
Ataques de codificação Unicode com aprendizado de máquina
Ataques de codificação Unicode com aprendizado de máquina. Ferramenta baseada em aprendizado de máquina para criar domínios falsos incríveis usando confusables. Alguns domínios podem enganar políticas IDN (Chrome e Firefox).
Eu criei o melhor (grande) dicionário de confusables usando redes neurais. Ele é usado na ferramenta e pode ser baixado de: https://github.com/mindcrypt/uriDeep/blob/master/data/deepDiccConfusables.txt
_mindcrypt@kali:~/tool/uriDeep# python3 uriDeep.py
_ ___
/\ /\ _ __(_) / \___ ___ _ __
/ / \ \ '__| | / /\ / _ \/ _ \ '_ \
\ \_/ / | | |/ /_// __/ __/ |_) |
\___/|_| |_/___,' \___|\___| .__/
|_|
Version Beta
Authors: Alfonso Muñoz (@mindcrypt)
Miguel Hernández (@MiguelHzBz)
usage: uriDeep.py [-h] [-d, --domain DOMAIN] [-i FILEINPUT] [-F [FLIPPER]]
[-H [HOMOGLYPH]] [-l] [-S [SUBSTITUTION]] [-c] [-w] [-vt]
[-key API] [-o OUTPUTFILE]
UriDeep: Tool based on machine learning to create amazing fake domains using
confusables. Some domains can deceive IDN policies
optional arguments:
-h, --help show this help message and exit
-d, --domain DOMAIN check similar domains to this one
-i FILEINPUT, --input FILEINPUT
List of targets. One input per line.
-F [FLIPPER], --flipper [FLIPPER]
Execute flipping attack
-H [HOMOGLYPH], --homoglyph [HOMOGLYPH]
Execute homoglyph attack with full table of
confusables
-l, --light To create fake domains that could deceive IDN policies
-S [SUBSTITUTION], --substitution [SUBSTITUTION]
Execute substitution attack
-c, --check check if this domain is alive
-w, --whois check whois
-vt, --virustotal check Virus Total
-key API, --api-key API
VirusTotal API Key
-o OUTPUTFILE, --output OUTPUTFILE
Output file
None
Need one type of input, {-i --input} or {-d --domain}
root@kali:~/tool/uriDeep# python3 uriDeep.py -H -d www.example.org
_ ___
/\ /\ _ __(_) / \___ ___ _ __
/ / \ \ '__| | / /\ / _ \/ _ \ '_ \
\ \_/ / | | |/ /_// __/ __/ |_) |
\___/|_| |_/___,' \___|\___| .__/
|_|