Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
Inveigh — .NET IPv4/IPv6 中间人攻击工具,用于渗透测试人员 | Kitploit
工具/GitHubGitHub/kevin-robertson/inveigh
渗透测试红队
GitHubkevin-robertson/inveigh

Inveigh

.NET IPv4/IPv6 中间人攻击工具,用于渗透测试人员

查看仓库
3.0k4721210个月前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

Inveigh

Inveigh 是一款面向渗透测试人员的跨平台 .NET IPv4/IPv6 中间人工具。此仓库包含主要的 C# 版本以及旧版 PowerShell 版本。

概述

Inveigh 通过数据包嗅探和基于协议特定的监听器/套接字来执行欺骗攻击以及哈希/凭据捕获。数据包嗅探方法(最初版本 PowerShell 版工具的基础)具有以下优势:

  • 通过 Windows SMB 服务捕获 SMB NTLM 挑战/响应
  • 主机系统上可见端口绑定更少

主要缺点是需要提升的访问权限。

在当今版本的 Windows 上,默认运行的 UDP 服务允许端口复用。因此,数据包嗅探不再具有绕过正在使用的 UDP 端口的优势。Inveigh 的所有 UDP 监听器均配置为利用端口复用。

版本说明

  • PowerShell Inveigh - 经多年开发的原始版本。目前(至少暂时),此版本(1.506)将不再进行额外更新。文档可在此处找到。
  • C# Inveigh(又名 InveighZero) - 原始 C# POC 代码与 PowerShell 版本大部分代码的 C# 移植版相结合。此版本现已为 C# 重建,并逐渐成为主要版本。

功能特性

C# 版本的 Inveigh 包含以下协议的攻击功能:

  • LLMNR [数据包嗅探 | 监听器]
  • DNS [数据包嗅探 | 监听器]
  • mDNS [数据包嗅探 | 监听器]
  • NBNS [数据包嗅探 | 监听器]
  • DHCPv6 [数据包嗅探 | 监听器]
  • ICMPv6 [特权原始套接字]
  • HTTP [监听器]
  • HTTPS [监听器]
  • SMB [数据包嗅探 | 监听器]
  • LDAP [监听器]
  • WebDAV [监听器]
  • 代理认证 [监听器]

在底层协议同时支持 IPv4 和 IPv6 的情况下,Inveigh 同样兼容这两种协议。

跨平台支持

Inveigh 的 SDK 风格项目文件设置为支持 .NET 3.5、4.6.2 和 6.0,其中 6.0 版本也适用于 Linux 和 macOS。

<TargetFrameworks>net35;net62;net6.0</TargetFrameworks>

已知问题

  • 由于原始套接字设置的差异,数据包嗅探器仅在 Windows 上可用。当为 Linux 或 macOS 编译时,数据包嗅探器将被禁用。此时,如果端口 445 处于开放状态,可使用 Inveigh 的 SMB 监听器。
  • macOS 需要存在用于加入多播组的路由。在我的测试中,必须为 DHCPv6 多播添加路由才能在此平台上执行该攻击。 sudo route -nv add -net ff02::1:2 -interface en0

执行

dotnet Inveigh.dll

Linux/macOS 平台定向构建

  • 目标系统已安装 .NET 6.0 时 dotnet publish -r linux-x64 -f net8.0 -p:AssemblyName=inveigh dotnet publish -r osx-x64 -f net8.0 -p:AssemblyName=inveigh

  • 目标系统未安装 .NET 6.0 时 dotnet publish --self-contained=true -p:PublishSingleFile=true -r linux-x64 -f net8.0 -p:AssemblyName=inveigh dotnet publish --self-contained=true -p:PublishSingleFile=true -r osx-x64 -f net8.0 -p:AssemblyName=inveigh

使用方法

默认参数值位于 Program.cs 开头。我建议在编译前查看所有内容并根据需要进行设置。所有启用/禁用参数均可设置为 Y/N 值。``` //begin parameters - set defaults as needed before compile public static string argCert = "MIIKaQIBAzCCC..." public static string argCertPassword = "password"; public static string argChallenge = ""; public static string argConsole = "5"; public static string argConsoleLimit = "-1"; public static string argConsoleStatus = "0"; public static string argConsoleUnique = "Y"; public static string argDHCPv6 = "N"; public static string argDHCPv6TTL = "30"; public static string argDNS = "Y"; ... //end parameters

### 参数帮助```
.\Inveigh.exe -?

Control:

  -Inspect        Default=Disabled: (Y/N) inspect traffic only.

  -IPv4           Default=Enabled: (Y/N) IPv4 spoofing/capture.

  -IPv6           Default=Enabled: (Y/N) IPv6 spoofing/capture.

  -RunCount       Default=Unlimited: Number of NetNTLM captures to perform before auto-exiting.

  -RunTime        Default=Unlimited: Run time duration in minutes.


Output:

  -Console        Default=5: Set the level for console output. (0=none, 1=only captures/spoofs, 2=no disabled, no informational, 3=no disabled, no filtered, 4=no disabled, 5=all)  

  -ConsoleLimit   Default=Unlimited: Limit to queued console entries.

  -ConsoleStatus  Default=Disabled: Interval in minutes for auto-displaying capture details.

