Ikhaya » Amathuluzi e-Linux » I-SN1per – Uhlaka oluzenzakalelayo lwe-Pentest | Qedela Isifundo

I-SN1per – Uhlaka oluzenzakalelayo lwe-Pentest | Qedela Isifundo

nge I-Suyash
sn1per

I-SN1per kungenye yezinhlaka ezingezinhle kakhulu ze-Pentest ze-augenerable scanning.

Ithuluzi linikeza izinhlobo ezimbili ezahlukene.

Eyodwa ngumphakathi(khululekile) nomunye ochwepheshe(-kholulile).

I-SN1per Professional yi-Xero Security's Premium Reports Addon yabahloli bokungena kochwepheshe, Abazingeli be-Bug, njll.

Ngaphezu kwalokho, Ithuluzi lisebenzisa amanye amathuluzi amangalisa kakhulu afana ne-SQLMAP, SSLSCAN, I-TheHarastvester ukuskena ubungozi.

Izithombe ezinhle kakhulu ze-SN1per [Uhlelo lomphakathi]:

  • Ngokuzenzakalelayo iqoqa kabusha emuva (ie. -qotho, iphini lin, I-DNS, njll.)
  • Iqala ngokuzenzakalela imibuzo ye-Google yokugenca nge-Target Domain
  • Ngokuzenzakalela kufaka amachweba avulekile nge-NMAP Port Scanning
  • Ngokuzenzakalela ukuxhaphaza ubungozi obujwayelekile
  • Amabutho ashubile ngokuzenzakalela abuthana ngemininingwane ye-DNS futhi ahlole ukudluliselwa kwe-zone
  • Ihlola ngokuzenzakalela ngokuduna kwesizinda esingezansi
  • Ngokuzenzakalelayo isebenza ngokuzenzakalelayo imibhalo ye-NMAP ngokumelene namachweba avulekile
  • Ngokuzenzakalelayo isebenza ngokuzenzakalelayo i-metasploit scan kanye namamojula axhaphaza
  • Iskena ngokuzenzakalelayo zonke izinhlelo zokusebenza zewebhu zengozi evamile
  • Brute Brute ngokuzenzakalelayo zonke izinsizakalo ezivulekile
  • Ahlole ngokuzenzakalela ukufinyelela okungaziwa kwe-FTP
  • Sebenzisa ngokuzenzakalelayo i-WPSCAN, I-Arachni, kanye ne-nikto yazo zonke izinsizakalo zeWebhu
  • Ngokuzenzakalela kufaka amasheya we-NFS
  • Ahlole ngokuzenzakalela ukufinyelela okungaziwa kwe-LDAP
  • Ngokuzenzakalelayo i-SSL / TLS CIPHERS, amaphrothokholi kanye nobungozi
  • Ngokuzenzakalelayo izintambo zomphakathi ze-SNMP, amasethingi, kanye nabasebenzisi
  • Bhala ngokuzenzakalela abasebenzisi be-SMB namasheya, Bheka izikhathi ze-null futhi uxhaphaze ms08-067
  • Ihlola ngokuzenzakalela amaseva we-X11 avulekile
  • Yenza ukufakwa okuphezulu kwenqanaba lamandla amaningi nama-subnets
  • Ihlangana ngokuzenzakalela nge-metasploit pro, I-MSFCOSONE neZenmap Yokubika
  • Ngokuzenzakalelayo kubutha ama-skrini kuwo wonke amawebhusayithi
  • Dala izindawo zokusebenzela zomuntu ngamunye ukuze ugcine konke ukuphuma kwe-SCAN
  • I-Scans ehleliwe
  • Ukuhlanganiswa kweSlack API
  • Ukuhlanganiswa kwe-Hunter.io API
  • Ukuhlanganiswa kwe-OpenVas API
  • Ukuhlanganiswa kwe-Bursusite 2.X Ukuhlanganiswa
  • Ukuhlanganiswa kweShodan API
  • Ukuhlanganiswa kwe-Constys API
  • Ukuhlanganiswa kwe-Metasploit

Ukufaka i-SN1per

Ukufaka ithuluzi kulula kakhulu.

Udinga nje ukubheka ezinye izisekelo ze-Linux futhi ulungele ukuhamba.

  1. Ayihlanganise ne-github repo:
$ git clone https://github.com/1N3/Sn1per

2. Ukuhambisa umkhombandlela we-sn1per kanye nezimvume eziguqukayo ze- installer.sh okulotshiwe:

$ CD SN1per
$ Chmod + x ukufaka.sh

3. Isinyathelo sokugcina sokufaka

$ ./faka

Ividiyo yokufaka ye-SN1per:

I-HTTPS://www.youtube.com/watch?v = 5vdodksi348

Umsebenzi:

Ukuthayipha-h Ukuthola zonke izindlela ezitholakalayo:

[*] Imodi ejwayelekile
sniper -t|--okuqondiwe <Okuqondiwe>

[*] Imodi ejwayelekile + Isi-osnt + Buyisakwe nje + I-Port Port Scan + Amandla we-Brute
sniper -t|--okuqondiwe <Okuqondiwe> -one|--i-osint -re|--Phinda wenze|--ngokugcwele -b|--ubroteforce

[*] Imodi ye-Stealth + Isi-osnt + Buyisakwe nje
sniper -t|--okuqondiwe <Okuqondiwe> -uhlobo|--Imodi eqinile -O|--i-osint -re|--buyisakwe nje

[*] Thola imodi
sniper -t|--okuqondiwe <Uhlobo lwezimbamba> -uhlobo|--Imodi yokutholwa -w|--indawo <I-WorSpace_ALIAS>

[*] Imodi ye-Flyover
sniper -t|--okuqondiwe <Okuqondiwe> -uhlobo|--I-Mode Fllover -w|--indawo <I-WorkSpace_ALIAS>

[*] Imodi ye-Airstrike
sniper -f|--Ifayela / FFLL/Path/to/targets.txt -m|--mode airstrike

[*] Imodi ye-NKE ngohlu oluqondiwe, UBruteFescer unikwe amandla, I-fullportscan inikwe amandla, Osint enikwe amandla, Ukuphinda kunikwe amandla, Indawo & I-Loot inikwe amandla
sniper -f - file /ful/path/to/targets.txt -m|--Mull nuking -w|--indawo <I-WorkSpace_ALIAS>

[*] Skena ethekwini elithile kuphela
sniper -t|--okuqondiwe <Okuqondiwe> -M port -p|--itheku <uhlobo lwasenkomba>

[*] Imodi ye-Fullponly Scan
sniper -t|--okuqondiwe <Okuqondiwe> -fp|--ngokugcwele

[*] Imodi ye-Port Scan
sniper -t|--okuqondiwe <Okuqondiwe> -uhlobo|--Imodi yemodi -P|--itheku <IPort_num>

[*] Imodi yewebhu - Itheku 80 + 443 Kuphela!
sniper -t|--okuqondiwe <Okuqondiwe> -uhlobo|--I-Mode Web

[*] Imodi ye-HTTP ye-HTTP ye-HTTP yeWebhu ye-HTTP HTTP yeWebhu
sniper -t|--okuqondiwe <Okuqondiwe> -uhlobo|--Imodi yeWebhuPorTTTTTP -P|--itheku <itheku>

[*] Imodi ye-HTTPS yewebhu ye-HTTPS
sniper -t|--okuqondiwe <Okuqondiwe> -uhlobo|--Imodi yeWebhuPorTHTTS -P|--itheku <itheku>

[*] Nika amandla BruteForce
sniper -t|--okuqondiwe <Okuqondiwe> -b|--ubroteforce

[*] Nika amandla Ukungenisa Ukungenisa ku-Metasploit
sniper -t|--okuqondiwe <Okuqondiwe>

