{"id":154,"date":"2023-08-01T10:00:00","date_gmt":"2023-08-01T02:00:00","guid":{"rendered":"http:\/\/www.redspear.cn\/index.php\/2023\/08\/01\/%e6%b8%97%e9%80%8f%e6%b5%8b%e8%af%95%e4%bf%a1%e6%81%af%e6%94%b6%e9%9b%86%e6%96%b9%e6%b3%95%e6%80%bb%e7%bb%93\/"},"modified":"2026-06-01T19:08:15","modified_gmt":"2026-06-01T11:08:15","slug":"%e6%b8%97%e9%80%8f%e6%b5%8b%e8%af%95%e4%bf%a1%e6%81%af%e6%94%b6%e9%9b%86%e6%96%b9%e6%b3%95%e6%80%bb%e7%bb%93","status":"publish","type":"post","link":"https:\/\/www.redspear.cn\/index.php\/2023\/08\/01\/%e6%b8%97%e9%80%8f%e6%b5%8b%e8%af%95%e4%bf%a1%e6%81%af%e6%94%b6%e9%9b%86%e6%96%b9%e6%b3%95%e6%80%bb%e7%bb%93\/","title":{"rendered":"\u4fe1\u606f\u6536\u96c6"},"content":{"rendered":"<h1>\u6e17\u900f\u6d4b\u8bd5\u4fe1\u606f\u6536\u96c6\u65b9\u6cd5\u603b\u7ed3<\/h1>\n<h2>\u6982\u8ff0<\/h2>\n<p>\u4fe1\u606f\u6536\u96c6\u662f\u6e17\u900f\u6d4b\u8bd5\u7684\u7b2c\u4e00\u6b65\uff0c\u4e5f\u662f\u6700\u5173\u952e\u7684\u4e00\u6b65\u3002\u6536\u96c6\u5230\u7684\u4fe1\u606f\u8d8a\u5168\u9762\uff0c\u540e\u7eed\u653b\u51fb\u7684\u6210\u529f\u7387\u8d8a\u9ad8\u3002\u4fe1\u606f\u6536\u96c6\u5206\u4e3a<strong>\u88ab\u52a8\u6536\u96c6<\/strong>\uff08\u4e0d\u76f4\u63a5\u63a5\u89e6\u76ee\u6807\uff09\u548c<strong>\u4e3b\u52a8\u6536\u96c6<\/strong>\uff08\u76f4\u63a5\u4e0e\u76ee\u6807\u4ea4\u4e92\uff09\u4e24\u79cd\u65b9\u5f0f\u3002<\/p>\n<h2>\u4e00\u3001\u4f01\u4e1a\u4fe1\u606f\u6536\u96c6<\/h2>\n<h3>1. \u4f01\u4e1a\u57fa\u672c\u4fe1\u606f<\/h3>\n<ul>\n<li><strong>\u5de5\u5177\uff1a<\/strong>\u4f01\u67e5\u67e5\u3001\u5929\u773c\u67e5\u3001\u7231\u4f01\u67e5<\/li>\n<li><strong>\u6536\u96c6\u5185\u5bb9\uff1a<\/strong>\n<ul>\n<li>\u516c\u53f8\u5168\u79f0\u3001\u7edf\u4e00\u793e\u4f1a\u4fe1\u7528\u4ee3\u7801<\/li>\n<li>\u6cd5\u4eba\u4fe1\u606f\u3001\u80a1\u4e1c\u4fe1\u606f<\/li>\n<li>\u5b50\u516c\u53f8\u3001\u5173\u8054\u516c\u53f8<\/li>\n<li>\u5907\u6848\u57df\u540d<\/li>\n<li>\u90ae\u7bb1\u3001\u7535\u8bdd<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h3>2. \u5907\u6848\u4fe1\u606f\u67e5\u8be2<\/h3>\n<ul>\n<li><strong>\u5de5\u5177\uff1a<\/strong>ICP\u5907\u6848\u67e5\u8be2\u3001\u7ad9\u957f\u5de5\u5177<\/li>\n<li><strong>\u7528\u9014\uff1a<\/strong>\u83b7\u53d6\u76ee\u6807\u6240\u6709\u5907\u6848\u57df\u540d<\/li>\n<\/ul>\n<h2>\u4e8c\u3001\u57df\u540d\u4fe1\u606f\u6536\u96c6<\/h2>\n<h3>1. \u5b50\u57df\u540d\u6536\u96c6<\/h3>\n<pre><code># \u5e38\u7528\u5de5\u5177\nOneForAll\uff1apython3 oneforall.py --target example.com run\nsubfinder\uff1asubfinder -d example.com\nLayer\u5b50\u57df\u540d\u6316\u6398\u673a\nSublist3r\uff1apython sublist3r.py -d