常见扫描工具特征
nmap
404会请求nice ports,/Trinity.txt.bakhttpx
默认UA,但是httpx支持随机UA
httpx - Open-source project (github.com/projectdiscovery/httpx)AWVS
匹配请求中包含域名bxss.meSqlmap
匹配UA,sqlmap同样可修改 “%s (%s)” % (VERSION_STRING, SITE)
即匹配https://sqlmap.orgRsas
匹配UA,Rsasmasscan
匹配UA,User-Agent: masscan/1.3 (https://github.com/robertdavidgraham/masscan)Appscan
Appscan第一个请求是提交自己的MAC地址
GET /AppScan_fingerprint/MAC_ADDRESS_真实的MAC地址.html HTTP/1.0nessus
匹配UA,nessusjexboss
请求体,http://webshell.jexboss.net/jsp_version.txt
本博客所有文章除特别声明外,均采用 CC BY-NC-SA 4.0 许可协议。转载请注明来自 Alex-null's Blog!