Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
SocialPwned — SocialPwned هي أداة OSINT تتيح الحصول على رسائل البريد الإلكتروني، من هدف معيّن، المنشورة على الشبكات الاجتماعية مثل Instagram وLinkedin وTwitter للعثور على تسريبات محتملة لبيانات الاعتماد في PwnDB أو Dehashed والحصول على معلومات حساب Google عبر GHunt. | Kitploit
أدوات/GitHubGitHub/mrtuxx/socialpwned
الاستخبارات مفتوحة المصدر (OSINT)كسر كلمات المرورالاستطلاعجمع المعلوماتأمن الويباختبار الاختراقالهندسة الاجتماعيةجمع البريد الإلكترونيArchived
GitHubmrtuxx/socialpwned

SocialPwned

SocialPwned هي أداة OSINT تتيح الحصول على رسائل البريد الإلكتروني، من هدف معيّن، المنشورة على الشبكات الاجتماعية مثل Instagram وLinkedin وTwitter للعثور على تسريبات محتملة لبيانات الاعتماد في PwnDB أو Dehashed والحصول على معلومات حساب Google عبر GHunt.

1.3k1235منذ سنة واحدةتمت المراجعة من قبل Kitploit

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
عرض المستودع

SocialPwned

SocialPwned

Python 3.8 License: GPL v3

SocialPwned هي أداة OSINT تسمح بالحصول على رسائل البريد الإلكتروني، من هدف معين، المنشورة في شبكات التواصل الاجتماعي مثل إنستغرام ولينكد إن وتويتر للعثور على تسريبات بيانات الاعتماد المحتملة في PwnDB أو Dehashed والحصول على معلومات حساب Google عبر GHunt.

الغرض من هذه الأداة هو تسهيل البحث عن الأهداف الضعيفة خلال مرحلة البصمة (Footprinting) في الاختراق الأخلاقي. من الشائع أن ينشر موظفو الشركة رسائلهم الإلكترونية في شبكات التواصل الاجتماعي، سواء المهنية أو الشخصية، لذا إذا تم تسريب بيانات اعتماد هذه الرسائل الإلكترونية، فمن الممكن أن تكون كلمات المرور التي تم العثور عليها قد أُعيد استخدامها في البيئة المراد تدقيقها. إذا لم يكن الأمر كذلك، فعلى الأقل سيكون لديك فكرة عن الأنماط التي يتبعها هذا الهدف لإنشاء كلمات المرور وستتمكن من تنفيذ هجمات أخرى بمستوى أعلى من الفعالية.

يستخدم SocialPwned وحدات مختلفة:

  • إنستغرام: باستخدام Instagram API غير الرسمي من @LevPasha، تم تطوير طرق مختلفة للحصول على رسائل البريد الإلكتروني المنشورة من قبل المستخدمين. يلزم حساب إنستغرام.
  • لينكد إن: باستخدام Linkedin API غير الرسمي من @tomquirk، تم تطوير طرق مختلفة للحصول على موظفي الشركة ومعلومات الاتصال الخاصة بهم (البريد الإلكتروني، تويتر أو الهاتف). بالإضافة إلى ذلك، يمكن إضافة الموظفين الذين تم العثور عليهم إلى جهات اتصالك، بحيث يمكنك لاحقاً الوصول إلى شبكة جهات الاتصال والمعلومات الخاصة بهم. تقوم هذه الوحدة أيضاً بإنشاء ملفات مختلفة بمجموعات من أسماء المستخدمين المحتملة لمؤسسة ما. يلزم حساب لينكد إن.
  • Twint: باستخدام Twint من @twintproject يمكنك تتبع جميع التغريدات المنشورة من قبل مستخدم للبحث عن بعض البريد الإلكتروني. ليس من الضروري وجود حساب تويتر.
  • PwnDB: مستوحاة من الأداة PwnDB التي أنشأها @davidtavarez، تم تطوير وحدة تبحث عن جميع تسريبات بيانات الاعتماد من رسائل البريد الإلكتروني التي تم العثور عليها. بالإضافة إلى ذلك، يتم إجراء طلب POST لكل بريد إلكتروني إلى HaveIBeenPwned لمعرفة مصدر التسريب.
  • Dehashed: توفر كلمات مرور واضحة وأيضاً تجزئة كلمات المرور التي لم يتم فك تشفيرها. من الضروري الدفع في Dehashed للحصول على مفتاح API، ولكن يمكن أن يكون بديلاً جيداً عندما تكون PwnDB بطيئة أو لا تقدم نتائج.
  • GHunt: باستخدام الأداة التي أنشأها @mxrch، GHunt، يمكن الحصول على معلومات متعلقة برسائل Gmail الإلكترونية، مثل المراجعات وصورة الملف الشخصي والموقع المحتمل أو أحداث التقويم العامة.

