Ronin 是一个用于安全研究与开发的免费开源 Ruby 工具包。Ronin 还允许通过第三方 Git 仓库快速开发和分发代码、漏洞利用、有效载荷等。
[Ronin][website] 是一个免费且开源的 [Ruby] 工具包,用于安全研究和开发。Ronin 包含许多不同的 CLI 命令 和 [Ruby 库][ronin-rb],用于处理各种安全任务,例如编码/解码数据、过滤 IP/主机/URL、查询 ASN、查询 DNS、HTTP、[扫描 Web 漏洞][ronin-vulns-synopsis]、[爬取网站][ronin-web-spider]、[安装第三方仓库][ronin-repos-synopsis] 中的 [漏洞利用][ronin-exploits] 和/或 [有效载荷][ronin-payloads]、[运行漏洞利用][ronin-exploits-synopsis]、[开发新的漏洞利用][ronin-exploits-examples]、[管理本地数据库][ronin-db-synopsis]、[模糊测试数据][ronin-fuzzer]、[进行侦察][ronin-recon-synopsis] 等。
ronin 命令快速处理和查询各种数据。ronin irb Ruby REPL 中高效处理代码和数据。ronin 库快速原型化 Ruby 脚本。Usage: ronin [options] [COMMAND [ARGS...]]
Options: -h, --help Print help information
Arguments: [COMMAND] The command name to run [ARGS ...] Additional arguments for the command
Commands: archive asn banner-grab bitflip cert-dump cert-gen cert-grab completion decode, dec decrypt dns dns-proxy email-addr encode, enc encrypt entropy escape extract grep help hexdump highlight hmac homoglyph host http ip iprange irb md5 netcat, nc new pack proxy public-suffix-list quote rot sha1 sha256 sha512 strings tld-list tips typo typosquat unarchive unescape unhexdump unpack unquote url xor
Additional Ronin Commands: $ ronin-repos $ ronin-wordlists $ ronin-db $ ronin-web $ ronin-fuzzer $ ronin-masscan $ ronin-nmap $ ronin-recon $ ronin-payloads $ ronin-exploits $ ronin-vulns $ ronin-app
列出 ronin 命令:```shell
$ ronin help
查看命令的手册页:```shell $ ronin help COMMAND
获取使用 `ronin` 的随机提示:```shell
$ ronin tips
打开 Ronin Ruby REPL:```
$ ronin irb
, Jµ ▓▓█▓
J▌ ▐▓██▌ ████ ██ ▐███D
╓▄▓▓█████▌ ██µ ████ ▄███ÖJ██▌ ███▌
,╓µ▄▄▄▄▄▄▄▄µ;, ,▄▓██████████ ▐███ ▐███▀ ███▌ ████µ ▄███
¬∞MÆ▓███████████████████████▓M ▄██████▀▀╙████▌ ████▌ ████ ▄███ J█████ ███▌
█████▀▀▀▀▀███████ -████▀└ ████ ▐█████n ▄███O ███▌ ██████████ ▓████L ████▀ ▓████ ▓███Ö ███████ ███▌ ▓███ ▐█████████▀ ▄████▀ ,╓▄▄▄█████ J████Ü ,███▌ ▄███████████ J███▀ ████ █████ J█████████████████─ ████▌ ████ ██████████▌ ████ ▐███Ü ▐███Ü
███████████▀▀▀╙└ ▐████ J███▌ ▓███▌ ²█████ J███Ü ███▌ ▀█▌
▓██████████▌ ████▌ ████ ;████ ▀███▀ ███▌ J▀▀▀- █
▄█████▀ ▀█████µ ▐████ ,▄▓████▀ ████▀ ███ J███ `
J█████- ╙▀███▄ ████████████▀╙ J█▀▀▀ █U ▀█▌
████▀ ▀███ ▄████████▀▀ ╨ █
▓██▀ ²▀█▄ █▀▀▀╙└
▄██╜ ╙W
J█▀
▌└
┘
irb(ronin)>
启动并打开 Ronin 的交互式 Web 用户界面:```
$ ronin-app
以多种格式对数据进行十六进制转储:```shell $ ronin hexdump /bin/ls
将十六进制转储文件还原为其原始的原始二进制数据:```shell
$ ronin unhexdump -o data.bin hexdump.txt
打印文件中的所有可打印字符串:```shell $ ronin strings /bin/ls
从文件中打印所有字母字符串:```shell
$ ronin strings --alpha /bin/ls
从文件中输出所有字母数字字符串:```shell $ ronin strings --alpha-num /bin/ls
打印文件中所有数字字符串:```shell
$ ronin strings --numeric /bin/ls
打印文件中的所有十六进制字符串:```shell $ ronin strings --hex /bin/ls
枚举一个域名的所有位翻转:```shell
$ ronin bitflip microsoft --alpha-num --append .com
licrosoft.com
oicrosoft.com
iicrosoft.com
eicrosoft.com
Microsoft.com
mhcrosoft.com
mkcrosoft.com
mmcrosoft.com
macrosoft.com
mycrosoft.com
...
将字符串进行Base64编码:```shell $ ronin encode --base64 --string "foo bar baz" Zm9vIGJhciBiYXo=
Zlib压缩,Base64编码,然后URI编码一个字符串:```shell
$ ronin encode --zlib --base64 --uri --string "foo bar"
%65%4A%78%4C%79%38%39%58%53%45%6F%73%41%67%41%4B%63%41%4B%61%0A
Base64 解码字符串:```shell $ ronin decode --base64 --string "Zm9vIGJhciBiYXo=" foo bar baz
URI 解码、Base64 解码,然后对字符串进行 zlib 解压:```shell
$ ronin decode --uri --base64 --zlib --string "%65%4A%78%4C%79%38%39%58%53%45%6F%73%41%67%41%4B%63%41%4B%61%0A"
foo bar
对字符串进行URI转义:```shell $ ronin escape --uri --string "foo bar" foo%20bar
对字符串进行URI解转义:```shell
$ ronin unescape --uri --string "foo%20bar"
foo bar
将文件转换为引用的C字符串:```shell $ ronin quote --c file.bin "..."
将文件转换为带引号的 JavaScript 字符串:```shell
$ ronin quote --js file.bin
去除C字符串的引号:```shell $ ronin unquote --c --string '"\x66\x6f\x6f\x20\x62\x61\x72"' foo bar
### 文本
从文件中提取高熵数据:```shell
$ ronin entropy -e 5.0 index.html
Grep 搜索常见的数据模式:```shell $ ronin grep --hash index.html
从数据中提取常见模式:```shell
$ ronin extract --hash index.html
生成一个单词的随机拼写错误:```shell $ ronin typo microsoft microssoft
枚举一个单词的每个拼写错误变体:```shell
$ ronin typo --enum microsoft
microosoft
microsooft
microssoft
生成一个词的随机同形异义版本:```shell $ ronin homoglyph CEO CEO
枚举一个单词的每个同形词变体:```shell
$ ronin homoglyph --enum CEO
ϹEO
СEO
ⅭEO
CEO
CΕO
CЕO
CEO
CEΟ
CEО
CEO
语法高亮一个文件:```shell $ ronin highlight index.html
### 密码学
使用AES-256加密文件:```shell
$ ronin encrypt --cipher aes-256-cbc --password "..." file.txt > encrypted.bin
解密数据:```shell $ ronin decrypt --cipher aes-256-cbc --password "..." encrypted.bin
为文件生成 HMAC:```shell
$ ronin hmac --hash sha1 --password "too many secrets" data.txt
为字符串生成HMAC:```shell $ ronin hmac --hash sha1 --password "too many secrets" --string "..."
计算字符串的MD5校验和:```shell
$ ronin md5 --string "hello world"
5eb63bbbe01eeed093cb22bb8f5acdc3
计算文件的MD5校验和:```shell $ ronin md5 file.txt
计算文件中每一行的 MD5 校验和:```shell
$ ronin md5 --multiline file.txt
计算字符串的 SHA1 校验和:```shell $ ronin sha1 --string "hello world" 2aae6c35c94fcfb415dbe95f408b9ce91ee846ed
计算文件的SHA1校验和:```shell
$ ronin sha1 file.txt
计算文件中每一行的SHA1校验和:```shell $ ronin sha1 --multiline file.txt
计算字符串的SHA256校验和:```shell
$ ronin sha256 --string "hello world"
b94d27b9934d3e08a52e52d7da7dabfac484efe37a5380ee9088f7ace2efcde9
计算文件的SHA256校验和:```shell $ ronin sha256 file.txt
计算文件中每一行的 SHA256 校验和:```shell
$ ronin sha256 --multiline file.txt
计算字符串的SHA512校验和:```shell $ ronin sha512 --string "hello world" 309ecc489c12d6eb4cc40f50c902f2b4d0ed77ee511a7c7a9bcd3ca86d4cd86f989dd35bc5ff499670da34255b45b0cfd830e81f605dcf7dc5542e93ae9cd76f
计算文件的SHA512校验和:```shell
$ ronin sha512 file.txt
计算文件中每一行的 SHA512 校验和:```shell $ ronin sha512 --multiline file.txt
ROT-13 对字符串进行编码:```shell
$ ronin rot --string "The quick brown fox jumps over the lazy dog"
Gur dhvpx oebja sbk whzcf bire gur ynml qbt
XOR 编码一个字符串:```shell $ ronin xor --key ABC --string "The quick brown fox jumps over the lazy dog" "\x15*&a36(!(a 1.5-a$,9b)4/32b,7'1a6+$b/ 8:a&,&"
### 网络