Skip to content
KitploitKITPLOIT
도구블로그
Log in
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
habu — 해킹 툴킷 | Kitploit
도구/GitHubGitHub/fportantier/habu
OSINT (Open Source Intelligence)Information GatheringWeb SecurityNetwork SecurityCryptographyPenetration TestingLearning & EducationDNS Analysis
GitHubfportantier/habu

habu

해킹 툴킷

저장소 보기
983163179개월 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

Habu Hacking Toolkit

저는 파이썬과 네트워크 해킹에 대한 몇 가지 개념을 가르치고 배우기 위해 Habu를 개발하고 있습니다.

현재 버전에 구현된 일부 기술은 다음과 같습니다:

  • ARP 포이즈닝 및 스니핑
  • DHCP 디스커버 및 스타베이션
  • 서브도메인 식별
  • 인증서 복제
  • TCP 분석 (ISN, 플래그)
  • 소셜 네트워크에서 사용자명 확인
  • 웹 기술 식별
  • 그리고 더 많은 것!

이 소프트웨어의 개발은 Securetia SRL (https://www.securetia.com/)이 지원합니다.

Hacking with Habu

다양한 유용한 사용 시나리오는 https://fportantier.github.io/hacking-with-habu/ 에 자세히 설명되어 있습니다.

사용 영상

다음 YouTube 재생 목록에는 설치 및 사용법을 보여주는 동영상이 포함되어 있습니다:

https://www.youtube.com/watch?v=rgp9seLLyqE&list=PL4HZnX8VnFXqSvNw7x-bXOn0dgxNdfnVD

텔레그램 그룹

Habu 기능, 개선 가능 사항 등에 대해 논의하고 싶다면 Habu 텔레그램 그룹을 사용할 수 있습니다: https://t.me/python_habu

기여하기

이슈와 풀 리퀘스트는 깃허브 저장소로 보내주세요: https://github.com/fportantier/habu

설치

권장 설치 방법:

::

$ python3 -m pip install --upgrade git+https://github.com/fportantier/habu.git

이 방법은 Python 3이 설치된 모든 시스템에서 작동해야 합니다.

참고: 일부 시스템(예: Microsoft Windows)에서는 명령을 조정하여 Python 실행 파일의 올바른 경로를 가리키도록 해야 합니다.

업그레이드

이제 Git 저장소에서 직접 업그레이드하고 더 이상 존재하지 않거나 이름이 변경된 이전 명령을 정리하는 명령이 있습니다.

::

$ habu.upgrade

도움말

모든 명령은 '--help' 옵션을 구현하며, 이는 도움말, 인수, 옵션 및 기본값을 보여줍니다.

상세 모드

거의 모든 명령이 '-v' 옵션으로 상세 모드를 구현합니다. 이는 habu가 수행 중인 작업에 대한 추가 정보를 제공할 수 있습니다.

명령 색인

  • arp.ping <#habuarpping>_
  • arp.poison <#habuarppoison>_
  • arp.sniff <#habuarpsniff>_
  • asydns <#habuasydns>_
  • b64 <#habub64>_
  • cert.clone <#habucertclone>_
  • cert.crtsh <#habucertcrtsh>_
  • cert.names <#habucertnames>_
  • config.del <#habuconfigdel>_
  • config.set <#habuconfigset>_
  • config.show <#habuconfigshow>_
  • crack.luhn <#habucrackluhn>_
  • crack.snmp <#habucracksnmp>_
  • crypto.fernet <#habucryptofernet>_
  • crypto.fernet.genkey <#habucryptofernetgenkey>_
  • crypto.gppref <#habucryptogppref>_
  • crypto.hasher <#habucryptohasher>_
  • crypto.xor <#habucryptoxor>_
  • data.enrich <#habudataenrich>_
  • data.extract.domain <#habudataextractdomain>_
  • data.extract.email <#habudataextractemail>_
  • data.extract.fqdn <#habudataextractfqdn>_
  • data.extract.ipv4 <#habudataextractipv4>_
  • data.filter <#habudatafilter>_
  • data.select <#habudataselect>_
  • dhcp.discover <#habudhcpdiscover>_
  • dhcp.starvation <#habudhcpstarvation>_
  • dns.lookup.forward <#habudnslookupforward>_
  • dns.lookup.reverse <#habudnslookupreverse>_
  • eicar <#habueicar>_
  • forkbomb <#habuforkbomb>_
  • fqdn.finder <#habufqdnfinder>_
  • gateway.find <#habugatewayfind>_
  • host <#habuhost>_
  • http.headers <#habuhttpheaders>_
  • http.options <#habuhttpoptions>_
  • http.tech <#habuhttptech>_
  • icmp.ping <#habuicmpping>_
  • ip.asn <#habuipasn>_
  • ip.geolocation <#habuipgeolocation>_
  • ip.internal <#habuipinternal>_
  • ip.public <#habuippublic>_
  • karma <#habukarma>_
  • karma.bulk <#habukarmabulk>_
  • land <#habuland>_
  • nc <#habunc>_
  • net.contest <#habunetcontest>_
  • net.interfaces <#habunetinterfaces>_
  • nmap.excluded <#habunmapexcluded>_
  • nmap.open <#habunmapopen>_
  • nmap.ports <#habunmapports>_
  • protoscan <#habuprotoscan>_
  • server.ftp <#habuserverftp>_
  • shodan <#habushodan>_
  • shodan.query <#habushodanquery>_
  • tcp.flags <#habutcpflags>_
  • tcp.isn <#habutcpisn>_
  • tcp.scan <#habutcpscan>_
  • tcp.synflood <#habutcpsynflood>_
  • traceroute <#habutraceroute>_
  • upgrade <#habuupgrade>_
  • usercheck <#habuusercheck>_
  • version <#habuversion>_
  • vhosts <#habuvhosts>_
  • virustotal <#habuvirustotal>_
  • web.report <#habuwebreport>_
  • web.screenshot <#habuwebscreenshot>_
  • whois.domain <#habuwhoisdomain>_
  • whois.ip <#habuwhoisip>_

