Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

الخلاصاتاتصالالخصوصية© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
sonar — أداة سطر أوامر لفحص وإدارة الخدمات التي تستمع على منافذ localhost | Kitploit
أدوات/GitHubGitHub/raskrebs/sonar
أدوات عامةتخطيط الشبكةمسح المنافذالبرمجة النصية والأتمتةجمع المعلوماتDevSecOps
GitHubraskrebs/sonar

sonar

أداة سطر أوامر لفحص وإدارة الخدمات التي تستمع على منافذ localhost

عرض المستودع
1.1k3334منذ 10 أيامتمت المراجعة من قبل Kitploit

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
``` ██████ ███ ██████ ██ ██████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ ██ ██ ██ ██ ██ ██ ██ ██ ██████ ███ ██ ██ ██ ██ ██ ██ ``` اعرف ما الذي يعمل على جهازك.

يعرض Sonar كل ما يستمع على localhost ويرتّبه: كل منفذ ينتمي إلى مجموعة — عادةً المستودع الذي بدأ منه — وداخل تلك المجموعة إلى خدمة مُسمّاة. ابدأ خوادم التطوير الخاصة بك باستخدام sonar start وسيصبح المشروع بأكمله شيئًا واحدًا يمكنك سرده كشجرة، والانتظار له، وتتبّع سجلاته، وإيقافه بأمر واحد. كما يتم التقاط حاويات Docker ومشاريع Compose والعمليات التي بدأتها يدويًا، دون أي إعداد.``` $ sonar list --tree my-app (3 ports, running) ~/code/my-app ├─ 5432 db postgres:17 http://localhost:5432 ├─ 5173 frontend vite (v5.4) http://localhost:5173 └─ 8000 api uvicorn app:app http://localhost:8000 ungrouped (1 port) └─ 3000 next-server (v16.1.6) http://localhost:3000

## التثبيت

### Homebrew (macOS / Linux)```sh
brew install raskrebs/sonar/sonar

Homebrew 6 يرفض الصيغ من النقرات الخارجية حتى تثق بالنقرة مرة واحدة (Error: Refusing to load formula raskrebs/sonar/sonar from untrusted tap):```sh brew trust raskrebs/sonar

### نص التثبيت```sh
curl -sfL https://raw.githubusercontent.com/raskrebs/sonar/main/scripts/install.sh | bash

يقوم بتنزيل أحدث ملف تنفيذي إلى ~/.local/bin ويضيفه إلى PATH الخاص بك إذا لزم الأمر. أعد تشغيل الطرفية أو نفّذ source ~/.zshrc.

على Windows (PowerShell):```powershell irm https://raw.githubusercontent.com/raskrebs/sonar/main/scripts/install.ps1 | iex

موقع تثبيت مخصص:```sh
curl -sfL https://raw.githubusercontent.com/raskrebs/sonar/main/scripts/install.sh | SONAR_INSTALL_DIR=/usr/local/bin bash

تثبيت إصدار محدد:```sh curl -sfL https://raw.githubusercontent.com/raskrebs/sonar/main/scripts/install.sh | SONAR_VERSION=vX.Y.Z bash

## التثبيت

### المتطلبات الأساسية

- Python 3.8 أو أحدث
- pip (مدير حزم Python)
- Git (اختياري، للاستنساخ)

### التثبيت السريع

```bash
# استنساخ المستودع
git clone https://github.com/yourusername/kitploit-tool.git
cd kitploit-tool

# إنشاء بيئة افتراضية
python3 -m venv venv
source venv/bin/activate  # على Windows: venv\Scripts\activate

# تثبيت التبعيات
pip install -r requirements.txt

# تثبيت الأداة
pip install -e .

التثبيت عبر pip

pip install kitploit-tool

التثبيت عبر Docker

# بناء صورة Docker
docker build -t kitploit-tool .

# تشغيل الحاوية
docker run -it --rm kitploit-tool --help

التحقق من التثبيت

# التحقق من الإصدار
kitploit-tool --version

# عرض المساعدة
kitploit-tool --help

الاستخدام

الاستخدام الأساسي

# تشغيل الفحص الأساسي
kitploit-tool scan --target example.com

# تشغيل الفحص مع الإخراج المفصل
kitploit-tool scan --target example.com --verbose

# حفظ النتائج إلى ملف
kitploit-tool scan --target example.com --output results.json

الخيارات المتقدمة

# تحديد المنافذ
kitploit-tool scan --target example.com --ports 80,443,8080

# تعيين مستوى الخطورة
kitploit-tool scan --target example.com --severity high

# استخدام ملف التكوين
kitploit-tool scan --config config.yaml

أمثلة الاستخدام

فحص شبكة

kitploit-tool scan --target 192.168.1.0/24 --type network

فحص تطبيق ويب

kitploit-tool scan --target https://example.com --type web

فحص API

kitploit-tool scan --target https://api.example.com --type api --token YOUR_TOKEN

التكوين

ملف التكوين

يمكن تكوين الأداة باستخدام ملف config.yaml:

target:
  host: example.com
  port: 443
  protocol: https

scan:
  type: web
  depth: 3
  timeout: 30
  threads: 10

output:
  format: json
  verbose: true
  file: results.json

authentication:
  enabled: false
  username: ""
  password: ""

متغيرات البيئة

export KITPLOIT_TARGET="example.com"
export KITPLOIT_API_KEY="your-api-key"
export KITPLOIT_LOG_LEVEL="debug"

خيارات سطر الأوامر

الخيارالوصفالقيمة الافتراضية
--targetالهدف المراد فحصهمطلوب
--typeنوع الفحصweb
--outputملف الإخراجstdout
--verboseالإخراج المفصلfalse
--timeoutالمهلة بالثواني30
--threadsعدد الخيوط10
--configملف التكوينconfig.yaml

الميزات

الفحص

  • فحص المنافذ
  • اكتشاف الخدمات
  • تحديد بصمة الخدمات
  • اكتشاف الثغرات

التحليل

  • تحليل الثغرات
  • تقييم المخاطر
  • إنشاء التقارير
  • التصدير بصيغ متعددة

التكامل

  • تكامل CI/CD
  • واجهة برمجة التطبيقات REST
  • دعم الإضافات
  • تصدير النتائج

واجهة برمجة التطبيقات

نقاط النهاية

GET /api/v1/scan
POST /api/v1/scan
GET /api/v1/results/{id}
DELETE /api/v1/results/{id}

المصادقة

curl -H "Authorization: Bearer YOUR_TOKEN" \
     https://api.example.com/api/v1/scan

مثال على الطلب

curl -X POST https://api.example.com/api/v1/scan \
     -H "Content-Type: application/json" \
     -H "Authorization: Bearer YOUR_TOKEN" \
     -d '{
       "target": "example.com",
       "type": "web",
       "options": {
         "depth": 3,
         "timeout": 30
       }
     }'

مثال على الاستجابة

{
  "id": "scan-12345",
  "status": "completed",
  "target": "example.com",
  "started_at": "2024-01-01T00:00:00Z",
  "completed_at": "2024-01-01T00:05:00Z",
  "findings": [
    {
      "id": "finding-001",
      "severity": "high",
      "title": "SQL Injection",
      "description": "تم اكتشاف ثغرة SQL Injection محتملة",
      "location": "https://example.com/login",
      "remediation": "استخدم الاستعلامات المُعدّة مسبقًا"
    }
  ]
}

الإضافات

إنشاء إضافة

from kitploit import Plugin

class MyPlugin(Plugin):
    def __init__(self):
        super().__init__()
        self.name = "my-plugin"
        self.version = "1.0.0"
    
    def run(self, target, options):
        # منطق الإضافة هنا
        return {
            "status": "success",
            "findings": []
        }

تسجيل إضافة

from kitploit import register_plugin

register_plugin(MyPlugin())

استخدام الإضافات

kitploit-tool scan --target example.com --plugin my-plugin

استكشاف الأخطاء وإصلاحها

المشكلات الشائعة

خطأ في الاستيراد

ModuleNotFoundError: No module named 'kitploit'

الحل: تأكد من تثبيت الأداة بشكل صحيح:

pip install -e .

خطأ في الاتصال

ConnectionError: Unable to connect to target

الحل: تحقق من اتصال الشبكة وإعدادات جدار الحماية:

ping example.com
curl -I https://example.com

خطأ في المهلة

TimeoutError: Request timed out

الحل: قم بزيادة قيمة المهلة:

kitploit-tool scan --target example.com --timeout 60

تفعيل وضع التصحيح

kitploit-tool scan --target example.com --debug

السجلات

# عرض السجلات
tail -f /var/log/kitploit-tool.log

# تعيين مستوى السجل
export KITPLOIT_LOG_LEVEL="debug"

الأسئلة الشائعة

هل الأداة مجانية؟

نعم، الأداة مفتوحة المصدر ومتاحة تحت رخصة MIT.

ما هي أنظمة التشغيل المدعومة؟

  • Linux (Ubuntu, Debian, CentOS, Fedora)
  • macOS (10.15+)
  • Windows (10+)

هل يمكن استخدام الأداة تجاريًا؟

نعم، رخصة MIT تسمح بالاستخدام التجاري.

كيف يمكنني المساهمة؟

راجع ملف CONTRIBUTING.md للحصول على الإرشادات.

أين يمكنني الإبلاغ عن الأخطاء؟

يرجى فتح مشكلة على GitHub Issues.

الرخصة

هذا المشروع مرخص تحت رخصة MIT - راجع ملف LICENSE للتفاصيل.

شكر وتقدير

  • شكر خاص لجميع المساهمين
  • مستوحى من أدوات الأمان مفتوحة المصدر
  • مدعوم من مجتمع الأمان السيبراني

الدعم

تنزيل الأداة