Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

扫描不work #3

Open
sevck opened this issue Dec 4, 2019 · 15 comments
Open

扫描不work #3

sevck opened this issue Dec 4, 2019 · 15 comments

Comments

@sevck
Copy link

sevck commented Dec 4, 2019

sevck@MacBook-Pro  ~/git-project/AssetScan   master  python3 AssetScan.py -i 114.55.253.62
_ _ ____
/ \ ___ ___ | |/ | ___ __ _ _ __
/ _ \ / / |/ _ \ _ \ / / ` | '
/ ___ \
_
\ / | ) | (| (| | | | |
/
/ __
/
/_
|_
|
/ ____,|| |_|

			Power by JE2Se   V1.2

~请输入 -h 获取命令帮助~

正在对目标地址进行存活检测~~
_ _ ____
/ \ ___ ___ | |/ | ___ __ _ _ __
/ _ \ / / |/ _ \ _ \ / / ` | '
/ ___ \
_
\ / | ) | (| (| | | | |
/
/ __
/
/_
|_
|
/ ____,|| |_|

请选择存活探测的方式~
(1)Ping探测~(适用于内网内没有禁用Ping)
(2)ARP探测~(适用于内网内禁用Pin探测,不能跨网段)

任意键退出程序~

请选择探测存活方式->1
存活地址已成功写入alive.txt中

_                 _   ____

/ \ ___ ___ | |/ | ___ __ _ _ __
/ _ \ / / |/ _ \ _ \ / / ` | '
/ ___ \
_
\ / | ) | (| (| | | | |
/
/ __
/
/_
|_
|
/ ____,|| |_|

请选择端口扫描的方式~
(1)风险端口探测 (Socket方式,适用于少IP)
(2)风险端口探测 (Masscan方式,适用于多IP)
(3)常规端口探测 (Nmap方式,Nmap的top1000端口)
(4)全端口探测 (Socket方式,适用于少IP,准确率高)
(5)全端口探测 (Masscan方式,适用于多IP,存在误报率)

任意键退出程序,并生成当前进度报告~

请填写扫描方式->3
正在目标常用端口进行探测扫描~~

_                 _   ____

/ \ ___ ___ | |/ | ___ __ _ _ __
/ _ \ / / |/ _ \ _ \ / / ` | '
/ ___ \
_
\ / | ) | (| (| | | | |
/
/ __
/
/_
|_
|
/ ____,|| |_|

是否进行风险端口漏洞探测~
(1)探测风险端口

任意键退出程序,并生成当前进度报告~

请选择是否进行漏洞探测->1
正在生成报告~
生成报告成功~
报告地址:./report/AssetScan_201912416494.docx
扫描结束~
sevck@MacBook-Pro  ~/git-project/AssetScan   master 

@sevck
Copy link
Author

sevck commented Dec 4, 2019

默认不选择 崩溃
✘ sevck@MacBook-Pro  ~/git-project/AssetScan   master  python3 AssetScan.py -i 121.42.182.208
_ _ ____
/ \ ___ ___ | |/ | ___ __ _ _ __
/ _ \ / / |/ _ \ _ \ / / ` | '
/ ___ \
_
\ / | ) | (| (| | | | |
/
/ __
/
/_
|_
|
/ ____,|| |_|

			Power by JE2Se   V1.2

~请输入 -h 获取命令帮助~

正在对目标地址进行存活检测~~
_ _ ____
/ \ ___ ___ | |/ | ___ __ _ _ __
/ _ \ / / |/ _ \ _ \ / / ` | '
/ ___ \
_
\ / | ) | (| (| | | | |
/
/ __
/
/_
|_
|
/ ____,|| |_|

请选择存活探测的方式~
(1)Ping探测~(适用于内网内没有禁用Ping)
(2)ARP探测~(适用于内网内禁用Pin探测,不能跨网段)

任意键退出程序~

请选择探测存活方式->
存活地址已成功写入alive.txt中

Traceback (most recent call last):
File "AssetScan.py", line 177, in
father(iplist)
File "AssetScan.py", line 70, in father
ipdata = open("./file/alive.txt","r")
FileNotFoundError: [Errno 2] No such file or directory: './file/alive.txt'

@JE2Se
Copy link
Owner

JE2Se commented Dec 4, 2019

好的 感谢反馈,马上处理

@sevck
Copy link
Author

sevck commented Dec 4, 2019

CIDR IP报错。。
sevck@MacBook-Pro  ~/git-project/AssetScan   master  python3 AssetScan.py -i 121.42.182.1/24
_ _ ____
/ \ ___ ___ | |/ | ___ __ _ _ __
/ _ \ / / |/ _ \ _ \ / / ` | '
/ ___ \
_
\ / | ) | (| (| | | | |
/
/ __
/
/_
|_
|
/ ____,|| |_|

			Power by JE2Se   V1.2

~请输入 -h 获取命令帮助~

Traceback (most recent call last):
File "AssetScan.py", line 176, in
iplist = IPinfo(ip)
File "/Users/sevck/git-project/AssetScan/lib/iplist.py", line 79, in IPinfo
IPauto(info)
File "/Users/sevck/git-project/AssetScan/lib/iplist.py", line 16, in IPauto
ipr = IP(ipl)
File "/Library/Frameworks/Python.framework/Versions/3.6/lib/python3.6/site-packages/IPy.py", line 260, in init
raise ValueError("%s has invalid prefix length (%s)" % (repr(self), self._prefixlen))
ValueError: IP('121.42.182.1/24') has invalid prefix length (24)

@JE2Se
Copy link
Owner

JE2Se commented Dec 4, 2019

感谢提BUG,已修复

@sevck
Copy link
Author

sevck commented Dec 5, 2019

image
不能运行

@sevck
Copy link
Author

sevck commented Dec 5, 2019

代码锁紧写错了。。

@sevck
Copy link
Author

sevck commented Dec 5, 2019

image
依旧不work

@sevck
Copy link
Author

sevck commented Dec 5, 2019

image
机器禁ping,arp无表,那不会扫么。。 端口也识别不出来,scan也不扫描,直接出报告

@JE2Se
Copy link
Owner

JE2Se commented Dec 5, 2019

目前的话,你要扫网段的话,暂时还不支持192.168.1.1/24格式,今支持192.168.1.0/24
缩进已更改,感谢
分享一下设计想发,程序仅第一次存活检测异常会退出程序,接下来的风险端口检测,端口开放检测如果存活检测不管你输入什么选项都会执行,出报告,设计场景为,如果我只想检测存活,不探测漏洞,我可以在检测存活后,输入任意键,非1或2直接生成报告,但是如果你alive.py没有报错,但是没有扫描出存活的地址到alive.txt,那么其余的徐香都会赋值默认值,导致出报告,
工具的核心,如果你扫描不出存活,其他的都无法工作,会赋值默认值,出报告,
当前仅支持ping,arp,如果你禁ping,禁arp,程序暂时无法继续工作。

@devsecops-SRC
Copy link

大佬微信 只检测口令 不检测其他漏洞

@devsecops-SRC
Copy link

image

@JE2Se
Copy link
Owner

JE2Se commented Dec 6, 2019

检测其他漏洞,只不过不存在罢了

@devsecops-SRC
Copy link

存在漏洞 没有检测出来 redis mogodb等等

@JE2Se
Copy link
Owner

JE2Se commented Dec 6, 2019

redis跟mongo目前只针对未授权测试。其他的没有检测,后期回增加

@WMdoit
Copy link

WMdoit commented Jul 27, 2020

win10电脑需要另外安装masscan和nmap吗?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants