Kayan aikin Hacking na ɗa'a

Kayan aikin Hacking na ɗa'a
Automation ya bar tambarin sa akan kowace masana'anta da ke can, kuma fannin hacking ɗin da'a ba shi da bambanci. Tare da farkon kayan aiki daban-daban a cikin masana'antar satar fasaha, an canza ta. Kayan aikin hacking na ɗabi'a suna taimakawa wajen tattara bayanai, ƙirƙira bayan gida da lodin kaya, fasa kalmar sirri da jerin sauran ayyuka. A cikin wannan labarin, za mu tattauna manyan kayan aikin hacking na ɗabi'a guda 10 har zuwa 2023.

Acunetix

Acunetix gwajin tsaro ne na aikace-aikacen gidan yanar gizo mai sarrafa kansa da  kayan aikin satar bayanai. Ana amfani da shi don tantance aikace-aikacen yanar gizon ku ta hanyar duba lahani kamar allurar SQL, rubutun giciye, da sauran lahani masu amfani. Gabaɗaya, Acunetix yana bincika kowane gidan yanar gizo ko aikace-aikacen gidan yanar gizo da ake samun dama ta hanyar burauzar gidan yanar gizo kuma yana amfani da ka'idar HTTP/HTTPS.
Acunetix yana ba da ƙaƙƙarfan mafita na musamman don nazarin kashe-kashe da aikace-aikacen gidan yanar gizo na al'ada gami da waɗanda ke amfani da JavaScript, AJAX da aikace-aikacen gidan yanar gizo 2.0. Acunetix yana da ci-gaba mai rarrafe wanda zai iya samun kusan kowane fayil. Wannan yana da mahimmanci tunda ba a iya bincika abin da ba a samu ba.

Metasploit

Metasploit  shine tsarin gwajin alkalami mai buɗewa da aka rubuta cikin Ruby. Yana aiki azaman hanyar jama'a don bincika raunin tsaro da haɓaka lamba. Wannan yana bawa mai gudanar da hanyar sadarwa damar shiga cikin nasa hanyar sadarwar don gano haɗarin tsaro da kuma rubuta abubuwan rashin lahani da yakamata a fara magance su. Har ila yau, yana ɗaya daga cikin ƴan kayan aikin kutse na ɗabi'a da masu satar kutse ke amfani da su don gudanar da ayyukansu. Hakanan yana ba ku damar kwafin gidajen yanar gizo don phishing da sauran dalilai na injiniyan zamantakewa. Tsarin ya ƙunshi saitin kayan aikin tsaro waɗanda za a iya amfani da su don:

Tsare-tsaren ganowaGun binciken rashin lafiyar tsaro Yana aiwatar da hare-hare mai nisaErididdigar cibiyoyin sadarwa da runduna
Wireshark software ce ta buɗe tushen kyauta wacce ke ba ku damar tantance zirga-zirgar hanyar sadarwa a ainihin lokacin. Godiya ga fasahar sa na numfashi, Wireshark ya shahara sosai don iya gano matsalolin tsaro a kowace hanyar sadarwa, da kuma tasirinsa wajen magance matsalolin sadarwar gabaɗaya. Yayin da ake shakar hanyar sadarwar, za ku iya tsangwama da karanta sakamakon a cikin tsarin da mutum zai iya karantawa, wanda ke sauƙaƙa gano matsalolin da za su iya yiwuwa (kamar ƙarancin latency), barazana da lahani.
Babban fasali:

Ajiye bincike don duba layi

Fakitin browser

GUI mai ƙarfi

Rich VoIP bincike

Yana dubawa kuma yana rage fayilolin gzip

Yana karanta sauran tsarin fayilolin kama ciki har da Sniffer Pro, Tcpdump, Microsoft cibiyar sadarwa mai saka idanu, Cisco Secure IDS IPlog, da sauransu.

Ana fitar da sakamako zuwa XML, PostScript, CSV, ko rubutu na fili

Wireshark yana goyan bayan ka'idojin cibiyar sadarwa daban-daban har 2000, kuma yana samuwa akan duk manyan tsarin aiki ciki har da:

Linux

Windows

Mac OS X

Samun ilimi mai amfani da ƙwarewa wajen ganowa da magance raunin da ya faru yayin wannan Kwararren  Ƙwa ) ne na Ƙarfafawa na Ƙaƙa na Ƙaƙa ) na Ƙaddamar da aka samu a cikin Ƙwararrun Ƙwararru.
Nikto

Nikto wani abin da aka fi so, sanannen yanki ne na Rarraba Linux Kalinus. Sauran shahararrun rabawa na Linux kamar Fedora sun riga sun zo tare da Nikto a cikin ma'ajin software na su ma. Ana amfani da wannan kayan aikin tsaro don bincika sabar gidan yanar gizo da yin gwaje-gwaje daban-daban akan ƙayyadadden mai masaukin nesa. Tsaftataccen layin umarni mai sauƙi da sauƙi yana sa ya zama da sauƙi don ƙaddamar da duk wani gwajin lahani a kan manufar ku.
Babban fasali na Nikto sun haɗa da:

Yana gano tsoffin fayilolin shigarwa akan kowane tsarin aiki

Yana gano tsoffin aikace-aikacen software

Haɗin kai tare da Tsarin Metasploit

Gudanar da gwajin raunin raunin rubutun giciye

Kashe hare-hare na tushen ƙamus

Ana fitar da sakamako a cikin rubutu na fili, CSV ko fayilolin HTML
John the Ripper
John the Ripper yana ɗaya daga cikin shahararrun masu fasa kalmar sirri na kowane lokaci. Hakanan yana ɗaya daga cikin mafi kyawun kayan aikin tsaro da ake da su don gwada ƙarfin kalmar sirri a cikin tsarin aiki, ko don duba ɗaya daga nesa. Wannan kalmar cracker tana iya gano nau'in boye-boye da ake amfani da ita a cikin kusan kowace kalmar sirri kuma za ta canza algorithm gwajin kalmar sirri daidai da haka, yana mai da shi daya daga cikin kayan aikin fasa kalmar sirri da aka fi sani da shi.

Wannan kayan aikin hacking na ɗabi'a yana amfani da fasaha mai ƙarfi don tantance kalmomin shiga da algorithms kamar:

DES, MD5, BlowfishKerberos AFSHash LM (Lan Manager), tsarin da aka yi amfani da shi a cikin Windows NT / 2000 / XP / 2003MD4, LDAP, MySQL (ta amfani da kayayyaki na ɓangare na uku)

Wani kari kuma shine JTR buɗaɗɗen tushe ne, dandamali da yawa kuma cikakke don Mac, Linux, Windows, da Android
Kismet

Kismet yana ɗaya daga cikin kayan aikin hacking ɗin da aka fi amfani da su. Yana aiki ganewar hanyar sadarwa, fakitin sniffer, da tsarin gano kutse don LANs mara waya ta 802.11. Kismet zai yi aiki tare da kowane katin mara waya wanda ke goyan bayan yanayin sa ido na ƙasa kuma yana iya shakar 802.11a, 802.11b, 802.11g, da 802.11n  zirga-zirga. Shirin yana gudana ƙarƙashin Linux, FreeBSD, NetBSD, OpenBSD, da Mac OS X. Abokin ciniki kuma yana iya aiki akan Microsoft Windows.

SQLninja

SQLNinja  shine wani na'urar daukar hoto mai lahani na SQL wanda aka haɗe tare da rarraba Kali Linux. Wannan kayan aikin hacking na ɗa'a an sadaukar da shi don manufa da kuma amfani da aikace-aikacen yanar gizo waɗanda ke amfani da MS SQL Server azaman uwar garken bayanan baya. Amfani da SQLNInja zaka iya:

Gwada tsarin bayanai

Bayanan nesa na yatsa

Hare-haren karfi da jerin kalmomi

Harsashi kai tsaye & baya harsashi

Ana samun SQLNinja a cikin Unix distros da yawa inda aka shigar da mai fassarar Perl, gami da:

Linux

Mac OS X da iOS

FreeBSD

Wapiti

Wapiti firarren buɗaɗɗen tushen umarni-layi ne wanda aka rubuta a cikin Python. Duk da yake ba shine mafi kyawun kayan aikin hacking na ɗa'a ba a cikin wannan filin, yana yin kyakkyawan aiki na gano kurakuran tsaro a yawancin aikace-aikacen yanar gizo. Yin amfani da Wapiti zai iya taimaka maka gano ramukan tsaro ciki har da:

XSS hare-hare

SQL injections

XPath injections

XXE injections

CRLF injections

Neman jabu na gefen uwar garke

Canvas babban madadin Metasploit, yana ba da fa'idodi sama da 800 don gwada hanyoyin sadarwa masu nisa. Immunity's CANVAS yana samuwa

daruruwan amfani

tsarin amfani mai sarrafa kansa

ingantaccen abin dogaro yana amfani da tsarin haɓakawa ga masu gwajin shiga da ƙwararrun tsaro a duk duniya

Babban abubuwan Canvas sun haɗa da:

Ɗaukar hotunan kariyar kwamfuta na tsarin nesa

Zazzage kalmomin shiga

Yana gyara fayiloli a cikin tsarin

Yana haɓaka gata don samun damar mai gudanarwa

Amfani da hanyar sadarwa mai nisa
Previous Post Next Post