
Bashベースのパッシブ偵察+攻撃対象マッピングスクリプト。公開APIと標準のLinuxツール(curl、dig、openssl、nmap、python3)のみを使用。
_ _ _ _ _ _______
| \ | | | | | |/ / ____|
| \| | | | | ' /| _|
| |\ | |_| | . \| |___
|_| \_|\___/|_|\_\_____|
N U K E // recon & attack surface mapper
-----------------------------------------
公開API + 標準Linuxツール(curl、dig、openssl、nmap、python3)のみを使用した、Bashベースのパッシブ偵察 + 攻撃対象マッピングスクリプト。
すべての出力は単一の .txt ファイルに書き込まれます: nuke_<domain>.txt。
subfinder、ffuf、gobuster、subjs、getJS、jshunter、js_snitch への依存はありません。
| # | モジュール | ソース / 手法 |
|---|---|---|
| 1 | CT経由のサブドメイン | crt.sh |
| 2 | 代替CT経由のサブドメイン | crt.name |
| 3 | サブドメイン(任意、キーが必要) | SecurityTrails API |
| 4 | サブドメイン + URL + IP | OTX AlienVault |
| 5 | ドメイン + IP + ASN/サーバー | urlscan.io |
| 6 | サブドメイン + 関連ドメイン + IP(キーが必要) | VirusTotal v2 |
| 7 | 統合サブドメイン | 全ソースの結合 + 重複排除 |
| 8 | DNS(TXT/SPF、A、AAAA、NS、MX、SOA + AXFR) | dns.google(DoH)+ dig/host — dnsrecon -d と同等 |
| 9 | WHOIS | rdap.org 経由のRDAP |
| 10 | IP / 逆引きDNS / RDAP-IP / HTTPステータス | dns.google PTR + rdap.org/ip + curl -I |
| 11 | Faviconハッシュ(Shodanハンティング)+ IP SSL検証 | ローカルShodan標準murmur3(http.favicon.hash)+ openssl + nmap --script ssl-cert |
| 12 | JSファイル + 抽出エンドポイント | <script src> 解析 + パス/URL正規表現(subjs/getJS/jshunter を置換) |
| 13 | 過去のURL | Wayback Machine CDX |
| 14 | オリジンIP発見(CDN/WAFバイパス) | DNS + OTX + urlscan + VT + SPF + Shodan を相関分析、RDAP org + Host: ヘッダーテストでフィルタリング |
| 15 | 内蔵ディスキャン | 高シグナル厳選ワードリスト、並列処理(ffuf/gobuster 不要) |
ハイライト:
pip install 不要)、すぐに使えるダーク付き: http.favicon.hash:X。ip4:/include:/a/mx)— インフラ / オリジンIPを漏洩。?api=、admin、token、.bak、.sql、.env、.git)。.git/HEAD、.env、backup.zip、phpinfo.php、actuator/env、swagger/、graphql、jenkins/ など。bash、curl、grep、sed、awk、sort、trdig または host → AXFR用python3 → favicon murmur3ハッシュ用(Shodan標準)nmap → nmap --script ssl-cert -p 443 <IP> 用openssl → 証明書CN/SAN検査用Kali、Ubuntu、Debian、WSL2で動作します。
git clone https://github.com/AnkhCorp/Nuke.sh.git
cd Nuke.sh
chmod +x nuke.sh
# 基本(100%無料、キー不要)
bash nuke.sh example.com
# キーを使用(引数経由)
bash nuke.sh example.com SECURITYTRAILS_KEY VIRUSTOTAL_KEY
# 環境変数経由でキーを使用(推奨 — キーをコミットしない)
export SECURITYTRAILS_API_KEY="your_key"
export VT_APIKEY="your_key"
export SHODAN_API_KEY="your_key" # 任意
export ZOOMEYE_KEY="your_key" # 任意
bash nuke.sh example.com
サポートされている環境変数:
| 変数 | 必須? | 取得先 |
|---|---|---|
SECURITYTRAILS_API_KEY | いいえ | https://securitytrails.com/app/signup |
VT_APIKEY | いいえ | https://www.virustotal.com/gui/my-apikey |
SHODAN_API_KEY | いいえ | https://account.shodan.io |
ZOOMEYE_KEY | いいえ | https://www.zoomeye.hk |
URLSCAN_SIZE | いいえ(デフォルト 1000) | 例: 最大にするには export URLSCAN_SIZE=10000 |
出力:
nuke_example.com.txt
===================================================================
== 7. CONSOLIDATED SUBDOMAINS (all sources)
===================================================================
crt.sh=45 | crt.name=38 | securitytrails=52 | otx=20 | urlscan=15 | virustotal=30
[UNIQUE total]: https://raw.githubusercontent.com/ankhcorp/nuke.sh/main/87
admin.example.com
api.example.com
...
===================================================================
== 14. ORIGIN IP DISCOVERY (consolidated)
===================================================================
[All candidate IPs (current DNS + OTX + urlscan + VT + SPF + Shodan)]:
https://raw.githubusercontent.com/ankhcorp/nuke.sh/main/1.2.3.4
5.6.7.8
...
IP: 1.2.3.4 | RDAP_ORG: CLOUDFLARENET
IP: 5.6.7.8 | RDAP_ORG: LOCAWEB
# Shodan — certificate
shodan search 'Ssl.cert.subject.CN:"example.com" 200 --fields ip_str'
# Shodan — favicon
shodan search 'http.favicon.hash:123456789'
# ZoomEye
ssl:"example.com" # at https://www.zoomeye.hk/
# Manual
https://crt.name/v1/search?apex=example.com
https://favicon-hash.kmsec.uk/
https://viewdns.info/iphistory/?domain=example.com
https://mxtoolbox.com/SuperTool.aspx
https://urlscan.io/search/#domain:example.com
オリジンIP候補の手動検証:
curl -sk -H 'Host: example.com' https://<CANDIDATE_IP>/ | head -n 20
echo | openssl s_client -connect <CANDIDATE_IP>:443 -servername example.com 2>/dev/null | openssl x509 -noout -subject -ext subjectAltName
nmap --script ssl-cert -p 443 <CANDIDATE_IP>
証明書が CN/SAN=example.com で応答する場合(またはタイトル/Serverがサイトと一致する場合)、それが実IPです。
| ツール | 置き換え理由 |
|---|---|
subfinder | crt.sh + crt.name + OTX + urlscan + VT + SecurityTrails で置き換え(すべてAPI経由、インストール不要) |
webanalyze | 信頼性の高い技術検出には有料API(Wappalyzer/BuiltWith)が必要 — 対象外 |
subjs / getJS | 内蔵の <script src> 抽出で置き換え(セクション12) |
jshunter | 内蔵のエンドポイント正規表現で置き換え(セクション12) |
js_snitch | 公開APIに相当するものなし |
dnsrecon -d | セクション8で同等(DoH + dig 経由のNS/MX/SOA/AXFR) |
httpx-toolkit | セクション10で部分的に同等(ホストごとのステータス/サーバー) |
ffuf / gobuster | 厳選ワードリスト + xargs -P による内蔵ディスキャン(セクション15)— 完全なファジングにはSecListsを使用: ffuf -u https://TARGET/FUZZ -w raft-medium-directories.txt |
テストを許可されているターゲット(自身の資産、スコープ内のバグバウンティプログラム、契約済みペネトレーションテスト)に対してのみ使用してください。
作者は悪用に対して責任を負いません。
MIT — 自由に使用、改変、共有できます。
PRを歓迎します! ロードマップのアイデア:
--only-ips / --only-subs フラグamass / anubis 統合