Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
edu-recon — 面向授权教育行业的侦察与分类编排工具(nmap/dirsearch/sqlmap/hydra + CVE-2024-4577、密钥/API密钥泄露、XSS、wp2shell),带Web控制面板 | Kitploit
工具/GitHubGitHub/yeee3642/edu-recon
侦察漏洞扫描器Web漏洞扫描器密码攻击端口扫描漏洞利用信息收集渗透测试秘密检测子域名枚举学习与教育
2221天前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
GitHub
yeee3642/edu-recon

edu-recon

面向授权教育行业的侦察与分类编排工具(nmap/dirsearch/sqlmap/hydra + CVE-2024-4577、密钥/API密钥泄露、XSS、wp2shell),带Web控制面板

查看仓库

edu-recon

面向教育行业红蓝对抗演练的授权侦察与分诊编排器。 放入目标,它就会运行扫描器、过滤噪声,并在 Web UI 中交给你一个按优先级排序的 待审队列。专为部署在你的 Linux 机器(Kali / 基础设施)上、通过浏览器驱动而构建。

⚠️ 仅限授权使用。 只可指向你已获授权测试的系统。 范围锁定默认关闭——授权由操作者负责。对于真实 交战,你可以在 config.yaml 中通过 scope_enforce: true 重新启用锁定的范围允许列表(此后每个阶段在执行前都会重新检查范围)。

快速开始 · 复制粘贴即可

Kali / Debian / Ubuntu —— 粘贴整段:

sudo apt update && sudo apt install -y python3 python3-venv git nmap sqlmap hydra dirsearch
git clone https://github.com/ericchen913900/edu-recon.git
cd edu-recon
chmod +x run.sh
./run.sh

就这样。run.sh 会构建 venv、克隆捆绑工具并安装依赖、 运行 doctor,然后在 http://127.0.0.1:8770 上启动全功率控制台并打开你的浏览器。(Ctrl-C 停止;随时可重新运行 ./run.sh。)

Windows(Git Bash / WSL):

git clone https://github.com/ericchen913900/edu-recon.git
cd edu-recon
bash run.sh          # first run auto-creates the venv + clones tools; nmap must be on PATH

功能说明

targets ─▶ expand (CIDR ping-sweep, subdomain enum)
        ─▶ per target:
             portscan   nmap -sV -sC (+ --script vuln)
             webdisco   dirsearch  (+ WordPress detect)
             exposures  .git / .env / backups / phpinfo / server-status / actuator …
                        + phpMyAdmin/Adminer exposure + open directory listing
             secrets    JS/HTML key-leak scan (AWS/GCP/GitHub/Slack/Stripe/JWT/私鑰/…)
                        + API-doc / GraphQL-introspection exposure   ← api leak
             phpcgi     CVE-2024-4577 / 8926  via Night-have-dreams/php-cgi-Injector
             react2shell CVE-2025-55182 React Server Components RCE
                        via hidden-investigations/react2shell-scanner (safe-check by default)
             webcve     built-in non-destructive safe-check probes for famous CVEs:
                        PHPUnit 2017-9841 · Apache-traversal 2021-41773 · Struts2 2017-5638
                        · Confluence 2022-26134 · Drupalgeddon2 2018-7600 · Next.js 2025-29927
             moodle     Moodle LMS fingerprint + version + outdated-branch +
                        web-exposed moodledata (the dominant .edu system)
             xss        dalfox + built-in reflected-XSS canary
             sqli       built-in SQL-error quick pass  +  sqlmap deep
             cred       hydra weak/default passwords (ssh/ftp/rdp/db/…)
             wp         xAL6/wp2shell WordPress SQLi→shell
        ─▶ triage: infer findings from services, drop soft-404 noise,
                   dedupe, rank by severity → review queue
        ─▶ report: JSON / Markdown / self-contained HTML

安装

git clone https://github.com/ericchen913900/edu-recon.git && cd edu-recon
python3 -m venv .venv && source .venv/bin/activate     # Windows: .venv\Scripts\activate
python recon.py setup          # clones php-cgi-Injector + react2shell-scanner + wp2shell + dirsearch, installs deps
python recon.py doctor         # shows which scanners resolved

在 Kali 上,重型扫描器(nmap/sqlmap/hydra/dirsearch)已是原生自带—— 完整配方见 在 Kali Linux 上部署。

在 Kali Linux 上部署

Kali 是预期平台:nmap、sqlmap、hydra、dirsearch 随发行版提供, 因此整条流水线(包括注入 + 弱口令)都能原生运行。

# 1) system tools — most are already on Kali; this is the complete set
sudo apt update
sudo apt install -y python3 python3-venv git nmap sqlmap hydra dirsearch
#   optional (better XSS + subdomain enum):
#   sudo apt install -y dalfox subfinder      # or: go install github.com/hahwul/dalfox/v2@latest ; \
#                                             #     go install github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest

# 2) get the code
git clone https://github.com/ericchen913900/edu-recon.git
cd edu-recon

# 3) isolated venv + Python deps + bundled script-tools
python3 -m venv .venv
source .venv/bin/activate
python recon.py setup          # clones php-cgi-Injector / react2shell-scanner / wp2shell / dirsearch, pip-installs deps