habu.arp.ping

.. code-block::

Usage: habu.arp.ping [OPTIONS] IP

  Send ARP packets to check if a host it's alive in the local network.

  Example:

  # habu.arp.ping 192.168.0.1
  Ether / ARP is at a4:08:f5:19:17:a4 says 192.168.0.1 / Padding

Options:
  -i TEXT  Interface to use
  -v       Verbose output
  --help   Show this message and exit.

habu.arp.poison

.. code-block::

Usage: habu.arp.poison [OPTIONS] VICTIM1 VICTIM2

  Send ARP 'is-at' packets to each victim, poisoning their ARP tables for
  send the traffic to your system.

  Note: If you want a full working Man In The Middle attack, you need to
  enable the packet forwarding on your operating system to act like a
  router. You can do that using:

  # echo 1 > /proc/sys/net/ipv4/ip_forward

  Example:

  # habu.arpoison 192.168.0.1 192.168.0.77
  Ether / ARP is at f4:96:34:e5:ae:1b says 192.168.0.77
  Ether / ARP is at f4:96:34:e5:ae:1b says 192.168.0.70
  Ether / ARP is at f4:96:34:e5:ae:1b says 192.168.0.77
  ...

Options:
  -i TEXT  Interface to use
  -v       Verbose
  --help   Show this message and exit.

habu.arp.sniff

.. code-block::

Usage: habu.arp.sniff [OPTIONS]

  Listen for ARP packets and show information for each device.

  Columns: Seconds from last packet | IP | MAC | Vendor

  Example:

  1   192.168.0.1     a4:08:f5:19:17:a4   Sagemcom Broadband SAS
  7   192.168.0.2     64:bc:0c:33:e5:57   LG Electronics (Mobile Communications)
  2   192.168.0.5     00:c2:c6:30:2c:58   Intel Corporate
  6   192.168.0.7     54:f2:01:db:35:58   Samsung Electronics Co.,Ltd

Options:
  -i TEXT  Interface to use
  --help   Show this message and exit.

habu.asydns

.. code-block::

Usage: habu.asydns [OPTIONS]

  Requests a DNS domain name based on public and private RSA keys using the
  AsyDNS protocol https://github.com/portantier/asydns

  Example:

  $ habu.asydns -v
  Generating RSA key ...
  Loading RSA key ...
  {
      "ip": "181.31.41.231",
      "name": "07286e90fd6e7e6be61d6a7919967c7cf3bbfb23a36edbc72b6d7c53.a.asydns.org"
  }

  $ dig +short 07286e90fd6e7e6be61d6a7919967c7cf3bbfb23a36edbc72b6d7c53.a.asydns.org
  181.31.41.231

Options:
  -u TEXT  API URL
  -g       Force the generation of a new key pair
  -r       Revoke the public key
  -v       Verbose output
  --help   Show this message and exit.

habu.b64

.. code-block::

Usage: habu.b64 [OPTIONS] [F]

  Encodes or decode data in base64, just like the command base64.

  $ echo awesome | habu.b64
  YXdlc29tZQo=

  $ echo YXdlc29tZQo= | habu.b64 -d
  awesome

Options:
  -d      decode instead of encode
  --help  Show this message and exit.

habu.cert.clone

.. code-block::

Usage: habu.cert.clone [OPTIONS] HOSTNAME PORT KEYFILE CERTFILE

  Connect to an SSL/TLS server, get the certificate and generate a
  certificate with the same options and field values.

  Note: The generated certificate is invalid, but can be used for social
  engineering attacks

  Example:

  $ habu.certclone www.google.com 443 /tmp/key.pem /tmp/cert.pem

Options:
  --copy-extensions  Copy certificate extensions (default: False)
  --expired          Generate an expired certificate (default: False)
  -v                 Verbose
  --help             Show this message and exit.

habu.cert.crtsh

.. code-block::

도구 다운로드