Skip to content
KitploitKITPLOIT
StrumentiExploitsBlog
Log in
Invia
StrumentiExploitsBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

FeedContattoPrivacy© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
EBurst — Questo script fornisce principalmente funzionalità di brute force degli account sui server di posta Exchange, integrando i metodi di brute force delle principali interfacce esistenti. | Kitploit
Strumenti/GitHubGitHub/grayddq/eburst
Scanner di VulnerabilitàAttacchi alle PasswordRaccolta InformazioniSicurezza WebPenetration TestingAutenticazioneSicurezza Email
GitHubgrayddq/eburst

EBurst

Questo script fornisce principalmente funzionalità di brute force degli account sui server di posta Exchange, integrando i metodi di brute force delle principali interfacce esistenti.

Vedi Repository
3436263 anni faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

EBurst 0.1

Questo script fornisce principalmente funzionalità di brute force degli account sui server Exchange, integrando i metodi di brute force delle principali interfacce esistenti. Dopo aver cercato in lungo e in largo gli strumenti su Internet, non ne ho trovato nessuno particolarmente valido, e nessuno che si adattasse davvero alle mie esigenze, così ho trovato il tempo di scrivere uno script semi-automatizzato.

Autore

咚咚呛

Per altri suggerimenti, potete contattarmi su WeChat 280495355

Dettagli tecnici

I dettagli tecnici sono i seguenti

1、Supporto al brute force multi-thread
2、Supporto al brute force con dizionario
3、Supporto alla funzionalità di verifica delle vulnerabilità di brute force
4、Supporto al riconoscimento del metodo di autenticazione dell'interfaccia e alla commutazione automatica
5、Le interfacce supportate per il brute force sono le seguenti:
    https://Exchangeserver/ecp
        https://Exchangeserver/ews
        https://Exchangeserver/oab
        https://Exchangeserver/owa
        https://Exchangeserver/rpc
        https://Exchangeserver/api
        https://Exchangeserver/mapi
        https://Exchangeserver/powershell
    	https://Exchangeserver/autodiscover
    	https://Exchangeserver/Microsoft-Server-ActiveSync
    

Utilizzo

I dettagli tecnici sono i seguenti

Download del programma

root# git clone https://github.com/grayddq/EBurst.git

root# cd EBurst

root# sudo pip install -r requirements.txt

Riferimento ai parametri

 [root@grayddq  EBurst]# ls
 EBurst.py  lib  pic  README.md  requirements.txt
 
 [root@grayddq  EBurst]# python EBurst.py 
 Usage: EBurst.py [options]
 
 Options:
   -h, --help            show this help message and exit
   -d DOMAIN             邮箱地址
   -L USERFILE           用户文件
   -P PASSFILE           密码文件
   -l USER               指定用户名
   -p PASSWORD           指定密码
   -T THREAD, --t=THREAD
                         线程数量,默认为100
   -C, --c               验证各接口是否存在爆破的可能性
   --protocol            通讯协议默认https,可无需指定,demo: --protocol http
 
   type:
     EBurst 扫描所用的接口
 
     --autodiscover      autodiscover接口,默认NTLM认证方式,自Exchange Server 2007开始推出的一项
                         自动服务,用于自动配置用户在Outlook中邮箱的相关设置,简化用户登陆使用邮箱的流程。
     --ews               ews接口,默认NTLM认证方式,Exchange Web
                         Service,实现客户端与服务端之间基于HTTP的SOAP交互
     --mapi              mapi接口,默认NTLM认证方式,Outlook连接Exchange的默认方式,在2013和2013之后开
                         始使用,2010 sp2同样支持
     --activesync        activesync接口,默认Basic认证方式,用于移动应用程序访问电子邮件
     --oab               oab接口,默认NTLM认证方式,用于为Outlook客户端提供地址簿的副本,减轻Exchange的负担
     --rpc               rpc接口,默认NTLM认证方式,早期的Outlook还使用称为Outlook Anywhere的RPC交互
     --api               api接口,默认NTLM认证方式
     --owa               owa接口,默认http认证方式,Exchange owa
                         接口,用于通过web应用程序访问邮件、日历、任务和联系人等
     --powershell        powershell接口(暂不支持),默认Kerberos认证方式,用于服务器管理的Exchange管理控制
                         台
     --ecp               ecp接口,默认http认证方式,Exchange管理中心,管理员用于管理组织中的Exchange的Web控
                         制台
 
 [root@grayddq  EBurst]# python EBurst.py -L users.txt -p 123456abc -d mail.xxx.com
 
 [root@grayddq  EBurst]# python EBurst.py -L users.txt -p 123456abc -d mail.xxx.com --ews

Screenshot dell'esecuzione del programma

Screenshot

Screenshot

Nota: il codice del framework multi-thread fa riferimento al codice open source di lijiejie, che ringrazio.

Scarica lo strumento