Skip to content
KitploitKITPLOIT
๋„๊ตฌ๋ธ”๋กœ๊ทธ
์ œ์ถœ
๋„๊ตฌ๋ธ”๋กœ๊ทธ
์ œ์ถœ

ํ•ดํ‚น, ์นจํˆฌ ํ…Œ์ŠคํŠธ ๋ฐ ์‚ฌ์ด๋ฒ„ ๋ณด์•ˆ ๋„๊ตฌ๋ฅผ ๋‹น์‹ ์˜ ๋ณด์•ˆ ๋ฌด๊ธฐ๊ณ ์—!

Kitploit์€ ํ•ดํ‚น, ์‚ฌ์ด๋ฒ„ ๋ณด์•ˆ ๋ฐ ์นจํˆฌ ํ…Œ์ŠคํŠธ ๋„๊ตฌ ๋””๋ ‰ํ† ๋ฆฌ์ž…๋‹ˆ๋‹ค. ์ตœ์‹  ํ”„๋กœ์ ํŠธ ์—…๋ฐ์ดํŠธ๋ฅผ ๋ฐœ๊ฒฌํ•˜์—ฌ ์ทจ์•ฝ์ ์„ ์ฐพ๊ณ , ์‹œ์Šคํ…œ์„ ๋ถ„์„ํ•˜๊ณ , ํ…Œ์ŠคํŠธ๋ฅผ ์ž๋™ํ™”ํ•˜๊ณ , ๋ณด์•ˆ์„ ๊ฐ•ํ™”ํ•˜์„ธ์š”.

ยทยทํ”ผ๋“œยท๋ฌธ์˜ยท๊ฐœ์ธ์ •๋ณดยทยฉ 2026 Kitploit

๋„๊ตฌ ๋””๋ ‰ํ† ๋ฆฌ

์นดํ…Œ๊ณ ๋ฆฌ

๋ชจ๋“  ์นดํ…Œ๊ณ ๋ฆฌ ๋ณด๊ธฐ
Loading categories
๋„๊ตฌ/GitHubGitHub/j3ers3/searpy
OSINT (Open Source Intelligence)ReconnaissanceDNS & Subdomain EnumerationInformation GatheringWeb SecuritySubdomain Enumeration
GitHubj3ers3/searpy

Searpy

๐Ÿฅ€ ๊ฒ€์ƒ‰ ์—”์ง„ ํˆดํ‚ท, URL ์ˆ˜์ง‘, Favicon ํ•ด์‹œ ๊ฐ’์œผ๋กœ ์‹ค์ œ IP ์ฐพ๊ธฐ, ์„œ๋ธŒ๋„๋ฉ”์ธ ์ฐพ๊ธฐ

์ €์žฅ์†Œ ๋ณด๊ธฐ
2142223๋…„ ์ „Kitploit ๊ฒ€ํ†  ์™„๋ฃŒ

์ธ๊ธฐ

๋ชจ๋‘ ๋ณด๊ธฐ โ†’

์ปค๋ฎค๋‹ˆํ‹ฐ์—์„œ ๊ฐ€์žฅ ๋งŽ์ด ์‚ฌ์šฉ๋˜๋Š” ๋„๊ตฌ๋ฅผ ์ฐพ์•„๋ณด์„ธ์š”.

๋ชจ๋“  ๋„๊ตฌ ํƒ์ƒ‰

๋„๊ตฌ ์ปฌ๋ ‰์…˜์„ ๋‘˜๋Ÿฌ๋ณด์„ธ์š”

๋ชจ๋“  ๋„๊ตฌ ๋ณด๊ธฐ โ†’
๊ณต์œ 

๐Ÿฅ€ Searpy Stage Python 2.7 Python 3.7 Build Status

๐Ÿ”ง ๋ฐฐ์น˜ ๊ฒ€์ƒ‰ ๋„๊ตฌ๋กœ, ์ˆ˜์ง‘ ๋ฐ ์ถœ์ฒ˜ ์ถ”์ ์— ์‚ฌ์šฉ ๊ฐ€๋Šฅ

py2 ๋ฐ py3 ์ง€์›

1. ์„ค์น˜

root@kitploit:~
git clone https://github.com/j3ers3/Searpy
pip install -r requirements.txt

