ABDURROZAK
ABDURROZAK.MY.ID // EBOOK

BAB 16 - KALI LINUX

SENJATA UTAMA PRAKTISI CYBER SECURITY
10 SUB-BAB ~90 MENIT BACA FASE 4 - PRAKTIK LEVEL: MENENGAH

PENGANTAR BAB

Selamat datang di Fase 4 - Praktik Cyber Security! Setelah memahami teori dan konsep di fase-fase sebelumnya, kini saatnya Anda memegang "senjata" sesungguhnya seorang praktisi cyber security: Kali Linux.

Kali Linux bukan sekadar distro Linux biasa. Ia adalah distribusi yang dirancang khusus untuk penetration testing, security research, computer forensics, dan reverse engineering. Dengan 600+ tools pre-installed, Kali Linux menjadi standar industri bagi profesional keamanan siber di seluruh dunia.

Bab ini akan membawa Anda dari pemahaman dasar tentang Kali Linux hingga kemampuan menginstal, mengonfigurasi, dan mengoperasikannya dengan benar - termasuk etika penggunaan yang sangat penting agar Anda tidak melanggar hukum.

600+
TOOLS PRE-INSTALLED
Kali Linux
2013
TAHUN DIRILIS
Pengganti BackTrack
Debian
DASAR DISTRO
Rolling release
Free
OPEN SOURCE
Gratis selamanya
TUJUAN PEMBELAJARAN
  • Memahami apa itu Kali Linux dan sejarahnya
  • Mengetahui fungsi dan tujuan Kali Linux
  • Memahami peran Kali dalam cyber security
  • Menginstal Kali Linux di berbagai platform
  • Mengoperasikan Kali Linux pada Virtual Machine
  • Mengenal desktop environment
  • Mengoperasikan terminal Linux
  • Mengelola package dengan APT
  • Memahami repository Kali Linux
  • Memahami etika dan legalitas penggunaan
16.1

APA ITU KALI LINUX

Definisi

Offensive Security

"Kali Linux is a Debian-derived Linux distribution designed for digital forensics and penetration testing. It is maintained and funded by Offensive Security."

Kali Linux adalah distribusi Linux berbasis Debian Testing yang dirancang khusus untuk tugas-tugas keamanan informasi seperti penetration testing, security research, computer forensics, dan reverse engineering. Dikembangkan dan didanai oleh Offensive Security, perusahaan yang juga menyelenggarakan sertifikasi OSCP (Offensive Security Certified Professional) - salah satu sertifikasi penetration testing paling bergengsi di dunia.

Sejarah Kali Linux

ANIMASI: EVOLUSI KALI LINUX
BackTrack 2006-2012 Based on Knoppix then Ubuntu Kali Linux March 2013 Based on Debian Complete rewrite Kali 2.0+ Aug 2015-now Systemd, new tools Rolling release BackTrack (2006) -> Kali 1.0 (2013) -> Kali 2.0+ (2015-now)

Timeline Penting:

TAHUNPERISTIWA
2006 BackTrack dirilis, berbasis Knoppix dan tools dari WHAX/WHoppiX
2009 BackTrack 4 dirilis, berbasis Ubuntu 8.10
2012 BackTrack 5 R3 - versi terakhir BackTrack
2013 (Maret) Kali Linux 1.0 dirilis - rewrite total, berbasis Debian Testing
2015 (Agustus) Kali Linux 2.0 - desktop baru, systemd, kernel upgrade
2019 Kali Linux NetHunter untuk mobile
2020 Kali Linux 2020.1 - Non-root default user, ZSH default shell
2024 Kali Linux 2024.x - rolling release terbaru

Karakteristik Utama Kali Linux

600+ TOOLS

Tools keamanan pre-installed untuk berbagai kategori

DEBIAN-BASED

Basis Debian Testing - stabil dan up-to-date

ROLLING RELEASE

Update berkelanjutan, tidak perlu reinstall

MOBILE SUPPORT

Kali NetHunter untuk Android

CLOUD IMAGES

Tersedia untuk AWS, Azure, GCP

ARM SUPPORT

Dukungan untuk Raspberry Pi, ARM devices

ANALOGI: KALI LINUX = KOTAK PERKAKAS DOKTER
  • Kali Linux = kotak perkakas lengkap dokter bedah
  • Tools = scalpel, forceps, jarum suntik, dll
  • OS biasa (Windows/Ubuntu) = kotak P3K standar
  • Pentester = dokter bedah yang menggunakan alat tersebut

Dokter bedah tidak menggunakan semua alat sekaligus, tapi memiliki akses ke semua alat yang dibutuhkan untuk berbagai prosedur. Begitu juga dengan Kali Linux - semua tools tersedia, tapi Anda hanya menggunakan yang dibutuhkan untuk tugas tertentu.

KALI LINUX BUKAN UNTUK DAILY DRIVER

Kali Linux tidak dirancang untuk penggunaan harian seperti browsing, office, atau multimedia. Ia dirancang khusus untuk security testing. Untuk penggunaan harian, gunakan distro Linux umum seperti Ubuntu, Fedora, atau Mint.

REFERENSI
  • Kali Linux Official - About Kali Linux (kali.org/docs/introduction/about-kali-linux)
  • Offensive Security - Kali Linux History
  • Kali Blog - Kali Linux Releases (kali.org/blog)
16.2

FUNGSI KALI LINUX

Tujuan Utama Kali Linux

Kali Linux dirancang untuk beberapa tujuan spesifik dalam dunia keamanan informasi:

PENETRATION TESTING

Simulasi serangan untuk menemukan vulnerability

SECURITY RESEARCH

Riset keamanan dan vulnerability research

COMPUTER FORENSICS

Investigasi forensik digital

REVERSE ENGINEERING

Analisis malware dan binary

EDUCATION

Pembelajaran security dan ethical hacking

SECURITY AUDIT

Audit keamanan sistem dan jaringan

Kategori Tools di Kali Linux

KATEGORIDESKRIPSICONTOH TOOLS
Information Gathering Mengumpulkan informasi tentang target Nmap, Maltego, theHarvester
Vulnerability Analysis Menemukan vulnerability Nessus, OpenVAS, Nikto
Web Application Analysis Testing aplikasi web Burp Suite, OWASP ZAP, SQLMap
Password Attacks Cracking password John the Ripper, Hashcat, Hydra
Wireless Attacks Attacking wireless networks Aircrack-ng, Wifite, Reaver
Exploitation Tools Eksploitasi vulnerability Metasploit, Searchsploit
Sniffing & Spoofing Menyadap dan memalsukan Wireshark, Bettercap, Ettercap
Post Exploitation Aksi setelah eksploitasi berhasil Mimikatz, Empire
Forensics Forensik digital Autopsy, Volatility, Binwalk
Reporting Tools Membuat laporan Dradis, Faraday
ANIMASI: KATEGORI TOOLS KALI LINUX
KALI LINUX 600+ tools RECON VULN SCAN WEB APP PASSWORD WIRELESS EXPLOIT

Keunggulan Kali Linux

KEUNGGULAN
  • Tools lengkap - 600+ tools pre-installed
  • Free & Open Source - gratis dan bisa dimodifikasi
  • Community support - komunitas besar dan aktif
  • Multi-platform - bisa diinstal di berbagai hardware
  • Regular updates - rolling release dengan update berkala
  • Custom kernel - dengan patch untuk wireless injection
  • Portable - bisa dijalankan dari USB (Live boot)
  • ARM support - untuk Raspberry Pi dan perangkat ARM
ANALOGI: KALI LINUX = PERPUSTAKAAN LENGKAP
  • Kali Linux = perpustakaan dengan koleksi buku lengkap tentang keamanan
  • Tools = buku-buku di berbagai kategori
  • Penetration tester = peneliti yang datang untuk membaca buku tertentu
  • Live boot = membaca buku tanpa perlu meminjam (tidak mengubah koleksi)
REFERENSI
  • Kali Linux Tools - Tools Category (kali.org/tools)
  • Offensive Security - Kali Linux Features
16.3

KALI LINUX UNTUK CYBER SECURITY

Peran Kali dalam Cyber Security

Kali Linux adalah standar industri untuk berbagai peran dalam cyber security:

PERANPENGGUNAAN KALI LINUXTOOLS KUNCI
Penetration Tester Melakukan penetration testing pada sistem, jaringan, aplikasi Metasploit, Burp Suite, Nmap
Security Researcher Riset vulnerability baru, exploit development GDB, Ghidra, Radare2
Forensic Investigator Investigasi insiden keamanan, analisis forensik Autopsy, Volatility, Sleuth Kit
Red Team Operator Simulasi adversary realistis Cobalt Strike, Empire, Covenant
Security Consultant Audit keamanan untuk klien Nessus, OpenVAS, Nikto
Bug Bounty Hunter Mencari vulnerability di program bug bounty Burp Suite, Subfinder, Nuclei

Workflow Penetration Testing dengan Kali

PLANNING
Scope & rules
RECONNAISSANCE
Info gathering
SCANNING
Vuln discovery
EXPLOITATION
Gain access
POST-EXPLOIT
Maintain access
REPORTING
Document findings

Contoh Penggunaan Tools

Bash - Common Kali Tools
# 1. Nmap - Network scanning
$ nmap -sV -sC 192.168.1.1
# Scan target with version detection and default scripts

