發表文章

目前顯示的是 7月, 2017的文章

nikto 說明

圖片
這是用來 針對網站(http)  去查看數百個漏洞或CGI問題... 因為 更新慢, 且指令 -update 無效 建議到官網 下載新版  說明: root@kali-shan:~# nikto - Nikto v2.1.6 --------------------------------------------------------------------------- + ERROR: No host specified -config+ Use this config file -Display+ Turn on/off display outputs -dbcheck check database and other key files for syntax errors -Format+ save file (-o) format -Help Extended help information -host+ target host -id+ Host authentication to use, format is id:pass or id:pass:realm -list-plugins List all available plugins -output+ Write output to this file -nossl Disables using SSL -no404 Disables 404 checks -Plugins+ List of plugins to run (default: ALL) -port+ Port to use (default 80) -root+ Prepend root value to

Easy-Creds 製作一個假AP

圖片
有時要使用一個新AP...來做假的AP, 收集每個連線進來資料 1. 先到  https://github.com/brav0hax/easy-creds    下載 easy-creds-master.zip 2. 執行 unzip easy-creds-master.zip cd easy-creds-master ./installer.sh  >>>選1  (安裝系統) 3.   ./easy-creds.sh 1.  FakeAP Attack Static 2.  FakeAP Attack EvilTwin 3.  Karmetasploit Attack 4.  FreeRadius Attack 5.  DoS AP Options 6.  Previous Menu Choice: 1  (製作一個假AP) 4. 接著跑... ____ ____ ____ ____ ____ ____ ____ ____ ____ ____ ||e |||a |||s |||y |||- |||c |||r |||e |||d |||s || ||__|||__|||__|||__|||__|||__|||__|||__|||__|||__|| |/__\|/__\|/__\|/__\|/__\|/__\|/__\|/__\|/__\|/__\| Version 3.8-dev - Garden of New Jersey At any time, ctrl+c  to cancel and return to the main menu Would you like to include a sidejacking attack? [y/N]: y Network Interfaces: Interface connected to the internet (ex. eth0): Interface connected to the internet (ex. eth0): eth0 PHY Interface Driver Chipset phy0 wlan0 rtl8187 Realtek Semiconductor Corp. RTL8187 Wireless interface name (ex. wlan0):