hacktricks/README.md

164 lines
8.9 KiB
Markdown
Raw Normal View History

# Mbinu za Kudukua
2022-04-28 16:01:33 +00:00
<figure><img src=".gitbook/assets/hacktricks.gif" alt=""><figcaption></figcaption></figure>
_Majina na muundo wa Hacktricks uliundwa na_ [_@ppiernacho_](https://www.instagram.com/ppieranacho/)_._
{% hint style="success" %}
**Karibu kwenye wiki ambapo utapata kila mbinu ya kudukua/kiufundi/chochote nilichojifunza kutoka kwa CTFs, programu halisi, kusoma utafiti, na habari.**
{% endhint %}
2024-06-05 12:41:51 +00:00
Ili kuanza fuata ukurasa huu ambapo utapata **mtiririko wa kawaida** ambao **unapaswa kufuata wakati wa kufanya ukaguzi wa kiusalama** kwenye moja au zaidi ya **mashine:**
{% content-ref url="generic-methodologies-and-resources/pentesting-methodology.md" %}
[pentesting-methodology.md](generic-methodologies-and-resources/pentesting-methodology.md)
{% endcontent-ref %}
2024-02-11 02:13:58 +00:00
## Wadhamini wa Kampuni
2022-05-01 12:41:36 +00:00
### [STM Cyber](https://www.stmcyber.com)
2021-11-26 01:20:02 +00:00
<figure><img src=".gitbook/assets/stm (1).png" alt=""><figcaption></figcaption></figure>
2021-11-26 01:20:02 +00:00
2024-06-05 12:41:51 +00:00
[**STM Cyber**](https://www.stmcyber.com) ni kampuni kubwa ya usalama wa mtandao ambayo kauli mbiu yao ni **KUDUKUA KISICHODUKIKA**. Wao hufanya utafiti wao wenyewe na kutengeneza zana zao za kudukua ili **kutoa huduma muhimu za usalama wa mtandao** kama ukaguzi wa usalama, Timu Nyekundu na mafunzo.
2021-11-26 12:13:08 +00:00
2024-06-05 12:41:51 +00:00
Unaweza kuangalia **blogi yao** kwenye [**https://blog.stmcyber.com**](https://blog.stmcyber.com)
2021-11-26 01:20:02 +00:00
2024-06-05 12:41:51 +00:00
**STM Cyber** pia hutoa msaada kwa miradi ya chanzo wazi ya usalama wa mtandao kama HackTricks :)
***
2021-11-26 01:20:02 +00:00
2022-10-25 14:58:43 +00:00
### [RootedCON](https://www.rootedcon.com/)
<figure><img src=".gitbook/assets/image (45).png" alt=""><figcaption></figcaption></figure>
2022-10-25 14:58:43 +00:00
2024-06-05 12:41:51 +00:00
[**RootedCON**](https://www.rootedcon.com) ni tukio muhimu zaidi la usalama wa mtandao nchini **Hispania** na moja ya muhimu zaidi barani **Ulaya**. Kwa lengo la kukuza maarifa ya kiufundi, kongamano hili ni mahali pa kukutana kwa wataalamu wa teknolojia na usalama wa mtandao katika kila nidhamu.
2022-10-25 14:58:43 +00:00
{% embed url="https://www.rootedcon.com/" %}
***
2022-10-25 14:58:43 +00:00
2022-06-09 08:38:14 +00:00
### [Intigriti](https://www.intigriti.com)
<figure><img src=".gitbook/assets/image (47).png" alt=""><figcaption></figcaption></figure>
2022-06-09 08:38:14 +00:00
2024-06-05 12:41:51 +00:00
**Intigriti** ni jukwaa la kwanza la kudukua kimaadili barani Ulaya na **bug bounty**.
2022-06-09 08:38:14 +00:00
2024-06-05 12:41:51 +00:00
**Mbinu ya bug bounty**: **jiandikishe** kwa **Intigriti**, jukwaa la **bug bounty** la malipo ya juu lililoanzishwa na wadukuzi, kwa wadukuzi! Jiunge nasi kwenye [**https://go.intigriti.com/hacktricks**](https://go.intigriti.com/hacktricks) leo, na anza kupata zawadi hadi **$100,000**!
2022-06-09 08:38:14 +00:00
{% embed url="https://go.intigriti.com/hacktricks" %}
***
2022-09-08 15:18:29 +00:00
### [Trickest](https://trickest.com/?utm\_campaign=hacktrics\&utm\_medium=banner\&utm\_source=hacktricks)
<figure><img src=".gitbook/assets/image (48).png" alt=""><figcaption></figcaption></figure>
2022-09-08 15:18:29 +00:00
\
2024-06-05 12:41:51 +00:00
Tumia [**Trickest**](https://trickest.com/?utm\_campaign=hacktrics\&utm\_medium=banner\&utm\_source=hacktricks) kujenga na **kutumia taratibu za kiotomatiki** zilizowezeshwa na zana za jamii za **juu zaidi** duniani.
