Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
naabu — 一款用Go编写的快速端口扫描器,注重可靠性和简洁性。设计用于与其他工具组合使用,在漏洞赏金和渗透测试中探索攻击面。 | Kitploit
工具/GitHubGitHub/projectdiscovery/naabu
侦察网络映射端口扫描脚本与自动化信息收集渗透测试信息收集 分类第 9 名网络映射 分类第 5 名端口扫描 分类第 5 名侦察 分类第 7 名
6.2k710521天前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
脚本与自动化 分类第 5 名
GitHubprojectdiscovery/naabu

naabu

一款用Go编写的快速端口扫描器,注重可靠性和简洁性。设计用于与其他工具组合使用,在漏洞赏金和渗透测试中探索攻击面。

查看仓库网站

naabu

许可证-MIT 欢迎贡献 Go报告卡 发布 推特关注 Discord

功能 • 安装 • 使用 • 运行naabu • 配置 • NMAP集成 • CDN/WAF排除 • Discord

Naabu 是一款用 Go 编写的端口扫描工具,能够以快速且可靠的方式枚举主机的有效端口。它是一款非常简单的工具,可对主机/主机列表执行快速的 SYN/CONNECT/UDP 扫描,并列出所有返回响应的端口。

功能

naabu

  • 快速简单的基于 SYN/CONNECT/UDP 探测的扫描
  • 针对易用性和轻量级资源消耗进行了优化
  • DNS 端口扫描
  • 自动 IP 去重(针对 DNS 端口扫描)
  • IPv4/IPv6 端口扫描(实验性)
  • 使用 Shodan Internetdb 的被动端口枚举
  • 主机发现扫描(实验性)
  • 集成 NMAP 进行服务发现
  • 针对 CONNECT 扫描的自定义 UDP 载荷
  • 由 nmap-service-probes 驱动的原生 UDP 服务探测
  • 多种输入支持 - STDIN/主机/IP/CIDR/ASN
  • 多种输出格式支持 - JSON/TXT/STDOUT

使用```sh

naabu -h

这将显示该工具的帮助信息。以下是它支持的所有开关选项。```yaml
Usage:
  naabu [flags]

Flags:
INPUT:
   -host string[]              hosts to scan ports for (comma-separated)
   -list, -l string            list of hosts to scan ports (file)
   -exclude-hosts, -eh string  hosts to exclude from the scan (comma-separated)
   -exclude-file, -ef string   list of hosts to exclude from scan (file)

PORT:
   -port, -p string            ports to scan (80,443, 100-200)
   -top-ports, -tp string      top ports to scan (default 100) [full,100,1000]
   -exclude-ports, -ep string  ports to exclude from scan (comma-separated)
   -ports-file, -pf string     list of ports to scan (file)
   -port-threshold, -pts int   port threshold to skip port scan for the host
   -exclude-cdn, -ec           skip full port scans for CDN/WAF (only scan for port 80,443)
   -display-cdn, -cdn          display cdn in use

RATE-LIMIT:
   -c int     general internal worker threads (default 25)
   -rate int  packets to send per second (default 1000)

UPDATE:
   -up, -update                 update naabu to latest version
   -duc, -disable-update-check  disable automatic naabu update check

OUTPUT:
   -o, -output string  file to write output to (optional)
   -j, -json           write output in JSON lines format
   -csv                write output in csv format

SERVICES-DISCOVERY:
   -sD, -service-discovery           identify services by port number
   -sV, -service-version             detect service versions using nmap-service-probes
   -sV-fast                          only probe port-hinted services (faster, skips fallback)
   -sV-timeout duration              timeout for service version probes (default 5s)
   -sV-workers int                   number of concurrent service version workers (default 25)
   -sV-probes string                 custom nmap-service-probes file path (auto-detected from local nmap install if empty)
   -uP, -udp-probes                  send protocol-specific payloads on UDP scans using nmap-service-probes

CONFIGURATION:
   -config string                   path to the naabu configuration file (default $HOME/.config/naabu/config.yaml)
   -scan-all-ips, -sa               scan all the IP's associated with DNS record
   -ip-version, -iv string[]        ip version to scan of hostname (4,6) - (default 4,6) (default ["4","6"])
   -scan-type, -s string            type of port scan (SYN/CONNECT) (default "c")
   -source-ip string                source ip and port (x.x.x.x:yyy - might not work on OSX) 
   -cp, -connect-payload string    payload to send in CONNECT scans (optional)
   -interface-list, -il             list available interfaces and public ip
   -interface, -i string            network Interface to use for port scan
   -nmap                            invoke nmap scan on targets (nmap must be installed) - Deprecated
   -nmap-cli string                 nmap command to run on found results (example: -nmap-cli 'nmap -sV')
   -r string                        list of custom resolver dns resolution (comma separated or from file)
   -proxy string                    socks5 proxy (ip[:port] / fqdn[:port]
   -proxy-auth string               socks5 proxy authentication (username:password)
   -dns-order string                dns resolution order (p/l/lp/pl) (default "l")
   -sr, -system-resolver            use system DNS as fallback resolver
   -resume                          resume scan using resume.cfg
   -stream                          stream mode (disables resume, nmap, verify, retries, shuffling, etc)
   -passive                         display passive open ports using shodan internetdb api (automatically enables stream mode)
   -irt, -input-read-timeout value  timeout on input read (default 3m0s)
   -no-stdin                        Disable Stdin processing

HOST-DISCOVERY:
   -sn, -host-discovery           Perform Only Host Discovery
   -show-dead                     show hosts that did not respond to host discovery (requires host discovery)
   -Pn, -skip-host-discovery      Skip Host discovery (Deprecated: use -wn/-with-host-discovery instead)
   -wn, -with-host-discovery      Enable Host discovery
   -ps, -probe-tcp-syn string[]   TCP SYN Ping (host discovery needs to be enabled)
   -pa, -probe-tcp-ack string[]   TCP ACK Ping (host discovery needs to be enabled)
   -pe, -probe-icmp-echo          ICMP echo request Ping (host discovery needs to be enabled)
   -pp, -probe-icmp-timestamp     ICMP timestamp request Ping (host discovery needs to be enabled)
   -pm, -probe-icmp-address-mask  ICMP address mask request Ping (host discovery needs to be enabled)
   -arp, -arp-ping                ARP ping (host discovery needs to be enabled)
   -nd, -nd-ping                  IPv6 Neighbor Discovery (host discovery needs to be enabled)
   -rev-ptr                       Reverse PTR lookup for input ips

OPTIMIZATION:
   -retries int                    number of retries for the port scan (default 3)
   -timeout int                    millisecond to wait before timing out (default 1000)
   -warm-up-time int               time in seconds between scan phases (default 2)
   -ping                           ping probes for verification of host
   -verify                         validate the ports again with TCP verification
   -ss, -smart-scan                predictive port scanning using port correlation model (not compatible with stream mode)
   -pt, -prediction-threshold int  minimum confidence for port predictions (0-100%) (default 20)
下载工具