Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
Lockdoor-Framework — 🔐 Lockdoor框架:一个包含网络安全资源的渗透测试框架 | Kitploit
工具/GitHubGitHub/sofianehamlaoui/lockdoor-framework
渗透测试框架权限提升密码攻击漏洞利用逆向工程信息收集Web安全社会工程学学习与教育
GitHubsofianehamlaoui/lockdoor-framework

Lockdoor-Framework

🔐 Lockdoor框架:一个包含网络安全资源的渗透测试框架

查看仓库
1.6k30021年前Kitploit 审核通过
网站

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

Lockdoor v2.3
⚠️ 该项目已不再维护。 ⚠️

了解更多:https://g.co/kgs/TtYRJJP

目录

  • 目录
  • 更新日志 📌 :
  • 徽章 📌 :
  • 支持我 💰 :
  • 贡献者 ⭐ :
  • 版本
    • 2021年6月 : 2.3
    • 2020年3月 : 2.2.3
  • 博客与文章 📰 :
  • 概述 📙 :
  • 特性 📙 :
    • 渗透测试工具选择 📙 :
    • 资源与速查表 📙 :
  • 截图 💻 :
  • 演示 💻 :
  • 安装 🛠️ :
  • Lockdoor 工具内容 🛠️ :
    • 信息收集 🔍 :
Web 黑客攻击 🌐 :
  • 权限提升 ⚠️ :
  • 逆向工程 ⚡ :
  • 漏洞利用 ❗ :
  • Shell 🐚 :
  • 密码攻击 ✳️ :
  • 加密与解密 🛡️ :
  • 社会工程学 🎭 :
  • Lockdoor 资源内容 📚 :
    • 信息收集 🔍 :
    • 密码学 🛡️ :
    • 漏洞利用 ❗ :
    • 网络 🖧 :
    • 密码攻击 ✳️ :
    • 后利用 ❗❗ :
    • 权限提升 ⚠️ :
    • 渗透测试与安全评估报告模板 📝 :
    • 逆向工程 ⚡ :
    • 社会工程学 🎭 :
    • 演练 🚶 :
    • Web 黑客攻击 🌐 :
    • 其他 📚 :
  • 贡献指南 :
  • 更新日志 📌 :

    版本 v2.3 已发布!!

    root@kitploit:~
        - 修复了一些 CI 问题
    
        - 构建更稳定的版本
    
        - 新的 Docker 镜像构建
    
        - 为每个支持的发行版添加了软件包
    

    徽章 📌 :

    made-with-python GitHub License TestedON

    支持我 💰 :

    • BTC 地址:1NR2oqsuevvWJwzCyhBXmqEA5eYAaSoJFk

    贡献者 ⭐ :

    commits

    版本

    2021年6月 : 2.3

    • 配置文件检查。

    • 更新工具。

    • 通过 -v 参数显示 Lockdoor 当前版本。

    • 检查版本并提示可能的更新。

    • 更易于自定义。

    • 目前未添加新工具。

    • 修复 Docker 配置错误,现在 Docker 版本完美运行。

      • 信息收集工具 (21)
      • Web 黑客工具 (15)
      • 逆向工程工具 (15)
      • 漏洞利用工具 (6)
      • 渗透测试与安全评估报告模板 (6)
      • 密码攻击工具 (4)
      • Shell 工具 + Blackarch 的 Webshell 集合 (4)
      • 演练与渗透测试流程辅助工具 (3)
      • 加密/解密工具 (2)
      • 社会工程学工具 (1)
      • 所有必要的权限提升脚本和漏洞利用

    2020年3月 : 2.2.3

    • 信息收集工具 (21)
    • Web 黑客工具 (15)
    • 逆向工程工具 (15)
    • 漏洞利用工具 (6)
    • 渗透测试与安全评估报告模板 (6)
    • 密码攻击工具 (4)
    • Shell 工具 + Blackarch 的 Webshell 集合 (4)
    • 演练与渗透测试流程辅助工具 (3)
    • 加密/解密工具 (2)
    • 社会工程学工具 (1)
    • 所有必要的权限提升脚本和漏洞利用
    • 适用于 Kali、Ubuntu、Arch、Fedora、OpenSUSE 和 Windows (Cygwin)

