uk
Feedback
SL Android Official ™ 🇱🇰

SL Android Official ™ 🇱🇰

Відкрити в Telegram

💢 SL Android වෙතින්, 💥 Termux Basic ඉදලා Advance දක්වා vedio+ post Full Course එකක් කරනවා 💥 Python ,PHP ,HTML ,CSS ,Shell Programming Full course 💥 Hacking 💥අමතර තාක්ෂණික දැනුම ලබා ගත හැක

Показати більше
2 763
Підписники
+324 години
-37 днів
-2630 днів

Триває завантаження даних...

Залучення підписників
жовт '26
жовтень '26
+12
в 0 каналах
вересень '26
+59
в 0 каналах
Get PRO
серпень '26
+97
в 0 каналах
Get PRO
липень '26
+49
в 0 каналах
Get PRO
червень '26
+27
в 0 каналах
Get PRO
травень '26
+54
в 0 каналах
Get PRO
квітень '26
+32
в 0 каналах
Get PRO
березень '26
+44
в 0 каналах
Get PRO
лютий '26
+45
в 0 каналах
Get PRO
січень '26
+39
в 0 каналах
Get PRO
грудень '25
+44
в 0 каналах
Get PRO
листопад '25
+56
в 0 каналах
Get PRO
жовтень '25
+32
в 0 каналах
Get PRO
вересень '25
+29
в 0 каналах
Get PRO
серпень '25
+38
в 0 каналах
Get PRO
липень '25
+44
в 0 каналах
Get PRO
червень '25
+65
в 0 каналах
Get PRO
травень '25
+53
в 0 каналах
Get PRO
квітень '25
+35
в 0 каналах
Get PRO
березень '25
+53
в 0 каналах
Get PRO
лютий '25
+58
в 0 каналах
Get PRO
січень '25
+91
в 0 каналах
Get PRO
грудень '24
+57
в 0 каналах
Get PRO
листопад '24
+67
в 0 каналах
Get PRO
жовтень '24
+107
в 0 каналах
Get PRO
вересень '24
+72
в 0 каналах
Get PRO
серпень '24
+100
в 0 каналах
Get PRO
липень '24
+73
в 0 каналах
Get PRO
червень '24
+83
в 0 каналах
Get PRO
травень '24
+82
в 0 каналах
Get PRO
квітень '24
+66
в 1 каналах
Get PRO
березень '24
+84
в 1 каналах
Get PRO
лютий '24
+76
в 1 каналах
Get PRO
січень '24
+86
в 0 каналах
Get PRO
грудень '23
+77
в 0 каналах
Get PRO
листопад '23
+57
в 0 каналах
Get PRO
жовтень '23
+69
в 0 каналах
Get PRO
вересень '23
+62
в 0 каналах
Get PRO
серпень '23
+69
в 0 каналах
Get PRO
липень '23
+52
в 0 каналах
Get PRO
червень '23
+55
в 0 каналах
Get PRO
травень '23
+74
в 0 каналах
Get PRO
квітень '23
+71
в 0 каналах
Get PRO
березень '23
+81
в 0 каналах
Get PRO
лютий '23
+70
в 0 каналах
Get PRO
січень '23
+109
в 0 каналах
Get PRO
грудень '22
+106
в 0 каналах
Get PRO
листопад '22
+139
в 0 каналах
Get PRO
жовтень '22
+118
в 0 каналах
Get PRO
вересень '22
+113
в 0 каналах
Get PRO
серпень '22
+69
в 0 каналах
Get PRO
липень '22
+121
в 0 каналах
Get PRO
червень '22
+131
в 0 каналах
Get PRO
травень '22
+203
в 0 каналах
Get PRO
квітень '22
+226
в 0 каналах
Get PRO
березень '22
+166
в 0 каналах
Get PRO
лютий '22
+135
в 0 каналах
Get PRO
січень '22
+181
в 0 каналах
Get PRO
грудень '21
+223
в 0 каналах
Get PRO
листопад '21
+215
в 0 каналах
Get PRO
жовтень '21
+255
в 0 каналах
Get PRO
вересень '21
+340
в 0 каналах
Get PRO
серпень '21
+367
в 0 каналах
Get PRO
липень '21
+242
в 0 каналах
Get PRO
червень '21
+367
в 0 каналах
Get PRO
травень '21
+222
в 0 каналах
Get PRO
квітень '21
+185
в 0 каналах
Get PRO
березень '21
+160
в 0 каналах
Get PRO
лютий '21
+205
в 0 каналах
Get PRO
січень '21
+793
в 0 каналах
Дата
Залучення підписників
Згадування
Канали
06 жовтня+2
05 жовтня+4
04 жовтня+3
03 жовтня0
02 жовтня+1
01 жовтня+2
Дописи каналу
🔥 Ethicaltools | 142+ Cybersecurity Tools 🛠️ Looking for a collection of cybersecurity and ethical hacking tools that you c
🔥 Ethicaltools | 142+ Cybersecurity Tools 🛠️ Looking for a collection of cybersecurity and ethical hacking tools that you can explore directly from Termux.? 👀 Ethicaltools is a tool collection designed for Termux, featuring 142+ tools for learning, security research, and authorized testing. ⚡ 📌 Installation
apt update && apt upgrade
pkg install git
pkg install python2

git clone https://github.com/saintmalik/Ethicaltools.git

cd Ethicaltools

chmod +x smtools.py

python2 smtools.py
🛠️ What can you explore.?
