BAB 16 - KALI LINUX
PENGANTAR BAB
Selamat datang di Fase 4 - Praktik Cyber Security! Setelah memahami teori dan konsep di fase-fase sebelumnya, kini saatnya Anda memegang "senjata" sesungguhnya seorang praktisi cyber security: Kali Linux.
Kali Linux bukan sekadar distro Linux biasa. Ia adalah distribusi yang dirancang khusus untuk penetration testing, security research, computer forensics, dan reverse engineering. Dengan 600+ tools pre-installed, Kali Linux menjadi standar industri bagi profesional keamanan siber di seluruh dunia.
Bab ini akan membawa Anda dari pemahaman dasar tentang Kali Linux hingga kemampuan menginstal, mengonfigurasi, dan mengoperasikannya dengan benar - termasuk etika penggunaan yang sangat penting agar Anda tidak melanggar hukum.
Kali Linux
Pengganti BackTrack
Rolling release
Gratis selamanya
- Memahami apa itu Kali Linux dan sejarahnya
- Mengetahui fungsi dan tujuan Kali Linux
- Memahami peran Kali dalam cyber security
- Menginstal Kali Linux di berbagai platform
- Mengoperasikan Kali Linux pada Virtual Machine
- Mengenal desktop environment
- Mengoperasikan terminal Linux
- Mengelola package dengan APT
- Memahami repository Kali Linux
- Memahami etika dan legalitas penggunaan
APA ITU KALI LINUX
Definisi
"Kali Linux is a Debian-derived Linux distribution designed for digital forensics and penetration testing. It is maintained and funded by Offensive Security."
Kali Linux adalah distribusi Linux berbasis Debian Testing yang dirancang khusus untuk tugas-tugas keamanan informasi seperti penetration testing, security research, computer forensics, dan reverse engineering. Dikembangkan dan didanai oleh Offensive Security, perusahaan yang juga menyelenggarakan sertifikasi OSCP (Offensive Security Certified Professional) - salah satu sertifikasi penetration testing paling bergengsi di dunia.
Sejarah Kali Linux
Timeline Penting:
| TAHUN | PERISTIWA |
|---|---|
| 2006 | BackTrack dirilis, berbasis Knoppix dan tools dari WHAX/WHoppiX |
| 2009 | BackTrack 4 dirilis, berbasis Ubuntu 8.10 |
| 2012 | BackTrack 5 R3 - versi terakhir BackTrack |
| 2013 (Maret) | Kali Linux 1.0 dirilis - rewrite total, berbasis Debian Testing |
| 2015 (Agustus) | Kali Linux 2.0 - desktop baru, systemd, kernel upgrade |
| 2019 | Kali Linux NetHunter untuk mobile |
| 2020 | Kali Linux 2020.1 - Non-root default user, ZSH default shell |
| 2024 | Kali Linux 2024.x - rolling release terbaru |
Karakteristik Utama Kali Linux
600+ TOOLS
Tools keamanan pre-installed untuk berbagai kategori
DEBIAN-BASED
Basis Debian Testing - stabil dan up-to-date
ROLLING RELEASE
Update berkelanjutan, tidak perlu reinstall
MOBILE SUPPORT
Kali NetHunter untuk Android
CLOUD IMAGES
Tersedia untuk AWS, Azure, GCP
ARM SUPPORT
Dukungan untuk Raspberry Pi, ARM devices
- Kali Linux = kotak perkakas lengkap dokter bedah
- Tools = scalpel, forceps, jarum suntik, dll
- OS biasa (Windows/Ubuntu) = kotak P3K standar
- Pentester = dokter bedah yang menggunakan alat tersebut
Dokter bedah tidak menggunakan semua alat sekaligus, tapi memiliki akses ke semua alat yang dibutuhkan untuk berbagai prosedur. Begitu juga dengan Kali Linux - semua tools tersedia, tapi Anda hanya menggunakan yang dibutuhkan untuk tugas tertentu.
Kali Linux tidak dirancang untuk penggunaan harian seperti browsing, office, atau multimedia. Ia dirancang khusus untuk security testing. Untuk penggunaan harian, gunakan distro Linux umum seperti Ubuntu, Fedora, atau Mint.
