面向授权教育行业的侦察与分类编排工具(nmap/dirsearch/sqlmap/hydra + CVE-2024-4577、密钥/API密钥泄露、XSS、wp2shell),带Web控制面板
面向教育行业红蓝对抗演练的授权侦察与分诊编排器。 放入目标,它就会运行扫描器、过滤噪声,并在 Web UI 中交给你一个按优先级排序的 待审队列。专为部署在你的 Linux 机器(Kali / 基础设施)上、通过浏览器驱动而构建。
⚠️ 仅限授权使用。 只可指向你已获授权测试的系统。 范围锁定默认关闭——授权由操作者负责。对于真实 交战,你可以在
config.yaml中通过scope_enforce: true重新启用锁定的范围允许列表(此后每个阶段在执行前都会重新检查范围)。
Kali / Debian / Ubuntu —— 粘贴整段:
sudo apt update && sudo apt install -y python3 python3-venv git nmap sqlmap hydra dirsearch
git clone https://github.com/ericchen913900/edu-recon.git
cd edu-recon
chmod +x run.sh
./run.sh
就这样。run.sh 会构建 venv、克隆捆绑工具并安装依赖、
运行 doctor,然后在
http://127.0.0.1:8770 上启动全功率控制台并打开你的浏览器。(Ctrl-C 停止;随时可重新运行 ./run.sh。)
Windows(Git Bash / WSL):
git clone https://github.com/ericchen913900/edu-recon.git
cd edu-recon
bash run.sh # first run auto-creates the venv + clones tools; nmap must be on PATH
targets ─▶ expand (CIDR ping-sweep, subdomain enum)
─▶ per target:
portscan nmap -sV -sC (+ --script vuln)
webdisco dirsearch (+ WordPress detect)
exposures .git / .env / backups / phpinfo / server-status / actuator …
+ phpMyAdmin/Adminer exposure + open directory listing
secrets JS/HTML key-leak scan (AWS/GCP/GitHub/Slack/Stripe/JWT/私鑰/…)
+ API-doc / GraphQL-introspection exposure ← api leak
phpcgi CVE-2024-4577 / 8926 via Night-have-dreams/php-cgi-Injector
react2shell CVE-2025-55182 React Server Components RCE
via hidden-investigations/react2shell-scanner (safe-check by default)
webcve built-in non-destructive safe-check probes for famous CVEs:
PHPUnit 2017-9841 · Apache-traversal 2021-41773 · Struts2 2017-5638
· Confluence 2022-26134 · Drupalgeddon2 2018-7600 · Next.js 2025-29927
moodle Moodle LMS fingerprint + version + outdated-branch +
web-exposed moodledata (the dominant .edu system)
xss dalfox + built-in reflected-XSS canary
sqli built-in SQL-error quick pass + sqlmap deep
cred hydra weak/default passwords (ssh/ftp/rdp/db/…)
wp xAL6/wp2shell WordPress SQLi→shell
─▶ triage: infer findings from services, drop soft-404 noise,
dedupe, rank by severity → review queue
─▶ report: JSON / Markdown / self-contained HTML
git clone https://github.com/ericchen913900/edu-recon.git && cd edu-recon
python3 -m venv .venv && source .venv/bin/activate # Windows: .venv\Scripts\activate
python recon.py setup # clones php-cgi-Injector + react2shell-scanner + wp2shell + dirsearch, installs deps
python recon.py doctor # shows which scanners resolved
在 Kali 上,重型扫描器(nmap/sqlmap/hydra/dirsearch)已是原生自带—— 完整配方见 在 Kali Linux 上部署。
Kali 是预期平台:nmap、sqlmap、hydra、dirsearch 随发行版提供,
因此整条流水线(包括注入 + 弱口令)都能原生运行。
# 1) system tools — most are already on Kali; this is the complete set
sudo apt update
sudo apt install -y python3 python3-venv git nmap sqlmap hydra dirsearch
# optional (better XSS + subdomain enum):
# sudo apt install -y dalfox subfinder # or: go install github.com/hahwul/dalfox/v2@latest ; \
# # go install github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest
# 2) get the code
git clone https://github.com/ericchen913900/edu-recon.git
cd edu-recon
# 3) isolated venv + Python deps + bundled script-tools
python3 -m venv .venv
source .venv/bin/activate
python recon.py setup # clones php-cgi-Injector / react2shell-scanner / wp2shell / dirsearch, pip-installs deps
