Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
xmap — 고성능 네트워크 스캐너로, 인터넷 전체 IPv4/IPv6 연구를 위한 다중 프로브 모듈(ICMP, TCP SYN, UDP, DNS)을 갖추고 있으며, 10G 링크에서 5분 이내에 전체 주소 공간 스캔이 가능합니다. | Kitploit
도구/GitHubGitHub/idealeer/xmap
ReconnaissanceNetwork MappingPort ScanningInformation GatheringNetwork SecurityDNS Analysis
GitHubidealeer/xmap

xmap

고성능 네트워크 스캐너로, 인터넷 전체 IPv4/IPv6 연구를 위한 다중 프로브 모듈(ICMP, TCP SYN, UDP, DNS)을 갖추고 있으며, 10G 링크에서 5분 이내에 전체 주소 공간 스캔이 가능합니다.

저장소 보기
489745개월 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

XMap: 인터넷 스캐너

Build Status

XMap는 인터넷 전체 IPv6 및 IPv4 네트워크 연구 스캐닝을 수행하도록 설계된 빠른 네트워크 스캐너입니다.

XMap는 ZMap에서 완전히 재구현 및 개선되었으며 ZMap과 완전히 호환되며 "5분" 프로빙 속도와 새로운 스캐닝 기술을 갖추고 있습니다. XMap는 32비트 주소 공간을 45분 이내에 스캔할 수 있습니다. 10기가비트 이더넷 연결과 PF_RING을 사용하면 XMap는 32비트 주소 공간을 5분 이내에 스캔할 수 있습니다. 또한 새로운 IPv6 스캐닝 방식을 활용하여 XMap는 IPv6 네트워크 경계를 빠르게 발견할 수 있습니다. 더 나아가 XMap는 2001:db8::/32-64, 192.168.0.1/16-20과 같이 모든 길이와 위치에서 네트워크 공간을 무작위로 스캔할 수 있습니다. 또한 XMap는 여러 포트를 동시에 프로브할 수 있습니다.

XMap는 GNU/Linux, macOS 및 BSD에서 작동합니다. XMap는 현재 ICMP Echo 스캔, TCP SYN 스캔, UDP 프로브 및 DNS 스캔(무상태, 상태 저장, 주소 스푸핑, EDNS) 을 위한 프로브 모듈을 구현했습니다.

배너 그래브 및 TLS 핸드셰이크 도구인 ZGrab2를 사용하면 더 복잡한 스캔을 수행할 수 있습니다.

설치

XMap의 최신 안정 버전은 2.0.5이며 Linux, macOS 및 BSD를 지원합니다. 배포판 패키지 관리자(아직 지원되지 않음)를 사용하는 대신 HEAD에서 XMap를 설치하는 것을 권장합니다.

소스에서 XMap 빌드에 대한 지침은 INSTALL에서 확인할 수 있습니다.

docker에서 설치: docker pull liii/xmap:latest

ArchLinux 패키지에서 설치

사용법

XMap 사용에 대한 가이드는 GitHub Wiki에서 확인할 수 있습니다.

XMap 사용을 위한 간단한 명령 및 옵션은 USAGE에서 확인할 수 있습니다.

DNS 프로빙 모듈 사용 방법은 Issue #11에서 확인하세요.

설명 비디오는 Pentester Academy TV에서 시청하세요.

스타 기록

Star History Chart

발표 및 영향

  • 2021 서호 사이버보안 컨퍼런스에서 발표: 사이버공간 보안 도구 발표

  • Pentester Academy TV에서 발표

  • 10개 이상의 최고 수준 보안 컨퍼런스 논문에서 참조

  • 특허 CN202110502369.2 지원

  • 2025 ACSAC 사이버보안 아티팩트 임팩트 어워드 2위 (이 상을 수상한 첫 번째 중국 기관)

논문

  • [DSN '21] Xiang Li, Baojun Liu, Xiaofeng Zheng, Haixin Duan, Qi Li, Youjun Huang. Fast IPv6 Network Periphery Discovery and Security Implications. In Proceedings of the 2021 IEEE/IFIP International Conference on Dependable Systems and Networks (DSN '21). 타이베이, 대만, 2021년 6월 21-24일 (가상). [PDF] [Slides] [Video].

    (채택률: 48/279=17.2%)

  • [NDSS '23] Xiang Li, Baojun Liu, Xuesong Bai, Mingming Zhang, Qifan Zhang, Zhou Li, Haixin Duan, and Qi Li. Ghost Domain Reloaded: Vulnerable Links in Domain Name Delegation and Revocation. In Proceedings of the 30th Annual Network and Distributed System Security Symposium (NDSS '23). 샌디에이고, 캘리포니아, 2023년 2월 27일 – 3월 3일. [PDF] [Slides] [Video]

라이선스 및 저작권

XMap 저작권 2021-2025, 난카이 대학교 올인원 보안 및 개인정보 연구실 (AOSP Lab)의 Xiang Li

Apache License, Version 2.0 (the "License")에 따라 라이선스가 부여됩니다. 라이선스를 준수하지 않는 한 이 파일을 사용할 수 없습니다. 라이선스 사본은 http://www.apache.org/licenses/LICENSE-2.0에서 얻을 수 있습니다.

