January 18, 2025

scan4all-一款支持15000+POC的漏洞扫描工具

15000+POC漏洞扫描工具

POC是什么

Proof Of Concept的缩写。在黑客圈指:观点验证程序。运行这个程序就可以得出预期的结果,也就验证了观点。

链接:

https://github.com/GhostTroops/scan4all

下载链接

https://github.com/GhostTroops/scan4all/releases

安装教程

https://github.com/GhostTroops/scan4all/blob/main/static/Installation.md

编译

sudo apt install -y libpcap-dev golang git
git clone https://github.com/hktalent/scan4all.git
cd scan4all
go build

1.在运行scan4all之前,你必须先安装libpcap库

1
2
3
4
5
6
7
8
9
# ubuntu、linux
apt update
apt install -yy libpcap0.8-dev
sudo apt install -y libpcap-dev
# cent os
yum install -yy glibc-devel.x86_64
yum install -yy libpcap
# mac os
brew install libpcap

2.前往 https://github.com/hktalent/scan4all/releases/ 下载scan4all最新版运行:

nmap官网

https://nmap.org/

ubuntu\kali–debian系列

sudo apt-get install nmap

sudo apt-get install golang-go

centos\renhat-红帽系列

sudo yum install -y nmap

sudo yum install -y golang && sudo yum install -y go

manjaro/blackarch–arch系列

sudo pacman -S nmap

sudo pacman -S golang-go && sudo pacman -S golang-dev

aur

yay -S nmap

特性

Vulnerabilities Scan;15000+PoC漏洞扫描;[ 23 ] 种应用弱口令爆破;7000+Web指纹;146种协议90000+规则Port扫描;Fuzz、HW打点、BugBounty神器…

图片

1
export PPSSWWDD=yourRootPswd

更多参考:config/doNmapScan.sh 默认使用 naabu 完成端口扫描 -stats=true 可以查看扫描进度 能否不扫描端口 ?跳过端口扫描,意外做基于端口指纹进行密码爆破的检测将失效,密码破解功能也一并被跳过

1
noScan=true  ./scan4all -l list.txt  -v
1
./scan4all -l nmapScanResults.xml  -v
TAG COUNT AUTHOR COUNT DIRECTORY COUNT SEVERITY COUNT TYPE COUNT
cve 1430 daffainfo 631 cves 1407 info 1474 http 3858
panel 655 dhiyaneshdk 584 exposed-panels 662 high 1009 file 76
edb 563 pikpikcu 329 vulnerabilities 509 medium 818 network 51
lfi 509 pdteam 269 technologies 282 critical 478 dns 17
xss 491 geeknik 187 exposures 275 low 225
wordpress 419 dwisiswant0 169 misconfiguration 237 unknown 11
exposure 407 0x_akoko 165 token-spray 230
cve2021 352 princechaddha 151 workflows 189
rce 337 ritikchaddha 137 default-logins 103
wp-plugin 316 pussycat0x 133 file 76

281 directories, 3922 files.

1
mkdir ~/MyWork/;cd ~/MyWork/;git clone  https://github.com/hktalent/log4j-scan

图片

About this Post

This post is written by 杨CC, licensed under CC BY-NC 4.0.

#信息收集-漏扫类