Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
freedomfighting — 一组脚本,在您的自由斗争活动中可能会派上用场。 | Kitploit
工具/GitHubGitHub/justicerage/freedomfighting
侦察加密/解密工具取证分析信息收集后渗透利用Web安全渗透测试红队网络爬虫远程访问工具日志分析
41868143年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
GitHub
justicerage/freedomfighting

freedomfighting

一组脚本,在您的自由斗争活动中可能会派上用场。

查看仓库

自由抗争脚本

此仓库包含一些在自由抗争活动中可能派上用场的脚本。它会偶尔更新,当我自己需要某些找不到在线资源的东西时。这里的所有内容均遵循 GPL v3 许可证 条款发布。

欢迎贡献和拉取请求。

目录

  • nojail.py,一个 Python 日志清理工具。
  • share.sh,一个安全文件共享脚本。
  • autojack.py,一个终端日志记录器。
  • listurl.py,一个站点映射器。
  • ersh.py,一个加密反向 Shell。
  • boot_check.py,一个检测邪恶女佣攻击的脚本。
  • notify_hook.py,一种在系统上调用某些二进制文件时触发警报的方式。
  • 杂项(联系与捐赠)

nojail.py

一个日志清理工具,用于删除以下位置中的有罪条目:

  • /var/run/utmp,/var/log/wtmp,/var/log/btmp(控制 who、w 和 last 命令的输出)
  • /var/log/lastlog(控制 lastlog 命令的输出)
  • /var/**/*.log(包括 .log.1、.log.2.gz 等)
  • 用户指定的任何其他文件或文件夹

删除基于 IP 地址和/或关联主机名的条目。

特别注意在篡改日志时避免破坏文件描述符。这意味着日志在被篡改后仍能继续写入,从而使清理工作更不易察觉。所有操作都在 tmpfs 驱动器中完成,创建的任何文件都会被安全擦除。

警告: 该脚本仅在 Linux 上测试过,无法在其他 Unix 变体上清理 UTMP 条目。

用法:```

usage: nojail.py [-h] [--user USER] [--ip IP] [--hostname HOSTNAME] [--verbose] [--check] [log_files [log_files ...]]

Stealthy log file cleaner.

positional arguments: log_files Specify any log files to clean in addition to /var/**/*.log.

optional arguments: -h, --help show this help message and exit --user USER, -u USER The username to remove from the connexion logs. --ip IP, -i IP The IP address to remove from the logs. --hostname HOSTNAME The hostname of the user to wipe. Defaults to the rDNS of the IP. --regexp REGEXP, -r REGEXP A regular expression to select log lines to delete (optional)

 --verbose, -v         Print debug messages.
 --check, -c           If present, the user will be asked to confirm each
                       deletion from the logs.
 --daemonize, -d       Start in the background and delete logs when the
                       current session terminates. Implies --self-delete.
 --self-delete, -s     Automatically delete the script after its execution.
默认情况下,如果没有提供参数,脚本将尝试根据 `SSH_CONNECTION` 环境变量确定要清除的 IP 地址。任何与该 IP 的反向 DNS 匹配的条目也将被移除。

#### 基本示例:```
./nojail.py --user root --ip 151.80.119.32 /etc/app/logs/access.log --check

...将移除所有root用户下IP地址为151.80.119.32或主机名为manalyzer.org的记录。由于使用了--check选项,在删除每条记录前会提示用户确认。最后,除了所有默认日志文件外,还会处理文件/etc/app/logs/access.log。

如果以位置参数形式指定了文件夹(例如/etc/app/logs/),脚本会递归遍历这些文件夹并清理所有扩展名为.log的文件(包括*.log.1、*.log.2.gz等)。

正则表达式

您可能还希望从日志文件中移除任意行。为此,请使用--regexp选项。例如,以下命令行将查找从指定IP发往PHP文件的所有POST请求:``` ./nojail.py --ip 151.80.119.32 --regexp "POST /.*?.php"