법률에 의해 요구되거나 서면으로 동의하지 않는 한, 라이선스에 따라 배포되는 소프트웨어는 명시적이든 묵시적이든 어떠한 종류의 보증이나 조건 없이 "있는 그대로" 배포됩니다. 라이선스 하의 특정 언어 권한 및 제한 사항은 LICENSE를 참조하세요.

도구 다운로드

(채택률: 94/581=16.2%, 여름 채택률: 36/183=19.7%), 가을 채택률: 58/398=14.6%)

  • OARC 39에서 발표
  • ICANN DNS Symposium 2022에서 발표
  • Black Hat Asia 2023에서 발표
  • RFC 초안: DNS 리졸버에 의한 위임 재검증에서 참조
  • [USENIX Security '23] Xiang Li, Chaoyi Lu, Baojun Liu, Qifan Zhang, Zhou Li, Haixin Duan, and Qi Li. The Maginot Line: Attacking the Boundary of DNS Caching Protection. In Proceedings of the 32nd USENIX Security Symposium (USENIX Security '23). 애너하임, 캘리포니아, 2023년 8월 9–11일. [PDF] [Slides] [Video]

    (채택률: 422/1,444=29.2%, 여름 채택률: 91/388=23.5%, 가을 채택률: 155/531=29.2%), 겨울 채택률: 176/525=33.5%)

    • Black Hat USA 2023에서 발표
    • BleepingComputer 및 APNIC 등 미디어 60+ 보도
    • 오스트리아 정부 CERT 일일 보고서
    • 스웨덴 정부 CERT 주간 뉴스
    • 본머스 대학교 (BU) CERT 뉴스
    • SHUZIHUANYU 토크에서 발표
    • KANXUE 2023 SDC에서 발표
    • Black Hat 웨비나에서 발표
  • [CCS '23] Wei Xuⓘ, Xiang Liⓘ, Chaoyi Lu, Baojun Liu, Jia Zhang, Jianjun Chen, Tao Wan, and Haixin Duan. TsuKing: Coordinating DNS Resolvers and Queries into Potent DoS Amplifiers. In Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security (CCS '23). 코펜하겐, 덴마크, 2023년 11월 26–30일. [PDF] [Slides] [Video]

    (채택률: 158/795=19.9%, 1차 채택률: ??%, 2차 채택률: ??%. ⓘ: 두 저자가 동등하게 기여함)

    • OARC 41에서 발표
    • Black Hat Europe 2023에서 발표
  • [CCS '23] Zhenrui Zhangⓘ, Geng Hongⓘ, Xiang Li, Zhuoqun Fu, Jia Zhang, Mingxuan Liu, Chuhan Wang, Jianjun Chen, Baojun Liu, Haixin Duan, Chao Zhang, and Min Yang. Under the Dark: A Systematical Study of Stealthy Mining Pools (Ab)use in the Wild. In Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security (CCS '23). 코펜하겐, 덴마크, 2023년 11월 26–30일. [PDF] [Slides] [Video]

    (채택률: 158/795=19.9%, 1차 채택률: ??%, 2차 채택률: ??%. ⓘ: 두 저자가 동등하게 기여함)

  • [IMC '23] Fenglu Zhang, Yunyi Zhang, Baojun Liu, Eihal Alowaisheq, Lingyun Ying, Xiang Li, Zaifeng Zhang, Ying Liu, Haixin Duan, Min Zhang. Wolf in Sheep's Clothing: Evaluating the Security Risks of the Undelegated Record on DNS Hosting Services. In Proceedings of ACM Internet Measurement Conference 2023 (IMC '23). 몬트리올, 캐나다, 2023년 10월 24-26일. [PDF] [Slides] [Video]

    (채택률: 52/208=25.0%)

  • [NDSS '24] Chuhan Wang, YASUHIRO KURANAGA, Yihang Wang, Mingming Zhang, Linkai Zheng, Xiang Li, Jianjun Chen, Haixin Duan, Yanzhong Lin, Qingfeng Pan. BreakSPF: How Shared Infrastructures Magnify SPF Vulnerabilities Across the Internet. In Proceedings of the 31st Annual Network and Distributed System Security Symposium (NDSS '24). 샌디에이고, 캘리포니아, 2024년 2월 26일 – 3월 1일. [PDF] [Slides] [Video]

