一些用于安全研究工具的安装脚本。
# ctf-tools 这是一系列设置脚本的集合,用于创建各种安全研究工具的安装。当然,这不是一个难题,但将它们集中在一个易于部署到新机器等地方,确实非常方便。这些工具的安装脚本会定期检查,因此希望它们有不错的成功率! 包含以下工具的安装程序: | 类别 | 工具 | 描述 | |----------|------|-------------| | binary | [angr](http://angr.io) |  来自Shellphish的下一代二进制分析引擎。 | <!--tool--> | binary | [angr-management](http://angr.io) |  一个GUI逆向工程与反编译工具。 | <!--tool--> | binary | [beef](https://github.com/beefproject/beef) |  浏览器利用框架。 | <!--tool--> | binary | [crosstool](http://crosstool-ng.org/) |  交叉编译器与跨架构工具。 | <!--tool--><!--no-test--> | binary | [cross2](http://kozos.jp/books/asm/asm.html) |  来自一本日语C语言书籍的交叉编译工具集。 | <!--tool--><!--no-test--> | binary | [decomp2dbg](https://github.com/mahaloz/decomp2dbg) |  一个插件,用于从反编译器中向调试器引入交互式符号。 | <!--tool--> | binary | [elfkickers](http://www.muppetlabs.com/~breadbox/software/elfkickers.html) |  一套用于处理ELF文件的实用工具。 | <!--tool--> | binary | [elfparser](https://github.com/mentebinaria/elfparser-ng) |  跨平台的命令行和图形界面工具,用于显示ELF文件信息。 | <!--tool--> | binary | [evilize](http://www.mathstat.dal.ca/~selinger/md5collision/) |  创建MD5碰撞二进制文件的工具。 | <!--tool--> | binary | [gdb](http://www.gnu.org/software/gdb/) |  最新版本的gdb,包含python2绑定。 | <!--tool--><!--slow-test--> | binary | [gef](https://github.com/hugsy/gef) |  针对gdb的增强环境。 | <!--tool--> | binary | [ghidra](https://ghidra-sre.org/) |  开源逆向工程与反编译工具。 | <!--tool--> | binary | [honggfuzz](https://github.com/google/honggfuzz) |  一个通用、易于使用的模糊测试器,具有有趣的分析选项。 | <!--tool--> | binary | [ida](https://hex-rays.com/ida-free) | 反编译与逆向工具(需要您自行下载到~/Downloads!)。 | <!--tool--><!--no-test--> | binary | [manticore](https://github.com/trailofbits/manticore) |  Manticore是一个用于动态二进制分析的原型工具,支持符号执行、污点分析和二进制插桩。 | <!--tool--> | binary | [one_gadget](https://github.com/david942j/one_gadget) |  针对libc的Magic gadget搜索工具。 | <!--tool--> | binary | [preeny](https://github.com/zardus/preeny) |  一组有用的预加载库(为多种架构编译!)。 | <!--tool--> | binary | [pwninit](https://github.com/io12/pwninit) |  用于自动化开始pwn挑战的脚本。 | <!--tool--> | binary | [pwndbg](https://github.com/pwndbg/pwndbg) |  针对gdb的增强环境,尤其适用于pwning。 | <!--tool--> | binary | [pwnsh](https://github.com/zardus/pwnsh) |  用于汇编、利用等方面的有用shell脚本。 | <!--tool--> | binary | [pwntools](https://github.com/Gallopsled/pwntools) |  有用的CTF实用工具。 | <!--tool--> | binary | [qemu](http://qemu.org) |  最新版本的qemu! | <!--tool--><!--slow-test--> | binary | [qiling](https://github.com/qilingframework/qiling) |  一个动态二进制插桩框架。 | <!--tool--> | binary | [qira](http://qira.me) |  并行、无时间限制的调试器。 | <!--tool--><!--slow-test--> | binary | [rappel](https://github.com/yrp604/rappel) |  基于Linux的汇编REPL。 | <!--tool--> | binary | [ropper](https://github.com/sashs/Ropper) |  另一个gadget查找工具。 | <!--tool--> | binary | [rp++](https://github.com/0vercl0k/rp) |  另一个gadget查找工具。 | <!--tool--> | binary | [seccomp-tools](https://github.com/david942j/seccomp-tools) |  为seccomp分析提供强大的工具 | <!--tool--> | binary | [shellnoob](https://github.com/reyammer/shellnoob) |  Shellcode编写辅助工具。 | <!--tool--> | binary | [taintgrind](https://github.com/wmkhoo/taintgrind) |  一个valgrind污点分析工具。 | <!--tool--><!--failing--> | binary | [valgrind](http://valgrind.org) |  一个带有内置工具的动态二进制插桩框架。 | <!--tool--> | binary | [villoc](https://github.com/wapiflapi/villoc) |  堆操作的可视化。 | <!--tool--> | binary | [xrop](https://github.com/acama/xrop) |  Gadget查找工具。 | <!--tool--><!--failing--> | forensics | [firmware-mod-kit](https://code.google.com/p/firmware-mod-kit/) |  固件打包/解包工具。 | <!--tool--> | forensics | [pdf-parser](http://blog.didierstevens.com/programs/pdf-tools/) |  用于挖掘PDF文件的工具 | <!--tool--> | forensics | [peepdf](https://github.com/cert-ee/peepdf) |  分析PDF文档的强大Python工具。 | <!--tool--> | forensics | [scrdec18](https://gist.github.com/bcse/1834878) |  编码的Windows脚本的解码器。 | <!--tool--> | forensics | [volatility](https://github.com/volatilityfoundation/volatility) |  系统内存转储分析器(经典的python2版本;需要python2工具)。 | <!--tool--> | forensics | [volatility3](https://github.com/volatilityfoundation/volatility3) |  系统内存转储分析器(最新版本)。 | <!--tool--> | crypto | [codext](https://github.com/dhondta/python-codext) |  Python编解码扩展,提供用于编码/解码任何内容的CLI工具,包括基于AI的猜解模式。 | <!--tool--> | crypto | [cribdrag](https://github.com/SpiderLabs/cribdrag) |  交互式 crib dragging 工具(用于密码学)。 | <!--tool--> | crypto | [fastcoll](https://www.win.tue.nl/hashclash/) |  一个md5sum碰撞生成器。 | <!--tool--> | crypto | [foresight](https://github.com/ALSchwalm/foresight) |  用于预测随机数生成器输出的工具。运行方式:执行 "foresee"。 | <!--tool--> | crypto | [featherduster](https://github.com/nccgroup/featherduster) |  一个自动化、模块化的密码分析工具。警告:需要python2(可通过ctf-tools安装)。 | <!--tool--> | crypto | [galois](http://web.eecs.utk.edu/~plank/plank/papers/CS-07-593) |  一个快速的伽罗瓦域算术库/工具包。 | <!--tool--> | crypto | [hashpump-partialhash](https://github.com/mheistermann/HashPump-partialhash) |  Hashpump,支持部分未知的哈希。 | <!--tool--> | crypto | [hash-identifier](https://code.google.com/p/hash-identifier/source/checkout) |  简单的哈希算法识别器。 | <!--tool--> | crypto | [libc-database](https://github.com/niklasb/libc-database) |  构建libc偏移数据库以简化漏洞利用。 | <!--tool--><!--slow-test--> | crypto | [msieve](http://sourceforge.net/projects/msieve/) |  Msieve是一个C库,实现了一整套用于分解大整数的算法。 | <!--tool--> | crypto | [nonce-disrespect](https://github.com/nonce-disrespect/nonce-disrespect) |  Nonce-Disrespecting Adversaries:针对TLS中GCM的实际伪造攻击。 | <!--tool--> | crypto | [pemcrack](https://github.com/robertdavidgraham/pemcrack) |  SSL PEM文件破解器。 | <!