- Kali Linux Official - About Kali Linux (kali.org/docs/introduction/about-kali-linux)
- Offensive Security - Kali Linux History
- Kali Blog - Kali Linux Releases (kali.org/blog)
FUNGSI KALI LINUX
Tujuan Utama Kali Linux
Kali Linux dirancang untuk beberapa tujuan spesifik dalam dunia keamanan informasi:
PENETRATION TESTING
Simulasi serangan untuk menemukan vulnerability
SECURITY RESEARCH
Riset keamanan dan vulnerability research
COMPUTER FORENSICS
Investigasi forensik digital
REVERSE ENGINEERING
Analisis malware dan binary
EDUCATION
Pembelajaran security dan ethical hacking
SECURITY AUDIT
Audit keamanan sistem dan jaringan
Kategori Tools di Kali Linux
| KATEGORI | DESKRIPSI | CONTOH TOOLS |
|---|---|---|
| Information Gathering | Mengumpulkan informasi tentang target | Nmap, Maltego, theHarvester |
| Vulnerability Analysis | Menemukan vulnerability | Nessus, OpenVAS, Nikto |
| Web Application Analysis | Testing aplikasi web | Burp Suite, OWASP ZAP, SQLMap |
| Password Attacks | Cracking password | John the Ripper, Hashcat, Hydra |
| Wireless Attacks | Attacking wireless networks | Aircrack-ng, Wifite, Reaver |
| Exploitation Tools | Eksploitasi vulnerability | Metasploit, Searchsploit |
| Sniffing & Spoofing | Menyadap dan memalsukan | Wireshark, Bettercap, Ettercap |
| Post Exploitation | Aksi setelah eksploitasi berhasil | Mimikatz, Empire |
| Forensics | Forensik digital | Autopsy, Volatility, Binwalk |
| Reporting Tools | Membuat laporan | Dradis, Faraday |
Keunggulan Kali Linux
- Tools lengkap - 600+ tools pre-installed
- Free & Open Source - gratis dan bisa dimodifikasi
- Community support - komunitas besar dan aktif
- Multi-platform - bisa diinstal di berbagai hardware
- Regular updates - rolling release dengan update berkala
- Custom kernel - dengan patch untuk wireless injection
- Portable - bisa dijalankan dari USB (Live boot)
- ARM support - untuk Raspberry Pi dan perangkat ARM
- Kali Linux = perpustakaan dengan koleksi buku lengkap tentang keamanan
- Tools = buku-buku di berbagai kategori
- Penetration tester = peneliti yang datang untuk membaca buku tertentu
- Live boot = membaca buku tanpa perlu meminjam (tidak mengubah koleksi)
- Kali Linux Tools - Tools Category (kali.org/tools)
- Offensive Security - Kali Linux Features
KALI LINUX UNTUK CYBER SECURITY
Peran Kali dalam Cyber Security
Kali Linux adalah standar industri untuk berbagai peran dalam cyber security:
| PERAN | PENGGUNAAN KALI LINUX | TOOLS KUNCI |
|---|---|---|
| Penetration Tester | Melakukan penetration testing pada sistem, jaringan, aplikasi | Metasploit, Burp Suite, Nmap |
| Security Researcher | Riset vulnerability baru, exploit development | GDB, Ghidra, Radare2 |
| Forensic Investigator | Investigasi insiden keamanan, analisis forensik | Autopsy, Volatility, Sleuth Kit |
| Red Team Operator | Simulasi adversary realistis | Cobalt Strike, Empire, Covenant |
| Security Consultant | Audit keamanan untuk klien | Nessus, OpenVAS, Nikto |
| Bug Bounty Hunter | Mencari vulnerability di program bug bounty | Burp Suite, Subfinder, Nuclei |
Workflow Penetration Testing dengan Kali
Scope & rules
Info gathering
Vuln discovery
Gain access
Maintain access
Document findings
Contoh Penggunaan Tools
