
exploitdb // المستودع الرسمي لـ Exploit-Database
# مستودع The Exploit Database على Git
هذا مستودع رسمي لـ [The Exploit Database](https://www.exploit-db.com/)، وهو [مشروع](https://www.offensive-security.com/community-projects/) برعاية [Offensive Security](https://www.offensive-security.com/).
مستودعاتنا هي:
- الاستغلالات وقنوات الـ Shellcodes: [gitlab.com/exploit-database/exploitdb](https://gitlab.com/exploit-database/exploitdb)
- الاستغلالات الثنائية: [gitlab.com/exploit-database/exploitdb-bin-sploits](https://gitlab.com/exploit-database/exploitdb-bin-sploits)
- الأبحاث: [gitlab.com/exploit-database/exploitdb-papers](https://gitlab.com/exploit-database/exploitdb-papers)
The Exploit Database هي أرشيف للاستغلالات العامة والبرمجيات الضعيفة المقابلة، طُوّرت لاستخدامها من قبل مختبري الاختراق وباحثي الثغرات. هدفها هو أن تكون المجموعة الأكثر شمولاً من [الاستغلالات](https://www.exploit-db.com/) و[شِل كود](https://www.exploit-db.com/shellcodes) و[الأبحاث](https://www.exploit-db.com/papers) التي جُمعت عبر التقديمات المباشرة والقوائم البريدية والمصادر العامة الأخرى، وتقديمها في قاعدة بيانات متاحة مجاناً وسهلة التصفح. The Exploit Database هي مستودع للاستغلالات وإثباتات المفاهيم (Proof-of-Concepts) بدلاً من النشرات الأمنية، مما يجعلها مورداً قيماً لمن يحتاجون إلى بيانات قابلة للتنفيذ فوراً.
يمكنك معرفة المزيد عن المشروع [هنا (أعلى اليمين -> حول Exploit-DB)](https://www.exploit-db.com/) و[هنا (التاريخ)](https://www.exploit-db.com/history).
يتم تحديث هذا المستودع يومياً بأحدث الإضافات المُقدَّمة. يمكن العثور على أي موارد إضافية في [مستودع الاستغلالات الثنائية](https://gitlab.com/exploit-database/exploitdb-bin-sploits).
تقع الاستغلالات في مجلد [`/exploits/`](https://gitlab.com/exploit-database/exploitdb/tree/main/exploits)، ويمكن العثور على قنوات الـ Shellcodes في مجلد [`/shellcodes/`](https://gitlab.com/exploit-database/exploitdb/tree/main/shellcodes).
- - -
## الترخيص
هذا المشروع (وSearchSploit) مُصدَر بموجب "[GNU General Public License v2.0](https://gitlab.com/exploit-database/exploitdb/-/blob/main/LICENSE.md)".
- - -
# SearchSploit
مشمول مع هذا المستودع برنامج **SearchSploit**، الذي يتيح لك البحث في الاستغلالات وقنوات الـ Shellcodes والأبحاث _(إذا كانت مثبتة)_ باستخدام مصطلح واحد أو أكثر.
لمزيد من المعلومات، يرجى الاطلاع على **[دليل SearchSploit](https://www.exploit-db.com/searchsploit)**.
## الاستخدام/مثال
```
kali@kali:~$ searchsploit -h
Usage: searchsploit [options] term1 [term2] ... [termN]
==========
Examples
==========
searchsploit afd windows local
searchsploit -t oracle windows
searchsploit -p 39446
searchsploit linux kernel 3.2 --exclude="(PoC)|/dos/"
searchsploit -s Apache Struts 2.0.0
searchsploit linux reverse password
searchsploit -j 55555 | jq
searchsploit --cve 2021-44228
For more examples, see the manual: https://www.exploit-db.com/searchsploit
=========
Options
=========
## Search Terms
-c, --case [term] Perform a case-sensitive search (Default is inSEnsITiVe)
-e, --exact [term] Perform an EXACT & order match on exploit title (Default is an AND match on each term) [Implies "-t"]
e.g. "WordPress 4.1" would not be detect "WordPress Core 4.1")
-s, --strict Perform a strict search, so input values must exist, disabling fuzzy search for version range
e.g. "1.1" would not be detected in "1.0 < 1.3")
-t, --title [term] Search JUST the exploit title (Default is title AND the file's path)
--exclude="term" Remove values from results. By using "|" to separate, you can chain multiple values
e.g. --exclude="term1|term2|term3"
--cve [CVE] Search for Common Vulnerabilities and Exposures (CVE) value
## Output
-j, --json [term] Show result in JSON format
-o, --overflow [term] Exploit titles are allowed to overflow their columns
-p, --path [EDB-ID] Show the full path to an exploit (and also copies the path to the clipboard if possible)
-v, --verbose Display more information in output
-w, --www [term] Show URLs to Exploit-DB.com rather than the local path
--id Display the EDB-ID value rather than local path
--disable-colour Disable colour highlighting in search results
## Non-Searching
-m, --mirror [EDB-ID] Mirror (aka copies) an exploit to the current working directory