#### 脚本守护进程化```
./nojail.py --daemonize

假设这是通过 SSH 连接运行的,该命令将在连接关闭后立即删除与当前用户活动相关的所有日志(包括检测到的 IP 地址和主机名)。随后,该脚本将自动删除自身。 请注意,您将无法收到来自应用程序的任何错误消息。建议您在生成守护进程之前先尝试删除一次日志,以确保指定的参数正确。 如果您处于没有 TTY 的 shell 中,脚本将无法检测会话何时结束。您会收到通知,告知日志将在 60 秒后被删除,并且您应该在此之前注销(否则可能会在脚本运行后创建更多条目)。

示例输出:```

root@proxy:~# ./nojail.py [ ] Cleaning logs for root (XXX.XXX.XXX.XXX - domain.com). [] 2 entries removed from /var/run/utmp! [] 4 entries removed from /var/log/wtmp! [ ] No entries to remove from /var/log/btmp. [] Lastlog set to 2017-01-09 17:12:49 from pts/0 at lns-bzn-XXX-XXX-XXX-XXX-XXX.adsl.proxad.net [] 4 lines removed from /var/log/nginx/error.log! [] 11 lines removed from /var/log/nginx/access.log! [] 4 lines removed from /var/log/auth.log!

### 免责声明
此脚本不提供任何保证。
如果它没有清除你不应该做的某些事情的痕迹,不要责怪我。

## share.sh

一个便携且安全的文件共享脚本。在自由斗争中,通常无法将文件通过scp传入被入侵的机器。需要其他上传文件的方式,但大多数共享服务要么限制太多,要么不提供从命令行轻松检索文件的方法。安全方面的考虑也可能阻止人们将敏感文件上传到云服务提供商,担心他们会永久保留副本。

这个小巧便携的bash脚本依赖[transfer.sh](https://transfer.sh)来解决这个问题。它...
* 在上传前加密文件(对称AES-256-CBC)。
* 如果系统上存在`torify`,则自动使用它来增加匿名性。

唯一需要的依赖是`openssl`以及`curl`或`wget`。

### 使用```
root@proxy:~# ./share.sh ~/file_to_share "My_Secure_Encryption_Key!"
Success! Retrieval command: ./share.sh -r file_to_share "My_Secure_Encryption_Key!" https://transfer.sh/BQPFz/28239
root@proxy:~# ./share.sh -r file_to_share "My_Secure_Encryption_Key!" https://transfer.sh/BQPFz/28239
File retrieved successfully!

Additional arguments during the upload allow you to control the maximum number of downloads allowed for the file (-m)
and how many days transfer.sh will keep it (-d). The default value for both these options is 1.

Warning: Do not use spaces in the encryption key, or only the first word of your passphrase will be taken into
account. This is due to the way getopts handles arguments (I think). Pull requests are welcome if anyone is interested in
fixing this.

autojack.py

AutoJack 是一个简短的脚本,利用 EmptyMonkey 的 shelljack 来记录
任何通过 SSH 连接的用户的终端。它监视 auth.log 中的成功连接,找出用户 bash 进程的 PID,
并将其余工作交由 shelljack 处理。shelljack.

Launch it in a screen, and wait until other users log-in. Their session will be logged to /root/.local/sj.log.[user].[timestamp].

The script is not particularly stealthy (no attempt is made to hide the shelljack process) but it will get the job done. Note that to avoid self-incrimination, the root user is not targeted (this can be trivially commented out in the code).

listurl.py

ListURL is a multi-threaded website crawler which obtains a list of available pages from the target. This script is useful for bug-bounty hunters trying to establish the attack surface of a web application.

usage: listurl.py [-h] [--max-depth MAX_DEPTH] [--threads THREADS] [--url URL]
                  [--external] [--subdomains] [-c COOKIE]
                  [--exclude-regexp EXCLUDE_REGEXP]
                  [--show-regexp SHOW_REGEXP] [--verbose]

通过递归抓取所有URL来映射网站。
下载工具