Bash - Common Kali Tools # 1. Nmap - Network scanning $ nmap -sV -sC 192.168.1.1 # Scan target with version detection and default scripts # 2. Nikto - Web vulnerability scanner $ nikto -h http://target.com # Scan web server for known vulnerabilities # 3. SQLMap - SQL injection tool $ sqlmap -u "http://target.com/page?id=1" --dbs # Test for SQL injection # 4. Hydra - Password cracker $ hydra -l admin -P /usr/share/wordlists/rockyou.txt ssh://192.168.1.1 # Brute force SSH login # 5. John the Ripper - Password cracker $ john hash.txt --wordlist=/usr/share/wordlists/rockyou.txt # Crack password hashes # 6. Aircrack-ng - Wireless attack $ aircrack-ng capture.cap # Crack WPA/WPA2 handshake # 7. Metasploit - Exploitation framework $ msfconsole msf> search exploit msf> use exploit/unix/ftp/vsftpd_234_backdoor msf> set RHOSTS 192.168.1.1 msf> exploit # 8. Wireshark - Packet analyzer $ wireshark # GUI packet analyzer $ tshark -i eth0 # CLI packet capture # 9. Burp Suite - Web proxy $ burpsuite # Web application security testing # 10. Hashcat - Advanced password recovery $ hashcat -m 0 hash.txt /usr/share/wordlists/rockyou.txt # Crack MD5 hashes with GPU acceleration
Struktur Menu Kali Linux
Kali Linux mengorganisir tools dalam menu yang terstruktur berdasarkan kategori:
| MENU | DESKRIPSI |
|---|---|
| Information Gathering | DNS analysis, OS identification, service enumeration |
| Vulnerability Analysis | Fuzzers, vulnerability scanners |
| Web Application Analysis | Web proxies, web crawlers |
| Password Attacks | Offline attacks, online attacks |
| Wireless Attacks | Wireless tools, WEP/WPA attacks |
| Exploitation Tools | Exploitation frameworks |
| Sniffing & Spoofing | Network sniffers, spoofing tools |
| Post Exploitation | OS backdoors, tunneling |
| Forensics | Forensic imaging, reporting |
- Penetration tester = dokter spesialis
- Tools = peralatan medis di setiap ruangan
- Menu kategori = departemen (bedah, radiologi, dll)
- Workflow = prosedur medis standar
Dokter tidak menggunakan semua alat sekaligus, tapi tahu alat mana yang dibutuhkan untuk kasus tertentu.
- PTES - Penetration Testing Execution Standard
- OWASP - Testing Guide
- Kali Linux Documentation - Tools Usage
INSTALASI KALI LINUX
Metode Instalasi
Kali Linux dapat diinstal dengan berbagai cara sesuai kebutuhan:
| METODE | DESKRIPSI | USE CASE |
|---|---|---|
| Bare Metal | Install langsung di hardware | Dedicated pentest machine |
| Virtual Machine | Jalankan di VM (VirtualBox, VMware) | Safe environment, snapshots |
| Live Boot | Boot dari USB tanpa install | Portable, forensics |
| WSL (Windows Subsystem) | Jalankan di Windows | Windows users |
| ARM Devices | Raspberry Pi, ARM devices | Portable, embedded |
| Cloud Images | AWS, Azure, GCP, DigitalOcean | Cloud pentesting |
| Docker | Container-based | Lightweight, reproducible |
Download Kali Linux
Download Kali Linux # 1. Kunjungi website resmi https://www.kali.org/get-kali/ # 2. Pilih installer sesuai kebutuhan: # - Installer Images: untuk install bare metal # - Live Boot: untuk boot dari USB # - Virtual Machines: pre-built VM images # - ARM: untuk ARM devices # - Cloud: untuk cloud platforms # 3. Verifikasi checksum (PENTING!) $ sha256sum kali-linux-2024.1-installer-amd64.iso # Bandingkan dengan checksum di website # 4. Download dengan checksum verification $ wget https://cdimage.kali.org/kali-2024.1/kali-linux-2024.1-installer-amd64.iso $ wget https://cdimage.kali.org/kali-2024.1/SHA256SUMS $ sha256sum -c SHA256SUMS --ignore-missing
Instalasi Bare Metal
Langkah-langkah:
- Buat bootable USB dengan Rufus (Windows) atau Etcher (cross-platform)
- Boot dari USB - masuk BIOS/UEFI, ubah boot order
- Pilih "Graphical Install"
- Pilih bahasa, lokasi, keyboard
- Konfigurasi jaringan - hostname, domain
- Setup user - username dan password (bukan root lagi!)