    (채택률: 104/694=15.0%, 여름 채택률: 41/211=19.4%, 가을 채택률: 63/483=13.0%)

  • [Oakland S&P '24] Xiang Li, Wei Xu, Baojun Liu, Mingming Zhang, Zhou Li✉, Jia Zhang, Deliang Chang, Xiaofeng Zheng, Chuhan Wang, Jianjun Chen, Haixin Duan✉, and Qi Li✉. TuDoor Attack: Systematically Exploring and Exploiting Logic Vulnerabilities in DNS Response Pre-processing with Malformed Packets. In Proceedings of 2024 IEEE Symposium on Security and Privacy (Oakland S&P '24). 샌프란시스코, 캘리포니아, 2024년 5월 20–23일. [PDF] [Slides] [Poster] [Video]

    (채택률: 261/1,466=17.8%, 1차 채택률: ??%, 2차 채택률: ??%, 3차 채택률: ??%. ✉: 교신 저자.)

    • OARC 42에서 발표
    • RFC 9520: DNS Resolution Failures의 네거티브 캐싱에서 참조
    • GeekCon 2024 International에서 발표
    • Black Hat USA 2024에서 발표
    • 2024 Pwnie Award 최고 혁신 연구 부문 후보 (해커 오스카) 수상
  • [USENIX Security '24] Qifan Zhang, Xuesong Bai, Xiang Li✉, Haixin Duan, Qi Li, and Zhou Li✉. ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response Fuzzing. In Proceedings of the 33rd USENIX Security Symposium (USENIX Security '24). 필라델피아, 펜실베이니아, 2024년 8월 14–16일. [PDF] [Slides] [Video]

    (채택률: 417/2,276=18.3%, 여름 채택률: ??%, 가을 채택률: ??%), 겨울 채택률: ??%. ✉: 두 저자 모두 교신 저자.)

    • SHUZIHUANYU 토크에서 발표
    • OARC 42에서 발표
  • [NDSS '24] Mingxuan Liu, Yiming Zhang, Xiang Li, Chaoyi Lu, Baojun Liu, Haixin Duan, Xiaofeng Zheng (2024). Understanding the Implementation and Security Implications of Protective DNS Services. In Proceedings of the 31st Annual Network and Distributed System Security Symposium (NDSS '24). 샌디에이고, 캘리포니아, 2024년 2월 26일 – 3월 1일. [PDF] [Slides] [Video]

    (채택률: 104/694=15.0%, 여름 채택률: 41/211=19.4%, 가을 채택률: 63/483=13.0%)

  • [Oakland S&P '24] Xiang Li, Dashuai Wu, Haixin Duan, and Qi Li. DNSBomb: A New Practical-and-Powerful Pulsing DoS Attack Exploiting DNS Queries-and-Responses. In Proceedings of 2024 IEEE Symposium on Security and Privacy (Oakland S&P '24). 샌프란시스코, 캘리포니아, 2024년 5월 20–23일. [PDF] [Slides] [Poster] [Video]

    (채택률: 261/1,466=17.8%, 1차 채택률: ??%, 2차 채택률: ??%, 3차 채택률: ??%)

    • GeekCon 2023에서 발표 (2등)
    • The Hacker News, Cyber Security News, dns-operation 등 미디어 40+ 보도
    • DNS OARC 43에서 발표
  • [NDSS '24] Qifan Zhang, Xuesong Bai, Xiang Li✉, Haixin Duan, Qi Li, and Zhou Li✉. Poster: ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response Fuzzing. In Proceedings of the 31st Annual Network and Distributed System Security Symposium (NDSS '24). 샌디에이고, 캘리포니아, 2024년 2월 26일 – 3월 1일. [PDF] [Slides] [Video]

    (채택률: 33/42=78.6%)

  • [USENIX Security '24] Yunyi Zhang, Baojun Liu, Haixin Duan, Min Zhang, Xiang Li, Fan Shi, Chengxi Xu, and Eihal Alowaisheq Rethinking the Security Threats of xxx DNS xxx. In Proceedings of the 33rd USENIX Security Symposium (USENIX Security '24). 필라델피아, 펜실베이니아, 2024년 8월 14–16일. [PDF] [Slides] [Video]

    (채택률: 417/2,276=18.3%, 여름 채택률: ??%, 가을 채택률: ??%), 겨울 채택률: ??%)

    • XCon 2024에서 발표
  • [CCS '25] Xiang Li, Mingming Zhang, Zuyao Xu, Fasheng Miao, Yuqi Qiu, Baojun Liu, Jia Zhang, Xiaofeng Zheng, Haixin Duan, Zheli Liu, Yunhai Zhang, and Dunqiu Fan. RebirthDay Attack: Reviving DNS Cache Poisoning with the Birthday Paradox. In Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25).

  • 기타 논문은 이 도구 또는 논문을 인용