Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
AutoDirbuster — 自动运行并保存针对多个IP的ffuf扫描 | Kitploit
工具/GitHubGitHub/netspi/autodirbuster
侦察Web漏洞扫描器脚本与自动化信息收集Web安全
GitHubnetspi/autodirbuster

AutoDirbuster

自动运行并保存针对多个IP的ffuf扫描

查看仓库
8226123个月前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

                    /   | __  __/ /_____  / __ \(_)____/ /_  __  _______/ /____  _____
                   / /| |/ / / / __/ __ \/ / / / / ___/ __ \/ / / / ___/ __/ _ \/ ___/
                  / ___ / /_/ / /_/ /_/ / /_/ / / /  / /_/ / /_/ (__  ) /_/  __/ /
                 /_/  |_\__,_/\__/\____/_____/_/_/  /_.___/\__,_/____/\__/\___/_/

### 自动运行并保存多个IP的ffuf扫描结果

## 目录
  * [快速运行](#quick-run)
  * [常见问题](#faq)
    * [为什么?](#why)
    * [推荐用法?](#what-is-the-recommended-usage)
    * [需要什么数据?](#what-data-does-this-need)
    * [这个脚本如何工作?](#how-does-this-script-work)
    * [程序无法工作](#this-program-isnt-working)
  * [使用](#usage)

## 快速运行

git clone https://github.com/NetSPI/AutoDirbuster.git cd AutoDirbuster && pip3 install -r requirements.txt python AutoDirbuster.py ip_port_list.txt -w my_wordlist.txt


## 常见问题
### 为什么?
Ffuf 是一个很棒的目录爆破工具,但针对多个IP和端口运行它是一个非常手动化的过程,扫描之间会有大量空档时间。本脚本尝试自动化该过程,并消除扫描之间的空档时间。

### 推荐用法?
**如果是攻击多个目标:**
* 运行Nmap并查找开放端口
* 查看Nmap结果,创建一个IP:port列表,每行一个
* 对开放端口运行AutoDirbuster
* AutoDirbuster将判断服务是否基于HTTP

  * `python AutoDirbuster.py ip_port_list.txt -w my_wordlist.txt --combine`

**如果是攻击单个目标:**

* `python AutoDirbuster.py -u example.com:80 -w my_wordlist.txt`

**有用的选项包括:**

| 选项          | 用途                                                               |
|-----------------|-------------------------------------------------------------------|
| --dns           | 将IP解析为主机名                                                  |
| --extensions    | 扫描时使用的文件扩展名                                            |
| --rate          | 每秒请求速率                                                      |
| --timeout       | 为每个主机设置超时值(分钟)                                      |
| --match-codes   | 匹配提供的HTTP状态码                                              |
| --combine       | 扫描后将所有CSV结果合并到一个文件中                               |
| --quiet         | 抑制ffuf的stderr输出(等效于2>/dev/null)                         |
| --custom-option | 指定AutoDirbuster默认不支持的ffuf选项                             |

指定`--help`标志以获取完整选项列表。

### 需要什么数据?
程序可以接受两个数据源:
1. IP:port或hostname:port的列表,每行一个

* `python AutoDirbuster.py ip_port_list.txt -w my_wordlist.txt`

2. 单个目标

* `python AutoDirbuster.py -u example.com:80 -w my_wordlist.txt`

### 这个脚本如何工作?
* 提供一个目标列表
* 发送HTTPS和HTTP请求,以判断服务是否基于HTTP以及是否需要TLS(HTTP请求本身作为连通性检查——无需单独进行TCP端口扫描)
* 如果HTTPS因TLS协商错误失败,则在回退到普通HTTP之前尝试宽松的TLS上下文
* 如果服务是HTTP,则检查同一目录中是否存在之前的报告文件
  * 报告文件的格式为:`ffuf-report-{proto}_{target}_{port}`
* 使用Python的`subprocess.Popen()`运行ffuf
* 下一个IP:port经历相同的流程(HTTP服务查询,目录爆破)

### 程序无法工作
请确保以下事项:
* 是否已安装`requirements.txt`中列出的所有依赖项?
* `ffuf`是否已安装并在系统路径中?
  * 尝试运行`ffuf -V`
  * 安装说明可在[ffuf GitHub仓库页面](https://github.com/ffuf/ffuf)找到
* 您可能需要使用Python 3.11+
  * 版本信息可通过运行`python -V`获取

## 使用

python AutoDirbuster.py --help

usage: ___ __ ____ _ __ __ / | __ / /___ / __ ()/ / __ / / _____ / /| |/ / / / __/ __ / / / / / __/ __ / / / / __/ __/ _ / __/ / ___ / // / // // / // / / / / // / // ( ) // __/ / // |_,/_/_/_____/// /./_,//_/___/_/

AutoDirbuster.py [options] {target file}

Automatically run and save ffuf scans for multiple IPs

options: -h, --help show this help message and exit

AutoDirbuster options: target Target file with IP:port, one per line -u, --url Single target mode, positional argument is target in IP:port format -f, --force Force mode; don't check if report file exists, this will result in previous reports being overwritten --dns Automatically resolve IP address to hostname to use during dirbust --debug Show debugging information --combine Combine all CSV results into a single file after scanning --quiet Suppress ffuf's stderr output (equivalent of 2>/dev/null); AutoDirbuster's own output and ffuf stdout are unaffected

ffuf options: -w WORDLIST, --wordlist WORDLIST Wordlist to use for list based brute force -X METHOD, --method METHOD HTTP method to use; default=GET -e EXTENSIONS, --extensions EXTENSIONS File extension list (e.g.: "asp,aspx"); default is None -t THREADS, --threads THREADS Override the default number of ffuf threads --rate RATE Rate of requests per second -to TIMEOUT, --timeout TIMEOUT Set a timeout value for each host in minutes; default is None -fr, --follow-redirects Follow redirects; default is False -r, --recursive Recursive mode; default is False -s STARTPOINT, --startpoint STARTPOINT Start point of the scan; default=/ -of OUTPUT_FORMAT, --output-format OUTPUT_FORMAT Output format to write results to; default=csv -mc MATCH_CODES, --match-codes MATCH_CODES Match HTTP status codes; default=200,204,301,302,307,401,403,405,500 -nac, --no-auto-calibrate Do not automatically calibrate filtering options -H HEADER, --header HEADER HTTP header "Name: Value", separated by colon --custom-option CUSTOM_OPTION [CUSTOM_OPTION ...] Specify ffuf option that AutoDirbuster doesn't support by default. Argument should be a key/value pair separated by a comma with no leading '-', example: --custom-option=ml,1. If the provided argument is a boolean, provide an empty value: --custom-option=sa,

Examples: python AutoDirbuster.py ip_port_list.txt -w my_wordlist.txt python AutoDirbuster.py -st example.com:80 -w my_wordlist.txt -mc 200,500 python AutoDirbuster.py ip_port_list.txt -w my_wordlist.txt -r -e "php,html" --dns

下载工具