلون معلوماتهم الشخصية الحساسة مثل كلمات المرور وبيانات الدخول في صفحات تمثل شركات أو منصات شهيرة.
توفر AdvPhishing مجموعة واسعة من القوالب الجاهزة لمختلف الشركات والمنصات الشهيرة مثل Facebook وInstagram وTwitter وGoogle وغيرها. يُمكن للمستخدمين تخصيص هذه القوالب وتعديلها وفقًا لاحتياجاتهم الخاصة، مما يجعل الصفحات الوهمية التي ينشئونها تبدو وكأنها أصلية وموثوق بها.
توفر AdvPhishing أيضًا مجموعة من الميزات الإضافية مثل إرسال رسائل الصيد الاجتماعي عبر البريد الإلكتروني والرسائل القصيرة (SMS)، والتقاط صور للضحايا عندما يدخلون بياناتهم الشخصية في الصفحات الوهمية. تساعد هذه الميزات المستخدمين على تحسين فعالية أدواتهم وزيادة نجاح عمليات الـ Phishing التي يقومون بها.
مع ذلك، يجب أن نذكر أن استخدام أدوات الـ Phishing لأغراض غير قانونية أو غير أخلاقية يعتبر جريمة. يجب على الأشخاص الذين يستخدمون هذه الأدوات أن يلتزموا بالقوانين والأعراف الأخلاقية وأن يحترموا خصوصية الآخرين.
اللغة الإنجليزية:
Phishing tools are commonly used in online fraud operations. These tools aim to deceive individuals and capture their sensitive personal information through identity theft techniques. Among these well-known tools is AdvPhishing.
AdvPhishing is a powerful and comprehensive tool that allows users to create professional-looking phishing pages quickly and easily. This tool relies on social engineering techniques to lure victims into entering their sensitive personal information, such as passwords and login credentials, on pages that mimic well-known companies or platforms.
AdvPhishing offers a wide range of ready-made templates for various popular companiesand platforms, such as Facebook, Instagram, Twitter, Google, and more. Users can customize and modify these templates according to their specific needs, making the phishing pages they create appear authentic and trustworthy.
AdvPhishing also provides additional features such as sending social engineering messages via email and SMS, as well as capturing images of victims when they enter their personal information on the phishing pages. These features help users enhance the effectiveness of their tools and increase the success of their phishing operations.
However, it is important to note that using phishing tools for illegal or unethical purposes is a crime. Individuals who use these tools should adhere to laws and ethical practices and respect the privacy of others.
آعتذر إذا تأخرت في الشرح أو الرد على رسائلكم... والسبب هو أن لدي مشكلة في هاتفي وحاسوبي المحمول، وأحاول قدر الإمكان أن أشرح وأنشر وأرد على جميع الرسائل.
شكرًا لكم
I am sorry if I am late in explaining or responding to your messages... The reason is that I have a problem with my phone and laptop, and I am trying as much as possible to explain, publish, and respond to all messages.
Thank you.
اللغة العربية:
في عالم الأمن السيبراني، تعتبر Kali Linux من أكثر توزيعات لينكس شعبية واستخدامًا. وتشتهر Kali Linux بتوفيرها لمجموعة واسعة من الأدوات والبرامج المتخصصة في اختبار الاختراق وتقييم الأمان. واحدة من هذه الأدوات المهمة هي أداة Mercury.
تم تطوير أداة Mercury كأداة ضمن مشروع Kali Linux لتوفير طرق فعالة لاختبار وتقييم أمان التطبيقات والشبكات. تعتبر Mercury أداة متعددة الاستخدامات وقوية، حيث توفر مجموعة واسعة من الوظائف التي تمكن المحترفين في مجال الأمان من تنفيذ اختبارات الاختراق وتحليل الثغرات بسهولة وفعالية.