# 2. Nikto - Web vulnerability scanner
$ nikto -h http://target.com
# Scan web server for known vulnerabilities

# 3. SQLMap - SQL injection tool
$ sqlmap -u "http://target.com/page?id=1" --dbs
# Test for SQL injection

# 4. Hydra - Password cracker
$ hydra -l admin -P /usr/share/wordlists/rockyou.txt ssh://192.168.1.1
# Brute force SSH login

# 5. John the Ripper - Password cracker
$ john hash.txt --wordlist=/usr/share/wordlists/rockyou.txt
# Crack password hashes

# 6. Aircrack-ng - Wireless attack
$ aircrack-ng capture.cap
# Crack WPA/WPA2 handshake

# 7. Metasploit - Exploitation framework
$ msfconsole
msf> search exploit
msf> use exploit/unix/ftp/vsftpd_234_backdoor
msf> set RHOSTS 192.168.1.1
msf> exploit

# 8. Wireshark - Packet analyzer
$ wireshark
# GUI packet analyzer
$ tshark -i eth0
# CLI packet capture

# 9. Burp Suite - Web proxy
$ burpsuite
# Web application security testing

# 10. Hashcat - Advanced password recovery
$ hashcat -m 0 hash.txt /usr/share/wordlists/rockyou.txt
# Crack MD5 hashes with GPU acceleration

Struktur Menu Kali Linux

Kali Linux mengorganisir tools dalam menu yang terstruktur berdasarkan kategori:

MENUDESKRIPSI
Information Gathering DNS analysis, OS identification, service enumeration
Vulnerability Analysis Fuzzers, vulnerability scanners
Web Application Analysis Web proxies, web crawlers
Password Attacks Offline attacks, online attacks
Wireless Attacks Wireless tools, WEP/WPA attacks
Exploitation Tools Exploitation frameworks
Sniffing & Spoofing Network sniffers, spoofing tools
Post Exploitation OS backdoors, tunneling
Forensics Forensic imaging, reporting
ANALOGI: KALI LINUX = RUMAH SAKIT
  • Penetration tester = dokter spesialis
  • Tools = peralatan medis di setiap ruangan
  • Menu kategori = departemen (bedah, radiologi, dll)
  • Workflow = prosedur medis standar

Dokter tidak menggunakan semua alat sekaligus, tapi tahu alat mana yang dibutuhkan untuk kasus tertentu.

REFERENSI
  • PTES - Penetration Testing Execution Standard
  • OWASP - Testing Guide
  • Kali Linux Documentation - Tools Usage
16.4

INSTALASI KALI LINUX

Metode Instalasi

Kali Linux dapat diinstal dengan berbagai cara sesuai kebutuhan:

METODEDESKRIPSIUSE CASE
Bare Metal Install langsung di hardware Dedicated pentest machine
Virtual Machine Jalankan di VM (VirtualBox, VMware) Safe environment, snapshots
Live Boot Boot dari USB tanpa install Portable, forensics
WSL (Windows Subsystem) Jalankan di Windows Windows users
ARM Devices Raspberry Pi, ARM devices Portable, embedded
Cloud Images AWS, Azure, GCP, DigitalOcean Cloud pentesting
Docker Container-based Lightweight, reproducible

Download Kali Linux

Download Kali Linux
# 1. Kunjungi website resmi
https://www.kali.org/get-kali/

# 2. Pilih installer sesuai kebutuhan:
# - Installer Images: untuk install bare metal
# - Live Boot: untuk boot dari USB
# - Virtual Machines: pre-built VM images
# - ARM: untuk ARM devices
# - Cloud: untuk cloud platforms

# 3. Verifikasi checksum (PENTING!)
$ sha256sum kali-linux-2024.1-installer-amd64.iso
# Bandingkan dengan checksum di website

# 4. Download dengan checksum verification
$ wget https://cdimage.kali.org/kali-2024.1/kali-linux-2024.1-installer-amd64.iso
$ wget https://cdimage.kali.org/kali-2024.1/SHA256SUMS
$ sha256sum -c SHA256SUMS --ignore-missing

Instalasi Bare Metal

Langkah-langkah:

  1. Buat bootable USB dengan Rufus (Windows) atau Etcher (cross-platform)
  2. Boot dari USB - masuk BIOS/UEFI, ubah boot order
  3. Pilih "Graphical Install"
  4. Pilih bahasa, lokasi, keyboard
  5. Konfigurasi jaringan - hostname, domain
  6. Setup user - username dan password (bukan root lagi!)
  7. Partitioning - pilih "Guided - use entire disk" atau manual
  8. Install GRUB bootloader
  9. Finish installation dan reboot
Bash - Create Bootable USB (Linux)
# 1. Identify USB device
$ lsblk
# Note the USB device (e.g., /dev/sdb)

# 2. Write ISO to USB
# WARNING: This will erase all data on USB!
$ sudo dd if=kali-linux-2024.1-installer-amd64.iso of=/dev/sdb bs=4M status=progress oflag=sync

# Alternative: Use balenaEtcher (GUI)
# Download from: https://www.balena.io/etcher/

Instalasi di WSL (Windows)

PowerShell - Install Kali on WSL
# 1. Enable WSL (if not already enabled)
PS> wsl --install

# 2. Install Kali Linux from Microsoft Store
PS> wsl --install -d kali-linux

# Or download from Microsoft Store directly

# 3. Launch Kali
PS> wsl -d kali-linux

# 4. Update Kali
$ sudo apt update && sudo apt upgrade -y

# 5. Install Kali tools (optional)
$ sudo apt install -y kali-linux-headless
# Or: kali-linux-default, kali-linux-everything

System Requirements

COMPONENTMINIMUMRECOMMENDED
CPU 64-bit (amd64) Multi-core 64-bit
RAM 2 GB 4 GB+
Disk Space 20 GB 50 GB+ (untuk tools)
USB 4 GB (untuk Live boot) 8 GB+
SELALU VERIFIKASI CHECKSUM

Sebelum menginstal Kali Linux, selalu verifikasi SHA256 checksum untuk memastikan file ISO tidak rusak atau dimodifikasi. Ini mencegah instalasi file yang telah di-tamper.

ANALOGI: INSTALASI KALI = MEMASANG PERALATAN
  • Bare metal = memasang peralatan di rumah sendiri
  • Virtual Machine = memasang peralatan di ruang simulasi (aman, bisa di-reset)
  • Live boot = membawa peralatan portable (tidak mengubah rumah)
  • WSL = memasang peralatan di rumah tetangga (Windows)
REFERENSI
  • Kali Linux Documentation - Installing Kali Linux
  • Kali Docs - Verifying ISO Image Integrity
  • Microsoft - WSL Installation Guide
16.5

KALI LINUX PADA VIRTUAL MACHINE

Mengapa Menggunakan VM?

KEUNGGULAN VM
  • Isolation - Kali terisolasi dari host system
  • Snapshots - bisa save dan restore state
  • Safety - eksperimen berbahaya tidak merusak host
  • Portability - mudah dipindahkan antar komputer
  • Multiple OS - jalankan beberapa OS sekaligus
  • Easy setup - pre-built images tersedia

Virtualization Software

SOFTWARELICENSEPLATFORMKEUNGGULAN
VirtualBox Free (GPL) Windows, Linux, macOS Open source, komunitas besar
VMware Workstation Commercial/Free Player Windows, Linux Performa tinggi, fitur enterprise
VMware Fusion Commercial macOS Optimized for Mac
Parallels Commercial macOS Best macOS integration
Hyper-V Free (Windows Pro) Windows Native Windows hypervisor

Menggunakan Pre-built VM Images

Setup Kali VM
# 1. Download pre-built VM image
https://www.kali.org/get-kali/#kali-virtual-machines

# Pilih:
# - VirtualBox image (.ova)
# - VMware image (vmwarevm)

# 2. Verify checksum
$ sha256sum kali-linux-2024.1-virtualbox-amd64.ova

# 3. Import ke VirtualBox
# File -> Import Appliance -> Select .ova file

# 4. Configure VM settings:
# - RAM: 2-4 GB
# - CPU: 2 cores
# - Network: NAT or Bridged
# - USB: Enable USB 2.0/3.0

# 5. Start VM

# 6. Default credentials (old versions):
# Username: kali
# Password: kali

# 7. Update system
$ sudo apt update && sudo apt full-upgrade -y

# 8. Install VirtualBox Guest Additions (if needed)
$ sudo apt install -y virtualbox-guest-x11

Network Configuration

MODEDESKRIPSIUSE CASE
NAT VM di belakang host, akses internet via host Default, aman untuk testing
Bridged VM langsung di network, dapat IP dari DHCP Network testing, akses ke LAN
Host-Only VM hanya bisa komunikasi dengan host Isolated testing
Internal Network VM hanya bisa komunikasi dengan VM lain Isolated lab environment
NAT Network Multiple VMs dengan NAT, bisa saling akses Multi-VM lab
ANIMASI: VM NETWORK MODES
HOST Physical Machine VM NAT VM BRIDGED INTERNET

Snapshots

VM Snapshots
# Snapshots memungkinkan save state VM
# Berguna untuk:
# - Save state sebelum eksperimen berbahaya
# - Restore ke state sebelumnya
# - Test berbeda skenario

# VirtualBox:
# Machine -> Take Snapshot
# Machine -> Snapshots -> Restore

# VMware:
# VM -> Snapshot -> Take Snapshot
# VM -> Snapshot -> Revert to Snapshot

# Best practice:
# 1. Buat snapshot "Clean Install" setelah install
# 2. Buat snapshot sebelum install tools baru
# 3. Buat snapshot sebelum eksperimen
ANALOGI: VM = RUANG SIMULASI
  • VM = ruang simulasi kedokteran
  • Host = rumah sakit asli
  • Snapshot = tombol reset di ruang simulasi
  • Snapshots = foto kondisi ruangan sebelum eksperimen

Di ruang simulasi, Anda bisa melakukan kesalahan tanpa konsekuensi nyata. Begitu juga dengan VM - Anda bisa bereksperimen dengan aman.

