
ハッキングツールキット
私は Habu を開発しています。これは Python とネットワークハッキングの概念を教え(そして学ぶ)ためのものです。
現在のバージョンで実装されているテクニックは以下のとおりです:
このソフトウェアの開発は、Securetia SRL (https://www.securetia.com/) によってサポートされています。
様々な便利な使用シナリオは https://fportantier.github.io/hacking-with-habu/ に詳しく記載されています。
次のYouTubeプレイリストには、インストールと使用方法を示す動画があります:
https://www.youtube.com/watch?v=rgp9seLLyqE&list=PL4HZnX8VnFXqSvNw7x-bXOn0dgxNdfnVD
Habu の機能や改善点などについて議論したい場合は、Habu Telegram グループ (https://t.me/python_habu) をご利用ください。
問題やプルリクエストは GitHub リポジトリ (https://github.com/fportantier/habu) に送ってください。
推奨インストール方法:
::
$ python3 -m pip install --upgrade git+https://github.com/fportantier/habu.git
これは Python 3 がインストールされているすべてのシステムで動作するはずです。
注意: 一部のシステム(Microsoft Windows など)では、Python 実行可能ファイルの正しいパスを指定するようにコマンドを調整する必要があります。
Git リポジトリから直接アップグレードし、存在しないか名前が変更された古いコマンドをクリーンアップするコマンドが用意されました。
::
$ habu.upgrade
すべてのコマンドには '--help' オプションがあり、ヘルプ、引数、オプション、デフォルト値を表示します。
ほとんどのコマンドは '-v' オプションで詳細モードを実装しています。これにより、habu が何をしているかに関する追加情報を得ることができます。
arp.ping <#habuarpping>_arp.poison <#habuarppoison>_arp.sniff <#habuarpsniff>_asydns <#habuasydns>_b64 <#habub64>_cert.clone <#habucertclone>_cert.crtsh <#habucertcrtsh>_cert.names <#habucertnames>_config.del <#habuconfigdel>_config.set <#habuconfigset>_config.show <#habuconfigshow>_crack.luhn <#habucrackluhn>_crack.snmp <#habucracksnmp>_crypto.fernet <#habucryptofernet>_crypto.fernet.genkey <#habucryptofernetgenkey>_crypto.gppref <#habucryptogppref>_crypto.hasher <#habucryptohasher>_crypto.xor <#habucryptoxor>_data.enrich <#habudataenrich>_data.extract.domain <#habudataextractdomain>_data.extract.email <#habudataextractemail>_data.extract.fqdn <#habudataextractfqdn>_data.extract.ipv4 <#habudataextractipv4>_data.filter <#habudatafilter>_data.select <#habudataselect>_dhcp.discover <#habudhcpdiscover>_dhcp.starvation <#habudhcpstarvation>_dns.lookup.forward <#habudnslookupforward>_dns.lookup.reverse <#habudnslookupreverse>_eicar <#habueicar>_forkbomb <#habuforkbomb>_fqdn.finder <#habufqdnfinder>_gateway.find <#habugatewayfind>_host <#habuhost>_http.headers <#habuhttpheaders>_http.options <#habuhttpoptions>_http.tech <#habuhttptech>_icmp.ping <#habuicmpping>_ip.asn <#habuipasn>_ip.geolocation <#habuipgeolocation>_ip.internal <#habuipinternal>_ip.public <#habuippublic>_karma <#habukarma>_karma.bulk <#habukarmabulk>_land <#habuland>_nc <#habunc>_net.contest <#habunetcontest>_net.interfaces <#habunetinterfaces>_nmap.excluded <#habunmapexcluded>_nmap.open <#habunmapopen>_nmap.ports <#habunmapports>_protoscan <#habuprotoscan>_server.ftp <#habuserverftp>_shodan <#habushodan>_shodan.query <#habushodanquery>_tcp.flags <#habutcpflags>_tcp.isn <#habutcpisn>_tcp.scan <#habutcpscan>_tcp.synflood <#habutcpsynflood>_traceroute <#habutraceroute>_upgrade <#habuupgrade>_usercheck <#habuusercheck>_version <#habuversion>_vhosts <#habuvhosts>_virustotal <#habuvirustotal>_web.report <#habuwebreport>_web.screenshot <#habuwebscreenshot>_whois.domain <#habuwhoisdomain>_whois.ip <#habuwhoisip>_.. code-block::
Usage: habu.arp.ping [OPTIONS] IP
Send ARP packets to check if a host it's alive in the local network.