2022-10-25 19:47:53 +00:00
2024-02-11 02:13:58 +00:00
Pata Ufikiaji Leo:
2022-09-08 15:18:29 +00:00
{% embed url="https://trickest.com/?utm_campaign=hacktrics&utm_medium=banner&utm_source=hacktricks" %}
***
2023-02-27 10:02:29 +00:00
### [HACKENPROOF](https://bit.ly/3xrrDrL)
2022-10-25 19:47:53 +00:00
<figure><img src=".gitbook/assets/image (50).png" alt=""><figcaption></figcaption></figure>
2022-10-25 19:47:53 +00:00
2024-06-05 12:41:51 +00:00
Jiunge na seva ya [**HackenProof Discord**](https://discord.com/invite/N3FrSbmwdy) ili kuwasiliana na wadukuzi wenye uzoefu na wawindaji wa bug bounty!
2023-02-27 09:20:33 +00:00
2024-06-05 12:41:51 +00:00
* **Machapisho ya Kudukua:** Shiriki na yaliyomo yanayochimba kina katika msisimko na changamoto za kudukua
* **Habari za Kudukua za Wakati Halisi:** Endelea kufahamishwa na ulimwengu wa kudukua unaobadilika haraka kupitia habari na ufahamu wa wakati halisi
* **Matangazo Mapya:** Endelea kufahamishwa na bug bounties mpya zinazoanzishwa na sasisho muhimu za jukwaa
2023-07-14 14:20:34 +00:00
2024-02-11 02:13:58 +00:00
**Jiunge nasi kwenye** [**Discord**](https://discord.com/invite/N3FrSbmwdy) na anza kushirikiana na wadukuzi bora leo!
2022-10-25 19:47:53 +00:00
***
2024-06-05 12:41:51 +00:00
### [Pentest-Tools.com](https://pentest-tools.com/) - Jumuishi ya zana za ukaguzi wa kuingilia
<figure><img src=".gitbook/assets/image (15) (1).png" alt=""><figcaption></figcaption></figure>
2024-06-05 12:41:51 +00:00
**Usanidi uliopo mara moja kwa tathmini ya udhaifu & ukaguzi wa kuingilia**. Tekeleza ukaguzi kamili kutoka popote na zana na vipengele zaidi ya 20 vinavyoanzia uchunguzi hadi ripoti. Hatuchukui nafasi ya wakaguzi wa kuingilia - tunatengeneza zana za desturi, ugunduzi & moduli za kutumia ili kuwarudishia muda wa kuchimba kina, kuvunja makompyuta, na kufurahi.
{% embed url="https://pentest-tools.com/" %}
***
### [SerpApi](https://serpapi.com/)
<figure><img src=".gitbook/assets/image (5) (1).png" alt=""><figcaption></figcaption></figure>
2024-06-05 12:41:51 +00:00
SerpApi inatoa APIs za haraka na rahisi za wakati halisi za **kufikia matokeo ya injini za utaftaji**. Wao huchimba injini za utaftaji, kushughulikia proksi, kutatua captchas, na kuchambua data iliyopangwa kwa utajiri kwa niaba yako.
2024-06-05 12:41:51 +00:00
Usajili kwa moja ya mipango ya SerpApi ni pamoja na ufikiaji wa APIs zaidi ya 50 tofauti za kuchimba injini za utaftaji tofauti, ikiwa ni pamoja na Google, Bing, Baidu, Yahoo, Yandex, na zingine.\
Tofauti na watoa huduma wengine, **SerpApi huchimba matokeo ya asili tu**. Majibu ya SerpApi mara kwa mara hujumuisha matangazo yote, picha na video za ndani, grafu za maarifa, na vipengele vingine na sifa zilizopo kwenye matokeo ya utaftaji.
Wateja wa sasa wa SerpApi ni pamoja na **Apple, Shopify, na GrubHub**.\
2024-06-05 12:41:51 +00:00
Kwa maelezo zaidi tembelea [**blogi yao**](https://serpapi.com/blog/)**,** au jaribu mfano kwenye [**uwanja wao wa michezo**](https://serpapi.com/playground)**.**\
Unaweza **kuunda akaunti ya bure** [**hapa**](https://serpapi.com/users/sign\_up)**.**
***
2024-03-25 15:45:34 +00:00
### [Try Hard Security Group](https://discord.gg/tryhardsecurity)
<figure><img src=".gitbook/assets/telegram-cloud-document-1-5159108904864449420.jpg" alt=""><figcaption></figcaption></figure>
{% embed url="https://discord.gg/tryhardsecurity" %}
***
2022-10-05 21:51:12 +00:00
### [WebSec](https://websec.nl/)
<figure><img src=".gitbook/assets/websec (1).svg" alt=""><figcaption></figcaption></figure>
2022-09-21 13:24:22 +00:00
2024-06-05 12:41:51 +00:00
[**WebSec**](https://websec.nl) ni kampuni ya kitaalamu ya usalama wa mtandao iliyoko **Amsterdam** ambayo husaidia **kulinda** biashara **ulimwenguni kote** dhidi ya vitisho vya usalama wa mtandao vya hivi karibuni kwa kutoa huduma za **usalama wa kushambulia** kwa njia **ya kisasa**.