- Partitioning - pilih "Guided - use entire disk" atau manual
- Install GRUB bootloader
- Finish installation dan reboot
Bash - Create Bootable USB (Linux) # 1. Identify USB device $ lsblk # Note the USB device (e.g., /dev/sdb) # 2. Write ISO to USB # WARNING: This will erase all data on USB! $ sudo dd if=kali-linux-2024.1-installer-amd64.iso of=/dev/sdb bs=4M status=progress oflag=sync # Alternative: Use balenaEtcher (GUI) # Download from: https://www.balena.io/etcher/
Instalasi di WSL (Windows)
PowerShell - Install Kali on WSL # 1. Enable WSL (if not already enabled) PS> wsl --install # 2. Install Kali Linux from Microsoft Store PS> wsl --install -d kali-linux # Or download from Microsoft Store directly # 3. Launch Kali PS> wsl -d kali-linux # 4. Update Kali $ sudo apt update && sudo apt upgrade -y # 5. Install Kali tools (optional) $ sudo apt install -y kali-linux-headless # Or: kali-linux-default, kali-linux-everything
System Requirements
| COMPONENT | MINIMUM | RECOMMENDED |
|---|---|---|
| CPU | 64-bit (amd64) | Multi-core 64-bit |
| RAM | 2 GB | 4 GB+ |
| Disk Space | 20 GB | 50 GB+ (untuk tools) |
| USB | 4 GB (untuk Live boot) | 8 GB+ |
Sebelum menginstal Kali Linux, selalu verifikasi SHA256 checksum untuk memastikan file ISO tidak rusak atau dimodifikasi. Ini mencegah instalasi file yang telah di-tamper.
- Bare metal = memasang peralatan di rumah sendiri
- Virtual Machine = memasang peralatan di ruang simulasi (aman, bisa di-reset)
- Live boot = membawa peralatan portable (tidak mengubah rumah)
- WSL = memasang peralatan di rumah tetangga (Windows)
- Kali Linux Documentation - Installing Kali Linux
- Kali Docs - Verifying ISO Image Integrity
- Microsoft - WSL Installation Guide
KALI LINUX PADA VIRTUAL MACHINE
Mengapa Menggunakan VM?
- Isolation - Kali terisolasi dari host system
- Snapshots - bisa save dan restore state
- Safety - eksperimen berbahaya tidak merusak host
- Portability - mudah dipindahkan antar komputer
- Multiple OS - jalankan beberapa OS sekaligus
- Easy setup - pre-built images tersedia
Virtualization Software
| SOFTWARE | LICENSE | PLATFORM | KEUNGGULAN |
|---|---|---|---|
| VirtualBox | Free (GPL) | Windows, Linux, macOS | Open source, komunitas besar |
| VMware Workstation | Commercial/Free Player | Windows, Linux | Performa tinggi, fitur enterprise | VMware Fusion | Commercial | macOS | Optimized for Mac |
| Parallels | Commercial | macOS | Best macOS integration |
| Hyper-V | Free (Windows Pro) | Windows | Native Windows hypervisor |
Menggunakan Pre-built VM Images
Setup Kali VM # 1. Download pre-built VM image https://www.kali.org/get-kali/#kali-virtual-machines # Pilih: # - VirtualBox image (.ova) # - VMware image (vmwarevm) # 2. Verify checksum $ sha256sum kali-linux-2024.1-virtualbox-amd64.ova # 3. Import ke VirtualBox # File -> Import Appliance -> Select .ova file # 4. Configure VM settings: # - RAM: 2-4 GB # - CPU: 2 cores # - Network: NAT or Bridged # - USB: Enable USB 2.0/3.0 # 5. Start VM # 6. Default credentials (old versions): # Username: kali # Password: kali # 7. Update system $ sudo apt update && sudo apt full-upgrade -y # 8. Install VirtualBox Guest Additions (if needed) $ sudo apt install -y virtualbox-guest-x11
Network Configuration
| MODE | DESKRIPSI | USE CASE |
|---|---|---|
| NAT | VM di belakang host, akses internet via host | Default, aman untuk testing |
| Bridged | VM langsung di network, dapat IP dari DHCP | Network testing, akses ke LAN |
| Host-Only | VM hanya bisa komunikasi dengan host | Isolated testing |
| Internal Network | VM hanya bisa komunikasi dengan VM lain | Isolated lab environment |
| NAT Network | Multiple VMs dengan NAT, bisa saling akses | Multi-VM lab |
Snapshots
VM Snapshots # Snapshots memungkinkan save state VM # Berguna untuk: # - Save state sebelum eksperimen berbahaya # - Restore ke state sebelumnya # - Test berbeda skenario # VirtualBox: # Machine -> Take Snapshot # Machine -> Snapshots -> Restore # VMware: # VM -> Snapshot -> Take Snapshot # VM -> Snapshot -> Revert to Snapshot # Best practice: # 1. Buat snapshot "Clean Install" setelah install # 2. Buat snapshot sebelum install tools baru # 3. Buat snapshot sebelum eksperimen
- VM = ruang simulasi kedokteran
- Host = rumah sakit asli
- Snapshot = tombol reset di ruang simulasi
- Snapshots = foto kondisi ruangan sebelum eksperimen
Di ruang simulasi, Anda bisa melakukan kesalahan tanpa konsekuensi nyata. Begitu juga dengan VM - Anda bisa bereksperimen dengan aman.