تعتمد أداة Mercury على تقنيات الاختبار الآلي والاختبار اليدوي لتحديد الثغرات والضعف في التطبيقات والشبكات. توفر الأداة واجهة سهلة الاستخدام تسمح للمستخدمين بتنفيذ اختبارات الاختراق الأساسية مثل الاختبارات المتكاملة للقرصنة والاختبارات للثغرات الشائعة في النظام والتطبيقات. بالإضافة إلى ذلك، تقدم Mercury قدرات تحليل الشبكات واختبار القرصنة واكتشاف الثغرات وتقييم الأمان.
توفر أداة Mercury أيضًا ميزات متقدمة مثل التحليل الثنائي الديناميكي والتحليل الثلاثي الديناميكي، مما يسمح للمستخدمين بفحص التطبيقات والنظم والشبكات للكشف عن ثغرات أمان محتملة. تتيح هذه الميزات القوية للمستخدمين تنفيذ اختبارات الاختراق الشاملة وتحليل الضعف بشكل شامل ودقيق.
باختصار، فإن أداة Mercury على Kali Linux تعد أداة قوية ومتعددة الاستخدامات لاختبار الاختراق وتقييم الأمان. توفر الأداة واجهة سهلة الاستخدام ومجموعة واسعة من الميزات المتقدمة، مما يجعلها خيارًا مثاليًا للمحترفين في مجال الأمان السيبراني الذين يرغبون في تنفيذ اختبارات الاختراق وتحليل الثغرات بكفاءة وسهولة.
اللغة الإنجليزية:
In theworld of cybersecurity, Kali Linux is one of the most popular and widely used Linux distributions. It is known for providing a wide range of tools and specialized software for penetration testing and security assessment. One of these important tools is Mercury.
Mercury was developed as part of the Kali Linux project to provide effective methods for testing and evaluating the security of applications and networks. Mercury is a versatile and powerful tool that offers a wide range of functionalities, enabling security professionals to easily and efficiently perform penetration tests and vulnerability analysis.
Mercury relies on both automated and manual testing techniques to identify vulnerabilities and weaknesses in applications and networks. The tool provides a user-friendly interface that allows users to perform core penetration tests, such as comprehensive penetration tests, system vulnerabilities, and common application vulnerabilities. Additionally, Mercury offers network analysis capabilities, penetration testing, vulnerability discovery, and security assessment.
Mercury also provides advanced features such as dynamic binary analysis and dynamic symbolic execution, allowing users to examine applications, systems, and networks to uncover potential security vulnerabilities. These powerful features enable users to conduct comprehensive penetration tests and thorough vulnerability analysis.
In summary, Mercury on Kali Linux is a powerful and versatile tool for penetration testing and security assessment. It offers a user-friendly interface and a wide range of advanced features, making it an ideal choice for cybersecurity professionals who want to efficiently and easily perform penetration tests and vulnerability
(الاجابه على اول تعليق)
العربية:
"Offline Attack" هو نوع من الهجمات التي تستهدف كشف كلمات المرور أو تحليل البيانات دون الحاجة إلى الاتصال بالإنترنت. تُستخدم هذه الهجمات عادة لكسر كلمات المرور أو فك تشفير البيانات المحمية في بيئة غير متصلة بالشبكة.
على سبيل المثال، يمكن استخدام تقنيات مثل "Brute Force" أو "Dictionary Attacks" لاختراق كلمات المرور أو تشفير الملفات بمجرد الحصول على وصول مادي إلى الأجهزة أو البيانات. من خلال استخدام أدوات مخصصة وتقنيات التشفير وفهم هياكل البيانات، يمكن للمهاجمين تحليل البيانات والكشف عن الثغرات بدون الحاجة للاتصال بالشبكة.
يُعد Kali Linux وسيلة فعالة لتنفيذ "Offline Attacks" واختبار الأمان في هذا السياق. باستخدام الأدوات المدمجة في Kali Linux ومجموعة متنوعة من تقنيات الهجوم والدفاع، يمكن للمستخدمين تقييم النقاط الضعيفة وتعزيز الأمان لمنع هذا النوع من الهجمات.
