Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
py-network-scanner — 先进网络渗透测试工具包,支持 SSH 漏洞评估、CVE-2018-15473 漏洞利用、隐蔽式暴力破解能力及 fail2ban 规避技术。专为授权渗透测试项目设计的专业级安全测试框架。 | Kitploit
工具/GitHubGitHub/anonymous121029034720384234234/py-network-scanner
侦察漏洞扫描器密码攻击漏洞利用IDS/IPS规避信息收集网络安全渗透测试学习与教育

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
GitHubanonymous121029034720384234234/py-network-scanner

py-network-scanner

先进网络渗透测试工具包,支持 SSH 漏洞评估、CVE-2018-15473 漏洞利用、隐蔽式暴力破解能力及 fail2ban 规避技术。专为授权渗透测试项目设计的专业级安全测试框架。

查看仓库
1161年前尚未审核
███╗   ██╗███████╗████████╗██╗    ██╗ ██████╗ ██████╗ ██╗  ██╗    ██████╗ ██████╗ ███████╗██████╗ 
████╗  ██║██╔════╝╚══██╔══╝██║    ██║██╔═══██╗██╔══██╗██║ ██╔╝    ██╔══██╗██╔══██╗██╔════╝██╔══██╗
██╔██╗ ██║█████╗     ██║   ██║ █╗ ██║██║   ██║██████╔╝█████╔╝     ██████╔╝██████╔╝█████╗  ██║  ██║
██║╚██╗██║██╔══╝     ██║   ██║███╗██║██║   ██║██╔══██╗██╔═██╗     ██╔═══╝ ██╔══██╗██╔══╝  ██║  ██║
██║ ╚████║███████╗   ██║   ╚███╔███╔╝╚██████╔╝██║  ██║██║  ██╗    ██║     ██║  ██║███████╗██████╔╝
╚═╝  ╚═══╝╚══════╝   ╚═╝    ╚══╝╚══╝  ╚═════╝ ╚═╝  ╚═╝╚═╝  ╚═╝    ╚═╝     ╚═╝  ╚═╝╚══════╝╚═════╝ 

🛡️ 高级网络渗透测试工具包

Python License Platform SSH Status

专业级网络侦察与 SSH 渗透测试框架,具备高级规避能力

🚀 快速上手 • 📖 文档 • 🎯 漏洞利用 • 🛡️ 防御 • ⚖️ 法律声明


⚠️ 法律声明

🔴 仅限授权测试

本工具仅用于教育目的和授权渗透测试。未经授权访问计算机系统属违法行为,可能招致刑事指控。

✅ 授权使用:

  • 您自己的系统和网络
  • 获得明确书面许可的系统
  • 教学实验环境
  • 专业渗透测试项目

❌ 未经授权的使用:

  • 任何您不拥有的系统
  • 公共网络或基础设施
  • 未经许可的企业系统
  • 任何恶意或有害的意图

使用本工具即表示您同意对自己的行为承担全部责任,并遵守所有适用法律。


🚀 功能特性

🌐 网络侦察与发现

  • 🔍 高级网络发现:智能 ping 扫描,支持可自定义时序
  • 🔎 多协议端口扫描:TCP 连接扫描,附带服务指纹识别
  • 🎨 横幅抓取与版本识别:自动化服务识别与版本检测
  • ⚡ 多线程:跨多主机的高性能并发扫描
  • 📊 进度跟踪:实时扫描进度显示,并附带预计剩余时间

🔐 SSH 安全评估框架

  • 🔍 深度 SSH 指纹识别:全面的 SSH 服务器分析与版本检测
  • 🛡️ 配置审计:自动检测 SSH 错误配置
  • 📝 漏洞数据库:CVE 映射与漏洞利用可用性检查
  • 📈 风险评估:自动化安全评分与优先级排序
  • 📄 详细报告:专业级漏洞评估报告

🎯 高级 SSH 漏洞利用引擎

💬 用户名枚举

  • CVE-2018-15473:基于时序的用户名枚举漏洞利用
  • 隐蔽模式:随机化延迟与连接节奏以规避检测
  • 自定义字典:可配置的用户名字典
  • 智能分析:统计时序分析,确保结果准确

🔑 凭据攻击框架

  • 字典攻击:使用自定义字典的高性能暴力破解
  • 智能暴力破解:智能凭据组合与常见模式
  • 隐蔽暴力破解:高级规避,含随机延迟与 IP 轮换
  • 会话管理:持久化攻击会话,支持断点续传
  • Fail2ban 规避:自适应时序以绕过入侵检测系统

🛡️ 规避与反检测

  • 连接速率限制:尝试之间可配置的延迟
  • 随机化时序:可变延迟以模拟人类行为
  • 连接池化:跨多个连接分布式攻击
  • 错误处理:优雅应对防御性对抗措施

⚙️ 高级配置系统

  • 📝 YAML 配置:通过 config.yaml 实现灵活的参数管理
  • 🎯 自定义端口列表:针对不同场景的可配置扫描配置
  • ⏱️ 时序控制:精细的超时与延迟自定义
  • 🗺️ 网络配置:针对不同网络类型的预配置设置
  • 📊 性能调优:线程池与连接优化

📦 安装

前置要求

# Ensure Python 3.6+ is installed
python3 --version

# Install required dependencies
pip3 install paramiko pyyaml colorama

快速安装

# Clone the repository
git clone https://github.com/floriankostov/network_scanner.git
cd network_scanner

# Make executable (Unix/Linux/macOS)
chmod +x scanner.py

# Run the scanner
python3 scanner.py

Docker 安装(可选)

# Build Docker image
docker build -t network-scanner .

# Run in container
docker run -it --network host network-scanner

🔧 使用指南

🚀 快速上手

python3 scanner.py

扫描器提供直观的菜单系统:

