fa
Feedback
xtawb

xtawb

رفتن به کانال در Telegram

🚩 Channel was restricted by Telegram

نمایش بیشتر
اطلاعاتی وجود ندارد
مشترکین
-324 ساعت
-197 روز
-2430 روز
آرشیو پست ها
Arabic : shimit هي أداة بيثون تنفذ هجوم Golden SAML. يتيح لك shimit إنشاء كائن SAMLResponse موقّع واستخدامه لفتح جلسة في مزود الخدمة. يدعم shimit الآن وحدة تحكم AWS كمقدم خدمة، وهناك المزيد قيد العمل... لتثبيت الوحدات المطلوبة ، قم بتشغيل الأمر التالي:
python -m pip install boto3 botocore defusedxml enum python_dateutil lxml signxml
لتطبيق الجلسة لـ AWS cli ، قم بتشغيل الأمر التالي:
python .\\shimit.py -idp http://adfs.lab.local/adfs/services/trust -pk key_file -c cert_file -u domain\\admin -n admin@domain.com -r ADFS-admin -r ADFS-monitor -id 123456789012
لتحميل shimit على termux ، قم بتشغيل الأوامر التالية:
pkg install git
pkg install python
git clone https://github.com/cyberark/shimit.git
cd shimit
chmod +x *
يمكنك الآن استخدام shimit على هاتفك باستخدام نفس الأوامر المذكورة أعلاه. English : shimit is a python tool that implements the Golden SAML attack. shimit allows you to create a signed SAMLResponse object, and use it to open a session in the Service Provider. shimit now supports AWS Console as a Service Provider, more are in the works... To install the required modules, run the following command:
python -m pip install boto3 botocore defusedxml enum python_dateutil lxml signxml
To apply the session for AWS cli, run the following command:
python .\\shimit.py -idp http://adfs.lab.local/adfs/services/trust -pk key_file -c cert_file -u domain\\admin -n admin@domain.com -r ADFS-admin -r ADFS-monitor -id 123456789012
To download shimit on termux, run the following commands:
pkg install git
pkg install python
git clone https://github.com/cyberark/shimit.git
cd shimit
chmod +x *
You can now use shimit on your phone using the same commands mentioned above.

photo content

photo content

- Internal Applications: - English : These attacks can be used to test internal security for companies. ### فوائد هجمات القوة الخامة: ### Benefits of raw force attacks: - اختبار الأمان: - اللغة العربية: يُستخدم هجوم القوة الخامة كأداة لاختبار قوة أنظمة الأمان. - Security Test: - English: Brute Force Attacks are used as a tool to test the strength of security systems. - استعادة كلمات المرور: - اللغة العربية: في بعض الحالات، تستخدم هذه الهجمات لاستعادة كلمات المرور المفقودة. - Recover Passwords: - English: In some cases, these attacks are used to recover lost passwords. - تقويم سياسات الأمان: - اللغة العربية: يساعد تحليل هجمات القوة الخامة على تحديد نقاط الضعف في سياسات الأمان. - Security Policy Calendar: - English: Analyzing Brute Force Attacks helps identify weaknesses in security policies.

