
公式リポジトリ vuls Scan: 15000+PoCs; 23種類のアプリケーションパスワードクラック; 7000+Webフィンガープリント; 146プロトコルと90000+ルールのポートスキャン; ファズ、HW、awesome BugBounty( ͡° ͜ʖ ͡°)...
README_中文 • コンパイル/インストール/実行 • パラメータ説明 • 使用方法 • シナリオ • POC一覧 • カスタムスキャン • ベストプラクティス
export PPSSWWDD=yourRootPswd
詳細は config/doNmapScan.sh を参照 デフォルトでは、naabuを使用してポートスキャンを実行します。-stats=trueでスキャン進行状況を表示。 ポートスキャンをしないことはできますか?
noScan=true ./scan4all -l list.txt -v
# nmap result default noScan=true
./scan4all -l nmapRssuilt.xml -v
281ディレクトリ、3922ファイル。
7000以上のWebフィンガープリントスキャン、識別をサポート。
146のプロトコルと90000以上のルールのポートスキャンをサポート。
高速HTTP機密ファイル検出、カスタム辞書可能。
ランディングページ検出。
複数の入力タイプをサポート - STDIN/HOST/IP/CIDR/URL/TXT
複数の出力タイプをサポート - JSON/TXT/CSV/STDOUT
高度に統合可能:結果のElasticsearchへの統一的保存が設定可能(強く推奨)。
スマートSSL分析:
ドメインに関連付けられた複数のIP(DNS)を自動識別し、関連する複数のIPを自動スキャン。
スマート処理:
自動化されたサプライチェーンの識別、分析、スキャン。
python3の<a href=https://github.com/hktalent/log4j-scan>log4j-scanと連携
mkdir ~/MyWork/;cd ~/MyWork/;git clone https://github.com/hktalent/log4j-scan
ハニーポットをインテリジェントに識別し、ターゲットをスキップ。この機能はデフォルトで無効。EnableHoneyportDetection=trueで有効化。
高度にカスタマイズ可能:config/config.json設定で独自の辞書を定義、またはnuclei、httpx、naabuなどを含む詳細を制御可能。
HTTPリクエストスマグリングをサポート:CL-TE、TE-CL、TE-TE、CL_CL、BaseErr

パラメータCookie='PHPSession=xxxx' ./scan4all -host xxxx.comをサポート、nuclei、httpx、go-poc、x-ray POC、filefuzz、httpスマグリングと互換性あり。
<a href=https://github.com/GhostTroops/scan4all/releases>リリースからダウンロード
go install github.com/GhostTroops/[email protected]
scan4all -h
mkdir -p logs data
docker run --restart=always --ulimit nofile=65536:65536 -p 9200:9200 -p 9300:9300 -d --name es -v $PWD/logs:/usr/share/elasticsearch/logs -v $PWD /config/elasticsearch.yml:/usr/share/elasticsearch/config/elasticsearch.yml -v $PWD/config/jvm.options:/usr/share/elasticsearch/config/jvm.options -v $PWD/data:/ usr/share/elasticsearch/data hktalent/elasticsearch:7.16.2
# Initialize the es index, the result structure of each tool is different, and it is stored separately
./config/initEs.sh
# Search syntax, more query methods, learn Elasticsearch by yourself
http://127.0.0.1:9200/nmap_index/_doc/_search?q=_id:192.168.0.111
where 92.168.0.111 is the target to query
go build
# Precise scan szUrl list UrlPrecise=true
UrlPrecise=true ./scan4all -l xx.txt
# Disable adaptation to nmap and use naabu port to scan its internally defined http-related Ports
priorityNmap=false ./scan4all -tp http -list allOut.txt -v
詳細は:<a href=https://github.com/GhostTroops/scan4all/discussions>discussions を参照
https://github.com/GhostTroops/scan4all/graphs/contributors
| Or | QQchat | Or | Tg | |
|---|---|---|---|---|
| Wechat Pay | AliPay | Paypal | BTC Pay | BCH Pay |
|---|---|---|---|---|
| paypal [email protected] |
| タグ | 数 | 作者 | 数 | ディレクトリ | 数 | 深刻度 | 数 | タイプ | 数 |
|---|
| cve | 1430 | daffainfo | 631 | cves | 1407 | info | 1474 | http | 3858 |
| panel | 655 | dhiyaneshdk | 584 | exposed-panels | 662 | high | 1009 | file | 76 |
| edb | 563 | pikpikcu | 329 | vulnerabilities | 509 | medium | 818 | network | 51 |
| lfi | 509 | pdteam | 269 | technologies | 282 | critical | 478 | dns | 17 |
| xss | 491 | geeknik | 187 | exposures | 275 | low | 225 | ||
| wordpress | 419 | dwisiswant0 | 169 | misconfiguration | 237 | unknown | 11 | ||
| exposure | 407 | 0x_akoko | 165 | token-spray | 230 | ||||
| cve2021 | 352 | princechaddha | 151 | workflows | 189 | ||||
| rce | 337 | ritikchaddha | 137 | default-logins | 103 | ||||
| wp-plugin | 316 | pussycat0x | 133 | file | 76 |