当前位置:网站首页>入侵检测——Uniscan
入侵检测——Uniscan
2022-07-08 01:13:00 【lainwith】
介绍
uniscan是一个外表低调内心狂放的WEB扫描器,其功能却远不仅限于WEB一域。除了常规WEB扫描器该有的所有功能全部具备之外,uniscan还提供了很多信息收集的功能,例如网络层路径追踪、端口发现、指纹探测、漏洞扫描等主动信息收集功能,以及DNS域名解析、搜索引擎信息收集等被动信息收集能力。甚至它还可以作为压力测试工具用来评估服务器的性能极限。uniscan-gui是它的图形化界面版本,功能与命令行界面的uniscan完全一致。
个人真实体验:不咋地。项目地址:https://github.com/poerschke/Uniscan,可以看到是一个很有历史的工具
使用
安装使用:apt install uniscan
(工具分为GUI版本和命令行),直接输入uniscan可以看到使用方法。
这里拿Web For Pentester靶机来试试,如下图
检测规则
工具的特征还是蛮明显的
得到snort检测规则:
alert tcp any any -> any any (msg:"1"; flow:to_server; content:"TE|3a 20 64 65 66 6c 61 74 65 2c 67 7a 69 70 3b 71 3d 30 2e 33|"; http_header; fast_pattern:only; content:"Connection|3a 20 54 45 2c 20 63 6c 6f 73 65|"; http_header; pcre:"/User-Agent\x3a\s\x22Mozilla\x2f\d\x2e\d\x28x11\x3blinuxx86_64\x29AppleWebKit\x2f[\d\x2e]+?\x28KHTML\x2clikeGecko\x29chrome\x2f[\d\x2e]+?safari\x2f[\d\x2e]+?\x22/iH"; detection_filter:track by_dst, count 20, seconds 10; metadata:service http; sid:1; rev:1;)
边栏推荐
- 线程死锁——死锁产生的条件
- [knowledge map paper] r2d2: knowledge map reasoning based on debate dynamics
- XXL job of distributed timed tasks
- 2022年5月互联网医疗领域月度观察
- Key points of data link layer and network layer protocol
- The circuit is shown in the figure, r1=2k Ω, r2=2k Ω, r3=4k Ω, rf=4k Ω. Find the expression of the relationship between output and input.
- 很多小伙伴不太了解ORM框架的底层原理,这不,冰河带你10分钟手撸一个极简版ORM框架(赶快收藏吧)
- Completion report of communication software development and Application
- Why did MySQL query not go to the index? This article will give you a comprehensive analysis
- [recommendation system paper reading] recommendation simulation user feedback based on Reinforcement Learning
猜你喜欢
Semantic segmentation | learning record (2) transpose convolution
LeetCode精选200道--链表篇
咋吃都不胖的朋友,Nature告诉你原因:是基因突变了
Unity 射线与碰撞范围检测【踩坑记录】
leetcode 866. Prime Palindrome | 866. prime palindromes
[knowledge map paper] r2d2: knowledge map reasoning based on debate dynamics
文盘Rust -- 给程序加个日志
Completion report of communication software development and Application
#797div3 A---C
数据链路层及网络层协议要点
随机推荐
From starfish OS' continued deflationary consumption of SFO, the value of SFO in the long run
For friends who are not fat at all, nature tells you the reason: it is a genetic mutation
VR/AR 的产业发展与技术实现
QT -- create QT program
Vim 字符串替换
[knowledge map paper] attnpath: integrate the graph attention mechanism into knowledge graph reasoning based on deep reinforcement
Disk rust -- add a log to the program
Force buckle 4_ 412. Fizz Buzz
关于TXE和TC标志位的小知识
BizDevOps与DevOps的关系
leetcode 869. Reordered Power of 2 | 869. Reorder to a power of 2 (state compression)
直接加比较合适
#797div3 A---C
CV2 read video - and save image or video
PHP calculates personal income tax
JVM memory and garbage collection-3-direct memory
阿南的判断
Completion report of communication software development and Application
Spock单元测试框架介绍及在美团优选的实践_第三章(void无返回值方法mock方式)
Deep understanding of cross entropy loss function