
Un scanner de ports écrit entièrement en PowerShell.
Un scanner de ports écrit purement en PowerShell.
Cet outil a été conçu uniquement à des fins légales ; les utilisateurs sont responsables de s'assurer que leur utilisation de cet outil est conforme à toutes les lois applicables. En utilisant cet outil, vous assumez l'entière responsabilité de toutes les actions que vous effectuez. Ni NCC Group ni l'auteur n'acceptent toute responsabilité pour les dommages causés par l'utilisation de cet outil.
SYNTAX
ps2.ps1 [-banners] [-delay <Int32>] [-inFiles <FileInfo[]>] [-hostnames <String[]>] [-ips <String[]>]
[-serviceMap <FileInfo>] [-noColour] [-noPing] [-overwrite] [-outAll <FileInfo>] [-outJson <FileInfo>]
[-outTxt <FileInfo>] [-ports <Int32[]>] [-quick] [-randomise] [-timeout <Int32>] [-topPorts <Int32>]
[-traceroute] -udp [-v]
ps2.ps1 [-banners] [-delay <Int32>] [-inFiles <FileInfo[]>] [-hostnames <String[]>] [-ips <String[]>]
[-serviceMap <FileInfo>] [-noColour] [-noPing] [-overwrite] [-outAll <FileInfo>] [-outJson <FileInfo>]
[-outTxt <FileInfo>] [-ports <Int32[]>] [-quick] [-randomise] [-timeout <Int32>] [-topPorts <Int32>]
[-traceroute] -tcp [-v]
ps2.ps1 [-delay <Int32>] [-inFiles <FileInfo[]>] [-hostnames <String[]>] [-ips <String[]>] [-noColour]
[-overwrite] [-outAll <FileInfo>] [-outJson <FileInfo>] [-outTxt <FileInfo>] [-randomise]
[-timeout <Int32>] [-traceroute] -ping [-v]
ps2.ps1 -help
PARAMETERS
-banners [<SwitchParameter>]
(-b) Attempt to grab banners from open ports
-delay <Int32>
(-d) Delay to use between each connection in milliseconds
-inFiles <FileInfo[]>
(-f) File(s) containing targets to scan (1 per line)
-help [<SwitchParameter>]
(-h) Displays help information
-hostnames <String[]>
(-n) Hostname(s) of target(s) to scan
-ips <String[]>
(-i) IP address(es) of target(s) to scan (supports individual IPv4 addresses, IPv4 address ranges,
IPv4 CIDR notation, and individual IPv6 addresses)
-serviceMap <FileInfo>
(-m) Service map to use (overrides default of <PS2_dir>/servicemap.csv)
-noColour [<SwitchParameter>]
(-nC) Do not use colour in terminal output
-noPing [<SwitchParameter>]
(-nP) Assume all hosts are up and do not ping them prior to scanning
-overwrite [<SwitchParameter>]
(-o) Force output files to be overwritten if they exist and do not prompt for confirmation
-outAll <FileInfo>
(-oA) Save output in txt and JSON formats to files with a specified name (supersedes -oJ and -oT
options)
-outJson <FileInfo>
(-oJ) Save output in JSON format to a specified file
-outTxt <FileInfo>
(-oT) Save output in txt format to a specified file
-ports <Int32[]>
(-p) Port(s) to scan [supports PowerShell ranges e.g. use "-p (1..65535)" to scan all ports] (overrides default of top 1000 commonly used ports)
-quick [<SwitchParameter>]
(-q) Scan only the top 100 most commonly used ports
-randomise [<SwitchParameter>]
(-r) Randomise the order in which hosts and ports are scanned
-timeout <Int32>
(-t) Timeout to use for connections in milliseconds (overrides default of 1000ms)
-topPorts <Int32>
Scan the top n most commonly used ports (maximum 1000)
-traceroute [<SwitchParameter>]
Trace hop path to each host
-ping [<SwitchParameter>]
(-sP) Perform a ping scan
-tcp [<SwitchParameter>]
(-sT) Perform a TCP connect scan
-udp [<SwitchParameter>]
(-sU) Perform a UDP scan
-v [<SwitchParameter>]
(-Verbose, -vb) Show verbose output
-------------------------- EXAMPLE 1 --------------------------
PS C:\>ps2.ps1 -sT -i 192.168.1.1
Perform a TCP connect scan against the top 1000 most commonly used ports
-------------------------- EXAMPLE 2 --------------------------
PS C:\>ps2.ps1 -sT -p (1..65535) -i 192.168.1.1
Perform a TCP connect scan against all ports
-------------------------- EXAMPLE 3 --------------------------
PS C:\>ps2.ps1 -sU -i 192.168.1.1
Perform a UDP scan against the top 1000 most commonly used ports
-------------------------- EXAMPLE 4 --------------------------
PS C:\>ps2.ps1 -sP -i 192.168.1.1
Perform a ping scan
Les cartes de services sont utilisées pour définir quels services sont connus pour fonctionner sur quels ports.
PS2 fonctionnera sans carte de services, mais il ne pourra pas fournir d'informations sur les services sans elle.
Par défaut, PS2 recherche servicemap.csv dans le même répertoire que ps2.ps1, mais cela peut être remplacé à l'aide des paramètres -serviceMap ou -m.
Le fichier de carte de services inclus dans ce dépôt a été généré sur une machine Kali Linux à l'aide de la commande suivante :
sed '/^#/d' /usr/share/nmap/nmap-services | sed '/^unknown\s/d' | cut -f 1,2 --output-delimiter "," | cut -d '/' -f 1,2 --output-delimiter "," | grep -P ',tcp$|,udp$' | unix2dos > servicemap.csv
PS2 devrait être compatible avec PowerShell version 5.1 et supérieure.
Les payloads UDP proviennent de udp-proto-scanner.