REFERENSI
  • VirtualBox Documentation - Networking
  • VMware Documentation - VM Configuration
  • Kali Docs - Virtual Machines
16.6

MENGENAL DESKTOP ENVIRONMENT

Apa itu Desktop Environment?

Desktop Environment (DE) adalah kumpulan software yang menyediakan graphical user interface (GUI) untuk Linux. Ini termasuk window manager, file manager, panel, dan aplikasi default.

Desktop Environment di Kali Linux

DESTATUSKARAKTERISTIK
Xfce Default Lightweight, fast, stable
GNOME Available Modern, feature-rich, resource-heavy
KDE Plasma Available Highly customizable, modern
MATE Available Classic GNOME 2 feel

Switch Desktop Environment

Bash - Switch Desktop Environment
# Install different DE
$ sudo apt update

# Install GNOME
$ sudo apt install -y kali-desktop-gnome

# Install KDE Plasma
$ sudo apt install -y kali-desktop-kde

# Install Xfce (default)
$ sudo apt install -y kali-desktop-xfce

# Switch default DE
$ sudo update-alternatives --config x-session-manager

# Atau pilih di login screen (display manager)
# Klik ikon gear di login screen

Konfigurasi Xfce (Default)

Komponen Utama:

  • Panel - taskbar di atas/bawah
  • Desktop - area kerja utama
  • Window Manager - mengatur window
  • File Manager - Thunar
  • Terminal - XFCE Terminal
  • Application Menu - menu aplikasi

Customization Tips:

Xfce Customization
# 1. Change theme
# Settings -> Appearance -> Style

# 2. Change icons
# Settings -> Appearance -> Icons

# 3. Add panel items
# Right-click panel -> Panel -> Add New Items

# 4. Change wallpaper
# Right-click desktop -> Desktop Settings

# 5. Configure keyboard shortcuts
# Settings -> Keyboard -> Application Shortcuts

# 6. Terminal transparency
# Edit -> Preferences -> Appearance
# Adjust transparency slider
ANALOGI: DE = INTERIOR RUMAH
  • Linux kernel = fondasi dan struktur rumah
  • Desktop Environment = interior dan dekorasi
  • Xfce = interior minimalis, fungsional
  • GNOME = interior modern, mewah
  • KDE = interior customizable, bisa diubah sesuai selera
REFERENSI
  • Xfce Documentation - Xfce Documentation
  • Kali Docs - Desktop Environment
16.7

MENGENAL TERMINAL

Apa itu Terminal?

Terminal (atau shell) adalah interface berbasis teks untuk berinteraksi dengan sistem operasi. Di Kali Linux, terminal adalah tools paling penting - hampir semua operasi dilakukan melalui command line.

Shell di Kali Linux

SHELLSTATUSKARAKTERISTIK
Zsh Default (sejak 2020.1) Feature-rich, customizable, oh-my-zsh
Bash Traditional Standard, widely used, compatible
Fish Alternative User-friendly, syntax highlighting

Basic Commands

Bash - Essential Commands
# === NAVIGATION ===
$ pwd                    # Print working directory
$ ls                     # List files
$ ls -la                 # List all files with details
$ cd /path/to/dir        # Change directory
$ cd ~                   # Go to home directory
$ cd -                   # Go to previous directory

# === FILE OPERATIONS ===
$ touch file.txt         # Create empty file
$ mkdir directory        # Create directory
$ mkdir -p dir1/dir2     # Create nested directories
$ cp file.txt backup.txt # Copy file
$ cp -r dir1 dir2        # Copy directory recursively
$ mv old.txt new.txt     # Move/rename file
$ rm file.txt            # Remove file
$ rm -r directory        # Remove directory recursively
# WARNING: rm -rf / akan menghapus semua!