Example:
# habu.arp.ping 192.168.0.1
Ether / ARP is at a4:08:f5:19:17:a4 says 192.168.0.1 / Padding
Options: -i TEXT 使用するインターフェース -v 詳細出力 --help このメッセージを表示して終了
.. code-block::
Usage: habu.arp.poison [OPTIONS] VICTIM1 VICTIM2
Send ARP 'is-at' packets to each victim, poisoning their ARP tables for
send the traffic to your system.
Note: If you want a full working Man In The Middle attack, you need to
enable the packet forwarding on your operating system to act like a
router. You can do that using:
# echo 1 > /proc/sys/net/ipv4/ip_forward
Example:
# habu.arpoison 192.168.0.1 192.168.0.77
Ether / ARP is at f4:96:34:e5:ae:1b says 192.168.0.77
Ether / ARP is at f4:96:34:e5:ae:1b says 192.168.0.70
Ether / ARP is at f4:96:34:e5:ae:1b says 192.168.0.77
...
Options: -i TEXT 使用するインターフェース -v 詳細 --help このメッセージを表示して終了
.. code-block::
Usage: habu.arp.sniff [OPTIONS]
Listen for ARP packets and show information for each device.
Columns: Seconds from last packet | IP | MAC | Vendor
Example:
1 192.168.0.1 a4:08:f5:19:17:a4 Sagemcom Broadband SAS
7 192.168.0.2 64:bc:0c:33:e5:57 LG Electronics (Mobile Communications)
2 192.168.0.5 00:c2:c6:30:2c:58 Intel Corporate
6 192.168.0.7 54:f2:01:db:35:58 Samsung Electronics Co.,Ltd
Options: -i TEXT 使用するインターフェース --help このメッセージを表示して終了
.. code-block::
Usage: habu.asydns [OPTIONS]
Requests a DNS domain name based on public and private RSA keys using the
AsyDNS protocol https://github.com/portantier/asydns
Example:
$ habu.asydns -v
Generating RSA key ...
Loading RSA key ...
{
"ip": "181.31.41.231",
"name": "07286e90fd6e7e6be61d6a7919967c7cf3bbfb23a36edbc72b6d7c53.a.asydns.org"
}
$ dig +short 07286e90fd6e7e6be61d6a7919967c7cf3bbfb23a36edbc72b6d7c53.a.asydns.org
181.31.41.231
Options: -u TEXT API URL -g 新しい鍵ペアの生成を強制 -r 公開鍵を失効させる -v 詳細出力 --help このメッセージを表示して終了
.. code-block::
Usage: habu.b64 [OPTIONS] [F]
Encodes or decode data in base64, just like the command base64.
$ echo awesome | habu.b64
YXdlc29tZQo=
$ echo YXdlc29tZQo= | habu.b64 -d
awesome
Options: -d エンコードではなくデコード --help このメッセージを表示して終了
.. code-block::
Usage: habu.cert.clone [OPTIONS] HOSTNAME PORT KEYFILE CERTFILE
Connect to an SSL/TLS server, get the certificate and generate a
certificate with the same options and field values.
Note: The generated certificate is invalid, but can be used for social
engineering attacks
Example:
$ habu.certclone www.google.com 443 /tmp/key.pem /tmp/cert.pem
Options: --copy-extensions 証明書拡張をコピー(デフォルト: False) --expired 期限切れの証明書を生成(デフォルト: False) -v 詳細 --help このメッセージを表示して終了
.. code-block::
Usage: habu.cert.crtsh [OPTIONS] DOMAIN
Downloads the certificate transparency logs for a domain and check with
DNS queries if each subdomain exists.
Uses multithreading to improve the performance of the DNS queries.
Example:
$ habu.crtsh securetia.com
alt.securetia.com
other.securetia.com
www.securetia.com
Options: -c キャッシュを無効にする -n DNS サブドメイン検証を無効にする -v 詳細出力 --json 出力を JSON 形式で表示 --help このメッセージを表示して終了
.. code-block::