2024-06-05 12:41:51 +00:00
WebSec ni kampuni ya usalama ya aina moja ambayo inamaanisha wanafanya yote; Ukaguzi wa Kuingilia, Ukaguzi wa Usalama, Mafunzo ya Uelewa, Kampeni za Udukuzi, Mapitio ya Kanuni, Maendeleo ya Udukuzi, Kutoa Wataalamu wa Usalama na mengi zaidi.
2024-06-05 12:41:51 +00:00
Jambo lingine zuri kuhusu WebSec ni kwamba tofauti na wastani wa tasnia WebSec ni **imara sana katika ujuzi wao**, kwa kiwango ambacho **wanahakikisha matokeo bora zaidi ya ubora**, inasemwa kwenye tovuti yao "**Ikiwa hatuwezi kudukua, Hulipi!**". Kwa maelezo zaidi angalia [**tovuti yao**](https://websec.nl/en/) na [**blogi**](https://websec.nl/blog/) yao!
2024-06-05 12:41:51 +00:00
Mbali na hayo WebSec pia ni **mchangiaji aliyejitolea wa HackTricks.**
2022-09-21 13:24:22 +00:00
{% embed url="https://www.youtube.com/watch?v=Zq2JycGDCPM" %}
### [WhiteIntel](https://whiteintel.io)
2024-04-18 02:50:39 +00:00
<figure><img src=".gitbook/assets/image (1227).png" alt=""><figcaption></figcaption></figure>
2024-04-18 02:50:39 +00:00
[**WhiteIntel**](https://whiteintel.io) ni injini ya utaftaji inayotumia **dark-web** ambayo inatoa huduma za **bure** za kuangalia ikiwa kampuni au wateja wake wameathiriwa na **malwares za kuiba**.
2024-04-18 02:50:39 +00:00
2024-06-05 12:41:51 +00:00
Lengo kuu la WhiteIntel ni kupambana na utekaji wa akaunti na mashambulio ya ransomware yanayotokana na programu hasidi za kuiba taarifa.
2024-04-18 02:50:39 +00:00
Unaweza kutembelea tovuti yao na kujaribu injini yao **bure** kwa:
{% embed url="https://whiteintel.io" %}
## Leseni & Taarifa ya Kisheria
2022-09-21 13:24:22 +00:00
2024-06-05 12:41:51 +00:00
Wapatie:
2022-04-28 16:01:33 +00:00
{% content-ref url="welcome/hacktricks-values-and-faq.md" %}
[hacktricks-values-and-faq.md](welcome/hacktricks-values-and-faq.md)
{% endcontent-ref %}
2024-04-18 02:50:39 +00:00
2024-06-05 12:41:51 +00:00
## Takwimu za Github
![Takwimu za Github za HackTricks](https://repobeats.axiom.co/api/embed/68f8746802bcf1c8462e889e6e9302d4384f164b.svg "Picha ya takwimu za Repobeats analytics")
2024-04-18 02:50:39 +00:00
<details>
2024-06-05 12:41:51 +00:00
<summary><strong>Jifunze kuhusu kudukua AWS kutoka sifuri hadi shujaa na</strong> <a href="https://training.hacktricks.xyz/courses/arte"><strong>htARTE (HackTricks AWS Red Team Expert)</strong></a><strong>!</strong></summary>
2024-04-18 02:50:39 +00:00
Njia nyingine za kusaidia HackTricks:
* Ikiwa unataka kuona **kampuni yako ikitangazwa kwenye HackTricks** au **kupakua HackTricks kwa PDF** Angalia [**MIPANGO YA KUJIUNGA**](https://github.com/sponsors/carlospolop)!
* Pata [**bidhaa rasmi za PEASS & HackTricks**](https://peass.creator-spring.com)
2024-06-05 12:41:51 +00:00
* Gundua [**Familia ya PEASS**](https://opensea.io/collection/the-peass-family), mkusanyiko wetu wa [**NFTs**](https://opensea.io/collection/the-peass-family) ya kipekee
2024-04-18 02:50:39 +00:00
* **Jiunge na** 💬 [**Kikundi cha Discord**](https://discord.gg/hRep4RUj7f) au kikundi cha [**telegram**](https://t.me/peass) au **tufuate** kwenye **Twitter** 🐦 [**@hacktricks\_live**](https://twitter.com/hacktricks\_live)**.**
2024-06-05 12:41:51 +00:00
* **Shiriki mbinu zako za kudukua kwa kuwasilisha PRs kwenye** [**HackTricks**](https://github.com/carlospolop/hacktricks) na [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) repos za github.
2024-04-18 02:50:39 +00:00
</details>