้…็ฝฎAPIๅŠ่ดฆๅท ./config.py

python Searpy -h

2. ๋„์›€๋ง

root@kitploit:~
Searpy Engine Tookit

optional arguments:
  -h, --help            show this help message and exit

ENGINE:
  --baidu               Using baidu Engine
  --google              Using google Engine
  --so                  Using 360so Engine
  --bing                Using bing Engine
  --shodan              Using shodan Engine
  --fofa                Using fofa Engine
  --zoomeye             Using zoomeye Engine
  --goo                 Using goo Engine
  --yahoo               Using yahoo Engine
  --quake               Using quake Engine
  --hunter              Using hunter Engine

SCRIPT:
  --shodan_icon SHODAN_ICON
                        Get ip list which using the same favicon.ico
  --fofa_icon FOFA_ICON
                        Get ip list which using the same favicon.ico

MISC:
  -s SEARCH             Speciy Keyword
  -o OUTPUT             Specify output file default output.txt
  -p PAGE               Search page (default 1)
  -l LIMIT              Maximum searching results (default:10) Only Shodan
  --proxy PROXY         HTTP Proxy, eg http://127.0.0.1:8080

2.1 ์˜ˆ์ œ

root@kitploit:~
python3 Searpy.py --fofa -s "app=jboss" -p10
python3 Searpy.py --shodan -s "weblogic" -l10 
python3 Searpy.py --quake -s 'domain="baidu.com"'
python3 Searpy.py --hunter -s 'domain="baidu.com"'

python3 Searpy.py --bing -s 'site:baidu.com'
python3 Searpy.py --google -s "inurl:login.action" -p1 --proxy http://127.0.0.1:1080

-w762

2.2 ๊ธฐํƒ€ ๊ธฐ๋Šฅ

favicon.icon ํ•ด์‹œ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋™์ผํ•œ ์•„์ด์ฝ˜์„ ์‚ฌ์šฉํ•˜๋Š” ์›น์‚ฌ์ดํŠธ๋ฅผ ์ฐพ์Šต๋‹ˆ๋‹ค. ์‹ค์ œ IP ์ถ”์  ๋ฐ ์ž์‚ฐ ๋ฐœ๊ฒฌ์— ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

root@kitploit:~
python3 Searpy.py --shodan_icon https://www.qq.com
python3 Searpy.py --fofa_icon https://www.qq.com

ๆˆชๅฑ2020-09-15 09.44.36

3. ๋ชจ๋“ˆ ํ˜ธ์ถœ

root@kitploit:~
>>> from Searpy import Bing
>>> s = Bing('inurl:php?id=1', 2)
>>> s.search()
>>> for i in s.result:
>>>     print(i)

4. ์ง€์› ๊ฒ€์ƒ‰ ์—”์ง„

  • Shodan
  • Fofa
  • Zoomeye
  • Censys
  • Dnsdb
  • Google
  • Baidu
  • Bing
  • 360so
  • Goo
  • Yahoo
  • Quake
  • Hunter

5. ํ•  ์ผ

  • ์„œ๋ธŒ๋„๋ฉ”์ธ ๊ฒ€์ƒ‰ ์ถ”๊ฐ€

6. ๋ณ€๊ฒฝ ๋กœ๊ทธ

v2.3

  • fix some bugs
  • add fofa_icon module

v2.2

  • fix some bugs

7. ๊ธฐ๋ถ€

  • XMR: 498AoZRwfC11Fa4LwAyVVp3wRD4Zyf1e1HziegczeWeSYVVTZ8gw8CoNPm5yhY91tkDqDMBg6A5KUfyowMtdkQDrDxE5aVN
  • BTC: 1ALWC7rGL4dHgbyy4R8uTVHmDugPDD7Rvt
๋„๊ตฌ ๋‹ค์šด๋กœ๋“œ