example.com\n\n# \u5728\u7ebf\u5e73\u53f0\nhttps:\/\/phpinfo.me\/domain\/\nhttps:\/\/www.virustotal.com\/\nhttps:\/\/crt.sh\/\uff08\u8bc1\u4e66\u900f\u660e\u5ea6\u67e5\u8be2\uff09<\/code><\/pre>\n<h3>2. \u57df\u540d\u89e3\u6790<\/h3>\n<pre><code># \u67e5\u8be2A\u8bb0\u5f55\u3001MX\u8bb0\u5f55\u3001CNAME\u8bb0\u5f55\nnslookup -type=A example.com\ndig example.com A\ndig example.com MX<\/code><\/pre>\n<h2>\u4e09\u3001IP\u4fe1\u606f\u6536\u96c6<\/h2>\n<h3>1. IP\u53cd\u67e5\u57df\u540d<\/h3>\n<ul>\n<li><strong>\u5de5\u5177\uff1a<\/strong>\u7ad9\u957f\u5de5\u5177IP\u53cd\u67e5\u3001\u5fae\u6b65\u5728\u7ebf<\/li>\n<li><strong>\u7528\u9014\uff1a<\/strong>\u67e5\u627e\u540c\u670d\u52a1\u5668\u5176\u4ed6\u7f51\u7ad9<\/li>\n<\/ul>\n<h3>2. C\u6bb5\u626b\u63cf<\/h3>\n<pre><code># nmap\u626b\u63cfC\u6bb5\u5b58\u6d3b\u4e3b\u673a\nnmap -sn 192.168.1.0\/24\n\n# masscan\u5feb\u901f\u626b\u63cf\u7aef\u53e3\nmasscan 192.168.1.0\/24 -p 80,443,8080 --rate=1000<\/code><\/pre>\n<h3>3. CDN\u8bc6\u522b<\/h3>\n<pre><code># \u591a\u5730ping\u68c0\u6d4bCDN\nhttps:\/\/ping.chinaz.com\/\nhttps:\/\/www.17ce.com\/\n\n# \u7ed5\u8fc7CDN\u627e\u771f\u5b9eIP\n1. \u5b50\u57df\u540d\u63a2\u6d4b\uff08\u53ef\u80fd\u6ca1\u8d70CDN\uff09\n2. \u5386\u53f2DNS\u8bb0\u5f55\u67e5\u8be2\n3. \u90ae\u4ef6\u670d\u52a1\u5668IP\n4. \u56fd\u5916\u4e3b\u673aping<\/code><\/pre>\n<h2>\u56db\u3001\u7aef\u53e3\u670d\u52a1\u6536\u96c6<\/h2>\n<h3>1. \u7aef\u53e3\u626b\u63cf<\/h3>\n<pre><code># nmap\u5168\u7aef\u53e3\u626b\u63cf\nnmap -sV -sC -p 1-65535 target.com\n\n# \u5feb\u901f\u626b\u63cf\u5e38\u7528\u7aef\u53e3\nnmap -sV -top-ports 1000 target.com\n\n# masscan\u5feb\u901f\u626b\u63cf\nmasscan target.com -p 1-65535 --rate=10000<\/code><\/pre>\n<h3>2. \u5e38\u89c1\u7aef\u53e3\u53ca\u5229\u7528<\/h3>\n<table>\n<tr>\n<th>\u7aef\u53e3<\/th>\n<th>\u670d\u52a1<\/th>\n<th>\u5229\u7528\u65b9\u5411<\/th>\n<\/tr>\n<tr>\n<td>21\/22<\/td>\n<td>FTP\/SSH<\/td>\n<td>\u533f\u540d\u767b\u5f55\u3001\u7206\u7834\u3001\u96a7\u9053\u8f6c\u53d1<\/td>\n<\/tr>\n<tr>\n<td>80\/443\/8080<\/td>\n<td>Web\u670d\u52a1<\/td>\n<td>Web\u6f0f\u6d1e\u653b\u51fb<\/td>\n<\/tr>\n<tr>\n<td>3306<\/td>\n<td>MySQL<\/td>\n<td>\u7206\u7834\u3001\u63d0\u6743<\/td>\n<\/tr>\n<tr>\n<td>6379<\/td>\n<td>Redis<\/td>\n<td>\u672a\u6388\u6743\u8bbf\u95ee<\/td>\n<\/tr>\n<tr>\n<td>7001\/7002<\/td>\n<td>WebLogic<\/td>\n<td>\u53cd\u5e8f\u5217\u5316\u3001\u5f31\u53e3\u4ee4<\/td>\n<\/tr>\n<tr>\n<td>27017<\/td>\n<td>MongoDB<\/td>\n<td>\u672a\u6388\u6743\u8bbf\u95ee<\/td>\n<\/tr>\n<\/table>\n<h2>\u4e94\u3001Web\u6307\u7eb9\u8bc6\u522b<\/h2>\n<h3>1. \u6846\u67b6\u8bc6\u522b<\/h3>\n<ul>\n<li><strong>\u5de5\u5177\uff1a<\/strong>Wappalyzer\u3001WhatWeb\u3001\u4e91\u6089\u6307\u7eb9<\/li>\n<li><strong>\u8bc6\u522b\u5185\u5bb9\uff1a<\/strong>\n<ul>\n<li>CMS\u7c7b\u578b\uff08WordPress\u3001ThinkPHP\u3001Spring