--tool--> | crypto | [pkcrack](https://www.unix-ag.uni-kl.de/~conrad/krypto/pkcrack.html) |  PkZip加密破解器。 | <!--tool--> | crypto | [reveng](http://reveng.sourceforge.net/) |  CRC查找工具。 | <!--tool--> | crypto | [rsactftool](https://github.com/RsaCtfTool/RsaCtfTool) |  RSA攻击工具。 | <!--tool--> | crypto | [ssh_decoder](https://github.com/jjyg/ssh_decoder) |  用于解码SSH流量的工具。你需要从 `https://launchpad.net/~brightbox/+archive/ubuntu/ruby-ng` 获取 `ruby1.8` 来运行它。使用 `ssh_decoder --help` 获取帮助,因为不带参数运行会导致崩溃。 | <!--tool--> | crypto | [sslsplit](https://github.com/droe/sslsplit) |  SSL/TLS中间人(MITM)。 | <!--tool--> | crypto | [xortool](https://github.com/hellman/xortool) |  XOR分析工具。 | <!--tool--> | crypto | [yafu](http://sourceforge.net/projects/yafu/) |  自动整数分解。 | <!--tool--> | web | [burpsuite](http://portswigger.net/burp) |  用于进行恶意Web操作的Web代理。 | <!--tool--><!--failing--> | web | [commix](https://github.com/stasinopoulos/commix) |  命令注入与利用工具。 | <!--tool--> | web | [mitmproxy](https://mitmproxy.org/) |  命令行Web代理和Python库。 | <!--tool--> | web | [subbrute](https://github.com/TheRook/subbrute) |  一个DNS元查询蜘蛛,枚举DNS记录和子域名。 | <!--tool--> | web | [webgrep](https://github.com/dhondta/webgrep) |  针对网页的 `grep`,具有JS去混淆、CSS解压缩和图像OCR功能。 | <!--tool--> | stego | [steganabara](http://www.caesum.com/handbook/stego.htm) |  另一个图像隐写求解器。 | <!--tool--> | stego | [stegano-tools](https://github.com/dhondta/stegano-tools) |  文本和图像隐写工具集(包括LSB、PVD、PIT)。 | <!--tool--> | stego | [stegdetect](http://www.outguess.org/) |  隐写检测/破解工具。 | <!--tool--> | stego | [stegsolve](http://www.caesum.com/handbook/stego.htm) |  图像隐写求解器。 | <!--tool--> | stego | [stegosaurus](https://github.com/AngelKitty/stegosaurus) |  一个隐写术工具,用于在Python字节码(pyc或pyo)文件中嵌入任意载荷。 | <!--tool--> | stego | [zsteg](https://github.com/zed-0xff/zsteg) |  检测PNG和BMP中隐写隐藏的数据。 | <!--tool--> | misc | [jdgui](http://jd.benow.ca/) |  Java反编译器。 | <!--tool--> | misc | [python2](https://www.python.org/downloads/release/python-2718/) |  当你真的需要它的时候…… | <!--tool--> | misc | [social-analyzer](https://github.com/qeeqbox/social-analyzer) |  社交媒体侦察工具…… | <!--tool--> | misc | [veles](https://codisec.com/veles/) |  二进制数据分析和可视化工具。 | <!--tool--> | misc | [xspy](https://gitlab.com/kalilinux/packages/xspy) |  用于监视X会话的小工具。 | <!--tool--> 还有一些用于非CTF内容的安装程序,以打破单调! | 类别 | 工具 | 描述 | |----------|------|-------------| | game | [df](http://www.bay12games.com/dwarves/) |  矮人要塞!帮助你在CTF后放松的工具! | <!--tool--> | web | [tor-browser](https://www.torproject.org/projects/torbrowser.html.en) |  当你需要从不同IP访问Web挑战时很有用。 | <!