  -ConsoleUnique  Default=Enabled: (Y/N) displaying only unique (user and system combination) hashes at time of capture.

  -FileDirectory  Default=Working Directory: Valid path to an output directory for enabled file output.

  -FileOutput     Default=Enabled: (Y/N) real time file output.

  -FilePrefix     Default=Inveigh: Prefix for all output files.

  -FileUnique     Default=Enabled: (Y/N) outputting only unique (user and system combination) hashes.

  -LogOutput      Default=Disabled: (Y/N) outputting log entries.


Spoofers:

  -DHCPV6         Default=Disabled: (Y/N) DHCPv6 spoofing.

  -DHCPv6TTL      Default=300: Lease lifetime in seconds.

  -DNS            Default=Enabled: (Y/N) DNS spoofing.

  -DNSHost        Fully qualified hostname to use SOA/SRV responses.

  -DNSSRV         Default=LDAP: Comma separated list of SRV request services to answer.

  -DNSSuffix      DNS search suffix to include in DHCPv6/ICMPv6 responses.

  -DNSTTL         Default=30: DNS TTL in seconds.

  -DNSTYPES       Default=A: (A, AAAA, SOA, SRV) Comma separated list of DNS types to spoof.

  -ICMPv6         Default=Enabled: (Y/N) sending ICMPv6 router advertisements.

  -ICMPv6Interval Default=200: ICMPv6 RA interval in seconds.
  
  -ICMPv6TTL	  Default=300: ICMPv6 TTL in seconds.

  -IgnoreDomains  Default=None: Comma separated list of domains to ignore when spoofing.



  -IgnoreIPs      Default=Local: Comma separated list of source IP addresses to ignore when spoofing.

  -IgnoreMACs     Default=Local: Comma separated list of MAC addresses to ignore when DHCPv6 spoofing.
  
  -IgnoreQueries  Default=None: Comma separated list of name queries to ignore when spoofing.

  -Local          Default=Disabled: (Y/N) performing spoofing attacks against the host system.

  -LLMNR          Default=Enabled: (Y/N) LLMNR spoofing.

  -LLMNRTTL       Default=30: LLMNR TTL in seconds.

  -MAC            Local MAC address for DHCPv6.

  -MDNS           Default=Enabled: (Y/N) mDNS spoofing.

  -MDNSQuestions  Default=QU,QM: Comma separated list of question types to spoof. (QU,QM)

  -MDNSTTL        Default=120: mDNS TTL in seconds.

  -MDNSTypes      Default=A: Comma separated list of mDNS record types to spoof. (A,AAAA,ANY)

  -MDNSUnicast    Default=Enabled: (Y/N) sending a unicast only response to a QM request.

  -NBNS           Default=Disabled: (Y/N) NBNS spoofing.

  -NBNSTTL        Default=165: NBNS TTL in seconds.

  -NBNSTypes      Default=00,20: Comma separated list of NBNS types to spoof. (00,03,20,1B)

  -ReplyToDomains Default=All: Comma separated list of domains to respond to when spoofing.

  -ReplyToIPs     Default=All: Comma separated list of source IP addresses to respond to when spoofing.

  -ReplyToMACs    Default=All: Comma separated list of MAC addresses to respond to when DHCPv6 spoofing.
  
  -ReplyToQueries Default=All: Comma separated list of name queries to respond to when spoofing.

  -SpooferIP      Default=Autoassign: IP address included in spoofing responses.

  -SpooferIPv6    Default=Autoassign: IPv6 address included in spoofing responses.

  -Repeat         Default=Enabled: (Y/N) repeated spoofing attacks against a system after NetNTLM capture.


Capture:

  -Cert           Base64 certificate for TLS.

  -CertPassword   Base64 certificate password for TLS.

  -Challenge      Default=Random per request: 16 character hex NetNTLM challenge for use with the TCP listeners.

  -HTTP           Default=Enabled: (Y/N) HTTP listener.

  -HTTPAuth       Default=NTLM: (Anonymous/Basic/NTLM) HTTP/HTTPS listener authentication.

  -HTTPPorts      Default=80: Comma seperated list of TCP ports for the HTTP listener.

  -HTTPRealm      Default=ADFS: Basic authentication realm.

  -HTTPResponse   Content to serve as the default HTTP/HTTPS/Proxy response.

  -HTTPS          Default=Enabled: (Y/N) HTTPS listener.

  -HTTPSPorts     Default=443: Comma separated list of TCP ports for the HTTPS listener.

  -IgnoreAgents   Default=Firefox: Comma separated list of HTTP user agents to ignore with wpad and proxy auth.

  -LDAP           Default=Enabled: (Y/N) LDAP listener.

  -LDAPPorts      Default=389: Comma separated list of TCP ports for the LDAP listener.

  -ListenerIP     Default=Any: IP address for all listeners.

  -ListenerIPv6   Default=Any: IPv6 address for all listeners.

  -MachineAccount Default=Enabled: (Y/N) machine account NetNTLM captures.

  -Proxy          Default=Disabled: (Y/N) proxy listener authentication captures.

  -ProxyAuth      Default=NTLM: (Basic/NTLM) Proxy authentication.

  -ProxyPort      Default=8492: Port for the proxy listener.

  -SMB            Default=Enabled: (Y/N) SMB sniffer/listener.
下载工具