    YouTube 视频 : 链接

    Youtube

    博客与文章 📰 :

    root@kitploit:~
      * Reddit : https://www.reddit.com/r/cybersecurity/comments/d4hthh/lockdoor_a_penetration_testing_framework_with/
      * Medium.com : https://medium.com/@SofianeHamlaoui/lockdoor-framework-a-penetration-testing-framework-with-cyber-security-resources-sofiane-22fbb7942378
      * Xploit Lab : https://xploitlab.com/lockdoor-framework-penetration-testing-framework-with-cyber-security-resources/
      * Station X : https://www.stationx.net/threat-intelligence-17th-september/
      * Kelvin Security : https://blog.kelvinsecurity.com/2019/09/12/lookdoor-framework-a-penetration-testing-framework-with-cyber-security-resources/
      * All About Hacking : https://www.allabouthack.com/2019/09/lookdoor-framework-penetration-testing.html
      * Wired Intel : http://wiredintel.bravehost.com/wired/2019/09/15/%F0%9F%94%90-lockdoor-a-penetration-testing-framework-with-cyber-security-resources
    
            * 社交网络 :
                  * LinkedIn :
                        * 作者 Nermin S. : https://www.linkedin.com/posts/nsmajic_sofianehamlaouilockdoor-framework-activity-6578952540564529152-B-0P
                  * Twitter :
                        * 我本人 :D : https://twitter.com/S0fianeHamlaoui/status/1173079963567820801
                        * 国家网络安全服务 : https://twitter.com/NationalCyberS1/status/1173917454151475202
                        * Xploit Lab : https://twitter.com/xploit_lab/status/1173990273644261376
                        * 更多 : https://twitter.com/search?q=Lockdoor%20Framework
                        * 更多 : https://twitter.com/search?q=Lookdoor%20Framework
                  * Facebook :
                        * 我本人 :D : https://www.facebook.com/S0fianeHamlaoui/posts/678704759315090
                        * 国家网络安全服务 : https://www.facebook.com/ncybersec/posts/1273735519463836
                        * Xploit Lab : https://www.facebook.com/XploitLab/posts/2098443780463126
                        * Root Developers : https://www.facebook.com/root.deve/posts/1181412315364265
                        * 更多 : https://www.facebook.com/search/top/?q=Lockdoor%20Framework
            * YouTube :
                  * 我的 YouTube 视频 : https://www.youtube.com/watch?v=_agvb29FQrs
                  * The Shadow Brokers 视频 : https://www.youtube.com/watch?v=6njKRrKQtow
    

    概述 📙 :

    LockDoor 是一个旨在帮助渗透测试人员、漏洞赏金猎人和网络安全工程师的框架。 该工具专为基于 Debian/Ubuntu/ArchLinux 的发行版设计,以创建一个类似且熟悉的渗透测试发行版。但它只包含渗透测试人员最喜欢和最常用的工具。 作为渗透测试人员,我们大多数人都拥有自己的 /pentest/ 目录,因此这个框架可以帮助你构建一个完美的目录。 不仅如此!它还自动化了渗透测试过程,帮助你更快、更轻松地完成工作。

    特性 📙 :

    渗透测试工具选择 📙 :

    • 工具:Lockdoor 并不包含所有渗透测试工具,说实话!有谁曾使用过所有渗透测试发行版中的全部工具?Lockdoor 只包含渗透测试人员最喜欢和最常用的工具。

    • 工具来源:Lockdoor 包含的工具来自 Kali、Parrot OS 和 BlackArch 中最好的工具,以及一些其他黑客团队的私有工具,如 InurlBr、iran-cyber。当然还有我在 GitHub 上找到的一些由优秀开发者制作的很酷很棒的工具。