🔹 Cybersecurity tools
🔹 Ethical hacking utilities
🔹 OSINT-related tools
🔹 Security testing concepts
🔹 Termux-based security learning
⚠️ DISCLAIMER Use these tools only on systems, networks, and accounts that you own or have explicit authorization to test. ❌ Do not use them for unauthorized access, attacks, or illegal activities. 🎯 Learn • Practice • Secure
𝑬𝑻𝑯𝑰𝑪𝑨𝑳 𝑪𝒀𝑩𝑬𝑹𝑺𝑬𝑪𝑼𝑹𝑰𝑻𝒀 ™

2
Speedtest CLI in Termux – Internet Speed Testing Tool Speedtest CLI is a simple internet speed testing tool that helps measure download speed, upload speed, and network ping directly from the terminal. It provides quick and accurate results without opening a web browser. You can install Speedtest CLI in Termux to test your internet connection and monitor network performance using simple commands. Here’s what you can do with Speedtest CLI in Termux: Check internet download speed. Check internet upload speed. Measure network ping. View Speedtest server information. Export results in CSV or JSON format. Test internet performance from the terminal. Install Speedtest CLI in Termux Below are the simple commands to install Speedtest CLI in Termux. Copy and run each command one by one to install the tool. pkg update && pkg upgrade -y pkg install python -y pip install speedtest-cli speedtest-cli --version After completing the installation, Speedtest CLI will be ready to use inside the Termux terminal. Use Speedtest CLI in Termux Run a complete internet speed test. speedtest-cli speedtest-cli --help speedtest-cli --no-upload speedtest-cli --no-download speedtest-cli --simple speedtest-cli --bytes speedtest-cli --list speedtest-cli --server SERVER_ID speedtest-cli --json speedtest-cli --csv speedtest-cli --csv-header speedtest-cli --share speedtest-cli --secure Choose the command you want and Speedtest CLI will automatically test your internet connection and display the results directly inside the Termux terminal. End Note Speedtest CLI is a useful networking tool for checking internet speed directly from the terminal. It allows you to measure download speed, upload speed, and ping without opening a browser, making it a simple tool for Termux.
63
3
Немає тексту...
48
4
Gameplay Controls: Left / Right – Move the piece Up – Rotate clockwise Down – Soft drop Spacebar – Hard drop C / Shift – Hold the piece Game Commands:Games P – Pause / Unpause Q / Escape – Quit the match Terminal Options: tetris -width 40 tetris -height 25 tetris -bg black tetris -bg white tetris -color tetris -mono tetris -ascii tetris -vt100 tetris -block "[]" tetris -tt tetris -tt-bg tetris -nomenu tetris -hiscores tetris -help game tetris -help term You can use these commands and keyboard controls to customize Vitetris, change the game display, and check high scores. End Note Vitetris is a fun and easy game to try in Termux. You can use the keyboard controls to play Tetris and use the available options to change how the game looks and works. It is a simple way to enjoy a text-based classic game in the terminal.
40
5
Vitetris in Termux – Play Tetris in the Terminal Vitetris is a simple Tetris game that runs in the Termux terminal. It lets y
Vitetris in Termux – Play Tetris in the Terminal Vitetris is a simple Tetris game that runs in the Termux terminal. It lets you move, rotate, hold, and drop blocks using your keyboard. You can also change the game size, colors, and display style with different options. You can check your high scores and play with other players using the built-in multiplayer options. Here’s what you can do with Vitetris in Termux: Play Tetris in the terminal. Move and rotate pieces. Use soft and hard drops. Hold pieces for later use. Pause and resume the game. Change the terminal display. Use colors or monochrome mode. View the highscore list. Adjust the game width and height. Install Vitetris pkg update && pkg upgrade -y pkg install vitetris -y tetris tetris -h Menu Navigation: Up / Down – Navigate options Enter – Select or confirm Escape / Q – Go back or exit
32
6
RECON-X කියන්නේ website/domain එකක් ගැන reconnaissance (information gathering) කරන්න භාවිතා කරන cybersecurity tool එකක්. සරලව කිව්වොත් 👇 🔎 RECON-X එකෙන් මොනවා කරන්න පුළුවන්ද.? Target website එකක් දීලා, එයට සම්බන්ධ publicly available information සහ attack surface එක ගැන data එකතු කිරීමට options කිහිපයක් ලබාදෙන tool එකක්. සාමාන්‍යයෙන් මෙවැනි recon tools වලින්: 🌐 Domain / IP information 🔍 Subdomain discovery 📡 DNS information 🛜 Network/host information 🔐 Open ports/services පිළිබඳ තොරතුරු 🧩 Technologies / frameworks හඳුනාගැනීම 📋 WHOIS වැනි public domain information 🔗 Website එකට සම්බන්ධ වෙනත් assets වගේ දේවල් authorized security testing වලදී සොයාගැනීමට භාවිතා කළ හැක. 📱 Termux එකේ install කිරීම දාලා තියෙන commands වලින් GitHub repository එක download කරලා install.sh script එක run කරනවා: pkg install git -y git clone https://github.com/Yashvendra/Recon-X cd Recon-X chmod +x install.sh ./install.sh ඊට පස්සේ tool එකේ menu එකෙන් option එකක් තෝරලා domain එක ලබාදෙන ආකාරයේ workflow එකක් තියෙනවා. ⚠️ වැදගත්: Recon කියන්නේ attack එකක්ම නෙවෙයි. නමුත් third-party website එකක් scan/recon කිරීම එහි ownerගේ අවසරයකින් තොරව කළොත් නීතිමය/සෙවා-නියම ගැටලු ඇතිවිය හැක. තමන්ගේ domain, lab/CTF, localhost හෝ explicit authorization තියෙන targets වල භාවිතා කිරීම සුදුසුයි.
60
7
Немає тексту...
57
8
🚨 KillSec හැකර් කල්ලියේ ප්‍රධාන මෙහෙයුම්කරු ලෙස සැක කළ 16 හැවිරිදි සිසුවෙක් අත්අඩංගුවට.! ස්පාඤ්ඤයේ Guardia Civil සහ කැටලෝනියානු Mossos d'Esquadra පොලිස් ඒකකය එක්ව සිදු කළ මෙහෙයුමකදී, KillSec හැකර් කල්ලියේ ප්‍රධාන මෙහෙයුම්කරුවෙකු ලෙස සැක කෙරෙන 16 හැවිරිදි රුමේනියානු ජාතිකයෙකු ස්පාඤ්ඤයේ Alicante නගරයේදී සැප්තැම්බර් 30 දා අත්අඩංගුවට ගෙන තිබෙනවා. 🛑💻 මෙය ස්පාඤ්ඤයට පමණක් සීමා වූ මෙහෙයුමක් නොවෙයි. 🇩🇪 ජර්මනිය 🇪🇸 ස්පාඤ්ඤය 🇬🇧 එක්සත් රාජධානිය 🇷🇴 රුමේනියාව යන රටවල නීතිය ක්‍රියාත්මක කිරීමේ ආයතන සම්බන්ධ වූ මෙම විමර්ශනයට Europol සහ Eurojust ද සහාය ලබාදී තිබෙනවා. ☠️ KillSec කියන්නේ කවුද.? විමර්ශකයන්ට අනුව, KillSec කණ්ඩායම ආයතනවල පද්ධතිවල දුර්වලතා සහ ආරක්ෂාව අඩු cloud storage ප්‍රවේශයන් සොයාගෙන සංවේදී දත්ත සොරකම් කිරීම සිදු කර තිබෙන බවට චෝදනා එල්ල වී තිබෙනවා. ඉන්පසුව එම දත්ත ප්‍රසිද්ධ කරන බවට තර්ජනය කරමින්, වින්දිත ආයතනවලින් ransom ඉල්ලා ඇති බව සඳහන්. 🤖 තවත් විශේෂ කරුණක් වන්නේ, විමර්ශකයන්ට අනුව කණ්ඩායම AI තාක්ෂණය භාවිත කර තිබීමයි. 2024 සිට ඔවුන්ගේ මෙහෙයුම්වලදී ransomware infrastructure පවත්වාගෙන යාමට සහ ඉලක්ක හඳුනාගැනීමට AI භාවිත කළ බවට තොරතුරු අනාවරණය වී තිබෙනවා. 📊 මෙහෙයුමේ විශාලත්වය 🔹 සැක කෙරෙන ප්‍රහාර — 1,000ක් පමණ 🔹 තහවුරු කළ සාර්ථක ප්‍රහාර — 500ක් පමණ 🔹 අත්පත් කරගත් දත්ත — 110+ TB 🔹 අත්පත් කරගත් servers — 5ක් 🔹 ඒ අතර ප්‍රධාන server එකක්ද තිබෙන බව සඳහන්. 👮 තවත් සැකකරුවන් 16 හැවිරිදි සැකකරුට අමතරව, වයස අවුරුදු 20 ගණන්වල තවත් පුද්ගලයන් දෙදෙනෙකු එක්සත් රාජධානියේ සහ රුමේනියාවේදී අත්අඩංගුවට ගෙන තිබෙනවා. එක්සත් රාජධානියේදී අත්අඩංගුවට ගත් Fouad Eltibrizi, online ලෝකයේ "Archduke" යන නාමයෙන් හඳුන්වා ඇති අතර, සැප්තැම්බර් 16 දා Puerto Rico හි federal grand jury එකක් ඔහුට එරෙහිව චෝදනා ඉදිරිපත් කර ඇති බවත්, ඔහුව Puerto Rico වෙත පිටුවහල් කිරීමට ඉල්ලීමක් කර ඇති බවත් වාර්තා වෙනවා. මීට අමතරව, අගෝස්තු මාසයේදී 18 වැනි විය සම්පූර්ණ කළ, ඇතැම් චෝදනා කරන ලද ක්‍රියා සිදු වූ අවස්ථාවේදී නාබාලකයෙකු වූ developer කෙනෙකුද හඳුනාගෙන තිබෙනවා. ඔහු තවමත් අත්අඩංගුවට ගෙන නැහැ. 🔎 මෙහෙයුම තවම අවසන් නැහැ... KillSec හි සියලුම සාමාජිකයන් අත්අඩංගුවට ගෙන ඇති බව බලධාරීන් තවමත් තහවුරු කර නැහැ. අත්අඩංගුවට ගත් පුද්ගලයන්ගෙන් සහ අත්පත් කරගත් servers/data වලින් ලැබෙන digital evidence හරහා තවත් වින්දිතයන්, cyberattacks සහ සම්බන්ධිත පුද්ගලයන් හඳුනාගැනීමට හැකිවනු ඇතැයි Eurojust සඳහන් කර තිබෙනවා. ⚠️ Cybersecurity Awareness: මෙවැනි සිදුවීම් cybersecurity vulnerabilities, cloud security සහ ransomware threats පිළිබඳ අවබෝධය ලබාගැනීම සඳහා පමණක් සාකච්ඡා කෙරේ. අනවසරයෙන් පද්ධතිවලට ප්‍රවේශ වීම හෝ දත්ත සොරකම් කිරීම නීති විරෝධී වේ. 𝑬𝑻𝑯𝑰𝑪𝑨𝑳 𝑪𝒀𝑩𝑬𝑹𝑺𝑬𝑪𝑼𝑹𝑰𝑻𝒀 ™
66
9
Немає тексту...
42
10
- Unusual outbound connections - Repeated beacon-like traffic - Process එකකට normal නොවන external destinations Endpoint Behavior - Unexpected screenshot activity - Keylogging-related behavior - Browser credential access - Unexpected file transfers ⚠️ එක indicator එකක් දැක්කා කියලා RAT කියලා conclude කරන්න බැහැ. Multiple behaviors correlate කිරීම stronger approach එකක්. 🧩 RAT එකක් සහ Legitimate Remote Access Software එක එකම දෙයක්ද? නැහැ. AnyDesk, TeamViewer, RMM platforms, Remote Desktop වගේ tools legitimate administrative purposes සඳහා භාවිතා කරනවා. නමුත් attacker කෙනෙක් compromised environment එකක legitimate remote-access software එක abuse කරන්නත් පුළුවන්. ඒ නිසා: «“Remote access software installed = Malware”» කියන conclusion එකත් වැරදියි. Defender කෙනෙක්ට වඩා useful questions: Who installed it? Why is it installed? Was it approved? Which account launched it? Where is it connecting? What happened before execution? What happened after execution? 🔥 RAT එක dangerous වෙන්නේ Remote Control නිසා විතරක් නෙමෙයි RAT එකක් foothold එකක් විතරක් වෙන්න පුළුවන්. එකෙන් attacker කෙනෙක්ට: Reconnaissance ↓ Credential Access ↓ Data Collection ↓ Additional Payloads ↓ Lateral Movement වගේ follow-on activity වලට move වෙන්න පුළුවන්. ඒ නිසා RAT එකක් detect කළාම වැදගත් question එක: «“මේ host එක control කරලා තිබුණ කාලය තුළ attacker මොනවා කළාද?”» 🧪 Famous RAT Examples Security research වල documented RAT families ගොඩක් තියෙනවා. 🐀 njRAT HTTP-based C2, persistence, keylogging, credential theft, screen capture සහ webcam-related capabilities වැනි behaviors සමඟ documented වෙලා තියෙන RAT family එකක්. 🐀 DarkComet Remote-control functionality, HTTP C2, keylogging, screen-related capabilities, webcam access සහ persistence වැනි behaviors සමඟ associated වෙලා තියෙන RAT family එකක්. 🐀 QuasarRAT Windows-based remote access capabilities සහ post-compromise behaviors ගණනාවක් සමඟ documented වෙලා තියෙන open-source remote administration tool එකක්. 🐀 AsyncRAT Windows/.NET ecosystem එකේ observed remote-access trojan family එකක් ලෙස security research වල documented වෙලා තියෙනවා. 🛡️ RAT වලින් Defend වෙන්නේ කොහොමද? RAT detection එක signature එකකට විතරක් rely කරන්න එපා. ✅ Endpoint Protection + EDR ✅ Application Control / Allow-listing ✅ Unapproved Remote-access Software restrict කිරීම ✅ Suspicious Persistence Changes monitor කිරීම ✅ Outbound Network Visibility ✅ DNS / HTTP / HTTPS behavior monitoring ✅ Browser Credential Protection ✅ Least Privilege ✅ User Execution Controls ✅ Incident-response telemetry preserve කිරීම Defense එකේ objective එක malware file එක delete කරන එක විතරක් නෙමෙයි. Compromise එකේ scope එක සහ attacker activity එක identify කිරීමත් වැදගත්. 🧠 Final Takeaway RAT එකක් කියන්නේ: «❌ “Remote mouse control malware” විතරක් නෙමෙයි.» ඒක: Execution + Persistence + C2 + Discovery + Credential Access + Collection + Remote Control වගේ capabilities එකට combine වෙන platform එකක් වෙන්න පුළුවන්. ඒ නිසා RAT incident එකක් analyse කරනකොට: «“RAT එක මොකක්ද?”» කියන question එකට වඩා, «“කොහොම execute වුණාද → කොහොම persist වුණාද → කොහෙට C2 කළාද → මොන data access කළාද → attacker ඊට පස්සේ මොනවා කළාද?”» කියන questions ටික වැදගත්. 🔍 ⚠️ ETHICAL / EDUCATIONAL DISCLAIMER RAT analysis සහ testing තමන්ගේම Lab, CTF, Sandbox හෝ explicit permission තියෙන environment එකක විතරක් කරන්න. Unauthorized system එකකට remote-control malware deploy කිරීම හෝ access ලබාගැනීම නීතිවිරෝධී සහ අනතුරුදායකයි. Learn → Test → Defend. 🛡️ 𝑬𝑻𝑯𝑰𝑪𝑨𝑳 𝑪𝒀𝑩𝑬𝑹𝑺𝑬𝑪𝑼𝑹𝑰𝑻𝒀 ™
57
11
🐀 RAT කියන්නේ මොකක්ද.? — “අනිත් පැත්තේ ඉඳලා PC එක Control කරන Virus එකක්” විතරක් නෙමෙයි ඔයා RAT එකක් කියන්නේ “අනිත් පැත්තේ ඉඳලා PC එක control කරන virus එකක්” කියලා විතරක් දන්නවා නම්, ඒක incomplete picture එකක්. RAT (Remote Access Trojan) කියන්නේ compromised system එකක් සහ attacker-controlled infrastructure එක අතර remote control / Command & Control (C2) capability ලබාදිය හැකි malware category එකක්. මේකේ dangerous part එක remote desktop එක විතරක් නෙමෙයි. RAT එකකට: 🔹 System information collect කරන්න 🔹 Commands execute කරන්න 🔹 Files access / transfer කරන්න 🔹 Keystrokes capture කරන්න 🔹 Screenshots ගන්න 🔹 Webcam / microphone access කරන්න 🔹 Persistence maintain කරන්න 🔹 Collected data C2 channel එක හරහා පිටතට යවන්න වගේ capabilities තිබිය හැක. ⚠️ හැබැයි හැම RAT එකකටම එකම feature set එකක් නැහැ. Capabilities RAT family එකෙන් family එකට වෙනස් වෙනවා. 🧠 RAT එකක් ඇතුළේ Basic Architecture එක සාමාන්‍යයෙන් මේක components දෙකක් විදිහට හිතන්න පුළුවන්: Victim Host │ └── RAT Implant / Malicious Component │ ▼ C2 Infrastructure (Command & Control) RAT එක infected machine එකෙන් C2 infrastructure එක වෙත connection එකක් establish කරනවා. ඊට පස්සේ C2 side එකෙන් instructions එන්න පුළුවන්, infected host එකෙන් results හෝ collected data ආපහු යන්න පුළුවන්. Communication එක HTTP/HTTPS වගේ application-layer protocols හරහා යන්න පුළුවන්. වෙනත් protocols භාවිතා කරන malware families ද තියෙනවා. ⚠️ “Port 80/443 නම් Safe” කියන assumption එක වැරදියි Malicious C2 traffic එක legitimate web traffic වගේ පෙනෙන්න හැදිය හැක. ඒ නිසා port number එකක් විතරක් බලලා RAT එකක් identify කරන්න බැහැ. 🎯 RAT එකක් compromise වුණාට පස්සේ කරන්න පුළුවන් දේවල් RAT family එක මත capabilities වෙනස් වුණත්, documented examples වල මේ වගේ behaviors දකින්න පුළුවන්: 🔹 System Information Discovery OS version, computer name, current user වගේ information collect කිරීම. 🔹 Process / File Discovery Running processes සහ local filesystem එක inspect කිරීම. 🔹 Command Execution Remote commands හෝ shell-based commands execute කිරීම. 🔹 Keylogging User type කරන keystrokes capture කිරීම. 🔹 Screen Capture Victim screen එකේ screenshots ලබාගැනීම. 🔹 Webcam / Audio Access Camera හෝ microphone capabilities abuse කිරීම. 🔹 Credential Theft සමහර RATs browser-stored credentials වැනි sensitive data target කරනවා. 🔹 File Transfer / Exfiltration Files victim machine එකට download කිරීම හෝ compromised system එකෙන් data පිටතට transfer කිරීම. 🔹 Persistence Restart එකකට පස්සේ malware එක නැවත execute වෙන්න Registry autoruns, Startup locations, services හෝ වෙනත් persistence mechanisms භාවිතා කළ හැක. ⚠️ RAT = Initial Access නෙමෙයි මෙතන beginners ලා විතරක් නෙමෙයි, experienced users ලාත් sometimes mix කරන point එකක් තියෙනවා. RAT එක = malware payload එක. ඒක system එකට ඇතුල් කරන delivery method එක වෙනම දෙයක්. Real-world campaigns වල RAT-related malware: 📧 Phishing attachments / links 💾 Malicious downloads 📦 Trojanized software 🌐 Drive-by installations වගේ mechanisms හරහා පැමිණිය හැක. ඒ නිසා incident එකක් analyse කරනකොට මේ mental model එක useful: Delivery ↓ Execution ↓ Persistence ↓ C2 ↓ Discovery ↓ Control ↓ Collection / Exfiltration 🔗 RAT සහ C2 අතර සම්බන්ධය RAT එකේ core capability එක remote control. ඒකට C2 channel එකක් අවශ්‍ය වෙනවා. Network defender කෙනෙක්ට මේ වගේ behavior chain එකක් වැදගත් signal එකක් වෙන්න පුළුවන්: Unknown Process ↓ Outbound Connection ↓ Repeated / Beacon-like Traffic ↓ Remote Instructions ↓ Unusual Child Processes Single IOC එකකට වඩා behavior correlation එක useful වෙන්න පුළුවන්. 🕵️ RAT එකක් Detect කරන්නේ File එකක් හොයාගෙන විතරක් නෙමෙයි Modern detection වලදී behavior වැදගත්. Defender කෙනෙක්ට බලන්න පුළුවන්: Process - Unknown executable - Suspicious parent/child process relationships - RAT process එකෙන් shell / scripting engine spawn වීම Persistence - Unexpected service creation - Suspicious Registry autorun changes Network
58
12
Немає тексту...
53
13
මේක Rugged Portable Cyberdeck / Portable Computer Workstation එකක්. Video එකේ පේන setup එකේ Intel NUC + Raspberry Pi + displays + cooling + power system + networking/electronics එකම rugged case එකකට custom build කරලා තියෙනවා. මේකෙන් කරන්න පුළුවන් දේවල් 👇 💻 සාමාන්‍ය PC එකක් වගේ Windows/Linux run කරලා programming, browsing, apps run කරන්න 🐧 Raspberry Pi/Linux projects කරන්න 🌐 Network administration & troubleshooting 🔐 Cybersecurity labs / authorized penetration testing 🧪 CTF සහ security-learning environments 🐍 Python, Bash, Git වගේ development tools run කරන්න 📡 Network devices configure/monitor කරන්න 🖥️ එකවර displays කිහිපයක් භාවිතා කරලා monitoring/dashboard වැඩ කරන්න 🔋 Built-in power system නිසා portable workstation එකක් වගේ භාවිතා කරන්න 🛠️ Electronics / Raspberry Pi / IoT projects control කරන්න components අනුව මේක එක computer එකක් විතරක් නෙවෙයි. Case එක ඇතුළේ systems කිහිපයක් තියෙන custom project එකක්: ┌──────────────────────────────┐ │ RUGGED CASE │ │ │ │ 🖥️ Intel NUC │ │ 🖥️ Display │ │ 🍓 Raspberry Pi │ │ ❄️ Cooling Fans │ │ 🌐 Network / USB │ │ ⚡ Power Management │ │ 🌡️ Temp / Voltage Monitoring│ │ ⌨️ Keyboard │ └──────────────────────────────┘ ඒකෙන් “Wi-Fi hack කරන්න විශේෂ machine එකක්” කියලාම හිතන්න එපා. Hardware/software අනුව ඒ හැකියාව වෙනස් වෙනවා.
98
14
Немає тексту...
77
15
🥧 HackberryPi CM5 කියන්නේ මොකද්ද.? HackberryPi CM5 කියන්නේ Raspberry Pi Compute Module 5 (CM5) පදනම් කරගෙන හදපු portable cybersecurity / hacking development device එකක්. සරලව කිව්වොත් 👉 Raspberry Pi CM5 + portable hardware + networking interfaces + security-focused features එකට එකතු කරපු mini computer එකක්. 🔧 සාමාන්‍යයෙන් භාවිතා කළ හැකි දේවල් 🐧 Linux / Kali Linux වගේ OS run කිරීම 🌐 Network security testing 🔍 Wi-Fi / network diagnostics 🛠️ Cybersecurity labs සහ CTF practice 💻 Portable Linux workstation එකක් ලෙස 🧪 Authorized penetration-testing environments 📡 Network monitoring / troubleshooting 🐍 Python, Bash වගේ programming tools run කිරීම 🧠 CM5 එකේ role එක Compute Module 5 (CM5) කියන්නේ Raspberry Pi 5 architecture එක පදනම් කරගත් compact computer module එකක්. HackberryPi වගේ devices වලදී CM5 එක තමයි ප්‍රධාන computing unit එක. Concept එක මෙහෙමයි: HackberryPi CM5 │ ┌──────┴──────┐ │ CM5 │ │ CPU / RAM │ └──────┬─────┘ │ ┌─────────┼─────────┐ │ │ │ Linux Network GPIO/ Tools Interfaces Hardware │ ├── Python ├── Bash ├── Security Tools └── CTF / Labs වැදගත්: HackberryPi එක "හදිසියේ ඕනෑම Wi-Fi එකක් hack කරන gadget එකක්" නෙවෙයි. Hardware එකේ තියෙන Wi-Fi/network capabilities සහ install කරන software අනුව security testing capabilities වෙනස් වෙනවා.
96
16
Немає тексту...
83
17
Doggo - Domain Information & Dns Lookup Doggo is a simple command-line DNS lookup tool that can query different DNS records,
Doggo - Domain Information & Dns Lookup Doggo is a simple command-line DNS lookup tool that can query different DNS records, such as A, AAAA, CNAME, MX, and TXT records. It can be used to check DNS records for a domain and learn what information different record types provide. https://termux.achik.us/doggo-in-termux-dns-lookup-and-domain-information-tool/ 📚 For educational and learning purposes only. Always use tools responsibly and with proper authorization.
