
Uno scanner di porte scritto puramente in PowerShell.
Uno scanner di porte scritto interamente in PowerShell.
Questo strumento è stato progettato solo per scopi legali; gli utenti sono responsabili di garantire che il loro utilizzo di questo strumento sia conforme a tutte le leggi applicabili. Utilizzando questo strumento, ti assumi la piena responsabilità di qualsiasi azione esegui. Né NCC Group né l'autore accettano alcuna responsabilità per danni causati dall'uso di questo strumento.
SYNTAX
ps2.ps1 [-banners] [-delay <Int32>] [-inFiles <FileInfo[]>] [-hostnames <String[]>] [-ips <String[]>]
[-serviceMap <FileInfo>] [-noColour] [-noPing] [-overwrite] [-outAll <FileInfo>] [-outJson <FileInfo>]
[-outTxt <FileInfo>] [-ports <Int32[]>] [-quick] [-randomise] [-timeout <Int32>] [-topPorts <Int32>]
[-traceroute] -udp [-v]
ps2.ps1 [-banners] [-delay <Int32>] [-inFiles <FileInfo[]>] [-hostnames <String[]>] [-ips <String[]>]
[-serviceMap <FileInfo>] [-noColour] [-noPing] [-overwrite] [-outAll <FileInfo>] [-outJson <FileInfo>]
[-outTxt <FileInfo>] [-ports <Int32[]>] [-quick] [-randomise] [-timeout <Int32>] [-topPorts <Int32>]
[-traceroute] -tcp [-v]
ps2.ps1 [-delay <Int32>] [-inFiles <FileInfo[]>] [-hostnames <String[]>] [-ips <String[]>] [-noColour]
[-overwrite] [-outAll <FileInfo>] [-outJson <FileInfo>] [-outTxt <FileInfo>] [-randomise]
[-timeout <Int32>] [-traceroute] -ping [-v]
ps2.ps1 -help
PARAMETERS
-banners [<SwitchParameter>]
(-b) Attempt to grab banners from open ports
-delay <Int32>
(-d) Delay to use between each connection in milliseconds
-inFiles <FileInfo[]>
(-f) File(s) containing targets to scan (1 per line)
-help [<SwitchParameter>]
(-h) Displays help information
-hostnames <String[]>
(-n) Hostname(s) of target(s) to scan
-ips <String[]>
(-i) IP address(es) of target(s) to scan (supports individual IPv4 addresses, IPv4 address ranges,
IPv4 CIDR notation, and individual IPv6 addresses)
-serviceMap <FileInfo>
(-m) Service map to use (overrides default of <PS2_dir>/servicemap.csv)
-noColour [<SwitchParameter>]
(-nC) Do not use colour in terminal output
-noPing [<SwitchParameter>]
(-nP) Assume all hosts are up and do not ping them prior to scanning
-overwrite [<SwitchParameter>]
(-o) Force output files to be overwritten if they exist and do not prompt for confirmation
-outAll <FileInfo>
(-oA) Save output in txt and JSON formats to files with a specified name (supersedes -oJ and -oT
options)
-outJson <FileInfo>
(-oJ) Save output in JSON format to a specified file
-outTxt <FileInfo>
(-oT) Save output in txt format to a specified file
-ports <Int32[]>
(-p) Port(s) to scan [supports PowerShell ranges e.g. use "-p (1..65535)" to scan all ports] (overrides default of top 1000 commonly used ports)
-quick [<SwitchParameter>]
(-q) Scan only the top 100 most commonly used ports
-randomise [<SwitchParameter>]
(-r) Randomise the order in which hosts and ports are scanned
-timeout <Int32>
(-t) Timeout to use for connections in milliseconds (overrides default of 1000ms)
-topPorts <Int32>
Scan the top n most commonly used ports (maximum 1000)
-traceroute [<SwitchParameter>]
Trace hop path to each host
-ping [<SwitchParameter>]
(-sP) Perform a ping scan
-tcp [<SwitchParameter>]
(-sT) Perform a TCP connect scan
-udp [<SwitchParameter>]
(-sU) Perform a UDP scan
-v [<SwitchParameter>]
(-Verbose, -vb) Show verbose output
-------------------------- EXAMPLE 1 --------------------------
PS C:\>ps2.ps1 -sT -i 192.168.1.1
Perform a TCP connect scan against the top 1000 most commonly used ports
-------------------------- EXAMPLE 2 --------------------------
PS C:\>ps2.ps1 -sT -p (1..65535) -i 192.168.1.1
Perform a TCP connect scan against all ports
-------------------------- EXAMPLE 3 --------------------------
PS C:\>ps2.ps1 -sU -i 192.168.1.1
Perform a UDP scan against the top 1000 most commonly used ports
-------------------------- EXAMPLE 4 --------------------------
PS C:\>ps2.ps1 -sP -i 192.168.1.1
Perform a ping scan
Le mappe dei servizi vengono utilizzate per definire quali servizi sono noti per essere eseguiti su quali porte.
PS2 funzionerà anche senza una mappa dei servizi, tuttavia non sarà in grado di fornire informazioni sui servizi senza di essa.
Per impostazione predefinita, PS2 cerca servicemap.csv nella stessa directory di ps2.ps1; tuttavia, questa impostazione può essere sovrascritta utilizzando i parametri -serviceMap o -m.
Il file della mappa dei servizi incluso in questo repository è stato generato su una macchina Kali Linux utilizzando il seguente comando:
sed '/^#/d' /usr/share/nmap/nmap-services | sed '/^unknown\s/d' | cut -f 1,2 --output-delimiter "," | cut -d '/' -f 1,2 --output-delimiter "," | grep -P ',tcp$|,udp$' | unix2dos > servicemap.csv
PS2 dovrebbe essere compatibile con PowerShell versione 5.1 e successive.
I payload UDP sono stati presi da udp-proto-scanner.