### هجمات القوة الخامة وفوائدها ### Brute Force Attack and its benefits --- #### اللغة العربية: تُعَدُّ هجمات القوة الخامة من بين أخطر وسائل الاختراق، حيث تُمَكِّن المهاجمين من استخدام القوة بشكل كامل لتخمين أو اكتشاف كلمات المرور تلقائيًا. سنلقي نظرة على أنواع مختلفة من هجمات القوة الخامة: 1. هجوم القوة الخامة البسيط (Simple Brute Force Attack): يعتمد على تجربة جميع التركيبات الممكنة لكلمة المرور حتى يتم العثور على الصحيحة. 2. هجوم القوة الخامة باستخدام القاموس (Dictionary Attack): يستخدم قائمة معينة من الكلمات المحتملة من قاموس لتخمين كلمة المرور. 3. هجوم القوة الخامة العكسي (Reverse Brute Force Attack): يستهدف اكتشاف اسم المستخدم أو الحساب بناءً على كلمة المرور المعروفة. 4. هجوم القوة الخامة الهجين (Hybrid Brute Force Attack): يجمع بين تقنيات هجوم القوة الخامة البسيط واستخدام القاموس لتحسين كفاءة الهجوم. 5. هجوم تجاوز المصادقة (Credential Stuffing Attack): يتمثل في استخدام أسماء مستخدمين وكلمات مرور سرية مسروقة للوصول إلى حسابات أخرى. #### English : Brute Force Attacks are among the most dangerous methods of unauthorized access to information systems. These attacks allow attackers to systematically guess or discover passwords automatically. Let's take a detailed look at several types of Brute Force Attacks: 1. Simple Brute Force Attack: Relies on trying all possible combinations of a password until the correct one is found. 2. Dictionary Attack: Uses a predefined list of potential words from a dictionary to guess the password. 3. Reverse Brute Force Attack: Targets discovering the username or account based on a known password. 4. Hybrid Brute Force Attack: Combines techniques of simple brute force and dictionary attacks to enhance efficiency. 5. Credential Stuffing Attack: Involves using stolen usernames and passwords from one service to gain unauthorized access to other accounts. These attack methods vary in their approach and complexity, highlighting the importance of robust security measures to mitigate the risks associated with Brute Force Attacks. --------- ### الفروق بين أنواع هجمات القوة الخامة: ### Differences between the types of raw force attacks: 1. هجوم القوة الخامة البسيط (Simple Brute Force Attack): - اللغة العربية: يعتمد على تجربة جميع التركيبات الممكنة لكلمة المرور. - English: Relies on trying all possible combinations of a password. 2. هجوم القوة الخامة باستخدام القاموس (Dictionary Attack): - اللغة العربية: يستخدم قائمة معينة من الكلمات المحتملة من قاموس لتخمين كلمة المرور. - English: Uses a predefined list of potential words from a dictionary to guess the password. 3. هجوم القوة الخامة العكسي (Reverse Brute Force Attack): - اللغة العربية: يستهدف اكتشاف اسم المستخدم أو الحساب بناءً على كلمة المرور المعروفة. - English: Targets discovering the username or account based on a known password. 4. هجوم القوة الخامة الهجين (Hybrid Brute Force Attack): - اللغة العربية: يجمع بين تقنيات هجوم القوة الخامة البسيط واستخدام القاموس لتحسين كفاءة الهجوم. - English: Combines techniques of simple brute force and dictionary attacks to enhance efficiency. 5. هجوم تجاوز المصادقة (Credential Stuffing Attack): - اللغة العربية: يتمثل في استخدام أسماء مستخدمين وكلمات مرور سرية مسروقة للوصول إلى حسابات أخرى. - English: Involves using stolen usernames and passwords from one service to gain unauthorized access to other accounts. ### الأماكن التي تستخدم فيها هذه الهجمات: - تطبيقات الويب والخدمات الإلكترونية: - اللغة العربية: تكون الحسابات عبر الإنترنت هدفًا شائعًا لهذه الهجمات. - Web applications and e-services: - English: Online accounts are a common target for these attacks. - الأنظمة والخوادم: - اللغة العربية: يستهدف المهاجمون الوصول إلى الأنظمة والخوادم. - Systems & Servers: - English: Attackers target gaining unauthorized access to systems and servers. - التطبيقات الداخلية: - اللغة العربية: يمكن استخدام هذه الهجمات لاختبار الأمان الداخلي للشركات.

photo content

httrack <URLs> [-option] [+<URL_FILTER>] [-<URL_FILTER>] [+<mime:MIME_FILTER>] [-<mime:MIME_FILTER>]
The <URLs> represent the URLs you wish to download, -option corresponds to configuration options for Httrack, and <URL_FILTER> and <MIME_FILTER> are criteria for including or excluding specific URLs or file types. For instance, to download an entire website along with external links, utilize the command below:
httrack https://example.com -O /home/user/example -e
Here, -O specifies the mirror path, logs, and cache, and -e allows exploration anywhere on the web. To run Httrack using the web interface, use the command:
webhttrack
This command opens your default web browser, presenting the Httrack interface, enabling you to initiate a new project, continue an existing one, or adjust settings. For installation on Termux on a mobile phone, follow these steps:
apt install curl
curl -LO https://raw.githubusercontent.com/Hax4us/httrack_In_termux/master/httrack
sh httrack
Subsequently, you can employ Httrack in Termux similarly to its usage in Kali Linux. BY : xtawb  THX <3

Arabic : Httrack هي اداة مجانية ومفتوحة المصدر للزحف على الويب والتصفح دون اتصال ، تم تطويرها بواسطة Xavier Roche وترخيصها بموجب رخصة GNU العمومية الإصدار 3. تتيح لك Httrack تنزيل موقع ويب كامل من الإنترنت إلى مجلد محلي ، بناءً على جميع الدلائل بشكل متكرر ، والحصول على ملفات HTML والصور والملفات الأخرى من الخادم إلى جهاز الكمبيوتر الخاص بك. ترتب Httrack بنية الرابط النسبية للموقع الأصلي. ببساطة ، افتح صفحة من موقع الويب \"المنعكس\" في متصفحك ، ويمكنك تصفح الموقع من رابط إلى رابط ، كما لو كنت تعرضه عبر الإنترنت. يمكن لـ Httrack أيضًا تحديث موقع معكوس موجود ، واستئناف التنزيلات المتقطعة. يمكن تكوين Httrack بالكامل ، ولديه نظام مساعدة مدمج. WinHTTrack هو إصدار Windows (من Windows 2000 إلى Windows 10 وما فوق) من Httrack ، و WebHTTrack هو إصدار Linux / Unix / BSD. يمكنك استخدام Httrack لأغراض مختلفة ، مثل إنشاء نسخة احتياطية من موقع ويب ، أو تحليل بنية موقع ويب ، أو تصفح موقع ويب دون اتصال ، أو اختبار روابط موقع ويب ، أو تعلم كيفية تصميم موقع ويب. لتثبيت Httrack على نظام Kali Linux ، يمكنك استخدام الأمر التالي في ترمينال:
sudo apt install httrack webhttrack
لتشغيل Httrack في وضع تفاعلي ، يمكنك استخدام الأمر التالي:
httrack
سيطلب منك Httrack إدخال اسم المشروع والمجلد والعنوان الأساسي والخيارات الأخرى. يمكنك أيضًا استخدام خيارات السطر الأخير لتخصيص عملية التنزيل. لتشغيل Httrack في وضع غير تفاعلي ، يمكنك استخدام الأمر التالي:
httrack <URLs> [-option] [+<URL_FILTER>] [-<URL_FILTER>] [+<mime:MIME_FILTER>] [-<mime:MIME_FILTER>]
حيث <URLs> هي عناوين URL التي تريد تنزيلها ، و -option هي خيارات تكوين Httrack ، و <URL_FILTER> و <MIME_FILTER> هي قواعد لتضمين أو استبعاد عناوين URL أو أنواع الملفات. على سبيل المثال ، إذا كنت تريد تنزيل موقع ويب بالكامل مع جميع الروابط الخارجية ، فيمكنك استخدام الأمر التالي:
httrack https://example.com -O /home/user/example -e
حيث -O هو خيار لتحديد مسار المرآة والسجلات والذاكرة المخبئة ، و -e هو خيار للذهاب إلى أي مكان على الويب. يمكنك أيضًا استخدام واجهة ويب لتشغيل Httrack بواسطة الأمر التالي:
webhttrack
سيفتح هذا الأمر متصفح الويب الافتراضي الخاص بك ويعرض واجهة Httrack ، حيث يمكنك إنشاء مشروع جديد أو متابعة مشروع موجود أو تعديل الإعدادات. بالنسبة لتطبيق Termux على الهاتف ، يمكنك تثبيت Httrack باستخدام الخطوات التالية:
apt install curl
curl -LO https://raw.githubusercontent.com/Hax4us/httrack_In_termux/master/httrack
sh httrack
بعد ذلك ، يمكنك استخدام Httrack في Termux بنفس الطريقة التي تستخدمها في Kali Linux. ------ BY : xtawb - - - - - - - - -  English : Httrack is a free and open-source web crawler and offline browser, developed by Xavier Roche and licensed under the GNU General Public License Version 3. Httrack allows you to download a whole website from the Internet to a local folder, building recursively all directories, getting HTML, images, and other files from the server to your computer. Httrack arranges the original site's relative link-structure. Simply, open a page of the "mirrored" website in your browser, and you can browse the site from link to link, as if you were viewing it online. Httrack can also update an existing mirrored site, and resume interrupted downloads. Httrack is fully configurable, and has an integrated help system. WinHTTrack is the Windows (from Windows 2000 to Windows 10 and above) release of Httrack, and WebHTTrack is the Linux/Unix/BSD release¹. You can use Httrack for various purposes, such as creating a backup of a website, analyzing a website's structure, browsing a website offline, testing a website's links, or learning how to design a website. To install Httrack on Kali Linux system, you can use the following command in terminal:
sudo apt install httrack webhttrack
To run Httrack in interactive mode, you can use the following command:
httrack
Httrack will ask you to enter the project name, folder, base URL, and other options. You can also use the command-line options to customize the download process. You can see the list of available options in [2](^2^). To run Httrack in non-interactive mode, you can use the following command:

photo content

Arabic: Webscarab هي أداة تحليل للتطبيقات التي تتواصل باستخدام بروتوكولي HTTP و HTTPS. إنها مكتوبة بلغة جافا ، وبالتالي فهي قابلة للتشغيل على العديد من المنصات. لديها عدة أوضاع للعمل ، يتم تنفيذها بواسطة عدد من الإضافات. في أكثر استخداماتها شيوعًا ، تعمل Webscarab كوكيل مقاطع ، مما يتيح للمشغل مراجعة وتعديل الطلبات التي ينشئها المتصفح قبل إرسالها إلى الخادم ، ومراجعة وتعديل الردود التي تعود من الخادم قبل استلامها من قبل المتصفح. تستطيع Webscarab مقاطعة كل من حركة المرور HTTP و HTTPS. يمكن للمشغل أيضًا مراجعة المحادثات (الطلبات والردود) التي مرت من خلال Webscarab. لتثبيت Webscarab على نظام كالي لينكس ، يمكنك استخدام الأمر التالي في الترمينال:
sudo apt install webscarab
لتشغيل Webscarab ، يمكنك استخدام الأمر التالي في الترمينال:
java -jar /usr/share/webscarab/webscarab.jar
للاستخدام Webscarab على تطبيق Termux على الهاتف ، يجب عليك أولاً تثبيت جافا على Termux باستخدام الأمر التالي:
pkg install openjdk-17
ثم يمكنك تنزيل ملف jar الخاص بـ Webscarab من وحفظه في مجلد Termux. بعد ذلك ، يمكنك تشغيل Webscarab باستخدام الأمر التالي ، مع استبدال اسم الملف بالاسم الفعلي:
java -jar webscarab.jar
------- BY : xtawb - - - - - - - English: Webscarab is a tool for analyzing applications that communicate using the HTTP and HTTPS protocols. It is written in Java, and is thus portable to many platforms. It has several modes of operation, implemented by a number of plugins. In its most common usage, Webscarab operates as an intercepting proxy, allowing the operator to review and modify requests created by the browser before they are sent to the server, and to review and modify responses returned from the server before they are received by the browser. Webscarab is able to intercept both HTTP and HTTPS traffic. The operator can also review the conversations (requests and responses) that have passed through Webscarab. To install Webscarab on Kali Linux, you can use the following command in the terminal:
sudo apt install webscarab
To run Webscarab, you can use the following command in the terminal:
java -jar /usr/share/webscarab/webscarab.jar
To use Webscarab on Termux app on the phone, you need to first install Java on Termux using the following command:
pkg install openjdk-17
Then you can download the jar file of Webscarab from and save it in the Termux folder. After that, you can run Webscarab using the following command, replacing the file name with the actual name:
java -jar webscarab.jar
BY:xtawb THX <3