(Answer to the first comment)
English:
"Offline Attack" is a type of attack that aims to crack passwords or analyze data without the need for an internet connection. These attacks are typically used to break passwords or decrypt protected data in an offline, disconnected environment.
For instance, techniques like "Brute Force" or "Dictionary Attacks" can be employed to breach passwords or file encryption once physical access to devices or data is obtained. By using specialized tools, encryption techniques, and understanding data structures, attackers can analyze data and uncover vulnerabilities without the need for network connectivity.
Kali Linux serves as an effective means to execute "Offline Attacks" and test security in this context. Using the built-in tools in Kali Linux and a variety of attack and defense techniques, users can assess weak points and enhance security to prevent this type of attack.
بالعربية:
Ngrok هي أداة رائعة تستخدم لإنشاء تونيل آمن يمكن الوصول إليه عبر الإنترنت إلى الخوادم المحلية. تُستخدم هذه الأداة بكثرة في تطوير واختبار تطبيقات الويب أو في مشاريع الـ "hackathon". من خلال تقديم اتصال عبر الإنترنت للخوادم المحلية، يُمكن للمطورين والمبرمجين الوصول إلى تطبيقاتهم أو مواقعهم المحلية من أي مكان في العالم.
يقوم Ngrok بتوفير عنوان URL عشوائي يتيح الوصول إلى الخادم المحلي، مما يتيح للمستخدمين فحص واختبار تطبيقاتهم قبل نشرها علنًا. كما أنه يتيح الدخول الآمن والمشفر للمواقع أو التطبيقات المحلية بطريقة تجعلها غير متاحة للجمهور العام.
باستخدامه في Kali Linux، يمكن للمستخدمين تثبيت Ngrok بسهولة واستخدامها في بيئة نظام التشغيل هذه. باستخدام سطر الأوامر، يُمكنك تنزيل وتثبيت Ngrok، ومن ثم استخدام الأوامر المناسبة لبدء الاتصال بخوادمك المحلية.
باستخدام هذه التقنية، يمكن للمستخدمين اختبار تطبيقاتهم على الإنترنت أو مشاركتها مع فريق العمل بسهولة، مما يجعل Ngrok أداة قيمة للمطورين والمبرمجين الذين يسعون لتبسيط عملية اختبار التطبيقات والوصول إليها عن بُعد.
In English:
Ngrok is a fantastic tool used to create a secure, internet-accessible tunnel to local servers. This tool is frequently employed in web application development and hackathon projects. By providing online access to local servers, developers and programmers can reach their local applications or websites from anywhere in the world.
Ngrok provides a random URL address to access the local server, allowing users to inspect and test their applications before publicly deploying them. It also enables secure, encrypted access to local sites or applications in a way that keeps them unavailable to the general public.
When used in Kali Linux, users can easily install Ngrok and utilize it within this operating system environment. Using the command line, you can download and install Ngrok, then use appropriate commands to initiate connections to your local servers.
Through this technology, users can test their applications online or share them with their team effortlessly, making Ngrok a valuable tool for developers and programmers seeking to streamline the process of testing and remote access to applications.
اللغة العربية:
Burp Suite هي أداة قوية مُصممة لاختبار الأمان واكتشاف الثغرات في تطبيقات الويب. تُستخدم على نطاق واسع في مجال الأمان السيبراني وتُعتبر أحد أفضل الأدوات لاختبار الاختراق.
تعتبر Kali Linux بيئة مثالية لتشغيل Burp Suite بفضل توفيرها لمجموعة واسعة من الأدوات والبرامج المتخصصة في الاختبارات والاختراق. يُمكنك تثبيت Burp Suite على Kali Linux بسهولة واستخدامها لاكتشاف الثغرات وتحليل البيانات المرسلة والمستقبلة بين المستعرض والخادم.
