结合渗透测试最常见就是单个域名扫指纹,自动子域名查找、获取所有子域名的IP,自动C段IP查找相同子域名,利用有效IP扫端口。
常见端口库扫描
service_list = {
21:"FTP",
22:"ssh",
25:"SMTP",
80:"web",
139:"Samba",
143:"IMAP",
161:"SNMP",
389:"Ldap目录访问协议",
443:"https",
445:"Microsoft SMB",
465:"SMTP SSL",
513:"rlogin",
546:"DHCP failover",
873:"rsync",
993:"IMAPS",
1080:"socks proxy",
1194:"OpenVPN",
1352:"Lotus domino",
1433:"MSSQL",
1521:"Oracle default",
2049:"Nfs",
2181:"ZooKeeper",
2375:"Docker",
3306:"MySQL",
3389:"Remote Desktop",
4440:"rundeck",
4848:"GlassFish控制台",
5000:"SysBase/DB2",
5432:"PostgreSQL",
5632:"pcanywhere",
5900:"vnc",
5984:"Apache CouchDB",
6082:"varnish",
6984:"Apache CouchDB SSL",
6379:"Redis",
7001:"weblogic_Server isten port",
7002:"Server Listen SSL Port",
8069:"zabbix",
8080:"web,jboss,tomcat etc..",
8089:"Jboss/Tomcat/Resin",
8083:"influxDB Web admin",
8086:"influxdb HTTP API",
8095:"Atlassian Crowd",
8161:"activemq",
8888:"Jupyter Notebook",
8983:"solr",
9000:"fastcgi",
9043:"VMware ESXI vsphere",
9080:"websphere http",
9083:"Hive default",
9090:"websphere admin",
9200:"Elsaticsearch http",
9300:"Elsaticsearch Node1",
10000:"HiveServer2",
11211:"memcached",
27017:"MongoDB",
50000:"SAP command excute",
50060:"hadoop web",
50070:"hadoop default",
60000:"HBase Master",
60010:"hbase.master.info.bindAddress",
}
利用文章
- ZooKeeper http://www.polaris-lab.com/index.php/archives/41/
- Docker http://www.polaris-lab.com/index.php/archives/253/
- 常见未授权漏洞 https://xz.aliyun.com/t/6103
- 信息泄露V1.1.pdf https://www.yuque.com/desm0nd/osrdpc/uebfz5
在线端口扫描服务
- yougetsignal | http://www.yougetsignal.com
- viewdns | http://viewdns.info
- hackertarget | https://hackertarget.com
- ipfingerprints | http://www.ipfingerprints.com
- pingeu | http://ping.eu
- spiderip | https://spiderip.com
- t1shopper | http://www.t1shopper.com
- standingtech | https://portscanner.standingtech.com
python自带库端口扫描
- nmap扫描端口 https://www.cnblogs.com/17bdw/p/10372236.html#_label2_0
- githubx项目 https://github.com/search?l=Python&q=port+scan&type=Repositories
考虑CDN
国外的公有云厂商IP地址公开列表:
- Azure https://www.microsoft.com/en-us/download/details.aspx?id=56519
- AWS https://docs.aws.amazon.com/general/latest/gr/aws-ip-ranges.html#aws-ip-download
- Google Cloud https://cloud.google.com/compute/docs/faq#find_ip_range
- IBM https://cloud.ibm.com/docs/infrastructure/virtual-router-appliance?topic=hardware-firewall-dedicated-ibm-cloud-ip-ranges