[*] Umsebenzi we-Loot Reimpport
sniper -w <I-WorkSpace_ALIAS> --cela

[*] Isimo Sokuhlola
sniper --status

[*] Vuselela Sniper
sniper -u|--buyekeza

Ukukhetha komhleli:

Izindlela:

  • -Ngokwejwayelekile: Yenza ukuskena okuyisisekelo kwamatshe okuhlosiwe kanye namachweba avulekile usebenzisa amasheke asebenzayo nawokuphela kokusebenza kahle.
  • Sola: Ngokushesha kwenze iphutha elilodwa elithile usebenzisa ukuskena okungekho emthethweni ukugwema ukuvimba kwe-waf / IPS.
  • Ugalofu: Izilinganiso ezisheshayo ezinamazinga aphezulu aphezulu anezingeniso eziningi (Iwusizo ukuqoqa idatha ephezulu kakhulu kubasi bukamasheke ngokushesha).
  • Airstrike: Ngokushesha avume amachweba avulekile / izinsizakalo kuma-Multiple Hot. Ukusebenzisa, Cacisa indawo ephelele yefayela eliqukethe wonke ama-hosts, I-IPS edinga ukuskenwa futhi iqhutshwe ./sn1per /Fburl/Path/to/Targets.txts Airstrike ukuze uqale ukuskena.
  • Maike: Qalisa ukucwaningwa okugcwele kwama-Multiple Homes achazwe kufayela lombhalo lokuzikhethela. Isibonelo sokusebenzisa: ./sniper /voot/targets.txt nuke.
  • Thola: Parses wonke ama-hosts ku-subnet / cidr (ie. 192.168.0.0/16) futhi iqala ukuskena kwe-sniper ngokumelene nomsingathi ngamunye. Iwusizo ekuskeneni kwenethiwekhi yangaphakathi.
  • Itheku: Iskena echwebeni elithile ukuze ubungozi. Ukubika akutholakali okwamanje kule modi.
  • Ngokugcwele: Yenza i-Port Scan ephelele yePort bese igcina imiphumela ku-XML.
  • Massportscan: Isebenza a “ngokugcwele” Skena kumatshe amaningi achazwe nge “-e f” shintsha.
  • Ubulembu: Ingeza uhlelo lokusebenza oluzenzakalelayo lwewebhu oluzenzakalelayo kwimiphumela (IPort 80 / TCP & 443/tcp kuphela). Ilungele izinhlelo zokusebenza zewebhu kepha ingakhuphula isikhathi sokuskena.
  • Isansimbi: Uyagijima “ubulembu” I-Mode Skena kumahlo athile acacisiwe nge “-e f” shintsha.
  • Webporthttp: Iqala ukuskena kwesicelo sewebhu esiphelele se-httpp ngokumelene nomgcini othize kanye nembobo ethile.
  • Iwebhu: Iqala ukuskena kwesicelo sewebhu esigcwele se-HTTPS ngokumelene nomgcini othize kanye nembobo ethile.
  • I-WebScan: Yethula i-http ephelele & I-HTTPS Web Isicelo Skena ngokumelene Bursuite nase-Arachni.
  • Masswebscan: Uyagijima “I-WebScan” Imodi yokuskena kwamatshe amaningi achazwe nge “-e f” shintsha.
  • I-AlnnScan: Ivula i-Openvas Esezingeni Eliphezulu.
  • MassVulnscan: Yethula a “I-AlnnScan” I-Mode Skena kumahlo athile acacisiwe nge “-e f” shintsha.

Amagama wokugcina:

Uma ufuna ngokuqinisekile unganikeza leli thuluzi.

I-SN1per ayisebenzi ngokuhlola konke ukungena ngokungena kepha ngokuqinisekile ikwenza kube lula.

Uma uthandile imizamo yethu esihlokweni se-SN1PER. Qiniseka ukushiya amazwana ngezansi. Noma iziphi iziphakamiso noma imibuzo iyaziswa.

Shiya Amazwana