    • 易于自定义:轻松添加/删除工具。

    • 安装:你可以使用 install.sh 自动安装工具,也可以手动安装或运行 Docker 镜像。

    资源与速查表 📙 :

    • 资源:这就是Lockdoor 的特点,Lockdoor 不仅包含工具!还有渗透测试和安全评估报告模板、渗透测试演练示例和模板等。

    • 速查表:每个人在操作或工具使用上都可能忘记某些内容,甚至是一些技巧。这时速查表就派上用场了!这里有关于所有工具、枚举、漏洞利用和后利用技术的速查表。

    截图 💻 :

    演示 💻 :

    安装 🛠️ :

    推荐使用 Lockdoor 的方式是拉取 Docker 镜像,这样你就不必担心依赖问题。

    • Docker 镜像可在 Docker Hub 上获取,并在每次更新时自动重建:https://hub.docker.com/r/sofianehamlaoui/lockdoor。它最初基于官方的 Debian Docker 镜像(debian)。
    • Docker 安装

      • 安装依赖
        root@kitploit:~
               sudo apt install docker < Debian-based distributions
               sudo dnf install docker < RPM-based distributions
               sudo pacman -S docker < Arch-based distributions
               sudo zypper install docker < OS-based distributions
               sudo yum install docker < RH-based distributions
        
      • 运行容器
        root@kitploit:~
               1. *拉取 Lockdoor Docker 镜像:*
                    sudo docker pull sofianehamlaoui/lockdoor
        
        
        root@kitploit:~
               2. *运行全新的 Docker 容器:*
                    sudo docker run -it --name lockdoor-container -w /Lockdoor-Framework --net=host sofianehamlaoui/lockdoor
        
        
        root@kitploit:~
               3. *运行 Lockdoor 框架*
                    sudo lockdoor
        
        
        root@kitploit:~
               4. *重新运行已停止的容器:*
                    sudo docker start -i sofianehamlaoui/lockdoor
        
        root@kitploit:~
               5. *在容器中打开多个 shell:*
                    sudo docker exec -it lockdoor-container bash
        
    • 使用 LockAller - Lockdoor 安装器

      使用脚本安装可能需要一些时间,具体取决于系统上已安装的软件包。 > 以下是在一个全新 Debian 发行版上的安装过程(无预装软件包):[11分钟]

      root@kitploit:~
      git clone https://github.com/SofianeHamlaoui/Lockdoor-Framework.git && cd Lockdoor-Framework && chmod +x ./install.sh && ./install.sh 
      

    Lockdoor 工具内容 🛠️ :

    信息收集 🔍 :

    • 工具:
      • dirsearch : Web 路径扫描器
      • brut3k1t : 面向安全的暴力破解框架
      • gobuster : 用 Go 编写的 DNS 和 VHost 爆破工具
      • Enyx : SNMP IPv6 枚举工具
      • Goohak : 针对目标域名执行 Google 黑客查询
      • Nasnum : NAS 枚举器
      • Sublist3r : 用于渗透测试的快速子域名枚举工具
      • wafw00f : 识别并指纹 Web 应用防火墙
      • Photon : 专为 OSINT 设计的超快速爬虫。
      • Raccoon : 用于侦察和漏洞扫描的进攻性安全工具
      • DnsRecon : DNS 枚举脚本
      • Nmap : 著名的安全扫描器、端口扫描器和网络探测工具
      • sherlock : 跨社交网络查找用户名
      • snmpwn : SNMPv3 用户枚举器和攻击工具
      • Striker : 进攻性信息收集和漏洞扫描器。
      • theHarvester : 电子邮件、子域名和名称收集工具
      • URLextractor : 信息收集与网站侦查
      • denumerator.py : 枚举子域名列表
      • other : 我在某处收集的其他信息收集、侦察和枚举脚本。
    • 框架:
      • ReconDog : 侦察瑞士军刀
      • RED_HAWK : 集信息收集、漏洞扫描和爬取于一体的工具
      • Dracnmap : 信息收集框架