photo content

very important مهم جدا

photo content

Arabic: Skipfish هي أداة مجانية ومفتوحة المصدر لاستطلاع أمن تطبيقات الويب. تقوم الأداة بإعداد خريطة تفاعلية للموقع المستهدف عن طريق إجراء عملية تسلل متكررة واختبارات قائمة على القاموس. تتم تعليق الخريطة الناتجة بالنتائج من عدد من الفحوصات الأمنية النشطة (ولكن نأمل أن تكون غير مزعجة). التقرير النهائي الذي تنتجه الأداة يهدف إلى أن يكون أساسًا لتقييمات أمن تطبيقات الويب المهنية. يمكنك تثبيت skipfish على نظام كالي لينكس باستخدام الأمر التالي:
sudo apt install skipfish
لاستخدام skipfish ، تحتاج إلى تحديد قائمة كلمات قابلة للكتابة ( -W ) ودليل الإخراج ( -o ) وعنوان URL للموقع الذي تريد فحصه. على سبيل المثال:
skipfish -W wordlist -o output_dir [7](http://example.com)
سيقوم skipfish بإرسال طلبات HTTP إلى الموقع وتحليل الاستجابات للعثور على روابط جديدة ومعلمات ونماذج ومشكلات أمنية. سيتم حفظ التقرير في دليل الإخراج المحدد. يمكنك عرض التقرير باستخدام متصفح الويب الخاص بك. يمكنك تخصيص سلوك skipfish باستخدام الخيارات المختلفة المتاحة. يمكنك الاطلاع على قائمة الخيارات بالكامل عن طريق تشغيل الأمر التالي:
skipfish -h
يمكنك أيضًا الاطلاع على الصفحة الرئيسية للأداة أو مستودع GitHub لمزيد من المعلومات والتوثيق والتحديثات. Skipfish هي أداة قوية وسهلة الاستخدام لاستطلاع أمن تطبيقات الويب. يمكنك استخدامها لاكتشاف الثغرات الأمنية في مواقع الويب الخاصة بك أو مواقع الويب التي تختبرها. نأمل أن تجد هذه الأداة مفيدة وممتعة. - - - - - - - BY: xtawb - - - - - - - - English : Skipfish is a free and open source tool for web application security reconnaissance. The tool prepares an interactive sitemap for the targeted site by carrying out a recursive crawl and dictionary-based probes. The resulting map is then annotated with the output from a number of active (but hopefully non-disruptive) security checks. The final report generated by the tool is meant to serve as a foundation for professional web application security assessments. You can install skipfish on Kali Linux using the following command:
sudo apt install skipfish
To use skipfish, you need to specify a writable wordlist ( -W ), an output directory ( -o ), and the URL of the site you want to scan. For example:
skipfish -W wordlist -o output_dir [7](http://example.com)
Skipfish will send HTTP requests to the site and analyze the responses to find new links, parameters, forms, and security issues. The report will be saved in the specified output directory. You can view the report using your web browser. You can customize the behavior of skipfish using the different options available. You can see the full list of options by running the following command:
skipfish -h
You can also check the tool homepage or the GitHub repository for more information, documentation, and updates. Skipfish is a powerful and easy-to-use tool for web application security reconnaissance. You can use it to discover security vulnerabilities in your own websites or the websites you are testing. We hope you find this tool useful and fun. BY : @xtawb THX <3

