Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
nemesis — 一个命令行网络数据包构造与注入工具 | Kitploit
工具/GitHubGitHub/libnet/nemesis
数据包嗅探与分析漏洞利用模糊测试网络安全渗透测试
GitHublibnet/nemesis

nemesis

一个命令行网络数据包构造与注入工具

查看仓库
52574293年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
网站

N E M E S I S - 构建与注入

License Badge GitHub Status Coverity Status

Nemesis 项目旨在为类 UNIX 和 Windows 系统提供一个基于命令行的、可移植的人类 IP 栈。该套件按协议分类,允许通过简单的 shell 脚本对注入的数据包进行有用的脚本化处理。

最新版本始终可在 GitHub 上获取:

https://github.com/libnet/nemesis/releases

主要特点

  • 支持 ARP/RARP、DNS、ETHERNET、ICMP、IGMP、IP、OSPF、RIP、TCP 和 UDP 协议
  • 在类 UNIX 系统上进行第 2 层或第 3 层注入
  • 在 Windows 系统上仅支持第 2 层注入
  • 数据包负载可从文件读取
  • IP 和 TCP 选项可从文件读取
  • 已在 OpenBSD、Linux、Solaris、Mac OS X 和 Windows 2000 上测试

每个支持的协议都使用自己的协议“注入器”,并附有说明其功能的 man 手册页。

有关发布详情,请参阅 ChangeLog;有关可用功能的深入描述,请参阅每个协议注入器的文档。

示例

  • 注入畸形的 ICMP 重定向

    root@kitploit:~
      sudo nemesis icmp -S 10.10.10.3 -D 10.10.10.1 -G 10.10.10.3 -i 5
    
  • DHCP 发现(必须使用 sudo 和 -d 以源 IP 0.0.0.0 发送):

    root@kitploit:~
      sudo nemesis dhcp -d eth0
    
  • IGMP v2 加入组 239.186.39.5

    root@kitploit:~
      sudo nemesis igmp -v -p 22 -S 192.168.1.20 -g 239.186.39.5 -D 239.186.39.5
    
  • IGMP v2 查询,最大响应时间 10 秒,带路由器警报 IP 选项

    root@kitploit:~
      echo -ne '\x94\x04\x00\x00' >RA
      sudo nemesis igmp -v -p 0x11 -c 100 -D 224.0.0.1 -O RA
    

    或

    root@kitploit:~
      echo -ne '\x94\x04\x00\x00' | sudo nemesis igmp -v -p 0x11 -c 100 -D 224.0.0.1 -O -
    
  • IGMP v3 查询,带路由器警报 IP 选项

    root@kitploit:~
      echo -ne '\x03\x64\x00\x00' > v3
      sudo nemesis igmp -p 0x11 -c 100 -i 0.0.0.0 -P v3 -D 224.0.0.1 -O RA
    
  • 随机 TCP 数据包

    root@kitploit:~
      sudo nemesis tcp
    
  • DoS 和 DDoS 测试

    root@kitploit:~
      sudo nemesis tcp -v -S 192.168.1.1 -D 192.168.2.2 -fSA -y 22 -P foo
      sudo nemesis udp -v -S 10.11.12.13 -D 10.1.1.2 -x 11111 -y 53 -P bindpkt
      sudo nemesis icmp redirect -S 10.10.10.3 -D 10.10.10.1 -G 10.10.10.3 -qR
      sudo nemesis arp -v -d eth0 -H 0:1:2:3:4:5 -S 10.11.30.5 -D 10.10.15.1
    

构建与安装

Nemesis 基于 libnet 构建。Windows 平台构建还需要 libpcap。Nemesis <= 1.4 基于 libnet 1.0 构建,Nemesis >= 1.5 需要 libnet 1.1 或更高版本。

Debian/Ubuntu

root@kitploit:~
curl -sS https://deb.troglobit.com/pubkey.gpg | sudo apt-key add -
echo "deb [arch=amd64] https://deb.troglobit.com/debian stable main" | sudo tee /etc/apt/sources.list.d/troglobit.list
sudo apt-get update && sudo apt-get install nemesis

从源码构建

在 Debian 和 Ubuntu 衍生的 GNU/Linux 系统上:

root@kitploit:~
sudo apt install libnet1-dev

这会将 libnet 头文件和库安装到标准位置,configure 脚本可以轻松找到。如果您的 libnet1 安装位于非标准位置,可以通过如下方式指定路径:

root@kitploit:~
configure LDFLAGS=-L/path/to/lib CPPFLAGS=-I/path/to/header

GNU 配置与构建 系统默认使用 /usr/local 作为安装前缀。通常这已经足够,下面的示例改为安装到 /usr:

root@kitploit:~
tar xf nemesis-1.7.tar.xz
cd nemesis-1.7/
./configure --prefix=/usr
make -j5
sudo make install-strip

在 Windows 上安装

nemesis.exe 可以安装在 Windows 系统的任意位置。但需要注意的是,LibnetNT.dll 必须与 nemesis.exe 位于同一目录,或者位于 %PATH% 变量列出的任意目录中。在 Windows 2000 上,这指的是 %SystemRoot%\System32

注意: Windows 版本已有十多年未经验证。请谨慎使用。

从 GIT 构建

如果您想贡献代码,或者只是想尝鲜尚未发布的最新特性,那么您需要了解一些关于 GNU 配置与构建 系统的知识:

  • configure.ac 和每个目录下的 Makefile.am 是关键文件
  • configure 和 Makefile.in 由 autogen.sh 生成,它们不存储在 GIT 中,而是为发布 tarball 自动生成的
  • Makefile 由 configure 脚本生成

要从 GIT 构建,您首先需要克隆仓库并运行 autogen.sh 脚本。这需要您的系统上安装了 automake 和 autoconf。

root@kitploit:~
git clone https://github.com/libnet/nemesis.git
cd nemesis/
./autogen.sh
./configure && make

GIT 源码是移动目标,不建议用于生产系统,除非您清楚自己在做什么!

起源与参考

  • 1999 年:Nemesis 由 Mark Grimes 创建
  • 2001 年:Jeff Nathan 接手维护
  • 2018 年:项目由 Joachim Nilsson 复活

该项目目前托管在 GitHub,旨在作为新开发的焦点。如果您有补丁和/或想法,请通过问题跟踪器或拉取请求提交。

下载工具