基于 Bash 的被动侦察 + 攻击面测绘脚本,仅使用公共 API + 标准 Linux 工具(curl、dig、openssl、nmap、python3)。
_ _ _ _ _ _______
| \ | | | | | |/ / ____|
| \| | | | | ' /| _|
| |\ | |_| | . \| |___
|_| \_|\___/|_|\_\_____|
N U K E // 侦察与攻击面测绘
-----------------------------------------
基于 Bash 的被动侦察 + 攻击面测绘脚本,仅使用公共 API + 系统自带 Linux 工具(curl、dig、openssl、nmap、python3)。
所有输出写入单个 .txt 文件:nuke_<domain>.txt。
不依赖 subfinder、ffuf、gobuster、subjs、getJS、jshunter 或 js_snitch。
| # | 模块 | 来源 / 技术 |
|---|---|---|
| 1 | 通过 CT 获取子域名 | crt.sh |
| 2 | 通过备用 CT 获取子域名 | crt.name |
| 3 | 子域名(可选,需要密钥) | SecurityTrails API |
| 4 | 子域名 + URL + IP | OTX AlienVault |
| 5 | 域名 + IP + ASN/服务器 | urlscan.io |
| 6 | 子域名 + 同级域名 + IP(需要密钥) | VirusTotal v2 |
| 7 | 合并子域名 | 所有来源的并集 + 去重 |
| 8 | DNS(TXT/SPF、A、AAAA、NS、MX、SOA + AXFR) | dns.google(DoH)+ dig/host — 等效于 dnsrecon -d |
| 9 | WHOIS | 通过 rdap.org 的 RDAP |
| 10 | IP / 反向 DNS / RDAP-IP / HTTP 状态 | dns.google PTR + rdap.org/ip + curl -I |
| 11 | Favicon 哈希(Shodan 搜索)+ IP SSL 验证 | 本地 Shodan 标准 murmur3(http.favicon.hash)+ openssl + nmap --script ssl-cert |
| 12 | JS 文件 + 提取的端点 | <script src> 解析 + 路径/URL 正则(替代 subjs/getJS/jshunter) |
| 13 | 历史 URL | Wayback Machine CDX |
| 14 | 源站 IP 发现(CDN/WAF 绕过) | 关联 DNS + OTX + urlscan + VT + SPF + Shodan,通过 RDAP org + Host: 头测试过滤 |
| 15 | 内置目录扫描 | 高信号精选字典,并行执行(无需 ffuf/gobuster) |
亮点:
pip install),附带即用型 dork:http.favicon.hash:X。ip4:/include:/a/mx)— 泄露基础设施 / 源站 IP。?api=、admin、token、.bak、.sql、.env、.git)。.git/HEAD、.env、backup.zip、phpinfo.php、actuator/env、swagger/、graphql、jenkins/ 等。bash、curl、grep、sed、awk、sort、trdig 或 host → 用于 AXFRpython3 → 用于 favicon murmur3 哈希(Shodan 标准)nmap → 用于 nmap --script ssl-cert -p 443 <IP>openssl → 用于证书 CN/SAN 检查适用于 Kali、Ubuntu、Debian、WSL2。
git clone https://github.com/AnkhCorp/Nuke.sh.git
cd Nuke.sh
chmod +x nuke.sh
# 基础用法(100% 免费,无需密钥)
bash nuke.sh example.com
# 使用密钥(通过参数传入)
bash nuke.sh example.com SECURITYTRAILS_KEY VIRUSTOTAL_KEY
# 通过环境变量传入密钥(推荐 — 切勿提交密钥)
export SECURITYTRAILS_API_KEY="your_key"
export VT_APIKEY="your_key"
export SHODAN_API_KEY="your_key" # 可选
export ZOOMEYE_KEY="your_key" # 可选
bash nuke.sh example.com
支持的环境变量:
| 变量 | 是否必需? | 获取地址 |
|---|---|---|
SECURITYTRAILS_API_KEY | 否 | https://securitytrails.com/app/signup |
VT_APIKEY | 否 | https://www.virustotal.com/gui/my-apikey |
SHODAN_API_KEY | 否 | https://account.shodan.io |
ZOOMEYE_KEY | 否 | https://www.zoomeye.hk |
URLSCAN_SIZE | 否(默认 1000) | 例如 export URLSCAN_SIZE=10000 以获取最大值 |
输出:
nuke_example.com.txt
===================================================================
== 7. CONSOLIDATED SUBDOMAINS (all sources)
===================================================================
crt.sh=45 | crt.name=38 | securitytrails=52 | otx=20 | urlscan=15 | virustotal=30
[UNIQUE total]: https://raw.githubusercontent.com/ankhcorp/nuke.sh/main/87
admin.example.com
api.example.com
...
===================================================================
== 14. ORIGIN IP DISCOVERY (consolidated)
===================================================================
[All candidate IPs (current DNS + OTX + urlscan + VT + SPF + Shodan)]:
https://raw.githubusercontent.com/ankhcorp/nuke.sh/main/1.2.3.4
5.6.7.8
...
IP: 1.2.3.4 | RDAP_ORG: CLOUDFLARENET
IP: 5.6.7.8 | RDAP_ORG: LOCAWEB
# Shodan — 证书
shodan search 'Ssl.cert.subject.CN:"example.com" 200 --fields ip_str'
# Shodan — favicon
shodan search 'http.favicon.hash:123456789'
# ZoomEye
ssl:"example.com" # 访问 https://www.zoomeye.hk/
# 手动
https://crt.name/v1/search?apex=example.com
https://favicon-hash.kmsec.uk/
https://viewdns.info/iphistory/?domain=example.com
https://mxtoolbox.com/SuperTool.aspx
https://urlscan.io/search/#domain:example.com
手动验证源站 IP 候选:
curl -sk -H 'Host: example.com' https://<CANDIDATE_IP>/ | head -n 20
echo | openssl s_client -connect <CANDIDATE_IP>:443 -servername example.com 2>/dev/null | openssl x509 -noout -subject -ext subjectAltName
nmap --script ssl-cert -p 443 <CANDIDATE_IP>
如果证书返回 CN/SAN=example.com(或标题/Server 与站点匹配),那就是真实 IP。
| 工具 | 替代原因 |
|---|---|
subfinder | 由 crt.sh + crt.name + OTX + urlscan + VT + SecurityTrails 替代(全部通过 API,无需安装任何东西) |
webanalyze | 可靠的技术检测需要付费 API(Wappalyzer/BuiltWith)— 超出范围 |
subjs / getJS | 由内置 <script src> 提取替代(第 12 节) |
jshunter | 由内置端点正则替代(第 12 节) |
js_snitch | 无公共 API 等效方案 |
dnsrecon -d | 第 8 节等效(通过 DoH + dig 实现 NS/MX/SOA/AXFR) |
httpx-toolkit | 第 10 节部分等效(每台主机的状态/服务器) |
ffuf / gobuster | 内置目录扫描,使用精选字典 + xargs -P(第 15 节)— 如需完整模糊测试请使用 SecLists:ffuf -u https://TARGET/FUZZ -w raft-medium-directories.txt |
仅对您获授权测试的目标使用(您自己的资产、范围内的漏洞赏金项目、签约渗透测试)。
作者不对滥用行为负责。
MIT — 可自由使用、修改和分享。
欢迎提交 PR!路线图构想:
--only-ips / --only-subs 标志amass / anubis 集成