# === VIEWING FILES ===
$ cat file.txt           # Display file content
$ less file.txt          # View file page by page
$ head file.txt          # Show first 10 lines
$ tail file.txt          # Show last 10 lines
$ tail -f log.txt        # Follow log file in real-time

# === SEARCH ===
$ grep "pattern" file    # Search for pattern in file
$ find /path -name "*.txt" # Find files by name
$ locate file.txt        # Quick file search
$ which command          # Find command location

# === SYSTEM INFO ===
$ whoami                 # Current user
$ id                     # User ID and groups
$ uname -a               # System information
$ hostname               # Hostname
$ uptime                 # System uptime
$ df -h                  # Disk usage
$ free -h                # Memory usage
$ ps aux                 # List processes
$ top                    # Real-time process monitor
$ kill PID               # Kill process

# === NETWORK ===
$ ip addr                # Show IP addresses
$ ip route               # Show routing table
$ ping google.com        # Test connectivity
$ netstat -tulpn         # Show listening ports
$ ss -tulpn              # Modern netstat alternative

# === PERMISSIONS ===
$ chmod 755 file         # Change permissions
$ chown user:group file  # Change owner

# === SUPERUSER ===
$ sudo command           # Run command as root
$ sudo -i                # Switch to root shell
$ su - username          # Switch to user

Keyboard Shortcuts

SHORTCUTFUNGSI
Ctrl + C Interrupt/kill current command
Ctrl + Z Suspend current process
Ctrl + D Exit/logout
Ctrl + L Clear screen
Tab Auto-complete
↑ / ↓ Navigate command history
Ctrl + R Search command history
Ctrl + A Move to beginning of line
Ctrl + E Move to end of line

File System Hierarchy

Linux File System
/
├── bin          # Essential user binaries
├── boot         # Boot loader files
├── dev          # Device files
├── etc          # Configuration files
├── home         # User home directories
│   └── kali     # Default user home
├── lib          # Essential shared libraries
├── media        # Mount point for removable media
├── mnt          # Temporary mount point
├── opt          # Optional software
├── proc         # Process information (virtual)
├── root         # Root user home
├── sbin         # System binaries
├── srv          # Service data
├── sys          # System devices (virtual)
├── tmp          # Temporary files
├── usr          # User programs
│   ├── bin      # User binaries
│   ├── lib      # User libraries
│   └── share    # Shared data
└── var          # Variable data (logs, spool)
ANALOGI: TERMINAL = REMOTE CONTROL UNIVERSAL
  • GUI = remote control dengan tombol-tombol fixed
  • Terminal = remote control universal yang bisa melakukan apa saja
  • Command = instruksi spesifik ke sistem
  • Shell = interpreter yang memahami instruksi
REFERENSI
  • Linux Command Line Cheat Sheet - cheatography.com
  • The Linux Documentation Project - Bash Guide for Beginners
  • Kali Docs - Terminal Usage
16.8

PACKAGE MANAGEMENT

Package Manager di Kali Linux

Kali Linux menggunakan APT (Advanced Package Tool) sebagai package manager, warisan dari Debian. APT memudahkan instalasi, update, dan removal software.

APT Commands

Bash - APT Package Management
# === UPDATE ===
$ sudo apt update           # Update package list
$ sudo apt upgrade          # Upgrade installed packages
$ sudo apt full-upgrade     # Full upgrade (may remove packages)
$ sudo apt dist-upgrade     # Distribution upgrade

# === INSTALL ===
$ sudo apt install package-name
$ sudo apt install -y package-name    # Auto-confirm

# Install Kali meta-packages
$ sudo apt install kali-linux-default      # Default tools
$ sudo apt install kali-linux-large        # More tools
$ sudo apt install kali-linux-everything   # All tools

# Install tool categories
$ sudo apt install kali-tools-web           # Web tools
$ sudo apt install kali-tools-wireless      # Wireless tools
$ sudo apt install kali-tools-forensics     # Forensics tools

# === REMOVE ===
$ sudo apt remove package-name
$ sudo apt purge package-name      # Remove with config
$ sudo apt autoremove              # Remove unused dependencies

# === SEARCH ===
$ apt search keyword
$ apt show package-name
$ apt list --installed

# === CLEAN ===
$ sudo apt clean                   # Remove cached packages
$ sudo apt autoclean               # Remove old cached packages

DPKG (Debian Package)

Bash - DPKG Commands
# Install .deb file directly
$ sudo dpkg -i package.deb

# Fix broken dependencies
$ sudo apt --fix-broken install

# List installed packages
$ dpkg -l

# Show package info
$ dpkg -s package-name

# List files in package
$ dpkg -L package-name

# Find which package owns a file
$ dpkg -S /path/to/file

Common Tasks

Bash - Common Package Tasks
# Update system completely
$ sudo apt update && sudo apt full-upgrade -y
$ sudo apt autoremove -y
$ sudo apt autoclean

# Install specific tool
$ sudo apt install nmap
$ sudo apt install wireshark
$ sudo apt install metasploit-framework

# Check tool version
$ nmap --version
$ msfconsole --version

# Install from source (if not in repo)
$ git clone https://github.com/tool/repo.git
$ cd repo
$ sudo apt install build-essential
$ ./configure
$ make
$ sudo make install

