3-da Aaladood ee ugu Sarreysa ee Khaaska ah ee jabsiga Anshaxa

3-da Aaladood ee ugu Sarreysa ee Khaaska ah ee jabsiga Anshaxa

Hordhac

Inkastoo phishing Weerarada waxaa isticmaali kara jilayaal xaasidnimo ah si ay u xadaan xogta shakhsiyeed ama u faafiyaan malware, jabsada akhlaaqda ayaa isticmaali kara tabo la mid ah si ay u tijaabiyaan dayacanka kaabayaasha ammaanka ee ururka. Kuwaas qalab waxaa loogu talagalay in lagu caawiyo jabsiga anshaxa si ay u ekaysiiyaan weerarrada phishing-ka ee dunida dhabta ah oo ay tijaabiyaan jawaabta ay shaqaalaha hay'addu ka bixiyaan weerarradan. Isticmaalka qalabkan, tuugada akhlaaqda ayaa aqoonsan kara dayacanka amniga ururka oo ka caawinaya inay qaadaan tillaabooyinka lagama maarmaanka ah si ay uga hortagaan weerarada phishingka. Maqaalkan, waxaan ku baari doonaa 3-da aaladood ee ugu sarreeya ee phishing-ka u ah jabsiga anshaxa.

SEToolkit

Qalabka injineernimada bulshada (SEToolkit) waa qalab Linux ah oo loogu talagalay in lagu caawiyo weerarrada injineernimada bulshada. Waxa ku jira dhowr nooc oo injineernimo bulsho oo toos ah. Kiis loo isticmaalo SEToolkit ayaa isku xidhaya mareegaha si loo goosto aqoonsiga. Tan waxaa lagu samayn karaa tallaabooyinka soo socda:

 

  1. Terminalkaada Linux, geli settoolkit.
  2. Laga soo bilaabo menu-ka, dooro ikhtiyaarka ugu horreeya adiga oo gelaya 1 galay terminaalka. 
  3. Natiijooyinka, geli 2 ee terminalka si aad u doorato Vectors Weerar Websaydh. Dooro Habka Weerar-Gurista Aqoonsiga, kadibna dooro Shabakadda Shabakadda 
  4. Dooro qaabka aad door bidayso. Ciwaanka IP-ga ee u jiheeya goobta la isku xidhay waa la soo celinayaa. 
  5. Haddii qof isku shabakad ah uu booqdo ciwaanka IP-ga oo uu geliyo aqoonsigiisa, waa la goostay waxaana laga arki karaa terminalka.

Xaalad halka tan lagu dabaqi karo waa haddii aad ku dhex jirto shabakad oo aad taqaanno arjiga shabakadda ee uu ururku isticmaalo. Waxaad kaliya xidhi kartaa arjigan oo aad kor u qaadi kartaa adigoo u sheegaya isticmaalaha inuu beddelo password ama deji furkooda.

Kingphisher

Kingphisher waa madal jilid kalluumaysi dhammaystiran oo kuu ogolaanaysa inaad maarayso ololayaashaaga kalluumaysi, dirto ololeyaal kalluumaysi oo badan, la shaqayso isticmaaleyaal badan, abuur bogag HTML ah, oo aad u kaydsato qaab qaabaysan. Isku xirka isticmaalaha garaafyada waa sahlan tahay in la isticmaalo oo waxaa lagu sii raray Kali. Interface-ku wuxuu kaloo kuu ogolaanayaa inaad la socoto haddii booqde bog furo ama haddii booqde uu riixo xiriiriye. Haddii aad u baahan tahay is-dhexgal naqshadeynta garaafyada si aad u bilowdo kalluumeysiga ama weerarrada injineernimada bulshada, Kingphisher waa ikhtiyaar wanaagsan

Gophish

Kani waa qaab-dhismeedka jilitaanka phishing-ka ugu caansan. Gofish waa qaab-dhismeed phishing ah oo dhamaystiran oo aad isticmaali karto si aad u sameyso nooc kasta oo weerar kalluumeysi ah. Waxay leedahay interface aad u nadiif ah oo isticmaale-saaxiibtinimo leh. Goobta waxa loo isticmaali karaa in lagu fuliyo weeraro phishing oo badan.

Waxaad samayn kartaa olole kalluumeysi oo kala duwan, profiles dirid oo kala duwan, bogag degitaan, iyo qaabab iimayl.

 

Abuuritaanka olole Gophish ah

  1. Dhinaca bidix ee console-ka, dhagsii Ololayaasha.
  2. Soo-gudbinta, Geli faahfaahinta lagama maarmaanka ah.
  3. Bilaw ololaha oo dir boostada tijaabada si aad u hubiso inay shaqaynayso
  4. Tusaalahaaga Gophish wuxuu diyaar u yahay ololayaasha phishingka.

Ugu Dambeyn

Gebagebadii, weerarrada phishing-ka ayaa weli ah khatar weyn oo ku wajahan ururrada nooc kasta leh, taasoo ka dhigaysa lama huraan u ah hackers-ka akhlaaqda ah inay naftooda si joogto ah ula socdaan agabkii iyo farsamooyinkii ugu dambeeyay ee ay isaga difaacaan weerarradaas. Saddexda aaladood ee aan kaga hadalnay maqaalkan – GoPhish, Social-Engineer Toolkit (SET), iyo King Phisher – waxa ay bixiyaan sifooyin kala duwan oo awood leh kuwaas oo ka caawin kara jabsiga akhlaaqda in ay tijaabiyaan oo ay wanaajiyaan qaabka amniga ururkooda. Iyadoo qalab kastaa leeyahay awoodo gaar ah iyo daciifnimo, adoo fahmaya sida ay u shaqeeyaan oo aad doorato midka ku habboon baahiyahaaga gaarka ah, waxaad kor u qaadi kartaa awooddaada inaad ku aqoonsato oo aad yarayso weerarrada phishingka.