- VirtualBox Documentation - Networking
- VMware Documentation - VM Configuration
- Kali Docs - Virtual Machines
MENGENAL DESKTOP ENVIRONMENT
Apa itu Desktop Environment?
Desktop Environment (DE) adalah kumpulan software yang menyediakan graphical user interface (GUI) untuk Linux. Ini termasuk window manager, file manager, panel, dan aplikasi default.
Desktop Environment di Kali Linux
| DE | STATUS | KARAKTERISTIK |
|---|---|---|
| Xfce | Default | Lightweight, fast, stable |
| GNOME | Available | Modern, feature-rich, resource-heavy |
| KDE Plasma | Available | Highly customizable, modern |
| MATE | Available | Classic GNOME 2 feel |
Switch Desktop Environment
Bash - Switch Desktop Environment # Install different DE $ sudo apt update # Install GNOME $ sudo apt install -y kali-desktop-gnome # Install KDE Plasma $ sudo apt install -y kali-desktop-kde # Install Xfce (default) $ sudo apt install -y kali-desktop-xfce # Switch default DE $ sudo update-alternatives --config x-session-manager # Atau pilih di login screen (display manager) # Klik ikon gear di login screen
Konfigurasi Xfce (Default)
Komponen Utama:
- Panel - taskbar di atas/bawah
- Desktop - area kerja utama
- Window Manager - mengatur window
- File Manager - Thunar
- Terminal - XFCE Terminal
- Application Menu - menu aplikasi
Customization Tips:
Xfce Customization # 1. Change theme # Settings -> Appearance -> Style # 2. Change icons # Settings -> Appearance -> Icons # 3. Add panel items # Right-click panel -> Panel -> Add New Items # 4. Change wallpaper # Right-click desktop -> Desktop Settings # 5. Configure keyboard shortcuts # Settings -> Keyboard -> Application Shortcuts # 6. Terminal transparency # Edit -> Preferences -> Appearance # Adjust transparency slider
- Linux kernel = fondasi dan struktur rumah
- Desktop Environment = interior dan dekorasi
- Xfce = interior minimalis, fungsional
- GNOME = interior modern, mewah
- KDE = interior customizable, bisa diubah sesuai selera
- Xfce Documentation - Xfce Documentation
- Kali Docs - Desktop Environment
MENGENAL TERMINAL
Apa itu Terminal?
Terminal (atau shell) adalah interface berbasis teks untuk berinteraksi dengan sistem operasi. Di Kali Linux, terminal adalah tools paling penting - hampir semua operasi dilakukan melalui command line.
