Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
zscan — Zscan スキャンブラストツールセット | Kitploit
ツール/GitHubGitHub/zyylhn/zscan
偵察脆弱性スキャナーネットワークマッピングパスワード攻撃ポートスキャンエクスプロイトペネトレーションテスト
GitHubzyylhn/zscan

zscan

Zscan スキャンブラストツールセット

リポジトリを見る
53974152年前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

Zscan a scan blasting tool set

Licens Releases go

📄English document

更新内容はログを参照log

結果出力形式 -出力された結果のスクリーンショット一部。2段階に分かれており、第1段階はスキャン中の出力(ホスト生存検出終了から)、第2段階はすべてのスキャン結果を整理した出力(port result listの出力開始から)

概要🎉

Zscanはオープンソースの内部ネットワークポートスキャナ、ブルートフォースツール、その他の実用的なツールを集めたツールキットです。内部ネットワークセグメントの発見、ホスト発見、ポートスキャンを基礎として、blastモジュールではmysql、mssql、redis、mongo、postgres、ftp、ssh、ldap、rdp、smbなどのサービスに対してブルートフォース攻撃が可能です。scanモジュールではnetbios、smb、oxid、socksサーバ(プロキシサーバのスキャン)、ms17010、httpのPoCスキャンなどのスキャン機能を実行できます。デフォルトでhttpのタイトルとフィンガープリント情報を取得します。serverモジュールではhttp(ファイルのアップロード/ダウンロード可能)とsocks5サーバ(プロキシサーバ)を起動でき、toolsモジュールには実用的な小さなツールとして現在はncのみが統合されています。最新で追加されたexploitモジュールでは、ブルートフォース成功したサービスを利用でき、sshインタラクティブログイン(ユーザ名+パスワードまたはキー)、redisマスタースレーブレプリケーションとLuaサンドボックスエスケープ(ファイルアップロードとコマンド実行)、ldapクエリ(よく使うクエリ文を内蔵)などが可能です。また、allモジュールではスキャン時にすべてのスキャンモジュールとブルートフォースモジュールを呼び出します。IPv6スキャン対応、ドメイン名入力対応、CDN自動識別対応。具体的なモジュール機能は以下の通りです。

ツールのサイズは大きめですが、後日軽量版をリリース予定。モジュール設計なので不要な機能を省くのも簡単です。``` all 调用所有扫描和爆破模块 ping 主机发现和网段发现 ps 基本的端口扫描和http指纹识别title抓取 scan 扫描模块 --->ms17010扫描 --->poc漏洞扫描(内置380个poc) --->proxyfind内网代理服务器扫描 --->winscan Windows的smb,netbios和oxid扫描 blast 爆破服务模块(包括以下爆破模块) --->ftp --->ldap --->mongo --->mssql --->mysql --->postgres --->rdp --->redis --->smb --->ssh server start http server or socks5 server --->http服务器(可上传下载文件) --->socks5服务器(可启动一个代理服务器,支持身份验证) exploit 漏洞利用模块 --->ldap查询 --->redis组从复制上传文件执行命令,lua沙箱逃逸RCE --->snmp查询 --->ssh登陆 --->sunlogin向日葵RCE tools 实用工具模块 --->nc简单的nc,可以开放端口连接端口 --->searchfile支持多线程正则搜索文件

使用形式は```
zscan 模块 参数

I understand. However, I don't see any content after "INPUT:" in your message. It appears the Markdown content for chunk 5 was not actually included. Without input text to translate, I cannot provide a translation. Please provide the content you'd like me to translate.```


/___ \ /\ \ /\ \ /\ __ \ /\ "-.\ \
/
/ /
\ _
\ \ \ _
__ \ \ __ \ \ \ -. \
/_\ /_\ \ ___\ \ _\ _\ \ _\"_\ // // /_____/ //// // //

Usage: zscan [command]

Available Commands: all Use all scan mode blast Common service blasting exploit sshlogin,redisexec help Help about any command ping ping scan to find computer ps Port Scan scan ms17010,proxyfind,snmp,winscan(smb,netbios,oxid),poc server start http server or socks5 server

Flags: -h, --help help for zscan --nobar disable portscan progress bar -o, --output string the path of result file (default "result.txt") --proxy string Connect with a proxy(user:[email protected]:1080 or 172.16.95.1:1080) -T, --thread thread Set thread eg:2000 (default 600) -t, --timeout time Set timeout(s) eg:5s (default 5s) -v, --verbose Show verbose information