    Web 黑客攻击 🌐 :

    • 工具:
      • Spaghetti : Web 应用安全扫描器
      • CMSmap : CMS 扫描器
      • BruteXSS : 用于发现 Web 应用中 XSS 漏洞的工具
      • J-dorker : 从 Bing 获取网站列表
      • droopescan : 扫描器,识别 CMS,如 Drupal、Silverstripe。
      • Optiva : Web 应用扫描器
      • V3n0M : 用 Python3.6 编写的 SQLi/XSS/LFI/RFI 及其他漏洞的渗透测试扫描器
      • AtScan : 高级 Dork 搜索与批量漏洞利用扫描器
      • WPSeku : WordPress 安全扫描器
      • Wpscan : 用 Python 编写的简单 WordPress 扫描器
      • XSStrike : 最先进的 XSS 扫描器。
      • Sqlmap : 自动 SQL 注入和数据库接管工具
      • WhatWeb : 下一代 Web 扫描器
      • joomscan : Joomla 漏洞扫描器项目
    • 框架:
      • Dzjecter : 服务器检查工具

    权限提升 ⚠️ :

    • 工具:
      • Linux 🐧 :
        • 脚本 :
          • linux_checksec.sh
          • linux_enum.sh
          • linux_gather_files.sh
          • linux_kernel_exploiter.pl
          • linux_privesc.py
          • linux_privesc.sh
          • linux_security_test
        • Linux_exploits 文件夹
      • Windows |Windows| :
        • windows-privesc-check.py
        • windows-privesc-check.exe
      • MySql :
        • raptor_udf.c
        • raptor_udf2.c

    逆向工程 ⚡ :

    • Radare2 : 类 Unix 的逆向工程框架
    • VirtusTotal : VirusTotal 工具
    • Miasm : 逆向工程框架
    • Mirror : 反转文件的字节
    • DnSpy : .NET 调试器和程序集
    • AngrIo : 用于分析二进制文件的 Python 框架(由 @Hamz-a 推荐)
    • DLLRunner : 用于在沙箱系统中分析恶意软件的智能 DLL 执行脚本。
    • Fuzzy Server : 使用预制的 Spike 脚本攻击 VulnServer 的程序。
    • yara : 旨在帮助恶意软件研究人员识别和分类恶意软件样本的工具
    • Spike : 协议模糊测试工具包 + 审计
    • other : 我在某处收集的其他脚本

    漏洞利用 ❗ :

    • Findsploit : 即时在本地和在线数据库中查找漏洞利用
    • Pompem : 漏洞利用和漏洞查找器
    • rfix : 帮助 RFI 利用的 Python 工具。
    • InUrlBr : 在搜索引擎中高级搜索
    • Burpsuite : 用于安全测试和扫描的 Burp Suite。
    • linux-exploit-suggester2 : 下一代 Linux 内核漏洞利用建议器
    • other : 我在某处收集的其他脚本。

    Shell 🐚 :

    • WebShells : BlackArch 的 Webshell 集合
    • ShellSum : 防御工具 - 检测本地目录中的 webshell
    • Weevely : 武器化的 webshell
    • python-pty-shells : Python PTY 后门

    密码攻击 ✳️ :

    • crunch : 单词表生成器
    • CeWL : 自定义单词表生成器
    • patator : 多用途暴力破解器,模块化设计,灵活使用

    加密与解密 🛡️ :

    • Codetective : 用于确定使用的加密/编码算法的工具
    • findmyhash : 使用在线服务破解哈希的 Python 脚本

    社会工程学 🎭 :

    • scythe : 账户枚举器

    Lockdoor 资源内容 📚 :

    信息收集 🔍 :