photo content

Arabic : Nessus هي أداة تقييم الثغرات الأمنية التي تساعدك على تحديد وتصحيح الثغرات في تطبيقات الويب والهواتف المحمولة والبنية التحتية للسحابة وغيرها من الأصول الرقمية. تستخدم Nessus من قبل عشرات الآلاف من المنظمات حول العالم لتحسين مستوى الأمان والامتثال للمعايير القانونية والتنظيمية². لتثبيت Nessus على نظام كالي لينكس ، يمكنك اتباع الخطوات التالية: - قم بشراء Nessus والحصول على رمز التفعيل من موقع Tenable أو من أحد الموزعين المعتمدين. - قم بتنزيل ملف الحزمة الخاص بنظام التشغيل والمعالج الخاص بك من موقع Tenable Downloads. - افتح نافذة الطرفية وانتقل إلى المجلد الذي تم تنزيل ملف Nessus إليه. ثم قم بتشغيل الأمر التالي لتثبيت الحزمة:
sudo dpkg -i Nessus-<version number>-debian6_amd64.deb
- بعد انتهاء التثبيت ، قم بتشغيل الأمر التالي لبدء خدمة Nessus:
sudo /bin/systemctl start nessusd.service
- افتح واجهة ويب Nessus في المتصفح الخاص بك على العنوان التالي: https://localhost:8834/. - اتبع معالج التثبيت لإنشاء حساب مسؤول وتفعيل Nessus باستخدام رمز التفعيل الخاص بك والسماح لـ Nessus بتنزيل ومعالجة الإضافات. لتستخدم Nessus في اختبار الاختراق ، يمكنك إنشاء مسح جديد وتحديد الأهداف والإعدادات والقوالب التي تريدها. ثم يمكنك تشغيل المسح ومراجعة النتائج والتقارير. للأسف ، لا يمكن تثبيت Nessus على تطبيق Termux على الهاتف ، لأنه لا يدعم نظام التشغيل Android. ومع ذلك ، يمكنك استخدام Nessus Agent لمسح الأجهزة المحمولة التي تعمل بنظامي Android و iOS. English: Nessus is a security vulnerability assessment tool that helps you identify and fix vulnerabilities in web applications, mobile devices, cloud infrastructure, and other digital assets. Nessus is used by tens of thousands of organizations around the world to improve their security level and comply with legal and regulatory standards¹². To install Nessus on Kali Linux system, you can follow these steps: - Purchase Nessus and obtain an activation code from Tenable website or from an authorized reseller. - Download the package file for your operating system and processor from Tenable Downloads site. - Open a terminal window and navigate to the folder where you downloaded the Nessus file. Then run the following command to install the package:
sudo dpkg -i Nessus-<version number>-debian6_amd64.deb
- After the installation is complete, run the following command to start the Nessus service:
sudo /bin/systemctl start nessusd.service
- Open the Nessus web interface in your browser at the following address: https://localhost:8834/. - Follow the installation wizard to create an administrator account, activate Nessus with your activation code, and let Nessus download and process the plugins. To use Nessus in penetration testing, you can create a new scan and specify the targets, settings, and templates that you want. Then you can run the scan and review the results and reports. Unfortunately, you cannot install Nessus on Termux app on the phone, because it does not support Android operating system. However, you can use Nessus Agent to scan mobile devices running Android and iOS systems.

photo content

- This is my account send me here - هذا هو حسابي ارسلو لي هنا
- This is my account send me here - هذا هو حسابي ارسلو لي هنا

🌐 English Version: 🔐 Exciting Announcement! Join xtawb Cybersecurity Team Now! 🔐 Dear Followers, We're thrilled to announce that applications are open for joining the xtawb cybersecurity and hacking team. 💻 Earn a salary based on completed tasks, with most missions offering a payout of no less than $1000 per task. Expect to tackle more than one mission each month! 🚀 Joining Requirements: - Professional cybersecurity experience of at least one year. - Possession of relevant certifications. Take your cybersecurity skills to the next level and be part of a dynamic team securing the digital landscape. Apply now and unlock a world of opportunities! 💼✨ To apply, join our Discord server: [xtawb Cybersecurity Discord](https://discord.com/invite/G6At4ggabm) and send a private message with "xtawb." 🌐 النسخة باللغة العربية: 🔐 إعلان مثير! انضم إلى فريق أمان xtawb الآن! 🔐 أعزائنا المتابعين، نحن مسرورون بالإعلان عن فتح باب التقديم للانضمام إلى فريق أمان xtawb في مجال الأمان السيبراني والاختراق. 💻 اربح راتبًا بناءً على إكمال المهام، حيث تقدم معظم المهام دفعة لا تقل عن 1000 دولار للمهمة الواحدة. توقع تنفيذ أكثر من مهمة في الشهر! 🚀 شروط الانضمام: - خبرة مهنية في مجال الأمان السيبراني لا تقل عن سنة. - وجود شهادات تعلم ذات صلة. خطوات متقدمة في مجال الأمان السيبراني والتحق بفريق دينامي يعمل على تأمين البيئة الرقمية. قدّم الآن واكتشف عالم الفرص! 💼✨ للتقديم، انضم إلى خادمنا على Discord: [خادم أمان xtawb على Discord](https://discord.com/invite/G6At4ggabm) وأرسل رسالة خاصة تحتوي على "xtawb".

مطلوب اعضاء جدد للفريق من يريد الانضمام. New team members are required who want to join.
Anonymous voting