今天给大家介绍一款名叫One-Lin3r的渗透测试工具工具,这款工具可谓是“懒人”的福音,因为只需要输入一行命令,它就可以帮助我们完成渗透测试任务。
One-Lin3r是一款简单的轻量级框架,而该工具的灵感来自于Metasploit的web-delivery模块。该工具提供了多种命令,例如:
Payload数据库目前还不算非常大,因为该工具只是第一个版本,但是随着代码的更新以及社区的贡献,数据库将会变得越来越大。
命令行参数:
usage:One-Lin3r.py [-h] [-r R] [-x X] [-q]
optionalarguments:
-h, --help show this help message and exit
-r Execute a resource file (history file).
-x Execute a specific command (use ; for multiples).
-q Quit mode (no banner).
框架命令:
Command Description
-------- -------------
help/? Show this help menu
list/show List payloads you can use in theattack.
search <Keyword> Search payloads for a specific one
use <payload> Use an available payload
info <payload> Get information about an available payload
banner Display banner
reload/refresh Reload the payloads database
check Prints the core version anddatabase version then check for them online.
history Display command line mostimportant history from the beginning
save_history Save command line history to a file
exit/quit Exit the framework
为了保证该工具能够正常运行,用户需满足以下条件:
Python3.x 或2.x (最好是3) Linux(已在Kali Linux下测试成功)或Windows系统(还未在macOS平台上进行过测试,但理论上是可以正常运行的)
针对Windows平台:(下载ZIP文件并解压缩)
cd One-Lin3r-master
python-m pip install -r win_requirements.txt
python One-Lin3r.py -h
针对Linux平台:
git clone https://github.com/D4Vinci/One-Lin3r.git
chmod 777 -R One-Lin3r
cd One-Lin3r
pip install -r requirements.txt
python One-Lin3r.py -h
* 参考来源:github,FB小编Alpha_h4ck编译,转载请注明来自FreeBuf.COM