Shell di Kali Linux
| SHELL | STATUS | KARAKTERISTIK |
|---|---|---|
| Zsh | Default (sejak 2020.1) | Feature-rich, customizable, oh-my-zsh |
| Bash | Traditional | Standard, widely used, compatible |
| Fish | Alternative | User-friendly, syntax highlighting |
Basic Commands
Bash - Essential Commands # === NAVIGATION === $ pwd # Print working directory $ ls # List files $ ls -la # List all files with details $ cd /path/to/dir # Change directory $ cd ~ # Go to home directory $ cd - # Go to previous directory # === FILE OPERATIONS === $ touch file.txt # Create empty file $ mkdir directory # Create directory $ mkdir -p dir1/dir2 # Create nested directories $ cp file.txt backup.txt # Copy file $ cp -r dir1 dir2 # Copy directory recursively $ mv old.txt new.txt # Move/rename file $ rm file.txt # Remove file $ rm -r directory # Remove directory recursively # WARNING: rm -rf / akan menghapus semua! # === VIEWING FILES === $ cat file.txt # Display file content $ less file.txt # View file page by page $ head file.txt # Show first 10 lines $ tail file.txt # Show last 10 lines $ tail -f log.txt # Follow log file in real-time # === SEARCH === $ grep "pattern" file # Search for pattern in file $ find /path -name "*.txt" # Find files by name $ locate file.txt # Quick file search $ which command # Find command location # === SYSTEM INFO === $ whoami # Current user $ id # User ID and groups $ uname -a # System information $ hostname # Hostname $ uptime # System uptime $ df -h # Disk usage $ free -h # Memory usage $ ps aux # List processes $ top # Real-time process monitor $ kill PID # Kill process # === NETWORK === $ ip addr # Show IP addresses $ ip route # Show routing table $ ping google.com # Test connectivity $ netstat -tulpn # Show listening ports $ ss -tulpn # Modern netstat alternative # === PERMISSIONS === $ chmod 755 file # Change permissions $ chown user:group file # Change owner # === SUPERUSER === $ sudo command # Run command as root $ sudo -i # Switch to root shell $ su - username # Switch to user
Keyboard Shortcuts
| SHORTCUT | FUNGSI |
|---|---|
Ctrl + C |
Interrupt/kill current command |
Ctrl + Z |
Suspend current process |
Ctrl + D |
Exit/logout |
Ctrl + L |
Clear screen |
Tab |
Auto-complete |
↑ / ↓ |
Navigate command history |
Ctrl + R |
Search command history |
Ctrl + A |
Move to beginning of line |
Ctrl + E |
Move to end of line |
File System Hierarchy
Linux File System / ├── bin # Essential user binaries ├── boot # Boot loader files ├── dev # Device files ├── etc # Configuration files ├── home # User home directories │ └── kali # Default user home ├── lib # Essential shared libraries ├── media # Mount point for removable media ├── mnt # Temporary mount point ├── opt # Optional software ├── proc # Process information (virtual) ├── root # Root user home ├── sbin # System binaries ├── srv # Service data ├── sys # System devices (virtual) ├── tmp # Temporary files ├── usr # User programs │ ├── bin # User binaries │ ├── lib # User libraries │ └── share # Shared data └── var # Variable data (logs, spool)
- GUI = remote control dengan tombol-tombol fixed
- Terminal = remote control universal yang bisa melakukan apa saja
- Command = instruksi spesifik ke sistem
- Shell = interpreter yang memahami instruksi
- Linux Command Line Cheat Sheet - cheatography.com
- The Linux Documentation Project - Bash Guide for Beginners
- Kali Docs - Terminal Usage
PACKAGE MANAGEMENT
Package Manager di Kali Linux
Kali Linux menggunakan APT (Advanced Package Tool) sebagai package manager, warisan dari Debian. APT memudahkan instalasi, update, dan removal software.
APT Commands
Bash - APT Package Management # === UPDATE === $ sudo apt update # Update package list $ sudo apt upgrade # Upgrade installed packages $ sudo apt full-upgrade # Full upgrade (may remove packages) $ sudo apt dist-upgrade # Distribution upgrade # === INSTALL === $ sudo apt install package-name $ sudo apt install -y package-name # Auto-confirm # Install Kali meta-packages $ sudo apt install kali-linux-default # Default tools $ sudo apt install kali-linux-large # More tools $ sudo apt install kali-linux-everything # All tools # Install tool categories $ sudo apt install kali-tools-web # Web tools $ sudo apt install kali-tools-wireless # Wireless tools $ sudo apt install kali-tools-forensics # Forensics tools # === REMOVE === $ sudo apt remove package-name $ sudo apt purge package-name # Remove with config $ sudo apt autoremove # Remove unused dependencies # === SEARCH === $ apt search keyword $ apt show package-name $ apt list --installed # === CLEAN === $ sudo apt clean # Remove cached packages $ sudo apt autoclean # Remove old cached packages
DPKG (Debian Package)
Bash - DPKG Commands # Install .deb file directly $ sudo dpkg -i package.deb # Fix broken dependencies $ sudo apt --fix-broken install # List installed packages $ dpkg -l # Show package info $ dpkg -s package-name # List files in package $ dpkg -L package-name # Find which package owns a file $ dpkg -S /path/to/file
Common Tasks
Bash - Common Package Tasks # Update system completely $ sudo apt update && sudo apt full-upgrade -y $ sudo apt autoremove -y $ sudo apt autoclean # Install specific tool $ sudo apt install nmap $ sudo apt install wireshark $ sudo apt install metasploit-framework # Check tool version $ nmap --version $ msfconsole --version # Install from source (if not in repo) $ git clone https://github.com/tool/repo.git $ cd repo $ sudo apt install build-essential $ ./configure $ make $ sudo make install
Troubleshooting
Bash - Package Troubleshooting # Fix broken packages $ sudo apt --fix-broken install # Reconfigure packages $ sudo dpkg --configure -a # Clean package cache $ sudo apt clean $ sudo apt autoclean # Update package lists $ sudo apt update # Check for held packages $ apt-mark showhold # Unhold package $ sudo apt-mark unhold package-name
- APT = App Store untuk Linux
- Repository = katalog aplikasi di App Store
- apt install = download dan install aplikasi
- apt update = refresh katalog
- apt upgrade = update semua aplikasi
- Debian - APT Howto
- Kali Docs - Package Management
- Ubuntu - APT Guide
REPOSITORY KALI LINUX
Apa itu Repository?