    • Cheatsheet_SMBEnumeration
    • configuration_management
    • dns_enumeration
    • file_enumeration
    • http_enumeration
    • information_gathering_owasp_guide
    • miniserv_webmin_enumeration
    • ms_sql_server_enumeration
    • nfs_enumeration
    • osint_recon_ng
    • passive_information_gathering
    • pop3_enumeration
    • ports_emumeration
    • rpc_enumeration
    • scanning
    • smb_enumeration
    • smtp_enumeration
    • snmb_enumeration
    • vulnerability_scanning

    密码学 🛡️ :

    • Crypto101.pdf

    漏洞利用 ❗ :

    • computer_network_exploits
    • file_inclusion_vulnerabilities
    • File_Transfers
    • nc_transfers
    • networking_pivoting_and_tunneling
    • network_pivoting_techniques
    • pivoting
    • pivoting_
    • Public Exploits
    • reverse_shell_with_msfvenom## 网络 🖧 :
    • bpf_syntax
    • Cheatsheet_Networking
    • Cheatsheet_Oracle
    • networking_concept
    • nmap_quick_reference_guide
    • tcpdump

    密码攻击 ✳️:

    • password_attacks
    • Some-Links-To-Wordlists

    后渗透利用 ❗❗:

    • Cheatsheet_AVBypass
    • Cheatsheet_BuildReviews
    • code-execution-reverse-shell-commands

    权限提升 ⚠️:

    • Cheatsheet_LinuxPrivilegeEsc
    • linux_enumeration
    • windows_enumeration
    • windows_priv_escalation
    • windows_priv_escalation_practical

    渗透测试与安全评估发现报告模板 📝 :

    • Demo Company - Security Assessment Findings Report.docx
    • linux-template.md
    • PWKv1-REPORT.doc
    • pwkv1_report.doc
    • template-penetration-testing-report-v03.pdf
    • windows-template.md
    • OSCP-OS-XXXXX-Lab-Report_Template3.2.docx
    • OSCP-OS-XXXXX-Exam-Report_Template3.2.docx
    • CherryTree_template.ctb
    • eventory-sample-pentest-report.pdf

    逆向工程 ⚡ :

    • Buffer_Overflow_Exploit
    • buffer_overflows
    • gdb_cheat_sheet
    • r2_cheatsheet
    • win32_buffer_overflow_exploitation
    • 64_ia_32_jmp_instructions
    • course_notes
    • debuging
    • IntelCodeTable_x86
    • Radare2 cheatsheet
    • x86_assembly_x86_architecture
    • x86_opcode_structure_and_instruction_overview

    社会工程学 🎭:

    • social_engineering

    实战演练 🚶 :

    • Cheatsheet_PenTesting.txt
    • OWASP Testing Guide v4
    • OWASPv4_Checklist.xlsx

    Web 黑客 🌐 :

    • auxiliary_info.md
    • Cheatsheet_ApacheSSL
    • Cheatsheet_AttackingMSSQL
    • Cheatsheet_DomainAdminExploitation
    • Cheatsheet_SQLInjection
    • Cheatsheet_VulnVerify.txt
    • code-execution-reverse-shell-commands
    • file_upload.md
    • html5_cheat_sheet
    • jquery_cheat_sheet_1.3.2
    • sqli
    • sqli_cheatsheet
    • sqli-quries
    • sqli-tips
    • web_app_security
    • web_app_vulns_Arabic
    • Xss_1
    • Xss_2
    • xss_actionscript
    • xxe

    其他 📚 :

    有史以来最好的收藏

    • 图片(留给你去发现)
    • Google Hacking DataBase
    • Google Fu

    贡献指南 :

    1. 阅读 贡献指南、行为准则 及 拉取请求模板
    2. Fork 本仓库 (https://github.com/SofianeHamlaoui/Lockdoor-Framework/fork)
    3. 创建你的特性分支
    4. 提交你的更改
    5. 推送到分支
    6. 创建一个新的拉取请求
    下载工具