
إطار عمل معياري مصمم لتسلسل وأتمتة اختبارات الأمان.
إطار عمل معياري مصمم لتسلسل وأتمتة اختبارات الأمان. يقوم بتحليل تعريفات الأهداف من سطر الأوامر وتشغيل الوحدات المقابلة وأدوات nullscan الخاصة بها بعد ذلك. يمكنه أيضًا أخذ المضيفين وبدء تشغيل nmap أولاً لإجراء فحص أساسي للمنافذ ثم تشغيل الوحدات بعد ذلك. أيضًا، يمكن لـ nullscan تحليل ملف سجل nmap معين بحثًا عن منافذ tcp و udp مفتوحة وتشغيل الوحدات مرة أخرى بعد ذلك. سيتم تسجيل جميع النتائج في أدلة محددة بهيكل نظيف ويمكن إنشاء تقرير HTML لاحقًا.
هذا الكود مخصص لصديقي زيلكو (رحمه الله)، الذي توفي في 2 ديسمبر 2012.
[ hacker@blackarch ~ ]$ nullscan -H
____
____ __ __/ / /_____________ _____
/ __ \/ / / / / / ___/ ___/ __ `/ __ \
/ / / / /_/ / / (__ ) /__/ /_/ / / / /
/_/ /_/\__,_/_/_/____/\___/\__,_/_/ /_/
--==[ by nullsecurity.net ]==--
usage
nullscan <modes> [options] | <misc>
modes
-t <targets> - hosts to scan via nmap and then attack - ? for info
-u <uris> - targets to attack directly via URIs - ? for info
-l <file> - parse nmap xml logfile and attack hosts on open ports
options
-o <opts> - extra options for modes - ? for info
-i <mods> - include modules (default: all) - ? for info
-I <tools> - include tools (default: all) - ? for info
-x <mods> - exclude modules (default: see nullscan.cfg) - ? for info
-X <tools> - exclude tools (default: see nullscan.cfg) - ? for info
-T <num> - num workers for parallel target checks (default: 15)
-M <num> - num workers to run parallel modules (default: 10)
-P <num> - num workers to run parallel tools (default: 15)
-k <sec> - num seconds for tool (global) timeout (default: 0.0)
-r - generate an html report
-R <dir> - work, log and report dir (default: pwd + date)
-c <file> - config file (default: /etc/nullscan.conf)
-v - verbose mode (default: false)
-d - debug mode (default: false)
misc
-C - check for missing tools (recommended)
-p <args> - print tools and exit - ? for info
-m <args> - create and add a new module - ? for info
-a <args> - add tool to existing module - ? for info
-V - print version of nullscan and exit
-H - print this help and exit
examples
-t 192.168.0.0/24 -i tcp=ssh,http -r -I hydra_ssh,crack_http_auth
-u 'tcp://nsa.gov:80=http,22=ssh;udp://foo.bar:1337;
http://fbi.gov,https://cia.gov;mail://[email protected];
person://justin bieber,noptrix;lan://eth0,tap0;wifi://wlan0'
-o 'user=root;plists=/tmp/pwds.txt;rhost=192.168.0.1;
sport=1337;dirsearch_web=-o my -p "own opts" -c 1 -f 4;'
-n /tmp/scanned.xml -i 'host=icmp;tcp=default' -r
-l hosts.txt -X sqlmap,wpscan -v -o 'httping_web=-p cia.gov;
rpcdump_udp=-f foo -b bar;nmap=-sT,-n,-p-;'
-p 'tcp=ssh,http;host=zonetransfer;udp'
-m 'icmp/ping ping_flood ping -f -s 9999'
-a 'tcp/ssh crack_ssh sshcracker -c arg -f arg'
قم بتشغيل setup.sh. بعد ذلك، قم بتثبيت وحدات python المطلوبة باستخدام pip install -r docs/requirements.txt.
noptrix
تحقق من docs/LICENSE.
نؤكد هنا أن المواد المتعلقة بالاختراق الموجودة على nullsecurity.net هي لأغراض تعليمية فقط. نحن لسنا مسؤولين عن أي أضرار. أنت مسؤول عن أفعالك الخاصة.