# 4) sanity check — on Kali nmap/sqlmap/hydra/dirsearch should all be OK (native)
python recon.py doctor

# 5a) web console — bind to localhost, drive from a browser
python recon.py serve --host 127.0.0.1 --port 8770
#     → http://127.0.0.1:8770   (paste targets → pick intensity → ARM & RUN)
#     remote Kali? tunnel instead of exposing it:
#         ssh -L 8770:127.0.0.1:8770 user@kali      # then browse http://localhost:8770

# 5b) or headless
python recon.py scan -t targets.txt --intensity full
python recon.py repro  <run-id>          # runnable reproduction PoC per confirmed finding
python recon.py payout <run-id>          # legal disclosure / bounty routing per finding

Kali 注意事项

  • dirsearch:会自动使用原生 dirsearch 进行完整的 db/dicc.txt 扫描(每个发现的目录/文件都会在控制台的 🗂 網站路徑 下列出)。跳过 apt 包,setup 会克隆 dirsearch 并通过 Python 运行它——无论哪种方式 webdisco 都能工作。
  • 完整流水线:配合原生 sqlmap/hydra/nmap,--intensity full 会实际执行注入 + 弱口令检查(其他位置为非破坏性安全检测)。
  • 范围锁定默认关闭(授权由操作者负责)。为付费交战锁定它: 在 config.yaml 中设置 scope_enforce: true + 在目标文件 / extra_allowed_cidrs 中列出你的授权范围。
  • 不要暴露控制台。 保持 --host 127.0.0.1 并通过 SSH 隧道访问;它自身没有认证。
  • systemd(可选) 用于保持控制台运行:
    # /etc/systemd/system/edu-recon.service
    [Service]
    WorkingDirectory=/home/kali/edu-recon
    ExecStart=/home/kali/edu-recon/.venv/bin/python recon.py serve --host 127.0.0.1 --port 8770
    Restart=on-failure
    User=kali
    [Install]
    WantedBy=multi-user.target
    
    sudo systemctl enable --now edu-recon

一键启动 · 单命令启动(全功率)

chmod +x run.sh && ./run.sh          # 滿血:自動 venv/setup/doctor → 全火力 console → 開瀏覽器
# HOST=0.0.0.0 PORT=9000 ./run.sh    # override bind/port

run.sh 在首次运行时创建 venv、克隆捆绑工具、运行 doctor, 然后以全功率提供控制台——强度 full、nmap -sC --script vuln、完整的 dirsearch db/dicc.txt 扫描、所有已解析的扫描器、范围锁定 关闭——位于 http://127.0.0.1:8770 并打开你的浏览器。Ctrl-C 停止。

使用 —— Web 控制面板

python recon.py serve --host 127.0.0.1 --port 8770

打开 URL,粘贴目标(每行一个:IP / host / URL / CIDR / domain / host:port),选择强度,点击開始掃描。实时观看每个 目标的阶段网格填充、按严重性过滤发现、展开证据、 打开原始工具日志、标记误报,并导出 HTML 报告。

使用 —— 无头模式

python recon.py scan -t targets.txt --intensity full
# reports land in runs/<run-id>/report.{md,html,json}

命令参考 · 指令一览

启动器:

命令作用
./run.sh单命令全功率启动:venv/setup/doctor → 控制台 → 打开浏览器。HOST=… PORT=… ./run.sh 可覆盖。

recon.py 子命令(前缀为 venv python,例如 .venv/bin/python):

命令作用
recon.py setup克隆捆绑工具(php-cgi-Injector / react2shell-scanner / wp2shell / dirsearch)+ pip 安装其依赖
recon.py doctor显示哪些扫描器已解析(nmap / sqlmap / hydra / dirsearch / dalfox / subfinder / 捆绑工具)
recon.py serve [--host H] [--port P]启动 Web 控制台(默认 127.0.0.1:8770)
recon.py scan -t targets.txt [--intensity full|recon|passive]对目标文件进行无头扫描
recon.py scan http://host/ 10.0.0.0/24 …对内联目标进行无头扫描
recon.py repro <run-id> [--finding <id>] [--out DIR]为每个已确认发现打印 / 写入可运行的复现 PoC
recon.py payout <run-id>为每个已确认发现提供合法披露 / 赏金路由

通用标志(所有子命令):--config FILE(yaml/json 覆盖)· --intensity · --concurrency N · --workdir DIR。

扫描目标接受:IP · host · URL · CIDR · domain · host:port(文件中每行一个,或内联 / 在控制台中粘贴)。

Web API(控制台所驱动的接口;便于脚本化):

端点用途
POST /api/runs {targets,intensity,concurrency,scope_enforce}启动一次运行 → {id}
GET /api/runs · GET /api/runs/{id}列出运行 · 完整运行(目标/阶段/发现/Web 路径)
GET /api/runs/{id}/logs?since=N增量实时日志
GET /api/runs/{id}/artifact?path=…原始工具日志 / 已保存转储
GET /api/runs/{id}/repro[?finding_id=…]复现 PoC 脚本
POST /api/runs/{id}/finding {finding_id,reviewed,false_positive}分诊一个发现
POST /api/runs/{id}/dump {finding_id} · POST …/dumps/clear捕获泄露(文件/.git 源码/密钥)· 清除捕获
POST /api/runs/{id}/report · POST …/cancel导出报告 · 取消运行

示例:

下载工具