模块里面的Flag代表当前命令的参数,Global Flags代表全局参数(所有命令都可以用)
这里的Flags为全局参数,所有模块都可以使用

- --log:启用这个参数会将当前运行结果以追加的形式写到log.txt(可以记下每次运行的结果)
- -o --output:默认在当前目录的中文件名为Hosts -o指定路径
- --proxy :设置代理,用户名密码(user:pass@ip:port)不需要省份验证(ip:port)
- -T --thread:指定线程数,默认100
- -t --timeout:设置延时,网络条件好追求速度的话可以设置成1s
- -v --verbose:设置显示扫描过程信息

## 功能模块😈

目前已有模块:

<details>
<summary><b>ping模块:普通用户权限调用系统ping,root权限可以选择使用icmp数据包</b></summary>```
zscan ping 

Nothing to translate.``` Usage: zscan ping [flags]

Flags: -d, --discover string Live network segment found,local parameter uses the local NIC information。eg:zscan ping -d local/zscan ping -d 172.18.0.0,172.19.0.0 -h, --help help for ping -H, --host hosts Set hosts(The format is similar to Nmap) --hostfile string Set host file -i, --icmp Icmp packets are sent to check whether the host is alive(need root)

Global Flags: --nobar disable portscan progress bar -o, --output string the path of result file (default "result.txt") --proxy string Connect with a proxy(user:[email protected]:1080 or 172.16.95.1:1080) -T, --thread thread Set thread eg:2000 (default 600) -t, --timeout time Set timeout(s) eg:5s (default 5s) -v, --verbose Show verbose information

必须指定host和hostfile两个参数其中的一个,当有root权限的时候可以使用-i不调用本地的ping而是自己发icmp数据包(线程开的特别高的话几千那种,调用本地ping命令会导致cpu占用过高)

--discover两种网段发现模式,一种是ping网络b段网关,一种是oxid扫描

--discover后面需要给一个参数,如果给local(zscan ping --disconver local)就会读取本地网卡信息,去扫描本地的网络b段,例如读取到本地的两张网卡192.168.13.13和172.16.95.23,那么他就会去ping192.168.0.0/16和172.16.0.0/16这两个b段

还可以给定一个或者多个b段ip例如172.17.0.0或者172.18.0.0,10.10.0.0,多个ip段用逗号隔开

</details>

<details>
<summary><b>ps模块:端口扫描和获取httptitle</b></summary>```
zscan ps
  • まず、pythonをインストールし、レジストリでpythonのパスを設定する必要があります。``` Usage: zscan ps [flags]

Flags: -b, --banner Return banner information -h, --help help for ps -H, --host hosts Set hosts(The format is similar to Nmap) eg:192.168.1.1/24,172.16.95.1-100,127.0.0.1 --hostfile string Set host file -i, --icmp Icmp packets are sent to check whether the host is alive(need root) --noping not ping discovery before port scanning --nowebscan Whether to perform HTTP scanning (httpTitle and HTTP vulnerabilities)(default on) -p, --port port Set port eg:1-1000,3306,3389 or use " zscan ps -p l" ) to scan less port(thirty port) -s, --syn use syn scan --vulscan Whether to perform HTTP vulnerabilities(default off)

Global Flags: --nobar disable portscan progress bar -o, --output string the path of result file (default "result.txt") --proxy string Connect with a proxy(user:[email protected]:1080 or 172.16.95.1:1080) -T, --thread thread Set thread eg:2000 (default 600) -t, --timeout time Set timeout(s) eg:5s (default 5s) -v, --verbose Show verbose information

--hostと--hostfileでターゲットを指定

-pでポートを指定、指定しない場合はデフォルトポートを使用、または"l"を指定してless port(約30の一般的なポート)を使用

--nopingでpingを行わずに直接すべてのターゲットをスキャン

--icmpでpingを使用する際にICMPパケットを使用してホスト発見

--nowebscan パラメータでWebスキャンを無効にし、ポートスキャンのみ実行

--vulscan パラメータでPOC検出を有効化(Webスキャンが有効な場合のみ使用可能。そうでなければ意味がない)

--syn でSYNスキャンを使用(高権限が必要)

</details>

<details>
<summary><b>allモジュール:すべてのスキャンとブルートフォースモジュールを呼び出してスキャン</b></summary>```
zscan all

(No input provided.)``` Usage: zscan all [flags]

ツールをダウンロード