Troubleshooting

Bash - Package Troubleshooting
# Fix broken packages
$ sudo apt --fix-broken install

# Reconfigure packages
$ sudo dpkg --configure -a

# Clean package cache
$ sudo apt clean
$ sudo apt autoclean

# Update package lists
$ sudo apt update

# Check for held packages
$ apt-mark showhold

# Unhold package
$ sudo apt-mark unhold package-name
ANALOGI: PACKAGE MANAGER = APP STORE
  • APT = App Store untuk Linux
  • Repository = katalog aplikasi di App Store
  • apt install = download dan install aplikasi
  • apt update = refresh katalog
  • apt upgrade = update semua aplikasi
REFERENSI
  • Debian - APT Howto
  • Kali Docs - Package Management
  • Ubuntu - APT Guide
16.9

REPOSITORY KALI LINUX

Apa itu Repository?

Repository (repo) adalah server yang menyimpan package software. APT menggunakan repository untuk download dan install software.

Repository Kali Linux

REPOSITORYDESKRIPSISTATUS
kali-rolling Rolling release, selalu up-to-date Default, recommended
kali-last-snapshot Point release, stable Stable releases
kali-dev Development branch Unstable, testing only
kali-experimental Experimental packages Experimental

Konfigurasi Repository

Bash - Repository Configuration
# View current repositories
$ cat /etc/apt/sources.list

# Default Kali Rolling repository:
# deb http://http.kali.org/kali kali-rolling main contrib non-free
# deb-src http://http.kali.org/kali kali-rolling main contrib non-free

# Edit sources list
$ sudo nano /etc/apt/sources.list

# Add custom repository
# deb http://example.com/repo kali main

# Add repository with GPG key
$ wget -O - https://example.com/key.gpg | sudo apt-key add -
$ echo "deb http://example.com/repo kali main" | sudo tee /etc/apt/sources.list.d/example.list

# Update after adding repository
$ sudo apt update

GPG Keys

Bash - GPG Key Management
# List installed keys
$ apt-key list

# Add Kali archive key (if missing)
$ wget -q -O - https://archive.kali.org/archive-key.asc | sudo apt-key add -

# Modern method (apt-key deprecated)
$ wget -O /usr/share/keyrings/kali-archive-keyring.asc https://archive.kali.org/archive-key.asc
$ echo "deb [signed-by=/usr/share/keyrings/kali-archive-keyring.asc] http://http.kali.org/kali kali-rolling main" | sudo tee /etc/apt/sources.list.d/kali.list

Mirror Selection

Bash - Use Mirror
# Use nearest mirror for faster downloads
# Edit /etc/apt/sources.list:
# deb http://http.kali.org/kali kali-rolling main contrib non-free

# Or use specific mirror:
# deb http://kali.mirror.Indonesia kali-rolling main

# List of mirrors:
# https://www.kali.org/docs/general-use/kali-linux-mirrors/

Meta-packages

META-PACKAGEDESKRIPSIUKURAN
kali-linux-default Default tools ~4 GB
kali-linux-large More tools ~6 GB
kali-linux-everything All tools ~15 GB
kali-tools-web Web application tools ~1 GB
kali-tools-wireless Wireless tools ~500 MB
kali-tools-forensics Forensics tools ~1 GB
ANALOGI: REPOSITORY = PERPUSTAKAAN
  • Repository = perpustakaan pusat
  • Mirror = cabang perpustakaan di berbagai kota
  • Package = buku di perpustakaan
  • apt install = meminjam buku
  • apt update = cek katalog baru
REFERENSI
  • Kali Docs - Kali Linux Repositories
  • Kali Docs - Kali Linux Mirrors
  • Debian - Repositories
16.10

ETIKA PENGGUNAAN

Legalitas Penggunaan Kali Linux

Kali Linux adalah tools yang netral - legal atau tidaknya tergantung pada bagaimana Anda menggunakannya. Seperti pisau - bisa untuk memasak (legal) atau melukai seseorang (ilegal).

