Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
工具/GitHubGitHub/anonymous121029034720384234234/py-network-scanner
侦察漏洞扫描器密码攻击漏洞利用IDS/IPS规避信息收集网络安全渗透测试学习与教育

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
py-network-scanner — 先进网络渗透测试工具包,支持 SSH 漏洞评估、CVE-2018-15473 漏洞利用、隐蔽式暴力破解能力及 fail2ban 规避技术。专为授权渗透测试项目设计的专业级安全测试框架。 | Kitploit
GitHubanonymous121029034720384234234/py-network-scanner

py-network-scanner

先进网络渗透测试工具包,支持 SSH 漏洞评估、CVE-2018-15473 漏洞利用、隐蔽式暴力破解能力及 fail2ban 规避技术。专为授权渗透测试项目设计的专业级安全测试框架。

查看仓库
111个月前尚未审核
root@kitploit:~
███╗   ██╗███████╗████████╗██╗    ██╗ ██████╗ ██████╗ ██╗  ██╗    ██████╗ ██████╗ ███████╗██████╗ 
████╗  ██║██╔════╝╚══██╔══╝██║    ██║██╔═══██╗██╔══██╗██║ ██╔╝    ██╔══██╗██╔══██╗██╔════╝██╔══██╗
██╔██╗ ██║█████╗     ██║   ██║ █╗ ██║██║   ██║██████╔╝█████╔╝     ██████╔╝██████╔╝█████╗  ██║  ██║
██║╚██╗██║██╔══╝     ██║   ██║███╗██║██║   ██║██╔══██╗██╔═██╗     ██╔═══╝ ██╔══██╗██╔══╝  ██║  ██║
██║ ╚████║███████╗   ██║   ╚███╔███╔╝╚██████╔╝██║  ██║██║  ██╗    ██║     ██║  ██║███████╗██████╔╝
╚═╝  ╚═══╝╚══════╝   ╚═╝    ╚══╝╚══╝  ╚═════╝ ╚═╝  ╚═╝╚═╝  ╚═╝    ╚═╝     ╚═╝  ╚═╝╚══════╝╚═════╝ 

🛡️ 高级网络渗透测试工具包

Python License Platform SSH Status

专业级网络侦察与 SSH 渗透测试框架,具备高级规避能力

🚀 快速上手 • 📖 文档 • 🎯 漏洞利用 • 🛡️ 防御 • ⚖️ 法律声明


⚠️ 法律声明

🔴 仅限授权测试

本工具仅用于教育目的和授权渗透测试。未经授权访问计算机系统属违法行为,可能招致刑事指控。

✅ 授权使用:

  • 您自己的系统和网络
  • 获得明确书面许可的系统
  • 教学实验环境
  • 专业渗透测试项目

❌ 未经授权的使用:

  • 任何您不拥有的系统
  • 公共网络或基础设施
  • 未经许可的企业系统
  • 任何恶意或有害的意图

使用本工具即表示您同意对自己的行为承担全部责任,并遵守所有适用法律。


🚀 功能特性

🌐 网络侦察与发现

  • 🔍 高级网络发现:智能 ping 扫描,支持可自定义时序
  • 🔎 多协议端口扫描:TCP 连接扫描,附带服务指纹识别
  • 🎨 横幅抓取与版本识别:自动化服务识别与版本检测
  • ⚡ 多线程:跨多主机的高性能并发扫描
  • 📊 进度跟踪:实时扫描进度显示,并附带预计剩余时间

🔐 SSH 安全评估框架

  • 🔍 深度 SSH 指纹识别:全面的 SSH 服务器分析与版本检测
  • 🛡️ 配置审计:自动检测 SSH 错误配置
  • 📝 漏洞数据库:CVE 映射与漏洞利用可用性检查
  • 📈 风险评估:自动化安全评分与优先级排序
  • 📄 详细报告:专业级漏洞评估报告

🎯 高级 SSH 漏洞利用引擎

💬 用户名枚举

  • CVE-2018-15473:基于时序的用户名枚举漏洞利用
  • 隐蔽模式:随机化延迟与连接节奏以规避检测
  • 自定义字典:可配置的用户名字典
  • 智能分析:统计时序分析,确保结果准确

🔑 凭据攻击框架

  • 字典攻击:使用自定义字典的高性能暴力破解
  • 智能暴力破解:智能凭据组合与常见模式
  • 隐蔽暴力破解:高级规避,含随机延迟与 IP 轮换
  • 会话管理:持久化攻击会话,支持断点续传
  • Fail2ban 规避:自适应时序以绕过入侵检测系统

🛡️ 规避与反检测

  • 连接速率限制:尝试之间可配置的延迟
  • 随机化时序:可变延迟以模拟人类行为
  • 连接池化:跨多个连接分布式攻击
  • 错误处理:优雅应对防御性对抗措施

⚙️ 高级配置系统

  • 📝 YAML 配置:通过 config.yaml 实现灵活的参数管理
  • 🎯 自定义端口列表:针对不同场景的可配置扫描配置
  • ⏱️ 时序控制:精细的超时与延迟自定义
  • 🗺️ 网络配置:针对不同网络类型的预配置设置
  • 📊 性能调优:线程池与连接优化

📦 安装

前置要求

root@kitploit:~
# Ensure Python 3.6+ is installed
python3 --version

# Install required dependencies
pip3 install paramiko pyyaml colorama

快速安装

root@kitploit:~
# Clone the repository
git clone https://github.com/floriankostov/network_scanner.git
cd network_scanner

# Make executable (Unix/Linux/macOS)
chmod +x scanner.py

# Run the scanner
python3 scanner.py

Docker 安装(可选)

root@kitploit:~
# Build Docker image
docker build -t network-scanner .

# Run in container
docker run -it --network host network-scanner

🔧 使用指南

🚀 快速上手

root@kitploit:~
python3 scanner.py

扫描器提供直观的菜单系统:

root@kitploit:~
╔══════════════════════════════════════════════════════════════════╗
║                    NETWORK SCANNER TOOLKIT                      ║
║                  Professional Penetration Testing               ║
╠══════════════════════════════════════════════════════════════════╣
║  1. 📡 Extended Port Scan    - Comprehensive port discovery     ║
║  2. ⚡ Basic Port Scan       - Quick essential port check       ║
║  3. 🔐 SSH Security Testing  - Advanced SSH vulnerability scan  ║
║  4. 🎯 Custom Target Scan    - Manual IP/range specification   ║
║  5. ❌ Exit                   - Quit the application            ║
╚══════════════════════════════════════════════════════════════════╝

🔍 网络发现

root@kitploit:~
# Automatic network detection
[+] Network: 192.168.1.0/24 (254 hosts)
[+] Gateway: 192.168.1.1
[+] Local IP: 192.168.1.100

# Custom network specification
python3 scanner.py --network 10.0.0.0/16

🎯 SSH 漏洞利用能力

💬 用户名枚举(CVE-2018-15473)

root@kitploit:~
# Standard enumeration
[EXPLOIT] CVE-2018-15473 Username Enumeration
[+] Target: 192.168.1.50:22 (OpenSSH 7.4)
[+] Testing 100 common usernames...
[✓] Valid users found: admin, user, test

# Stealth enumeration with evasion
[STEALTH] Enabling anti-detection measures
[+] Random delays: 0.5-2.0 seconds
[+] Connection variation: randomized
[✓] Valid users found: admin (confirmed)

🔑 高级暴力破解攻击

root@kitploit:~
# Smart brute force
[EXPLOIT] Smart SSH Brute Force
[+] Target: 192.168.1.50:22
[+] Valid users: admin, user
[+] Wordlist: 500 common passwords
[✓] Credentials found: admin:password123

# Stealth brute force with fail2ban evasion
[STEALTH] Advanced evasion enabled
[+] Adaptive delays: 3-8 seconds
[+] Connection resets: every 5 attempts
[+] IP rotation: enabled
[!] Intrusion detection bypass: active

🛡️ 防御绕过功能

  • 时序随机化:0.1-10 秒之间的可变延迟
  • 连接管理:自动连接轮换以避免检测
  • 错误分析:智能处理 fail2ban 与 IDS 响应
  • 速率限制:根据目标响应自适应调整速度

🔧 高级配置

📝 配置文件(config.yaml)

root@kitploit:~
# Network scanning settings
network:
  ping_timeout: 1.0
  port_timeout: 3.0
  thread_count: 50
  max_hosts: 254

# SSH exploitation settings
ssh:
  timeout: 10.0
  retry_count: 3
  stealth_mode: true
  delay_min: 0.5
  delay_max: 2.0
  
# Exploitation parameters
exploits:
  user_enumeration:
    max_users: 100
    timing_threshold: 0.05
  brute_force:
    max_attempts: 50
    wordlist_size: 500
    fail2ban_detection: true

🎯 自定义端口列表

root@kitploit:~
port_lists:
  basic: [22, 80, 443, 8080]
  extended: [21, 22, 23, 25, 53, 80, 110, 143, 443, 993, 995, 8080]
  comprehensive: [1-1000, 3389, 5432, 5900, 8080-8090]

🛡️ 防御与修复

🔒 SSH 加固建议

立即执行的操作

root@kitploit:~
# Disable root login
echo "PermitRootLogin no" >> /etc/ssh/sshd_config

# Require key-based authentication
echo "PasswordAuthentication no" >> /etc/ssh/sshd_config
echo "PubkeyAuthentication yes" >> /etc/ssh/sshd_config

# Change default port
echo "Port 2222" >> /etc/ssh/sshd_config

# Restart SSH service
systemctl restart sshd

长期安全措施

  1. 入侵检测:安装并配置 fail2ban
  2. 网络分段:使用防火墙规则隔离 SSH 访问
  3. 监控:实施 SSH 连接日志记录与告警
  4. 定期更新:通过安全补丁保持 SSH 软件最新
  5. 访问控制:使用 SSH 证书与集中式密钥管理

🚨 检测特征

需要监控的日志模式

root@kitploit:~
# Username enumeration attempts
grep "Invalid user" /var/log/auth.log

# Brute force detection
grep "Failed password" /var/log/auth.log | head -10

# Connection frequency analysis
awk '{print $1, $2, $3, $11}' /var/log/auth.log | grep "sshd" | sort | uniq -c

Fail2ban 配置

root@kitploit:~
[sshd]
enabled = true
port = ssh
filter = sshd
logpath = /var/log/auth.log
maxretry = 3
bantime = 3600
findtime = 600

🔬 技术深度解析

🎯 CVE-2018-15473 漏洞利用技术细节

漏洞概述

  • CVE 编号:CVE-2018-15473
  • 受影响版本:OpenSSH < 7.7、Cisco IOS 等
  • 影响:通过时序攻击进行用户名枚举
  • CVSS 评分:5.3(中危)

漏洞利用方法

  1. 时序分析:测量有效与无效用户名的响应时间差异
  2. 统计验证:多次采样以确认时序差异
  3. 规避技术:随机化延迟以避免检测
  4. 结果验证:与常见用户名模式交叉验证
root@kitploit:~
# Simplified timing attack pseudocode
def enumerate_users(target, usernames):
    timings = {}
    for user in usernames:
        start = time.time()
        try_authentication(target, user, "invalid_password")
        end = time.time()
        timings[user] = end - start
    
    # Analyze timing patterns
    return analyze_timing_anomalies(timings)

🔍 反检测机制

隐蔽模式特性

  • 抖动引入:0.1-10 秒之间的随机延迟
  • 连接轮换:定期建立新连接
  • 请求间隔:根据目标响应自适应调整时序
  • 错误处理:优雅应对防御性措施

📊 扫描结果示例

网络发现输出

root@kitploit:~
╔══════════════════════════════════════════════════════════════════╗
║                       NETWORK SCAN RESULTS                      ║
╠══════════════════════════════════════════════════════════════════╣
║ Network: 192.168.1.0/24                                         ║
║ Active Hosts: 12/254                                             ║
║ Scan Duration: 45.3 seconds                                     ║
╚══════════════════════════════════════════════════════════════════╝

📡 DISCOVERED HOSTS:
┌─────────────────┬──────────────────┬─────────────────────────────┐
│ IP Address      │ Hostname         │ Response Time               │
├─────────────────┼──────────────────┼─────────────────────────────┤
│ 192.168.1.1     │ gateway.local    │ 1.2ms                      │
│ 192.168.1.50    │ server.local     │ 2.1ms                      │
│ 192.168.1.100   │ workstation.local│ 0.8ms                      │
└─────────────────┴──────────────────┴─────────────────────────────┘

SSH 漏洞报告

root@kitploit:~
╔══════════════════════════════════════════════════════════════════╗
║                    SSH VULNERABILITY REPORT                     ║
║                      Target: 192.168.1.50:22                   ║
╠══════════════════════════════════════════════════════════════════╣
║ SSH Version: OpenSSH 7.4                                        ║
║ Risk Level: HIGH                                                 ║
║ Vulnerabilities: 3 Critical, 2 High, 1 Medium                  ║
╚══════════════════════════════════════════════════════════════════╝

🔴 CRITICAL VULNERABILITIES:
┌─────────────────┬────────────────────────────────────────────────┐
│ CVE-2018-15473  │ Username Enumeration via Timing Attack        │
│ Status          │ ✅ EXPLOITABLE - 3 valid users discovered     │
│ Impact          │ Information Disclosure, Attack Preparation    │
│ Users Found     │ admin, user, test                             │
└─────────────────┴────────────────────────────────────────────────┘

┌─────────────────┬────────────────────────────────────────────────┐
│ Brute Force     │ Weak Authentication Configuration              │
│ Status          │ ✅ EXPLOITABLE - Password auth enabled        │
│ Impact          │ Unauthorized Access, Credential Compromise    │
│ Attempts        │ 45/50 tested, 1 credential found             │
└─────────────────┴────────────────────────────────────────────────┘

💥 EXPLOITATION RESULTS:
╔══════════════════════════════════════════════════════════════════╗
║ ✅ Successfully compromised SSH service                          ║
║ 🔑 Credential: admin:password123                                ║
║ 🎯 Access Level: Administrative                                 ║
║ ⚠️  Recommend immediate credential change and hardening         ║
╚══════════════════════════════════════════════════════════════════╝

🤝 贡献指南

我们欢迎安全社区做出贡献!请遵循以下指南:

🔄 开发流程

  1. Fork 该仓库
  2. 创建功能分支:git checkout -b feature/new-exploit
  3. 提交更改:git commit -am 'Add new SSH exploit'
  4. 推送到分支:git push origin feature/new-exploit
  5. 创建 Pull Request

📝 贡献规范

  • 道德导向:所有贡献必须服务于教育/防御目的
  • 代码质量:遵循 Python PEP 8 标准
  • 文档:为新功能提供全面文档
  • 测试:为新的漏洞利用模块添加单元测试
  • 安全:包含适当的警告与保护措施

🐛 Bug 报告

请包含:

  • Python 版本与操作系统
  • 完整的错误信息
  • 复现步骤
  • 预期行为与实际行为

📚 资源与参考

🔗 安全资源

  • OWASP 测试指南
  • NIST 网络安全框架
  • CVE 数据库
  • SSH 安全最佳实践

📖 相关项目

  • Nmap - 网络发现与安全审计
  • Hydra - 密码破解工具
  • SSH-Audit - SSH 配置审计

🎓 教育内容

  • 渗透测试方法论
  • SSH 协议深度解析
  • 网络安全基础

⚖️ 许可证

本项目依据教育使用许可证授权 - 详情请参阅 LICENSE 文件。

仅限教育使用:本软件仅用于教育目的与经授权的安全测试。任何恶意使用均被严格禁止,并可能招致刑事起诉。


🙏 致谢

  • OpenSSH 团队:持续维护安全的 SSH 实现
  • 安全研究社区:负责任地披露安全漏洞
  • OWASP:提供安全测试方法论
  • Python 社区:提供优秀的网络库

⚠️ 请记住:能力越大,责任越大

请以道德、合法且负责任的方式使用本工具。

报告问题 • 请求功能 • 安全联系

下载工具