ميزات Burp Suite تتضمن القدرة على تسجيل وتحليل حركة البيانات، وتقديم تقارير شاملة حول الثغرات، وتعديل الطلبات والاستجابات لفحص الضعف، مما يساعد في تقييم أمان التطبيقات وحمايتها من الهجمات الإلكترونية.
English Language:
Burp Suite is a powerful tool designed for security testing and vulnerability assessment in web applications. Widely used in the cybersecurity domain, it is considered one of the best tools for penetration testing.
Kali Linux provides an ideal environment to run Burp Suite due to its wide array of tools and software specialized in testing and penetration. Installing Burp Suite on Kali Linux is straightforward, allowing users to detect vulnerabilities and analyze data sent between the browser and the server.
Burp Suite features include the ability to record and analyze data traffic, provide comprehensive reports on vulnerabilities, and modify requests and responses for vulnerability assessment, aiding in evaluating the security of applications and shielding them from cyber attacks.
APT-Hunter - أداة صيد التهديدات لسجلات أحداث Windows التي تم إنشاؤها بواسطة فريق Purple Team Mindset لتوفير كشف حركات APT المخفية في بحر سجلات أحداث Windows لتقليل الوقت اللازم للكشف عن الأنشطة المشبوهة
APT-Hunter - Threat Hunting Tool For Windows Event Logs Which Made By Purple Team Mindset To Provide Detect APT Movements Hidden In The Sea Of Windows Event Logs To Decrease The Time To Uncover Suspicious Activity
SniffAir هو إطار عمل أمني لاسلكي مفتوح المصدر يوفر القدرة على تحليل البيانات اللاسلكية المجمعة بشكل سلبي بسهولة
SniffAir is an open-source wireless security framework which provides the ability to easily parse passively collected wireless data as
بالعربية:
في هذا المنشور، سنتحدث عن كيفية استخدام الهاكر أداة Metasploit وأداة Ngrok معًا على نظام Kali Linux. تعتبر Metasploit أحد أشهر الأدوات في مجال اختبار الاختراق واستغلال الثغرات. يمكن للهاكر استخدام Metasploit لاكتشاف الثغرات في الأنظمة وتنفيذ هجمات على الأجهزة.
أما بالنسبة لأداة Ngrok، فهي تستخدم لإنشاء اتصال آمن من الخارج إلى الداخل عبر الإنترنت. تُستخدم Ngrok لإعادة توجيه حركة المرور من الإنترنت إلى الأنظمة المستهدفة داخل الشبكة.
عند جمع هاتين الأداة معًا على نظام Kali Linux، يمكن للهاكر استخدام Metasploit لاختراق الأنظمة المستهدفة ومن ثم استخدام Ngrok لتوجيه الاتصالات من الضحية إلى الهاكر بطريقة مجهولة. هذا يسمح للهاكر بالتلاعب بأنظمة الضحايا دون أن يتم اكتشافه بسهولة.
بالإنجليزية:
In this post, we will discuss how hackers use the Metasploit tool and Ngrok together on a Kali Linux system. Metasploit is one of the most well-known tools in the field of penetration testing and vulnerability exploitation. Hackers can use Metasploit to discover vulnerabilities in systems and execute attacks on devices.
As for the Ngrok tool, it is used to create a secure connection from the outside to the inside via the internet. Ngrok is used to redirect internet traffic to target systems within the network.
When these two tools are combined on a Kali Linux system, hackers can use Metasploit to breach the targeted systems and then employ Ngrok to route communications from the victim to the hacker in an anonymous manner. This allows the hacker to manipulate the victim's systems without being easily detected.