# 4) sanity check — on Kali nmap/sqlmap/hydra/dirsearch should all be OK (native)
python recon.py doctor
# 5a) web console — bind to localhost, drive from a browser
python recon.py serve --host 127.0.0.1 --port 8770
# → http://127.0.0.1:8770 (paste targets → pick intensity → ARM & RUN)
# remote Kali? tunnel instead of exposing it:
# ssh -L 8770:127.0.0.1:8770 user@kali # then browse http://localhost:8770
# 5b) or headless
python recon.py scan -t targets.txt --intensity full
python recon.py repro <run-id> # runnable reproduction PoC per confirmed finding
python recon.py payout <run-id> # legal disclosure / bounty routing per finding
Kali 注意事项
dirsearch 进行完整的
db/dicc.txt 扫描(每个发现的目录/文件都会在控制台的
🗂 網站路徑 下列出)。跳过 apt 包,setup 会克隆 dirsearch 并通过
Python 运行它——无论哪种方式 webdisco 都能工作。sqlmap/hydra/nmap,--intensity full
会实际执行注入 + 弱口令检查(其他位置为非破坏性安全检测)。config.yaml 中设置 scope_enforce: true + 在目标文件 / extra_allowed_cidrs 中列出你的授权范围。--host 127.0.0.1 并通过 SSH
隧道访问;它自身没有认证。# /etc/systemd/system/edu-recon.service
[Service]
WorkingDirectory=/home/kali/edu-recon
ExecStart=/home/kali/edu-recon/.venv/bin/python recon.py serve --host 127.0.0.1 --port 8770
Restart=on-failure
User=kali
[Install]
WantedBy=multi-user.target
sudo systemctl enable --now edu-reconchmod +x run.sh && ./run.sh # 滿血:自動 venv/setup/doctor → 全火力 console → 開瀏覽器
# HOST=0.0.0.0 PORT=9000 ./run.sh # override bind/port
run.sh 在首次运行时创建 venv、克隆捆绑工具、运行 doctor,
然后以全功率提供控制台——强度 full、nmap -sC --script vuln、完整的 dirsearch db/dicc.txt 扫描、所有已解析的扫描器、范围锁定
关闭——位于 http://127.0.0.1:8770 并打开你的浏览器。Ctrl-C 停止。
python recon.py serve --host 127.0.0.1 --port 8770
打开 URL,粘贴目标(每行一个:IP / host / URL / CIDR /
domain / host:port),选择强度,点击開始掃描。实时观看每个
目标的阶段网格填充、按严重性过滤发现、展开证据、
打开原始工具日志、标记误报,并导出 HTML 报告。
python recon.py scan -t targets.txt --intensity full
# reports land in runs/<run-id>/report.{md,html,json}
启动器:
| 命令 | 作用 |
|---|---|
./run.sh | 单命令全功率启动:venv/setup/doctor → 控制台 → 打开浏览器。HOST=… PORT=… ./run.sh 可覆盖。 |
recon.py 子命令(前缀为 venv python,例如 .venv/bin/python):
| 命令 | 作用 |
|---|---|
recon.py setup | 克隆捆绑工具(php-cgi-Injector / react2shell-scanner / wp2shell / dirsearch)+ pip 安装其依赖 |
recon.py doctor | 显示哪些扫描器已解析(nmap / sqlmap / hydra / dirsearch / dalfox / subfinder / 捆绑工具) |
recon.py serve [--host H] [--port P] | 启动 Web 控制台(默认 127.0.0.1:8770) |
recon.py scan -t targets.txt [--intensity full|recon|passive] | 对目标文件进行无头扫描 |
recon.py scan http://host/ 10.0.0.0/24 … | 对内联目标进行无头扫描 |
recon.py repro <run-id> [--finding <id>] [--out DIR] | 为每个已确认发现打印 / 写入可运行的复现 PoC |
recon.py payout <run-id> | 为每个已确认发现提供合法披露 / 赏金路由 |
通用标志(所有子命令):--config FILE(yaml/json 覆盖)· --intensity · --concurrency N · --workdir DIR。
扫描目标接受:IP · host · URL · CIDR · domain · host:port(文件中每行一个,或内联 / 在控制台中粘贴)。
Web API(控制台所驱动的接口;便于脚本化):
| 端点 | 用途 |
|---|---|
POST /api/runs {targets,intensity,concurrency,scope_enforce} | 启动一次运行 → {id} |
GET /api/runs · GET /api/runs/{id} | 列出运行 · 完整运行(目标/阶段/发现/Web 路径) |
GET /api/runs/{id}/logs?since=N | 增量实时日志 |
GET /api/runs/{id}/artifact?path=… | 原始工具日志 / 已保存转储 |
GET /api/runs/{id}/repro[?finding_id=…] | 复现 PoC 脚本 |
POST /api/runs/{id}/finding {finding_id,reviewed,false_positive} | 分诊一个发现 |
POST /api/runs/{id}/dump {finding_id} · POST …/dumps/clear | 捕获泄露(文件/.git 源码/密钥)· 清除捕获 |
POST /api/runs/{id}/report · POST …/cancel | 导出报告 · 取消运行 |
示例: