
نصوص التثبيت لنظامي لينكس وmacOS وويندوز لأدوات cnquery وcnspec
أسهل طريقة لتثبيت mql و cnspec هي استخدام نصوص التثبيت.
https://install.mondoo.com/sh```bash
bash -c "$(curl -sSL https://install.mondoo.com/sh)"
### عبر PowerShell (Windows)
[`https://install.mondoo.com/ps1`](https://install.mondoo.com/ps1)```powershell
Set-ExecutionPolicy Unrestricted -Scope Process -Force;
[System.Net.ServicePointManager]::SecurityProtocol = [System.Net.ServicePointManager]::SecurityProtocol -bor 3072;
iex ((New-Object System.Net.WebClient).DownloadString('https://install.mondoo.com/ps1'));
Install-Mondoo;
مرّر الوكيل إلى سكربت التثبيت باستخدام -x (لينكس و macOS) أو -Proxy
(ويندوز). يوجّه السكربت تنزيلاته الخاصة، وتثبيت الحزمة،
وcnspec login والمحدّث التلقائي عبره. يحدث التنزيل الأولي
للسكربت قبل قراءة العَلم، لذا وجّه ذلك إلى الوكيل أيضًا:```bash
export https_proxy='http://proxy.example.com:3128'
curl -sSL --proxy "$https_proxy" https://install.mondoo.com/sh | bash -s -- -x "$https_proxy"
## الميزات الرئيسية
- **اكتشاف تلقائي**: يكتشف تلقائيًا جميع نقاط النهاية (endpoints) المتاحة من مواصفات OpenAPI
- **توليد ذكي للحمولات (Payloads)**: ينشئ حمولات اختبار واقعية بناءً على مخططات API
- **اختبار أمني شامل**: يختبر نقاط الضعف الشائعة في API بما في ذلك:
- حقن SQL (SQL Injection)
- البرمجة النصية عبر المواقع (XSS)
- تجاوز المصادقة (Authentication Bypass)
- الوصول غير المصرح به (IDOR)
- حقن الأوامر (Command Injection)
- اجتياز المسار (Path Traversal)
- وحقن NoSQL
- **تقارير مفصلة**: ينشئ تقارير شاملة بتنسيقات متعددة (JSON، HTML، Markdown)
- **دعم المصادقة**: يدعم طرق المصادقة المتعددة (Bearer Token، API Key، Basic Auth)
- **تكوين مرن**: خيارات تكوين شاملة عبر ملفات التكوين أو متغيرات البيئة
- **جاهز لـ CI/CD**: يتكامل بسهولة مع خطوط أنابيب CI/CD
## التثبيت
### من المصدر
```bash
git clone https://github.com/yourusername/api-fuzzer.git
cd api-fuzzer
pip install -r requirements.txt
pip install api-fuzzer
docker build -t api-fuzzer .
docker run -v $(pwd)/reports:/app/reports api-fuzzer -s https://api.example.com/openapi.json
python api_fuzzer.py -s https://api.example.com/openapi.json
python api_fuzzer.py \
-s https://api.example.com/openapi.json \
-o reports \
-f json html markdown \
-t 20 \
--timeout 15 \
--auth-type bearer \
--auth-token YOUR_TOKEN \
-v
| الخيار | الوصف | الافتراضي |
|---|---|---|
-s, --spec | مسار أو URL لمواصفات OpenAPI | مطلوب |
-o, --output | دليل الإخراج للتقارير | reports |
-f, --format | تنسيقات التقرير (json، html، markdown) | json |
-t, --threads | عدد الخيوط المتزامنة | 10 |
--timeout | مهلة الطلب بالثواني | 10 |
--auth-type | نوع المصادقة (bearer، api_key، basic) | none |
--auth-token | رمز المصادقة أو مفتاح API | none |
--config | مسار ملف التكوين | none |
-v, --verbose | تمكين الإخراج المفصل | false |
أنشئ ملف config.yaml:
target:
spec_url: "https://api.example.com/openapi.json"
base_url: "https://api.example.com"
timeout: 10
authentication:
type: "bearer"
token: "your_token_here"
fuzzing:
threads: 10
delay: 0.1
max_requests_per_endpoint: 50
payloads:
sql_injection: true
xss: true
command_injection: true
path_traversal: true
nosql_injection: true
reporting:
formats:
- json
- html
- markdown
output_dir: "reports"
include_poc: true
export API_FUZZER_SPEC_URL="https://api.example.com/openapi.json"
export API_FUZZER_AUTH_TOKEN="your_token_here"
export API_FUZZER_THREADS=20
python api_fuzzer.py -s https://petstore.swagger.io/v2/swagger.json -o reports
python api_fuzzer.py \
-s https://api.example.com/openapi.json \
--auth-type bearer \
--auth-token "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..." \
-f json html
python api_fuzzer.py --config config.yaml
api-fuzzer/
├── api_fuzzer.py # نقطة الدخول الرئيسية
├── requirements.txt # تبعيات Python
├── config.yaml # مثال على ملف التكوين
├── Dockerfile # تكوين Docker
├── README.md # هذا الملف
├── modules/
│ ├── __init__.py
│ ├── parser.py # محلل مواصفات OpenAPI
│ ├── fuzzer.py # محرك الاختبار
│ ├── payloads.py # مولّد الحمولات
│ ├── auth.py # معالجة المصادقة
│ └── reporter.py # توليد التقارير
└── tests/
├── __init__.py
└── test_fuzzer.py # اختبارات الوحدة
نرحب بالمساهمات! يرجى اتباع الخطوات التالية:
git checkout -b feature/amazing-feature)git commit -m 'Add amazing feature')git push origin feature/amazing-feature)هذا المشروع مرخص بموجب ترخيص MIT - راجع ملف LICENSE للحصول على التفاصيل.
للاستخدام التعليمي والاختبار الأمني المصرح به فقط.
هذه الأداة مخصصة لاختبار الاختراق الأخلاقي واختبار الأمان. يجب عليك:
المطورون غير مسؤولين عن أي سوء استخدام أو أضرار ناتجة عن هذه الأداة.