PRINSIP UTAMA: AUTHORIZATION

JANGAN PERNAH menggunakan Kali Linux untuk menyerang sistem yang tidak Anda miliki atau tidak memiliki izin tertulis untuk mengujinya. Ini adalah ilegal dan bisa berujung pada:

  • Pidana penjara (di Indonesia: UU ITE Pasal 30-32)
  • Denda besar
  • Tuntutan perdata dari korban
  • Reputasi rusak

Hukum di Indonesia

PASALATURANSANKSI
UU ITE Pasal 30 Mengakses komputer tanpa izin 6-8 tahun penjara, denda Rp 600-800 juta
UU ITE Pasal 31 Intersepsi/transmisi tanpa izin 10 tahun penjara, denda Rp 800 juta
UU ITE Pasal 32 Manipulasi data komputer 8-10 tahun penjara, denda Rp 2-3 miliar

Penggunaan yang Legal

PENGGUNAAN YANG LEGAL
  • Testing sistem sendiri - lab pribadi, VM sendiri
  • Dengan izin tertulis - penetration testing dengan kontrak
  • Bug bounty program - dalam scope yang ditentukan
  • Learning & education - di lingkungan terkontrol
  • Security research - dengan etika dan responsible disclosure
  • CTF competitions - Capture The Flag competitions

Etika Ethical Hacking

PRINSIP ETHICAL HACKING
  1. Get proper authorization - selalu dapatkan izin tertulis
  2. Define scope - tentukan batasan pengujian
  3. Respect privacy - jangan akses data sensitif
  4. Report vulnerabilities - laporkan temuan dengan responsible disclosure
  5. Do no harm - jangan merusak sistem
  6. Maintain confidentiality - jaga kerahasiaan temuan
  7. Be honest - jujur dalam reporting

Rules of Engagement

Rules of Engagement Template
# ============================================
# RULES OF ENGAGEMENT
# Penetration Testing Authorization
# ============================================

Client: [Nama Perusahaan]
Tester: [Nama Anda]
Date: [Tanggal]

Scope:
  - IP Range: 192.168.1.0/24
  - Domain: example.com
  - Applications: web.example.com

Out of Scope:
  - Production database
  - Third-party services
  - Social engineering

Testing Window:
  - Start: 2026-09-10 09:00
  - End: 2026-09-15 18:00

Restrictions:
  - No DoS attacks
  - No data exfiltration
  - No social engineering
  - Testing hours: 09:00 - 18:00 WIB

Emergency Contact:
  - Name: [Contact Person]
  - Phone: [Phone Number]
  - Email: [Email]

Authorization:
  Client Signature: _______________
  Date: _______________

  Tester Signature: _______________
  Date: _______________

Responsible Disclosure

RESPONSIBLE DISCLOSURE PROCESS
  1. Find vulnerability - temukan vulnerability
  2. Document - dokumentasikan dengan detail
  3. Report privately - laporkan ke vendor/owner secara privat
  4. Allow time to fix - beri waktu untuk memperbaiki (biasanya 30-90 hari)
  5. Follow up - follow up jika tidak ada respons
  6. Public disclosure - publikasi setelah patch dirilis

White Hat vs Black Hat

ASPEKWHITE HATBLACK HAT
Tujuan Meningkatkan keamanan Keuntungan pribadi, merusak
Authorization Dengan izin Tanpa izin
Reporting Laporkan ke owner Eksploitasi atau jual
Legalitas Legal Ilegal
Etika Etis Tidak etis
ANALOGI: ETHICAL HACKER = SATPAM YANG MENYAMAR
  • White hat = satpam yang menyamar untuk menguji keamanan bank
  • Black hat = perampok bank yang sebenarnya
  • Authorization = surat tugas dari bank
  • Responsible disclosure = melaporkan celah keamanan ke bank, bukan ke media

Keduanya punya skill yang sama, tapi niat dan authorization yang membedakan.

INGAT SELALU

"With great power comes great responsibility" - Uncle Ben

Kali Linux memberikan Anda kekuatan yang luar biasa. Gunakan kekuatan ini dengan bijak, etis, dan legal. Jangan pernah menggunakan skill Anda untuk hal yang merugikan orang lain.

REFERENSI
  • UU No. 11 Tahun 2008 jo. UU No. 19 Tahun 2016 - Informasi dan Transaksi Elektronik
  • EC-Council - Code of Ethics
  • Offensive Security - Legal Disclaimer
  • OWASP - Legal
Q

DIAGNOSTIK KOMPETENSI

Uji pemahaman Anda tentang Bab 16! Target minimal: 70% untuk melanjutkan ke Bab 17.

PETUNJUK
  • Total 10 pertanyaan pilihan ganda
  • Klik opsi untuk menjawab - feedback langsung
  • Benar = HIJAU, salah = MAGENTA
  • Penjelasan muncul setelah menjawab
  • Klik "LIHAT HASIL AKHIR" untuk skor final
SKOR ANDA
0/ 10
-

-

REFERENSI BAB 16 SECARA KESELURUHAN
  • Kali Linux Official Documentation - kali.org/docs
  • Offensive Security - Kali Linux Revealed (free ebook)
  • Debian Documentation - Debian Administrator's Handbook
  • UU ITE - Undang-Undang Informasi dan Transaksi Elektronik
ABDURROZAK.MY.ID // JARINGAN SOSIAL