
أداة سطر أوامر لفحص وإدارة الخدمات التي تستمع على منافذ localhost
يعرض Sonar كل ما يستمع على localhost ويرتّبه: كل منفذ
ينتمي إلى مجموعة — عادةً المستودع الذي بدأ منه — وداخل
تلك المجموعة إلى خدمة مُسمّاة. ابدأ خوادم التطوير الخاصة بك باستخدام
sonar start وسيصبح المشروع بأكمله شيئًا واحدًا يمكنك سرده كشجرة،
والانتظار له، وتتبّع سجلاته، وإيقافه بأمر واحد. كما يتم التقاط حاويات Docker ومشاريع
Compose والعمليات التي بدأتها يدويًا، دون أي
إعداد.```
$ sonar list --tree
my-app (3 ports, running) ~/code/my-app
├─ 5432 db postgres:17 http://localhost:5432
├─ 5173 frontend vite (v5.4) http://localhost:5173
└─ 8000 api uvicorn app:app http://localhost:8000
ungrouped (1 port)
└─ 3000 next-server (v16.1.6) http://localhost:3000
## التثبيت
### Homebrew (macOS / Linux)```sh
brew install raskrebs/sonar/sonar
Homebrew 6 يرفض الصيغ من النقرات الخارجية حتى تثق بالنقرة مرة واحدة
(Error: Refusing to load formula raskrebs/sonar/sonar from untrusted tap):```sh
brew trust raskrebs/sonar
### نص التثبيت```sh
curl -sfL https://raw.githubusercontent.com/raskrebs/sonar/main/scripts/install.sh | bash
يقوم بتنزيل أحدث ملف تنفيذي إلى ~/.local/bin ويضيفه إلى PATH الخاص بك إذا لزم الأمر. أعد تشغيل الطرفية أو نفّذ source ~/.zshrc.
على Windows (PowerShell):```powershell irm https://raw.githubusercontent.com/raskrebs/sonar/main/scripts/install.ps1 | iex
موقع تثبيت مخصص:```sh
curl -sfL https://raw.githubusercontent.com/raskrebs/sonar/main/scripts/install.sh | SONAR_INSTALL_DIR=/usr/local/bin bash
تثبيت إصدار محدد:```sh curl -sfL https://raw.githubusercontent.com/raskrebs/sonar/main/scripts/install.sh | SONAR_VERSION=vX.Y.Z bash
## التثبيت
### المتطلبات الأساسية
- Python 3.8 أو أحدث
- pip (مدير حزم Python)
- Git (اختياري، للاستنساخ)
### التثبيت السريع
```bash
# استنساخ المستودع
git clone https://github.com/yourusername/kitploit-tool.git
cd kitploit-tool
# إنشاء بيئة افتراضية
python3 -m venv venv
source venv/bin/activate # على Windows: venv\Scripts\activate
# تثبيت التبعيات
pip install -r requirements.txt
# تثبيت الأداة
pip install -e .
pip install kitploit-tool
# بناء صورة Docker
docker build -t kitploit-tool .
# تشغيل الحاوية
docker run -it --rm kitploit-tool --help
# التحقق من الإصدار
kitploit-tool --version
# عرض المساعدة
kitploit-tool --help
# تشغيل الفحص الأساسي
kitploit-tool scan --target example.com
# تشغيل الفحص مع الإخراج المفصل
kitploit-tool scan --target example.com --verbose
# حفظ النتائج إلى ملف
kitploit-tool scan --target example.com --output results.json
# تحديد المنافذ
kitploit-tool scan --target example.com --ports 80,443,8080
# تعيين مستوى الخطورة
kitploit-tool scan --target example.com --severity high
# استخدام ملف التكوين
kitploit-tool scan --config config.yaml
kitploit-tool scan --target 192.168.1.0/24 --type network
kitploit-tool scan --target https://example.com --type web
kitploit-tool scan --target https://api.example.com --type api --token YOUR_TOKEN
يمكن تكوين الأداة باستخدام ملف config.yaml:
target:
host: example.com
port: 443
protocol: https
scan:
type: web
depth: 3
timeout: 30
threads: 10
output:
format: json
verbose: true
file: results.json
authentication:
enabled: false
username: ""
password: ""
export KITPLOIT_TARGET="example.com"
export KITPLOIT_API_KEY="your-api-key"
export KITPLOIT_LOG_LEVEL="debug"
| الخيار | الوصف | القيمة الافتراضية |
|---|---|---|
--target | الهدف المراد فحصه | مطلوب |
--type | نوع الفحص | web |
--output | ملف الإخراج | stdout |
--verbose | الإخراج المفصل | false |
--timeout | المهلة بالثواني | 30 |
--threads | عدد الخيوط | 10 |
--config | ملف التكوين | config.yaml |
GET /api/v1/scan
POST /api/v1/scan
GET /api/v1/results/{id}
DELETE /api/v1/results/{id}
curl -H "Authorization: Bearer YOUR_TOKEN" \
https://api.example.com/api/v1/scan
curl -X POST https://api.example.com/api/v1/scan \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_TOKEN" \
-d '{
"target": "example.com",
"type": "web",
"options": {
"depth": 3,
"timeout": 30
}
}'
{
"id": "scan-12345",
"status": "completed",
"target": "example.com",
"started_at": "2024-01-01T00:00:00Z",
"completed_at": "2024-01-01T00:05:00Z",
"findings": [
{
"id": "finding-001",
"severity": "high",
"title": "SQL Injection",
"description": "تم اكتشاف ثغرة SQL Injection محتملة",
"location": "https://example.com/login",
"remediation": "استخدم الاستعلامات المُعدّة مسبقًا"
}
]
}
from kitploit import Plugin
class MyPlugin(Plugin):
def __init__(self):
super().__init__()
self.name = "my-plugin"
self.version = "1.0.0"
def run(self, target, options):
# منطق الإضافة هنا
return {
"status": "success",
"findings": []
}
from kitploit import register_plugin
register_plugin(MyPlugin())
kitploit-tool scan --target example.com --plugin my-plugin
ModuleNotFoundError: No module named 'kitploit'
الحل: تأكد من تثبيت الأداة بشكل صحيح:
pip install -e .
ConnectionError: Unable to connect to target
الحل: تحقق من اتصال الشبكة وإعدادات جدار الحماية:
ping example.com
curl -I https://example.com
TimeoutError: Request timed out
الحل: قم بزيادة قيمة المهلة:
kitploit-tool scan --target example.com --timeout 60
kitploit-tool scan --target example.com --debug
# عرض السجلات
tail -f /var/log/kitploit-tool.log
# تعيين مستوى السجل
export KITPLOIT_LOG_LEVEL="debug"
نعم، الأداة مفتوحة المصدر ومتاحة تحت رخصة MIT.
نعم، رخصة MIT تسمح بالاستخدام التجاري.
راجع ملف CONTRIBUTING.md للحصول على الإرشادات.
يرجى فتح مشكلة على GitHub Issues.
هذا المشروع مرخص تحت رخصة MIT - راجع ملف LICENSE للتفاصيل.