
强大的内网渗透辅助工具集-让Yasso像风一样 支持rdp,ssh,redis,postgres,mongodb,mssql,mysql,winrm等服务爆破,快速的端口扫描,强大的web指纹识别,各种内置服务的一键利用(包括ssh完全交互式登陆,mssql提权,redis一键利用,mysql数据库查询,winrm横向利用,多种服务利用支持socks5代理执行)
Powerful intranet penetration auxiliary toolset - let Yasso be like the wind. Supports brute-forcing of RDP, SSH, Redis, PostgreSQL, MongoDB, MSSQL, MySQL, WinRM and other services, fast port scanning, powerful web fingerprint recognition, one-click exploitation of various built-in services (including SSH fully interactive login, MSSQL privilege escalation, Redis one-click exploitation, MySQL database query, WinRM lateral movement, multiple service exploitation supporting SOCKS5 proxy execution)
Changed scanning and brute-forcing methods based on the original, removed unnecessary features, code is more complete and clean Added protocol identification and port recognition
Usage:
Yasso [command]
Available Commands:
all Use all scanner module (.attention) Traffic is very big
completion Generate the autocompletion script for the specified shell
exploit Exploits to attack the service
help Help about any command
service Detection or blasting services by module
Flags:
-h, --help help for Yasso
--output string set logger file (default "result.txt")
For details, refer to -h