Repository (repo) adalah server yang menyimpan package software. APT menggunakan repository untuk download dan install software.
Repository Kali Linux
| REPOSITORY | DESKRIPSI | STATUS |
|---|---|---|
| kali-rolling | Rolling release, selalu up-to-date | Default, recommended |
| kali-last-snapshot | Point release, stable | Stable releases |
| kali-dev | Development branch | Unstable, testing only |
| kali-experimental | Experimental packages | Experimental |
Konfigurasi Repository
Bash - Repository Configuration # View current repositories $ cat /etc/apt/sources.list # Default Kali Rolling repository: # deb http://http.kali.org/kali kali-rolling main contrib non-free # deb-src http://http.kali.org/kali kali-rolling main contrib non-free # Edit sources list $ sudo nano /etc/apt/sources.list # Add custom repository # deb http://example.com/repo kali main # Add repository with GPG key $ wget -O - https://example.com/key.gpg | sudo apt-key add - $ echo "deb http://example.com/repo kali main" | sudo tee /etc/apt/sources.list.d/example.list # Update after adding repository $ sudo apt update
GPG Keys
Bash - GPG Key Management # List installed keys $ apt-key list # Add Kali archive key (if missing) $ wget -q -O - https://archive.kali.org/archive-key.asc | sudo apt-key add - # Modern method (apt-key deprecated) $ wget -O /usr/share/keyrings/kali-archive-keyring.asc https://archive.kali.org/archive-key.asc $ echo "deb [signed-by=/usr/share/keyrings/kali-archive-keyring.asc] http://http.kali.org/kali kali-rolling main" | sudo tee /etc/apt/sources.list.d/kali.list
Mirror Selection
Bash - Use Mirror # Use nearest mirror for faster downloads # Edit /etc/apt/sources.list: # deb http://http.kali.org/kali kali-rolling main contrib non-free # Or use specific mirror: # deb http://kali.mirror.Indonesia kali-rolling main # List of mirrors: # https://www.kali.org/docs/general-use/kali-linux-mirrors/
Meta-packages
| META-PACKAGE | DESKRIPSI | UKURAN |
|---|---|---|
| kali-linux-default | Default tools | ~4 GB |
| kali-linux-large | More tools | ~6 GB |
| kali-linux-everything | All tools | ~15 GB |
| kali-tools-web | Web application tools | ~1 GB |
| kali-tools-wireless | Wireless tools | ~500 MB |
| kali-tools-forensics | Forensics tools | ~1 GB |
- Repository = perpustakaan pusat
- Mirror = cabang perpustakaan di berbagai kota
- Package = buku di perpustakaan
- apt install = meminjam buku
- apt update = cek katalog baru
- Kali Docs - Kali Linux Repositories
- Kali Docs - Kali Linux Mirrors
- Debian - Repositories
ETIKA PENGGUNAAN
Legalitas Penggunaan Kali Linux
Kali Linux adalah tools yang netral - legal atau tidaknya tergantung pada bagaimana Anda menggunakannya. Seperti pisau - bisa untuk memasak (legal) atau melukai seseorang (ilegal).