110
18
🧠 Cybersecurity වල real lesson එක: Attack එක stop කරන්න කලින්, attacker එක මොන authentication weakness එක exploit කරනවාද කියන එක තේරුම් ගන්න ඕන. 📢 TELEGRAM SECURITY / MODERATION NOTICE මෙම post එක Cybersecurity Education & Awareness සඳහා පමණක් නිර්මාණය කර ඇති educational content එකකි. මෙහි සඳහන් Brute Force, Password Guessing, Password Cracking, Password Spraying සහ Credential Stuffing වැනි concepts, cybersecurity professionals සහ studentsලාට authentication attacks ක්‍රියා කරන ආකාරය තේරුම් ගැනීමට සහ ඒවාට ආරක්ෂාව සකස් කිරීමට explain කිරීම සඳහා පමණි. ⚠️ මෙම post එක: ❌ Unauthorized account access සඳහා නොවේ ❌ වෙනත් පුද්ගලයන්ගේ credentials ලබාගැනීම සඳහා නොවේ ❌ Real-world accounts / systems attack කිරීම සඳහා නොවේ ❌ Credential theft හෝ account takeover promote කිරීම සඳහා නොවේ ❌ Illegal activity සඳහා instructions ලබාදීමේ අරමුණක් නැත මෙහි technical concepts demonstrate/test කිරීමට අදහස් කරන්නේ තමන්ගේම systems, intentionally vulnerable labs, CTF environments, sandboxes හෝ explicit authorization ලබාදී ඇති systems පමණි. 🎯 මෙම content එකේ primary purpose එක: Understand the Attack → Identify the Weakness → Detect the Behavior → Build the Defense ඒ නිසා මෙම post එකේ Brute Force techniques discuss කරන්නේ attack කිරීම සඳහා නොව, ඒවා හඳුනාගැනීම, prevent කිරීම සහ defend කිරීම සඳහා cybersecurity knowledge ලබාදීමටයි. 🛡️ ETHICAL CYBERSECURITY AWARENESS Security knowledge should be used to protect systems, not compromise them. මෙම post එකේ අන්තර්ගතය review කරන ඕනෑම moderator / security reviewer කෙනෙකුට එහි context එක පැහැදිලිව පෙන්වීම සඳහා මෙම notice එක ඇතුළත් කර ඇත.
169
19
Long password එකක් තිබුණාම automatically secure කියලා හිතන්න බැහැ. Password එක වෙනත් service එකක breach එකක already exposed නම්, length එකෙන් credential stuffing නවත්වන්නේ නැහැ. 🔍 Brute Force Attack එක detect කරන්නේ කොහොමද.? Security team එකකට obvious signal එක: Many Failed Logins ↓ Short Time Window ↓ Suspicious Source / User Pattern හැබැයි advanced detection එක single IP එකක් විතරක් බලන එක නෙවෙයි. Pattern A 1 IP ↓ User A User B User C User D → Password spraying / credential stuffing වගේ behavior එකක් විය හැක. Pattern B User A ↓ IP 1 IP 2 IP 3 IP 4 → distributed attack pattern එකක් විය හැක. Pattern C Many Failed Attempts ↓ Successful Login MITRE detection guidance එකේ high-volume authentication failures followed by a successful authentication, multiple failures across users, සහ correlated authentication logs වැනි signals explicitly සඳහන් කරයි. OWASP ද login endpoint එකට per-account සහ per-IP / per-IP+ASN rate controls වෙන් වෙන්ව සලකා බලන approach එකක් විස්තර කරයි, distributed attacks සහ credential-stuffing patterns දෙකම address කිරීමට. 🛡️ Brute Force වලට defense කරන්නේ කොහොමද.? 1️⃣ Rate Limiting Login attempts unlimited වෙන්න දෙන්න එපා. NIST SP 800-63B අනුව online guessing වලට rate-limiting mechanism එකක් තිබිය යුතු අතර, current guidance එකේ failed authentication attempts control කිරීම explicit requirement එකක්. 2️⃣ MFA Password compromise වුණත් second authentication factor එකක් attackerට තවත් barrier එකක් create කරනවා. OWASP Authentication guidance එක MFA එක password-related attacks වලට ප්‍රධාන defense එකක් ලෙස දක්වයි. 3️⃣ Compromised Password Blocklist User කෙනෙක් common / previously breached password එකක් select කරන එක prevent කරන්න password blocklist භාවිතා කළ හැක. NIST current guidance එක known compromised passwords, dictionary words සහ context-specific weak passwords වැනි values blocklist එකකට ඇතුළත් කිරීම ගැන සඳහන් කරයි. 4️⃣ Account-Level Controls IP address එකක් block කළාම attack එක අවසන් වෙනවා කියලා assume කිරීම වැරදියි. Attacker IPs rotate කළොත්.? IP 1 → Account A IP 2 → Account A IP 3 → Account A IP 4 → Account A ඒ නිසා username/account-level controls සහ source-level controls දෙකම consider කළ යුතුයි. OWASP මේ distinction එක explicitly highlight කරයි. ❌ Common Misconceptions Brute Force කියන්නේ හැම password එකක්ම try කරන එක. ❌ Incomplete. Brute Force technique family එකට Password Guessing, Password Cracking, Password Spraying සහ Credential Stuffing ඇතුළත් වෙනවා. Strong password එකක් තිබුණාම safe. ❌ Not necessarily. Credential stuffing එකේ attacker password එක guess කරන්නේ නැහැ; previously compromised username/password pair එක reuse කරනවා. IP block කළාම Brute Force නවතිනවා. ❌ Not necessarily. Distributed sources, proxies, bot infrastructure සහ multiple origin addresses නිසා source-only blocking එක insufficient වෙන්න පුළුවන්. OWASP login throttling guidance එක source-level සහ account-level controls දෙකම consider කරයි. Account lockout තමයි perfect solution. ❌ Not always. Overly aggressive lockout policy එක legitimate usersව lock out කිරීමට හේතුවක් වෙන්න පුළුවන්, ඒක operationally denial-of-service condition එකකටත් lead වෙන්න පුළුවන්. MITRE සහ OWASP දෙකම lockout policy එක carefully design කිරීම ගැන සඳහන් කරයි. 