用于SOCKS5代理链、端口扫描、DNS枚举、哈希破解、反向shell生成、隐写术和匿名化的多模块攻击性安全工具包。
██╗ ██╗ ██████╗ ██╗██████╗ ███████╗███████╗ ██████╗
██║ ██║██╔═══██╗██║██╔══██╗██╔════╝██╔════╝██╔════╝
██║ ██║██║ ██║██║██║ ██║███████╗█████╗ ██║
╚██╗ ██╔╝██║ ██║██║██║ ██║╚════██║██╔══╝ ██║
╚████╔╝ ╚██████╔╝██║██████╔╝███████║███████╗╚██████╗
╚═══╝ ╚═════╝ ╚═╝╚═════╝ ╚══════╝╚══════╝ ╚═════╝
v3.0.0 | 18 个模块 | 50+ 条命令 | 零依赖
不是又一个脚本小子工具。这个是真能干活的。
# Clone the repository
git clone https://github.com/VoidSecSoftwares/voidsec-proxy.git
# Enter the directory
cd voidsec-proxy
# Install (basic)
pip install -e .
# Install with crypto support (AES-GCM, ChaCha20, steganography)
pip install -e ".[crypto]"
要求: Python 3.8+ | 零强制依赖
# Start a SOCKS5 proxy chain
voidsec-proxy proxy -f proxies.txt
# Scan a target
voidsec-proxy scan -t 10.0.0.1
# Resolve DNS
voidsec-proxy dns example.com
# Generate a password
voidsec-proxy password -l 20 -c 5
# Full recon on a target
voidsec-proxy recon -t 10.0.0.1
带自动轮换的 SOCKS5 代理链。
# Basic usage
voidsec-proxy proxy -f proxies.txt
# Custom listen address and port
voidsec-proxy proxy -f proxies.txt -l 0.0.0.0 -p 1080
# Shuffle proxy order on start
voidsec-proxy proxy -f proxies.txt -s
| 参数 | 描述 | 默认值 |
|---|---|---|
-f, --file | 代理文件(必填) | — |
-l, --listen | 监听地址 | 127.0.0.1 |
-p, --port | 监听端口 | 9050 |
-s, --shuffle | 打乱代理顺序 | false |
多线程 TCP 端口扫描器,支持 banner 抓取。
# Scan common ports
voidsec-proxy scan -t 10.0.0.1
# Scan specific ports
voidsec-proxy scan -t 10.0.0.1 -p 22,80,443,3389
# Scan port range, export to JSON
voidsec-proxy scan -t 10.0.0.1 -r 1-1000 -o results.json -f json
| 参数 | 描述 | 默认值 |
|---|---|---|
-t, --target | 目标主机(必填) | — |
-p, --ports | 逗号分隔的端口 | 常见端口 |
-r, --port-range | 端口范围(例如 1-1000) | — |
-o, --output | 输出文件 | stdout |
-f, --format | 输出格式(text、json、csv) | text |
DNS 解析、反向查询和子域名枚举。
# Resolve A records
voidsec-proxy dns example.com
# Multiple record types
voidsec-proxy dns example.com -t A -t MX -t TXT
# Reverse DNS lookup
voidsec-proxy dns 8.8.8.8 -r
# Subdomain enumeration
voidsec-proxy dns example.com -e -w wordlist.txt
| 参数 | 描述 | 默认值 |
|---|---|---|
domain | 目标域名(必填) | — |
-t, --type | 记录类型(可重复) | A |
-r, --reverse | 反向 DNS 查询 | false |
-e, --enumerate | 子域名枚举 | false |
-w, --wordlist | 用于枚举的字典 | — |
支持字典的哈希破解。
# Crack MD5 hash
voidsec-proxy crack --hash 5f4dcc3b5aa765d61d8327deb882cf99 -t md5 -w rockyou.txt
# Hash text with SHA256
voidsec-proxy crack --hash-text "hello" -t sha256
# Hash file
voidsec-proxy crack --hash-file secret.bin -t sha512
| 参数 | 描述 | 默认值 |
|---|---|---|
--hash | 要破解的哈希 | — |
--hash-text | 要哈希的文本 | — |
--hash-file | 要哈希的文件 | — |
-t, --type | 哈希类型(md5、sha1、sha256、sha512) | md5 |
-w, --wordlist | 用于破解的字典 | — |
带强度审计的密码生成器。
# Generate 5 passwords, 20 chars each
voidsec-proxy password -l 20 -c 5
# Audit a password
voidsec-proxy password -a "MyP@ssw0rd"
# Generate 6-word passphrase
voidsec-proxy password --passphrase -l 6
| 参数 | 描述 | 默认值 |
|---|---|---|
-l, --length | 密码长度 / 单词数量 | 16 |
-c, --count | 要生成的密码数量 | 5 |
-a, --audit | 审计密码强度 | — |
--passphrase | 改为生成口令短语 | false |
--separator | 口令短语单词分隔符 | - |
--no-upper | 排除大写字母 | false |
--no-lower | 排除小写字母 | false |
--no-digits | 排除数字 | false |
--no-symbols | 排除符号 | false |
字典变异引擎。
# Apply all mutations
voidsec-proxy mutate -w wordlist.txt -o mutated.txt -m leet,upper,append_num,dups
# Leet speak + numbers
voidsec-proxy mutate -w wordlist.txt -o out.txt -m leet,append_num
| 参数 | 描述 | 默认值 |
|---|---|---|
-w, --wordlist | 输入字典(必填) | — |
-o, --output | 输出文件(必填) | — |
-m, --mutations | 逗号分隔:leet、upper、append_num、prepend_num、dups、reverse、append_sym | 全部 |
完整的网络侦察。
# Full recon (IP, geo, ASN, open ports)
voidsec-proxy recon -t 10.0.0.1
# WHOIS lookup
voidsec-proxy recon --whois example.com
# IP geolocation
voidsec-proxy recon --geo 8.8.8.8
# ASN lookup
voidsec-proxy recon --asn 8.8.8.8
# Traceroute
voidsec-proxy recon --traceroute 8.8.8.8
| 参数 | 描述 |
|---|---|
-t, --target | 用于完整侦察的目标主机 |
--whois | WHOIS 查询 |
--geo | IP 地理位置 |
--asn | ASN 查询 |
--traceroute | 到目标的 Traceroute |
Web 应用指纹识别和目录爆破。
# Full fingerprint
voidsec-proxy web -u https://target.com
# Header analysis
voidsec-proxy web --headers https://target.com
# Directory brute-force
voidsec-proxy web --dirbust https://target.com -w wordlist.txt
| 参数 | 描述 |
|---|---|
-u, --url | 目标 URL |
--headers | 获取并分析响应头 |
--fingerprint | 技术指纹识别 |
--dirbust | 目录爆破 |
-w, --wordlist | 用于爆破的字典 |
隐蔽信道与数据编码。
# Encode data
voidsec-proxy exfil --encode "secret data" -m base64
voidsec-proxy exfil --encode "secret data" -m morse
voidsec-proxy exfil --encode "secret data" -m dns
# Decode data
voidsec-proxy exfil --decode "dGVzdA==" -m base64
# Vigenere cipher
voidsec-proxy exfil --vigenere "encrypted" --key "secret"
| 参数 | 描述 |
|---|---|
--encode | 要编码的文本 |
--decode | 要解码的文本 |
-m, --method | base32、base64、hex、morse、binary、rot13、caesar、dns |
-s, --shift | 凯撒密码位移 |
--vigenere | 维吉尼亚密码文本 |
--key | 密码密钥 |
--decrypt | 解密而非加密 |
AES-GCM 文件加密。
# Encrypt a file
voidsec-proxy encrypt -i secret.txt -o secret.enc -p "mypassword"
# Decrypt a file
voidsec-proxy encrypt -i secret.enc -o secret.txt -p "mypassword" -d
| 参数 | 描述 |
|---|---|
-i, --input | 输入文件(必填) |
-o, --output | 输出文件(必填) |
-p, --password | 加密密码(必填) |
-d, --decrypt | 解密而非加密 |
多遍覆写的安全文件删除。
# Shred file with 5 passes
voidsec-proxy shred -f file.txt -n 5
| 参数 | 描述 | 默认值 |
|---|---|---|
-f, --file | 要粉碎的文件(必填) | — |
-n, --passes | 覆写遍数 | 3 |
PNG 隐写术 — 在图像中隐藏和提取数据。
# Hide data in image
voidsec-proxy stego -i image.png -f secret.txt -o stego.png
# Extract hidden data
voidsec-proxy stego -i stego.png -e -o extracted.txt
| 参数 | 描述 |
|---|---|
-i, --image | PNG 图像文件 |
-f, --secret | 要隐藏的机密文件 |
-o, --output | 输出文件 |
-e, --extract | 提取而非隐藏 |
带 payload 编码的反弹 shell 生成器。
# Python reverse shell
voidsec-proxy shell --lhost 10.0.0.1 --lport 4444 -t python
# Bash with base64 encoding
voidsec-proxy shell --lhost 10.0.0.1 --lport 4444 -t bash -e base64