JANGAN PERNAH menggunakan Kali Linux untuk menyerang sistem yang tidak Anda miliki atau tidak memiliki izin tertulis untuk mengujinya. Ini adalah ilegal dan bisa berujung pada:
- Pidana penjara (di Indonesia: UU ITE Pasal 30-32)
- Denda besar
- Tuntutan perdata dari korban
- Reputasi rusak
Hukum di Indonesia
| PASAL | ATURAN | SANKSI |
|---|---|---|
| UU ITE Pasal 30 | Mengakses komputer tanpa izin | 6-8 tahun penjara, denda Rp 600-800 juta |
| UU ITE Pasal 31 | Intersepsi/transmisi tanpa izin | 10 tahun penjara, denda Rp 800 juta |
| UU ITE Pasal 32 | Manipulasi data komputer | 8-10 tahun penjara, denda Rp 2-3 miliar |
Penggunaan yang Legal
- Testing sistem sendiri - lab pribadi, VM sendiri
- Dengan izin tertulis - penetration testing dengan kontrak
- Bug bounty program - dalam scope yang ditentukan
- Learning & education - di lingkungan terkontrol
- Security research - dengan etika dan responsible disclosure
- CTF competitions - Capture The Flag competitions
Etika Ethical Hacking
- Get proper authorization - selalu dapatkan izin tertulis
- Define scope - tentukan batasan pengujian
- Respect privacy - jangan akses data sensitif
- Report vulnerabilities - laporkan temuan dengan responsible disclosure
- Do no harm - jangan merusak sistem
- Maintain confidentiality - jaga kerahasiaan temuan
- Be honest - jujur dalam reporting
Rules of Engagement
Rules of Engagement Template # ============================================ # RULES OF ENGAGEMENT # Penetration Testing Authorization # ============================================ Client: [Nama Perusahaan] Tester: [Nama Anda] Date: [Tanggal] Scope: - IP Range: 192.168.1.0/24 - Domain: example.com - Applications: web.example.com Out of Scope: - Production database - Third-party services - Social engineering Testing Window: - Start: 2026-09-10 09:00 - End: 2026-09-15 18:00 Restrictions: - No DoS attacks - No data exfiltration - No social engineering - Testing hours: 09:00 - 18:00 WIB Emergency Contact: - Name: [Contact Person] - Phone: [Phone Number] - Email: [Email] Authorization: Client Signature: _______________ Date: _______________ Tester Signature: _______________ Date: _______________
Responsible Disclosure
- Find vulnerability - temukan vulnerability
- Document - dokumentasikan dengan detail
- Report privately - laporkan ke vendor/owner secara privat
- Allow time to fix - beri waktu untuk memperbaiki (biasanya 30-90 hari)
- Follow up - follow up jika tidak ada respons
- Public disclosure - publikasi setelah patch dirilis
White Hat vs Black Hat
| ASPEK | WHITE HAT | BLACK HAT |
|---|---|---|
| Tujuan | Meningkatkan keamanan | Keuntungan pribadi, merusak |
| Authorization | Dengan izin | Tanpa izin |
| Reporting | Laporkan ke owner | Eksploitasi atau jual |
| Legalitas | Legal | Ilegal |
| Etika | Etis | Tidak etis |
- White hat = satpam yang menyamar untuk menguji keamanan bank
- Black hat = perampok bank yang sebenarnya
- Authorization = surat tugas dari bank
- Responsible disclosure = melaporkan celah keamanan ke bank, bukan ke media
Keduanya punya skill yang sama, tapi niat dan authorization yang membedakan.
"With great power comes great responsibility" - Uncle Ben
Kali Linux memberikan Anda kekuatan yang luar biasa. Gunakan kekuatan ini dengan bijak, etis, dan legal. Jangan pernah menggunakan skill Anda untuk hal yang merugikan orang lain.
- UU No. 11 Tahun 2008 jo. UU No. 19 Tahun 2016 - Informasi dan Transaksi Elektronik
- EC-Council - Code of Ethics
- Offensive Security - Legal Disclaimer
- OWASP - Legal
DIAGNOSTIK KOMPETENSI
Uji pemahaman Anda tentang Bab 16! Target minimal: 70% untuk melanjutkan ke Bab 17.
- Total 10 pertanyaan pilihan ganda
- Klik opsi untuk menjawab - feedback langsung
- Benar = HIJAU, salah = MAGENTA
- Penjelasan muncul setelah menjawab
- Klik "LIHAT HASIL AKHIR" untuk skor final
-
- Kali Linux Official Documentation - kali.org/docs
- Offensive Security - Kali Linux Revealed (free ebook)
- Debian Documentation - Debian Administrator's Handbook
- UU ITE - Undang-Undang Informasi dan Transaksi Elektronik