--tool--> ## 用法 要使用,请执行:```bash # set up the path /path/to/ctf-tools/bin/manage-tools setup source ~/.bashrc # list the available tools manage-tools list # install gdb, allowing it to try to sudo install dependencies manage-tools -s install gdb # install pwntools, but don't let it sudo install dependencies manage-tools install pwntools # install qemu, but use "nice" to avoid degrading performance during compilation manage-tools -n install qemu # uninstall gdb manage-tools uninstall gdb # uninstall all tools manage-tools uninstall all # search for a tool manage-tools search preload ``` 在可能的情况下,这些工具会使其安装非常自包含(即在 `tool/` 目录中),而且大多数卸载操作只是调用 `git clean`(**注意**,这**并不**谨慎;工具目录下的所有内容,包括你正在处理的工作,都会在卸载时被清除)。 Python 和 Ruby 工具会被安装在特定于工具虚拟环境中。 如果你想向该环境中添加其他包,请查看 `ctf-tools/TOOL/pipx` 或 `ctf-tools/TOOL/gems` 目录。 ## 帮助! 有什么不工作吗? 我(几乎)没有编写这些工具中的任何一个,但如果情况紧急,可以前往 [discord](https://discord.gg/KRcjyn4pBH)。 也许有好心人愿意帮忙! ## Docker 化工具 ### 预构建工具容器 你可以从 [https://hub.docker.com/r/ctftools](https://github.com/zardus/ctf-tools/blob/master/dockerhub) 获取大多数这些工具的预构建容器。 例如:```console $ echo hi | docker run -i ctftools/taintgrind taintgrind --taint-stdin=yes /bin/cat /home/ctf/tools/taintgrind/valgrind-3.21.0/build/bin/valgrind --tool=taintgrind --taint-stdin=yes /bin/cat ==8== Taintgrind, the taint analysis tool ==8== Copyright (C) 2010-2018, and GNU GPL'd, by Wei Ming Khoo. ==8== Using Valgrind-3.21.0 and LibVEX; rerun with -h for copyright info ==8== Command: /bin/cat ==8== 0xFFFFFFFF: _syscall_read | Read:3 | 0x0 | 4a5a000_unknownobj hi ==8== ``` ### 构建你自己的 你可以使用以下命令构建一个 Docker 镜像:```bash git clone https://github.com/zardus/ctf-tools cd ctf-tools docker build -t ctf-tools --build-arg PREINSTALLED=some-tool . ``` 并使用以下命令运行它:```bash docker run -it ctf-tools ``` 构建的镜像将包含已克隆并准备就绪的 ctf-tools 以及您安装的工具。 ## Kali Linux Kali Linux(Sana 和 Rolling 版本),由于手动设置某些库不使用最新可用版本(有时会落后数年),导致某些工具根本无法安装,或者以奇怪的方式失败。 覆盖这些库会破坏 Kali 中包含的其他工具,因此您唯一的解决方案是:要么忍受某些 Kali 工具被破坏,要么使用 Docker,要么另外运行其他发行版,例如 Ubuntu。 ## Adding Tools 要添加一个工具(例如,名为 *toolname*),请执行以下操作: 1. 创建一个 `toolname` 目录。 2. 创建一个 `install` 脚本。 3. 将其添加到 README 中。 4. (可选)如果需要特殊的卸载步骤,请创建一个 `uninstall` 脚本。 ### Install Scripts 安装脚本将以 `$PWD` 为 `toolname` 的方式运行。它应尽可能以自包含的方式将工具安装到此目录中。 理想情况下,应可通过 `git clean` 实现完全卸载。 安装脚本应创建一个 `bin` 目录,并将其可执行文件放入其中。 这些可执行文件将自动链接到仓库的主 `bin` 目录中。 它们可以从任何目录启动,因此不要对 `$0` 的位置做任何假设! ## License 各个工具均使用其自己的许可证进行许可。 至于 ctf-tools 本身,它采用 BSD 2-Clause 许可证进行许可。 如果您觉得它有用,请在 GitHub 上给它加星标 (https://github.com/zardus/ctf-tools)。 祝您好运! # See Also 这里有一个精选的 CTF 工具列表,但没有安装程序:https://github.com/apsdehal/aWEsoMe-cTf。 这里有一个包含许多大型框架的 Vagrant 配置:https://github.com/thebarbershopper/epictreasure。 ## Useful CTF tools in apt repos 随着工具被正式打包,我们转而仅建议您使用 apt 安装它们! | 类别 | 来源 | 工具 | 描述 | |----------|--------|------|-------------| | 二进制 | apt | [aflplusplus](https://github.com/AFLplusplus/AFLplusplus) | 最先进的模糊测试工具。 | | 二进制 | apt | [checksec](https://github.com/slimm609/checksec.sh) | 检查二进制加固设置。 | | 二进制 | apt | [radare2](http://www.radare.org/) | crowell 喜欢的一些疯狂的东西。 | | 二进制 | apt | [rr](http://rr-project.org) | 记录与回放调试框架 | | 二进制 | apt | [wcc](https://github.com/endrazine/wcc) | Witchcraft Compiler Collection 是一组编译工具,用于在 GNU/Linux 和其他 POSIX 平台上执行二进制黑魔法。 | | 取证 | apt | [binwalk](https://github.com/ReFirmLabs/binwalk) | 固件(及任意文件)分析工具。 | | 取证 | apt | [foremost](http://foremost.sourceforge.net/) | 文件雕刻工具。 | | 取证 | apt | [dislocker](http://www.hsc.fr/ressources/outils/dislocker/) | 用于读取 Bitlocker 加密分区的工具。 | | 取证 | apt | [origami-pdf](http://github.com/gdelugre/origami) | PDF 操作工具。 | | 取证 | apt | [testdisk](http://www.cgsecurity.org/wiki/TestDisk) | 用于文件恢复的 Testdisk 和 photorec。 | | Web | apt | [dirb](http://dirb.sourceforge.net/) | Web 路径扫描器。 | | Web | apt | [dirsearch](https://github.com/maurosoria/dirsearch) | Web 路径扫描器。 | | Web | apt | [sqlmap](http://sqlmap.org/) | SQL 注入自动化引擎。 | | 隐写 | apt | [pngtools](https://launchpad.net/ubuntu/+source/pngtools) | PNG 分析工具。 | | 隐写 | apt | [sonic-visualizer](http://www.sonicvisualiser.org/) | 音频文件可视化。 | | 网络 | apt | [dsniff](http://www.monkey.org/~dugsong/dsniff/) | 从 pcaps/网络流中抓取密码和其他数据。 | | 网络 | apt | [bettercap](https://www.bettercap.org/) | 网络恶作剧的瑞士军刀。 | | 杂项 | apt | [z3](https://github.com/Z3Prover/z3) | 来自微软研究的定理证明器。 | | OSINT | apt | [sherlock](https://github.com/sherlock-project/sherlock) | 通过用户名在 400 多个社交网络中搜索社交媒体账户的工具。 | ## Useful CTF tools in docker images 以前,此仓库包含一些包装了 `docker pull` 的脚本。 我们相信您可以自行完成 :-) | 类别 | 来源 | 工具 | 描述 | |----------|--------|------|-------------| | 二进制 | docker | [panda](https://github.com/panda-re/panda) | 架构无关的动态分析平台。 | | 隐写 | Docker | [stego-toolkit](https://github.com/DominicBreuker/stego-toolkit) | 包含数十种隐写工具的 Docker 镜像。 | ## Useful CTF Libraries 以前,此仓库包含库安装程序。 由于库的安装偏好非常定制化(例如,与工具不同,每个库是否需要虚拟环境并不明确),我们已停止提供它们,并在此处链接以供后续参考。 | 类别 | 来源 | 工具 | 描述 | |----------|--------|------|-------------| | 二进制 | 库 | [capstone](http://www.capstone-engine.org) | 多架构反汇编框架。 | | 二进制 | 库 | [keystone](http://www.keystone-engine.org) | 轻量级多架构汇编框架。 | | 二进制 | 库 | [lief](https://lief.quarkslab.com/) | 用于插装可执行格式的库。 | | 二进制 | 库 | [miasm](https://github.com/cea-sec/miasm) | 基于 Python 的逆向工程框架。 | | 二进制 | 库 | [unicorn](http://www.unicorn-engine.org) | 多架构 CPU 模拟器框架。 | | 二进制 | 库 | [virtualsocket](https://github.com/antoniobianchi333/virtualsocket) | 与二进制交互的好用的库。 | | 密码学 | 库 | [cryptanalib3](https://github.com/unicornsasfuel/cryptanalib3) | featherduster 密码分析工具的幸存核心,已更新至 python3。 | | 密码学 | 库 | [python-paddingoracle](https://github.com/mwielgoszewski/python-paddingoracle) | Padding oracle 攻击自动化。 |