╔══════════════════════════════════════════════════════════════════╗
║                    NETWORK SCANNER TOOLKIT                      ║
║                  Professional Penetration Testing               ║
╠══════════════════════════════════════════════════════════════════╣
║  1. 📡 Extended Port Scan    - Comprehensive port discovery     ║
║  2. ⚡ Basic Port Scan       - Quick essential port check       ║
║  3. 🔐 SSH Security Testing  - Advanced SSH vulnerability scan  ║
║  4. 🎯 Custom Target Scan    - Manual IP/range specification   ║
║  5. ❌ Exit                   - Quit the application            ║
╚══════════════════════════════════════════════════════════════════╝

🔍 网络发现

# Automatic network detection
[+] Network: 192.168.1.0/24 (254 hosts)
[+] Gateway: 192.168.1.1
[+] Local IP: 192.168.1.100

# Custom network specification
python3 scanner.py --network 10.0.0.0/16

🎯 SSH 漏洞利用能力

💬 用户名枚举(CVE-2018-15473)

# Standard enumeration
[EXPLOIT] CVE-2018-15473 Username Enumeration
[+] Target: 192.168.1.50:22 (OpenSSH 7.4)
[+] Testing 100 common usernames...
[✓] Valid users found: admin, user, test

# Stealth enumeration with evasion
[STEALTH] Enabling anti-detection measures
[+] Random delays: 0.5-2.0 seconds
[+] Connection variation: randomized
[✓] Valid users found: admin (confirmed)

🔑 高级暴力破解攻击

# Smart brute force
[EXPLOIT] Smart SSH Brute Force
[+] Target: 192.168.1.50:22
[+] Valid users: admin, user
[+] Wordlist: 500 common passwords
[✓] Credentials found: admin:password123

# Stealth brute force with fail2ban evasion
[STEALTH] Advanced evasion enabled
[+] Adaptive delays: 3-8 seconds
[+] Connection resets: every 5 attempts
[+] IP rotation: enabled
[!] Intrusion detection bypass: active

🛡️ 防御绕过功能

  • 时序随机化:0.1-10 秒之间的可变延迟
  • 连接管理:自动连接轮换以避免检测
  • 错误分析:智能处理 fail2ban 与 IDS 响应
  • 速率限制:根据目标响应自适应调整速度

🔧 高级配置

📝 配置文件(config.yaml)

# Network scanning settings
network:
  ping_timeout: 1.0
  port_timeout: 3.0
  thread_count: 50
  max_hosts: 254

# SSH exploitation settings
ssh:
  timeout: 10.0
  retry_count: 3
  stealth_mode: true
  delay_min: 0.5
  delay_max: 2.0
  
# Exploitation parameters
exploits:
  user_enumeration:
    max_users: 100
    timing_threshold: 0.05
  brute_force:
    max_attempts: 50
    wordlist_size: 500
    fail2ban_detection: true

🎯 自定义端口列表

port_lists:
  basic: [22, 80, 443, 8080]
  extended: [21, 22, 23, 25, 53, 80, 110, 143, 443, 993, 995, 8080]
  comprehensive: [1-1000, 3389, 5432, 5900, 8080-8090]

🛡️ 防御与修复

🔒 SSH 加固建议

立即执行的操作

# Disable root login
echo "PermitRootLogin no" >> /etc/ssh/sshd_config

# Require key-based authentication
echo "PasswordAuthentication no" >> /etc/ssh/sshd_config
echo "PubkeyAuthentication yes" >> /etc/ssh/sshd_config

# Change default port
echo "Port 2222" >> /etc/ssh/sshd_config

# Restart SSH service
systemctl restart sshd

长期安全措施

  1. 入侵检测:安装并配置 fail2ban
  2. 网络分段:使用防火墙规则隔离 SSH 访问
  3. 监控:实施 SSH 连接日志记录与告警
  4. 定期更新:通过安全补丁保持 SSH 软件最新
  5. 访问控制:使用 SSH 证书与集中式密钥管理

🚨 检测特征

需要监控的日志模式

# Username enumeration attempts
grep "Invalid user" /var/log/auth.log

# Brute force detection
grep "Failed password" /var/log/auth.log | head -10

# Connection frequency analysis
awk '{print $1, $2, $3, $11}' /var/log/auth.log | grep "sshd" | sort | uniq -c

Fail2ban 配置

[sshd]
enabled = true
port = ssh
filter = sshd
logpath = /var/log/auth.log
maxretry = 3
bantime = 3600
findtime = 600

🔬 技术深度解析

🎯 CVE-2018-15473 漏洞利用技术细节

漏洞概述

  • CVE 编号:CVE-2018-15473
  • 受影响版本:OpenSSH < 7.7、Cisco IOS 等
  • 影响:通过时序攻击进行用户名枚举
  • CVSS 评分:5.3(中危)

漏洞利用方法

  1. 时序分析:测量有效与无效用户名的响应时间差异
  2. 统计验证:多次采样以确认时序差异
  3. 规避技术:随机化延迟以避免检测
  4. 结果验证:与常见用户名模式交叉验证
# Simplified timing attack pseudocode
def enumerate_users(target, usernames):
    timings = {}
    for user in usernames:
        start = time.time()
        try_authentication(target, user, "invalid_password")
        end = time.time()
        timings[user] = end - start
    
    # Analyze timing patterns
    return analyze_timing_anomalies(timings)

🔍 反检测机制

隐蔽模式特性

  • 抖动引入:0.1-10 秒之间的随机延迟
  • 连接轮换:定期建立新连接
  • 请求间隔:根据目标响应自适应调整时序
  • 错误处理:优雅应对防御性措施

📊 扫描结果示例

下载工具