التثبيت 🛠

الطريقة السهلة

root@kitploit:~
$ service docker start
$ docker pull mrtuxx/socialpwned
$ docker run -v $(pwd)/credentials.json:/socialpwned/credentials.json -v $(pwd)/output:/socialpwned/output -it mrtuxx/socialpwned socialpwned.py --credentials credentials.json --help

ملاحظة: ستحتاج إلى تثبيت خدمة docker بشكل صحيح.

الطريقة اليدوية

يعتمد تثبيت Tor على نظامك. على دبيان:

root@kitploit:~
$ sudo apt-get install tor
$ /etc/init.d/tor start

استنساخ المستودع باستخدام Git:

root@kitploit:~
$ git clone https://github.com/MrTuxx/SocialPwned.git
$ cd SocialPwned
$ sudo pip3 install --user --upgrade git+https://github.com/twintproject/twint.git@origin/master#egg=twint
$ sudo pip3 install -r requirements.txt
$ sudo python3 socialpwned.py --credentials credentials.json --help

لكي تعمل وحدة GHunt بشكل صحيح، يجب اتباع هذه الخطوات:

  • GHunt التثبيت اليدوي

الاستخدام

لاستخدام ميزات إنستغرام ولينكد إن، يجب أن يكون لديك حساب تم إنشاؤه على كل من شبكات التواصل الاجتماعي. يجب الإشارة إلى بيانات الاعتماد في ملف JSON:

root@kitploit:~
{
    "instagram":{
        "username":"username",
        "password":"password"
    },
    "linkedin":{
        "email":"email",
        "password":"password"
    },
    "ghunt":{
        "SID":"SID",
        "SSID":"SSID",
        "APISID":"APISID",
        "SAPISID":"SAPISID",
        "HSID":"HSID"
    },
    "dehashed":{
         "email":"email",
         "apikey":"apikey"
    }
}

ملاحظة: يمكن الحصول على ملفات تعريف الارتباط اللازمة لوحدة GHunt باتباع الخطوات الموضحة هنا.

root@kitploit:~
usage: socialpwned.py [-h] --credentials CREDENTIALS [--pwndb] [--tor-proxy PROXY] [--instagram] [--info QUERY]
                      [--location LOCATION_ID] [--hashtag-ig QUERY] [--target-ig USERNAME] [--search-users-ig QUERY]
                      [--my-followers] [--my-followings] [--followers-ig] [--followings-ig] [--linkedin]
                      [--company COMPANY_ID] [--search-companies QUERY] [--employees] [--my-contacts]
                      [--user-contacts USER_ID] [--search-users-in QUERY] [--target-in USERNAME] [--add-contacts]
                      [--add-a-contact USER_ID] [--twitter] [--limit LIMIT] [--year YEAR] [--since DATE]
                      [--until DATE] [--profile-full] [--all-tw] [--target-tw USERNAME] [--hashtag-tw USERNAME]
                      [--followers-tw] [--followings-tw] [--ghunt] [--email-gh [email protected]] [--dehashed]
                      [--email-dh [email protected]]

إذا قمت بسحب صورة docker، فيجب تشغيل:

root@kitploit:~
docker run -v $(pwd)/<YOUR CREDENTIALS JSON FILE>:/socialpwned/credentials.json -v $(pwd)/output:/socialpwned/output -it mrtuxx/socialpwned socialpwned.py --credentials credentials.json <COMMANDS>

نصائح 📌

  1. احتفظ بجلسات لينكد إن وإنستغرام في متصفح لحل أي حظر محتمل. تفاعل بطريقة طبيعية.

  2. قبل محاولة الحصول على جميع رسائل البريد الإلكتروني لموظفي مؤسسة ما على لينكد إن، تأكد من أن لديك شبكة واسعة من جهات الاتصال، وأصدقاء مشتركين، وبعض الموظفين المضافين إلى شبكتك. في كثير من الأحيان لا يمكنك رؤية معلومات جهة اتصال إذا لم تكن في شبكتك.

  3. حاول عدم إجراء عمليات بحث ضخمة لتجنب الحظر.

  4. قم بدمج الوحدات عندما يكون الهدف محدداً أو لن يتم التعامل مع كمية كبيرة من المعلومات، وإلا فقد تفشل أو يتم حظرك.

تنسيق الإخراج 💾

في كل مرة يتم تشغيل SocialPwned، سيتم إنشاء دليل بالتنسيق التالي:

root@kitploit:~
output
└── session_year_month_day_time
    ├── dehashed
    │   ├── raw_dehashed.txt
    │   └── socialpwned_dehashed.txt
    ├── emails
    │   └── socialpwned_emails.txt
    ├── instagram
    │   └── socialpwned_instagram.txt
    ├── linkedin_userames
    │   ├── first.last.txt
    │   ├── firstl.txt
    │   ├── first.txt
    │   ├── f.last.txt
    │   ├── flast.txt
    │   ├── lastf.txt
    │   └── rawnames.txt
    ├── pwndb
    │   ├── passwords_pwndb.txt
    │   ├── pwndb.txt
    │   └── socialpwned_pwndb.txt
    ├── socialpwned.json
    └── twitter
        └── socialpwned_twitter.txt
  • يحتوي دليل dehashed على معلومات API الخام في ملف واحد وكلمات المرور المتعلقة بالبريد الإلكتروني في ملف آخر.
  • يحتوي دليل pwndb على ملف يحتوي على كلمات المرور فقط، وآخر يحتوي على كلمات المرور ورسائل البريد الإلكتروني ذات الصلة، وأخيراً ملف يضيف مصادر التسريبات.
  • يحتوي دليل emails على ملف يحتوي على جميع رسائل البريد الإلكتروني التي تم الحصول عليها.
  • يحتوي دليل instagram على ملف يحتوي على حسابات المستخدمين وعناوين بريدهم الإلكتروني ذات الصلة.
  • يحتوي دليل twitter على ملف يحتوي على حسابات المستخدمين وعناوين بريدهم الإلكتروني ذات الصلة.
  • يحتوي دليل linkedin على ملفات مختلفة بمجموعات من أسماء المستخدمين التي تم الحصول عليها. مستوحاة من أداة linkedin2username.
  • يوفر ملف socialpwned.json بتنسيق JSON جميع المعلومات التي تم الحصول عليها بواسطة SocialPwned ووحداته المختلفة. حيث يكون معرف كل عنصر هو البريد الإلكتروني، وفي حالة وجود معلومات عن مستخدم ولكن ليس بريده الإلكتروني، سيكون المعرف هو معرف شبكة التواصل الاجتماعي الفريد الخاص به.

أمثلة أساسية ومجموعات 🚀

فيديو توضيحي

SocialPwned

فيما يلي بعض الأمثلة:

إنستغرام

SocialPwned SocialPwned

root@kitploit:~
docker run -v $(pwd)/credentials.json:/socialpwned/credentials.json -v $(pwd)/output:/socialpwned/output -it mrtuxx/socialpwned socialpwned.py --credentials credentials.json --instagram --info España
root@kitploit:~
docker run -v $(pwd)/credentials.json:/socialpwned/credentials.json -v $(pwd)/output:/socialpwned/output -it mrtuxx/socialpwned socialpwned.py --credentials credentials.json --instagram --location 832578276
root@kitploit:~
docker run -v $(pwd)/credentials.json:/socialpwned/credentials.json -v $(pwd)/output:/socialpwned/output -it mrtuxx/socialpwned socialpwned.py --credentials credentials.json --instagram --hashtag-ig someHashtag --pwndb
root@kitploit:~
docker run -v $(pwd)/credentials.json:/socialpwned/credentials.json -v $(pwd)/output:/socialpwned/output -it mrtuxx/socialpwned socialpwned.py --credentials credentials.json --instagram --target-ig username --pwndb
root@kitploit:~
docker run -v $(pwd)/credentials.json:/socialpwned/credentials.json -v $(pwd)/output:/socialpwned/output -it mrtuxx/socialpwned socialpwned.py --credentials credentials.json --instagram --target-ig username --followers-ig --followings-ig --pwndb

لينكد إن

SocialPwned SocialPwned SocialPwned

root@kitploit:~
docker run -v $(pwd)/credentials.json:/socialpwned/credentials.json -v $(pwd)/output:/socialpwned/output -it mrtuxx/socialpwned socialpwned.py --credentials credentials.json --linkedin --search-companies "My Target"
root@kitploit:~
docker run -v $(pwd)/credentials.json:/socialpwned/credentials.json -v $(pwd)/output:/socialpwned/output -it mrtuxx/socialpwned socialpwned.py --credentials credentials.json --linkedin --search-companies "My Target" --employees --pwndb
root@kitploit:~
docker run -v $(pwd)/credentials.json:/socialpwned/credentials.json -v $(pwd)/output:/socialpwned/output -it mrtuxx/socialpwned socialpwned.py --credentials credentials.json --linkedin --company 123456789 --employees --pwndb
root@kitploit:~
docker run -v $(pwd)/credentials.json:/socialpwned/credentials.json -v $(pwd)/output:/socialpwned/output -it mrtuxx/socialpwned socialpwned.py --credentials credentials.json --linkedin --company 123456789 --employees --add-contacts
root@kitploit:~
docker run -v $(pwd)/credentials.json:/socialpwned/credentials.json -v $(pwd)/output:/socialpwned/output -it mrtuxx/socialpwned socialpwned.py --credentials credentials.json --linkedin --user-contacts user-id --pwndb
root@kitploit:~
docker run -v $(pwd)/credentials.json:/socialpwned/credentials.json -v $(pwd)/output:/socialpwned/output -it mrtuxx/socialpwned socialpwned.py --credentials credentials.json --linkedin --user-contacts user-id --add-contacts

تويتر

SocialPwned

root@kitploit:~
docker run -v $(pwd)/credentials.json:/socialpwned/credentials.json -v $(pwd)/output:/socialpwned/output -it mrtuxx/socialpwned socialpwned.py --credentials credentials.json --twitter --hashtag-tw someHashtag --pwndb --limit 200 --dehashed
root@kitploit:~
docker run -v $(pwd)/credentials.json:/socialpwned/credentials.json -v $(pwd)/output:/socialpwned/output -it mrtuxx/socialpwned socialpwned.py --credentials credentials.json --twitter --target-tw username --all-tw --pwndb --dehashed --ghunt
root@kitploit:~
docker run -v $(pwd)/credentials.json:/socialpwned/credentials.json -v $(pwd)/output:/socialpwned/output -it mrtuxx/socialpwned socialpwned.py --credentials credentials.json --twitter --target-tw username --all-tw --followers-tw --followings-tw --pwndb

GHunt

SocialPwned

root@kitploit:~
docker run -v $(pwd)/credentials.json:/socialpwned/credentials.json -v $(pwd)/output:/socialpwned/output -it mrtuxx/socialpwned socialpwned.py --credentials credentials.json --ghunt --email-gh "[email protected]"

ملاحظة: كلما أضفت العلامة --ghunt سيتم تنفيذ هذه الوحدة. إذا قمت بذلك في بحث جماعي، فقد تفشل بسبب كمية الطلبات.

Dehashed

SocialPwned

root@kitploit:~
docker run -v $(pwd)/credentials.json:/socialpwned/credentials.json -v $(pwd)/output:/socialpwned/output -it mrtuxx/socialpwned socialpwned.py --credentials credentials.json --dehashed --email-dh "[email protected]"

ملاحظة: إضافة العلامة --dehashed في نهاية كل بحث سيقوم بتقديم طلب API لكل بريد إلكتروني.

المجموعات

root@kitploit:~
docker run -v $(pwd)/credentials.json:/socialpwned/credentials.json -v $(pwd)/output:/socialpwned/output -it mrtuxx/socialpwned socialpwned.py --credentials credentials.json --instagram --target-ig username --followers-ig --followings-ig --linkedin --company 123456789 --employees --twitter --target-tw username --all-tw --pwndb --ghunt --dehashed
root@kitploit:~
docker run -v $(pwd)/credentials.json:/socialpwned/credentials.json -v $(pwd)/output:/socialpwned/output -it mrtuxx/socialpwned socialpwned.py --credentials credentials.json --instagram --target-ig username --linkedin --target-in username --twitter --target-tw username --all-tw --pwndb --ghunt --dehashed

المراجع 📚

  • Instagram API. المؤلف: LevPasha
  • Linkedin API. المؤلف: tomquirk
  • Twint. المؤلف: twintproject
  • PwnDB. المؤلف: davidtavarez
  • GHunt. المؤلف: mxrch

إخلاء مسؤولية ⚠️

استخدام SocialPwned لمهاجمة أهداف دون موافقة مسبقة متبادلة هو أمر غير قانوني. بالإضافة إلى ذلك، يستخدم وحدات مختلفة تنتهك قواعد لينكد وإن وإنستغرام، وبالتالي، سيتم حظرك مؤقتاً أو دائماً.

تقع على عاتق المستخدم النهائي مسؤولية استخدام SocialPwned. المطورون ليسوا مسؤولين ولا يتحملون أي مسؤولية عن أي سوء استخدام أو ضرر ناتج.

تنزيل الأداة