Boot\uff09<\/li>\n<li>\u4e2d\u95f4\u4ef6\uff08Tomcat\u3001Nginx\u3001Apache\uff09<\/li>\n<li>\u524d\u7aef\u6846\u67b6\uff08jQuery\u3001Vue\u3001React\uff09<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h3>2. \u7279\u5f81\u6536\u96c6<\/h3>\n<ul>\n<li>robots.txt<\/li>\n<li>sitemap.xml<\/li>\n<li>404\u9875\u9762\u7279\u5f81<\/li>\n<li>HTTP\u54cd\u5e94\u5934<\/li>\n<\/ul>\n<h2>\u516d\u3001\u76ee\u5f55\u6587\u4ef6\u6536\u96c6<\/h2>\n<h3>1. \u76ee\u5f55\u626b\u63cf<\/h3>\n<pre><code># \u5e38\u7528\u5de5\u5177\ndirsearch\uff1apython3 dirsearch.py -u target.com\ngobuster\uff1agobuster dir -u target.com -w wordlist.txt\n\u5fa1\u5251\u540e\u53f0\u626b\u63cf\ndirmap<\/code><\/pre>\n<h3>2. \u654f\u611f\u6587\u4ef6<\/h3>\n<ul>\n<li>\/admin\u3001\/manager \u2014 \u7ba1\u7406\u540e\u53f0<\/li>\n<li>\/backup\u3001\/db \u2014 \u5907\u4efd\u6587\u4ef6<\/li>\n<li>\/.git \u2014 Git\u6cc4\u9732<\/li>\n<li>\/.svn \u2014 SVN\u6cc4\u9732<\/li>\n<li>\/robots.txt \u2014 \u722c\u866b\u89c4\u5219<\/li>\n<li>\/.DS_Store \u2014 Mac\u76ee\u5f55\u7f13\u5b58<\/li>\n<li>\/WEB-INF\/web.xml \u2014 Java\u914d\u7f6e\u6587\u4ef6<\/li>\n<\/ul>\n<h2>\u4e03\u3001JS\u6587\u4ef6\u5206\u6790<\/h2>\n<h3>1. JS\u4fe1\u606f\u63d0\u53d6<\/h3>\n<pre><code># \u5de5\u5177\nJSFinder\uff1apython3 JSFinder.py -u target.com\nLinkFinder\uff1apython3 linkfinder.py -i target.com -o cli\n\n# \u67e5\u627e\u5185\u5bb9\nAPI\u63a5\u53e3\n\u9690\u85cf\u53c2\u6570\n\u786c\u7f16\u7801\u5bc6\u94a5\u3001Token\n\u5185\u7f51\u5730\u5740<\/code><\/pre>\n<h2>\u516b\u3001\u641c\u7d22\u5f15\u64ce\u5229\u7528<\/h2>\n<h3>1. Google Hacking<\/h3>\n<pre><code># \u5e38\u7528\u8bed\u6cd5\nsite:example.com \u2014 \u9650\u5b9a\u7f51\u7ad9\ninurl:admin \u2014 URL\u5305\u542badmin\nintitle:\u540e\u53f0 \u2014 \u6807\u9898\u5305\u542b\u540e\u53f0\nfiletype:pdf \u2014 \u6587\u4ef6\u7c7b\u578b\nintext:password \u2014 \u6b63\u6587\u5305\u542bpassword\n\n# \u7ec4\u5408\u4f7f\u7528\nsite:example.com filetype:sql\nsite:example.com inurl:login\nsite:example.com intext:\u6570\u636e\u5e93<\/code><\/pre>\n<h3>2. \u7f51\u7edc\u7a7a\u95f4\u641c\u7d22\u5f15\u64ce<\/h3>\n<ul>\n<li><strong>FOFA\uff1a<\/strong>https:\/\/fofa.info\/<\/li>\n<li><strong>ZoomEye\uff1a<\/strong>https:\/\/www.zoomeye.org\/<\/li>\n<li><strong>Shodan\uff1a<\/strong>https:\/\/www.shodan.io\/<\/li>\n<\/ul>\n<h2>\u4e5d\u3001\u81ea\u52a8\u5316\u5de5\u5177<\/h2>\n<h3>1. \u706f\u5854ARL<\/h3>\n<pre><code># \u81ea\u52a8\u5316\u8d44\u4ea7\u6536\u96c6+\u6f0f\u6d1e\u626b\u63cf\ndocker pull tophant\/arl\ndocker-compose up -d<\/code><\/pre>\n<h3>2. \u8d44\u4ea7\u7ba1\u7406\u5e73\u53f0<\/h3>\n<ul>\n<li>\u706f\u5854ARL<\/li>\n<li>LangSrc<\/li>\n<li>AssetScan<\/li>\n<\/ul>\n<h2>\u603b\u7ed3<\/h2>\n<p>\u4fe1\u606f\u6536\u96c6\u7684\u5b8c\u6574\u6d41\u7a0b\uff1a<\/p>\n<ol>\n<li>\u4f01\u4e1a\u4fe1\u606f \u2192 \u786e\u5b9a\u76ee\u6807\u8303\u56f4<\/li>\n<li>\u57df\u540d\u6536\u96c6 \u2192 \u5b50\u57df\u540d\u3001\u5907\u6848\u57df\u540d<\/li>\n<li>IP\u6536\u96c6 \u2192 \u771f\u5b9eIP\u3001C\u6bb5<\/li>\n<li>\u7aef\u53e3\u626b\u63cf \u2192 \u5f00\u653e\u670d\u52a1<\/li>\n<li>\u6307\u7eb9\u8bc6\u522b \u2192 \u6846\u67b6\u3001\u4e2d\u95f4\u4ef6<\/li>\n<li>\u76ee\u5f55\u626b\u63cf \u2192 \u654f\u611f\u6587\u4ef6\u3001\u540e\u53f0<\/li>\n<li>JS\u5206\u6790 \u2192 API\u63a5\u53e3\u3001\u9690\u85cf\u53c2\u6570<\/li>\n<\/ol>\n<blockquote>\n<p>\u6e17\u900f\u7684\u672c\u8d28\u5c31\u662f\u4fe1\u606f\u6536\u96c6\uff0c\u6536\u96c6\u5f97\u8d8a\u5168\u9762\uff0c\u6210\u529f\u7684\u6982\u7387\u8d8a\u9ad8\u3002<\/p>\n<\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>\u6e17\u900f\u6d4b\u8bd5\u4fe1\u606f\u6536\u96c6\u65b9\u6cd5\u603b\u7ed3 \u6982\u8ff0 \u4fe1\u606f\u6536\u96c6\u662f\u6e17\u900f\u6d4b\u8bd5\u7684\u7b2c\u4e00\u6b65\uff0c\u4e5f\u662f\u6700\u5173\u952e\u7684\u4e00\u6b65\u3002\u6536\u96c6\u5230\u7684\u4fe1\u606f\u8d8a\u5168\u9762\uff0c\u540e\u7eed\u653b\u51fb\u7684\u6210 &hellip; <\/p>\n","protected":false},"author":3,"featured_media":177,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[],"class_list":["post-154","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-pentest-basic"],"_links":{"self":[{"href":"https:\/\/www.redspear.cn\/index.php\/wp-json\/wp\/v2\/posts\/154","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.redspear.cn\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.redspear.cn\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.redspear.cn\/index.php\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.redspear.cn\/index.php\/wp-json\/wp\/v2\/comments?post=154"}],"version-history":[{"count":2,"href":"https:\/\/www.redspear.cn\/index.php\/wp-json\/wp\/v2\/posts\/154\/revisions"}],"predecessor-version":[{"id":202,"href":"https:\/\/www.redspear.cn\/index.php\/wp-json\/wp\/v2\/posts\/154\/revisions\/202"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.redspear.cn\/index.php\/wp-json\/wp\/v2\/media\/177"}],"wp:attachment":[{"href":"https:\/\/www.redspear.cn\/index.php\/wp-json\/wp\/v2\/media?parent=154"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.redspear.cn\/index.php\/wp-json\/wp\/v2\/categories?post=154"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.redspear.cn\/index.php\/wp-json\/wp\/v2\/tags?post=154"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}