-x, --examine [EDB-ID] Examine (aka opens) the exploit using $PAGER
## Non-Searching
-h, --help Show this help screen
-u, --update Check for and install any exploitdb package updates (brew, deb & git)
## Automation
--nmap [file.xml] Checks all results in Nmap's XML output with service version
e.g.: nmap [host] -sV -oX file.xml
=======
Notes
=======
* You can use any number of search terms
* By default, search terms are not case-sensitive, ordering is irrelevant, and will search between version ranges
* Use '-c' if you wish to reduce results by case-sensitive searching
* And/Or '-e' if you wish to filter results by using an exact match
* And/Or '-s' if you wish to look for an exact version match
* Use '-t' to exclude the file's path to filter the search results
* Remove false positives (especially when searching using numbers - i.e. versions)
* When using '--nmap', adding '-v' (verbose), it will search for even more combinations
* When updating or displaying help, search terms will be ignored
kali@kali:~$
kali@kali:~$ searchsploit afd windows local
---------------------------------------------------------------------------------------- -----------------------------------
Exploit Title | Path
---------------------------------------------------------------------------------------- -----------------------------------
Microsoft Windows (x86) - 'afd.sys' Local Privilege Escalation (MS11-046) | windows_x86/local/40564.c
Microsoft Windows - 'afd.sys' Local Kernel (PoC) (MS11-046) | windows/dos/18755.c
Microsoft Windows - 'AfdJoinLeaf' Local Privilege Escalation (MS11-080) (Metasploit) | windows/local/21844.rb
Microsoft Windows 7 (x64) - 'afd.sys' Dangling Pointer Privilege Escalation (MS14-040) | windows_x86-64/local/39525.py
Microsoft Windows 7 (x86) - 'afd.sys' Dangling Pointer Privilege Escalation (MS14-040) | windows_x86/local/39446.py
Microsoft Windows XP - 'afd.sys' Local Kernel Denial of Service | windows/dos/17133.c
Microsoft Windows XP/2003 - 'afd.sys' Local Privilege Escalation (K-plugin) (MS08-066) | windows/local/6757.txt
Microsoft Windows XP/2003 - 'afd.sys' Local Privilege Escalation (MS11-080) | windows/local/18176.py
---------------------------------------------------------------------------------------- -----------------------------------
Shellcodes: No Result
kali@kali:~$
kali@kali:~$ searchsploit -p 39446
Exploit: Microsoft Windows 7 (x86) - 'afd.sys' Dangling Pointer Privilege Escalation (MS14-040)
URL: https://www.exploit-db.com/exploits/39446
Path: /Users/b/Projects/git/forks/exploitdb/exploits/windows_x86/local/39446.py
Codes: N/A
Verified: False
File Type: Python script text executable, ASCII text
Copied EDB-ID #39446's path to the clipboard
kali@kali:~$
```
- - -
## التثبيت
يتطلب SearchSploit إما "CoreUtils" أو "أدوات مساعدة" (مثل `bash`, `sed`, `grep`, `awk`، إلخ) لكي تعمل الميزات الأساسية.
ستتطلب وظيفة التحديث الذاتي `git`، ولكي يعمل خيار Nmap XML، سيتطلب `xmllint` (موجود في حزمة `libxml2-utils` في الأنظمة المبنية على دبيان).
يمكنك العثور على **دليل أكثر تفصيلاً في [دليل SearchSploit](https://www.exploit-db.com/searchsploit)**.
**Kali Linux**
إن Exploit-DB/SearchSploit معبأ بالفعل داخل Kali-Linux. إحدى طرق التثبيت هي:
```
kali@kali:~$ sudo apt -y install exploitdb
```
_ملاحظة، اختياري هو تثبيت الحزم الإضافية:_
```
kali@kali:~$ sudo apt -y install exploitdb-bin-sploits exploitdb-papers
```
**Git**
باختصار، استنسخ المستودع، وأضف الملف الثنائي إلى `$PATH`، وعدّل ملف الإعدادات ليعكس مسار git:
```
$ sudo git clone https://gitlab.com/exploit-database/exploitdb.git /opt/exploitdb
$ sudo ln -sf /opt/exploitdb/searchsploit /usr/local/bin/searchsploit
```
**Homebrew**
إذا كان لديك [homebrew](http://brew.sh/) ([الحزمة](https://github.com/Homebrew/homebrew-core/blob/master/Formula/exploitdb.rb)، [الصيغة](https://formulae.brew.sh/formula/exploitdb)) مثبتاً، فتشغيل ما يلي سيهيئ لك البيئة:
```
user@MacBook:~$ brew update && brew install exploitdb
```
- - -
## شكر وتقدير
الأشخاص التاليون جعلوا هذا ممكناً:
- [Offensive Security](https://www.offensive-security.com/)
- [@Unix-Ninja](https://github.com/unix-ninja)
- [@g0tmi1k](https://blog.g0tmi1k.com/)