بالعربية:
في هذا المنشور، سنستعرض أداة LAZY وكيفية استخدامها على نظام Kali Linux. LAZY هي أداة تستخدم في مجال اختبار الاختراق وأمن المعلومات وتوفر مجموعة من الوظائف والأدوات المتقدمة للباحثين وأخصائيي الأمان.
LAZY تم تطويرها باستخدام لغة Python وهي جزء من مجموعة أدوات Kali Linux التي تُستخدم في اختبار الأمان وتقييم الثغرات. تعمل LAZY على تسهيل العمليات المختلفة مثل الاستغلال واختبار الثغرات الأمنية وفحص الشبكات.
من ميزات LAZY البارزة هي واجهة المستخدم البسيطة التي تسهل على المستخدمين تنفيذ الأوامر والاختبارات بفعالية. توفر LAZY مجموعة متنوعة من الأوامر لفحص الشبكات، واكتشاف الأجهزة المتصلة، واستغلال الثغرات الأمنية.
بالإضافة إلى ذلك، يمكن لمستخدمي LAZY إنشاء تقارير مفصلة حول نتائج الاختبارات والاستغلال، مما يسهل توثيق الاكتشافات ومشاركتها مع فرق الأمان والزملاء.
بالإنجليزية:
In this post, we will introduce the LAZY tool and how it can be used on the Kali Linux operating system. LAZY is a tool used in the field of penetration testing and information security, providing a range of advanced functions and tools for researchers and security professionals.
LAZY is developed using the Python language and is part of the Kali Linux toolset used in security testing and vulnerability assessment. LAZY simplifies various operations such as exploitation, security vulnerability testing, and network scanning.
One of the standout features of LAZY is its user-friendly interface that makes it easy for users to efficiently execute commands and tests. LAZY provides a variety of commands for network scanning, device discovery, and security vulnerability exploitation.
Furthermore, LAZY allows users to generate detailed reports on test results and exploitation, making it easy to document findings and share them with security teams and colleagues.
بالعربية:
في هذا المنشور، سنستعرض أداة "th3inspeckor" وكيف يمكن استخدامها على نظام Kali Linux. تُعد "th3inspeckor" أداة قوية ومتعددة الاستخدامات في مجال الأمن السيبراني واختبار الاختراق.
"th3inspeckor" هي أداة مفتوحة المصدر تم تطويرها بلغة Python. تمكن المحترفين في مجال أمن المعلومات من تنفيذ العديد من الأوامر والوظائف المفيدة لاختبار الأمان وتقييم الثغرات. تتضمن مزاياها القدرة على فحص الشبكات واكتشاف الأجهزة المتصلة، والبحث عن الثغرات الأمنية المحتملة.
يوفر "th3inspeckor" واجهة مستخدم بسيطة وسهلة الاستخدام، مما يجعلها مناسبة للمبتدئين والخبراء على حد سواء. يمكن استخدامها لإجراء اختبارات الاختراق ومراقبة أمان الشبكة وتحليل العروض المرورية.
ميزة أخرى مهمة لـ "th3inspeckor" هي قدرتها على توليد تقارير مفصلة حول الاختبارات والنتائج، مما يسهل على المستخدمين توثيق ما تم اكتشافه ومشاركته مع الزملاء والفرق الأمنية.
بالإنجليزية:
In this post, we will explore the "th3inspeckor" tool and how it can be used on the Kali Linux operating system. "th3inspeckor" is a powerful and versatile tool in the field of cybersecurity and penetration testing.
"th3inspeckor" is an open-source tool developed in Python. It enables information security professionals to execute various commands and functions for security testing and vulnerability assessment. Its features include the ability to scan networks, discover connected devices, and search for potential security vulnerabilities.
"th3inspeckor" provides a simple and user-friendly interface, making it suitable for both beginners and experts. It can be used to conduct penetration tests, monitor network security, and analyze network traffic.
Another important feature of "th3inspeckor" is its ability to generate detailed reports about tests and results, making it easy for users to document their findings and share them with colleagues and security teams.