🔥 TAKEAWAY Brute Force Attack එකේ core idea එක සරලයි: Repeatedly try candidates until valid credentials are discovered. නමුත් modern authentication attacks වල complexity එක මෙතනින් ගොඩක් එහා යනවා. Brute Force ├── Password Guessing ├── Password Cracking ├── Password Spraying └── Credential Stuffing ඒ නිසා effective defense එකත් එක control එකකින් වෙන්නේ නැහැ. Strong Authentication + Rate Limiting + MFA + Compromised Password Detection + Account / IP Controls + Monitoring & Detection
122
20
🔐 Brute Force Attack කියන්නේ ඇත්තටම මොකක්ද.? Password එකක් “guess කිරීම” කියන සරල අදහසකට Brute Force Attack එක සීමා කරන්න බැහැ. Technical side එකෙන් බැලුවොත්, attacker කෙනෙක්ට valid credentials නොදන්නා අවස්ථාවක, repetitive / systematic attempts භාවිතා කරලා authentication secret එක හඳුනාගැනීමට උත්සාහ කරන attack family එකක් තමයි MITRE ATT&CK T1110 — Brute Force. මෙය online authentication service එකකට against කරන attempts වගේම, ලබාගත් password hashes offline ලෙස crack කිරීමට කරන attempts ද ඇතුළත් කරයි. ඒ කියන්නේ: Unknown Credential │ ▼ Candidate Credentials │ ▼ Repeated Attempts │ ├── Failed → Next Attempt │ └── Success → Valid Credential හැබැයි මෙතන වැදගත් point එකක් තියෙනවා. ⚠️ Modern Brute Force හැම possible password එකක්ම එකින් එක try කරනවා MITRE ATT&CK අනුව Brute Force technique එකට sub-techniques 4 ක් තියෙනවා: 01 Password Guessing Target account එකකට passwords එකින් එක guess කිරීම. Common passwords, dictionary-based candidates, contextual guesses වගේ දේවල් භාවිතා වෙන්න පුළුවන්. Repeated failed authentication attempts නිසා account lockout එකක් trigger වීමේ අවදානමත් තියෙනවා. 02 Password Cracking මේක online login form එකක් hit කරන එකට වඩා වෙනස්. Attacker කෙනෙක්ට password hash එකක් ලැබුණා කියලා හිතන්න. Password ↓ Hash Function ↓ Password Hash ඊට පස්සේ attacker-controlled environment එකක candidate passwords generate කරලා ඒවා hash කරමින් target hash එකට match වෙන එක හොයන්න පුළුවන්. මේ නිසා password cracking එකේදී target login server එකට request hundreds/thousands ගණනක් යවන්න අවශ්‍ය නොවෙන්න පුළුවන්. MITRE මෙය offline credential attack එකක් ලෙසද පැහැදිලි කරයි. 03 Password Spraying මෙතන strategy එක වෙනස්. එක් account එකකට passwords විශාල ගණනක් try කරනවා වෙනුවට Password123 ↓ user01 user02 user03 user04 user05 එක weak/common password එකක් accounts ගණනාවක් against try කරනවා. මේකෙන් individual account එකක failed-attempt threshold එක ඉක්මවා account lockout trigger කිරීමෙන් වැළකීමට attacker උත්සාහ කරයි. 04 Credential Stuffing මේකත් brute-force family එකේ තියෙන නමුත් mechanism එක වෙනස්. Attacker guess කරන එකක් නෙවෙයි. වෙනත් service එකක breach එකකින් ලැබුණු: username + password pairs target service එකක නැවත භාවිතා කරලා login attempt කරනවා. මේ attack එකේ underlying problem එක තමයි password reuse. User කෙනෙක් එකම password එක services කිහිපයක භාවිතා කළොත්, එක් service එකක compromise එකක් වෙනත් accounts වලටත් අවදානමක් වෙන්න පුළුවන්. 🌐 Online vs Offline Brute Force මේ distinction එක cybersecurity වලදී ඉතා වැදගත්. Online Attack Attacker │ │ Login Attempt ▼ Authentication Server │ ├── Fail └── Success Server එක request එක verify කරන නිසා rate limiting, lockout, CAPTCHA/bot controls, MFA වගේ defenses attacker's attempt rate එක dramatically reduce කරන්න පුළුවන්. NIST current guidance එක online guessing වලට rate-limiting controls අවශ්‍ය බව explicitly සඳහන් කරයි. Offline Attack Password Hash │ ▼ Attacker-controlled System │ ├── Candidate Password ├── Hash ├── Compare └── Repeat Server එකට repeated login requests යවන්නේ නැති නිසා online throttling එකෙන් මේ attack process එක directly stop කරන්න බැහැ. ඒ නිසා secure password hashing + unique passwords + strong authentication architecture critical වෙනවා. 🧠 Brute Force වැඩ කරන්නේ මොන මතද.? මූලිකව attacker's success එක බලපාන්නේ: Search Space + Credential Quality + Authentication Controls + Attack Environment උදාහරණයක් ලෙස password එකේ possible combinations වැඩි වෙනකොට exhaustive search එක theoretically වැඩි වෙන්න පුළුවන්. නමුත් real-world attackers හැම වෙලාවෙම mathematical brute force එකෙන් පටන් ගන්නේ නැහැ. Common passwords, breached credentials, password reuse සහ human patterns වගේ දේවල් exploitation කිරීම බොහෝ විට attack surface එක practical ලෙස වෙනස් කරනවා. OWASP ද common-password dictionaries, compromised credentials සහ automated authentication attacks ගැන අවධාරණය කරයි. ඒ නිසා:
104