阿布云

你所需要的,不仅仅是一个好用的代理。

网络流量squidmag

阿布云 发表于

分析基于 Web 的网络流量:squidmagic – Hacker Tools - 开源安全黑客工具分享

squidmagic 是设计用于分析一个基于网络的网络流量以检测中央命令和控制(C&C)服务器和恶意网站,使用 Squid 代理服务器和 Spamhaus 的一个工具。

 

安装 Ubuntu 16.04

克隆这个回购和执行脚本

squidmagic# ./install.sh ✓ Installing system packages ✓ Cloning repositories ✓ Installing python packages ✓ Installing php packages

1

2

3

4

5

6

7

8

squidmagic# ./install.sh

 

Installing system packages

Cloning repositories

Installing python packages

Installing php packages

 

 

 

用法

 

squidmagic # python squidmagic.py /var/log/squid3/access.log _ _ _ (_) | | (_) ___ __ _ _ _ _ __| |_ __ ___ __ _ __ _ _ ___ / __|/ _` | | | | |/ _` | '_ ` _ \ / _` |/ _` | |/ __| \__ \ (_| | |_| | | (_| | | | | | | (_| | (_| | | (__ |___/\__, |\__,_|_|\__,_|_| |_| |_|\__,_|\__, |_|\___| | | __/ | |_| |___/ Analyzing... Analyzing by SBL Advisory... Spam server detected, ip is 65.182.101.221 Analyzing by SBL_CSS Advisory... safe server detected, host or ip is 65.182.101.221 Analyzing by PBL Advisory... safe server detected, host or ip is 65.182.101.221

1

2

3

4

5

6

7

8

9

10

11

12

13

14

15

16

17

18

19

20

squidmagic # python squidmagic.py /var/log/squid3/access.log

 

                 _     _                       _      

                (_)   | |                     (_)    

___  __ _ _   _ _  __| |_ __ ___   __ _  __ _ _  ___

/ __|/ _` | | | | |/ _` | '_ ` _ \ / _` |/ _` | |/ __|

\__ \ (_| | |_| | | (_| | | | | | | (_| | (_| | | (__

|___/\__, |\__,_|_|\__,_|_| |_| |_|\__,_|\__, |_|\___|

        | |                               __/ |      

        |_|                              |___/        

     Analyzing...

 

Analyzing by SBL Advisory...

Spam server detected, ip is 65.182.101.221

Analyzing by SBL_CSS Advisory...

safe server detected, host or ip is 65.182.101.221

Analyzing by PBL Advisory...

safe server detected, host or ip is 65.182.101.221

 

 

 

运行服务器

<span class="pl-s1"><span class="pl-k">&lt;</span>?<span class="pl-c1">php</span></span> <span class="pl-s1"><span class="pl-k">namespace</span> <span class="pl-en">SquidApp\Core</span>;</span> <span class="pl-s1"><span class="pl-k">require</span> <span class="pl-c1">dirname</span>(<span class="pl-c1">__DIR__</span>) <span class="pl-k">.</span> <span class="pl-s"><span class="pl-pds">'</span>/lib/vendor/autoload.php<span class="pl-pds">'</span></span>;</span> <span class="pl-s1"><span class="pl-smi">$banner</span> <span class="pl-k">=</span> <span class="pl-k">new</span> <span class="pl-c1">\SquidApp\</span><span class="pl-c1">Squid</span>();</span> <span class="pl-s1"><span class="pl-smi">$squidmagic</span> <span class="pl-k">=</span> <span class="pl-k">new</span> <span class="pl-c1">FileSystem</span>();</span> <span class="pl-s1"><span class="pl-c">// output banner</span></span> <span class="pl-s1"><span class="pl-c1">echo</span> <span class="pl-smi">$banner</span><span class="pl-k">-&gt;</span>bannerAction();</span> <span class="pl-s1"><span class="pl-c">// Scans a directory for files</span></span> <span class="pl-s1"><span class="pl-smi">$squidmagic</span><span class="pl-k">-&gt;</span>scandirs(<span class="pl-s"><span class="pl-pds">'</span>squidmagic/Collector path<span class="pl-pds">'</span></span>);</span> <span class="pl-s1"><span class="pl-c">// Checks if file exists in certain location </span></span> <span class="pl-s1"><span class="pl-smi">$squidmagic</span><span class="pl-k">-&gt;</span>fileExists(<span class="pl-s"><span class="pl-pds">'</span>Collector Path/server.php<span class="pl-pds">'</span></span>);</span> <span class="pl-s1"><span class="pl-c">// run server</span></span> <span class="pl-s1"><span class="pl-smi">$squidmagic</span><span class="pl-k">-&gt;</span>openInBackground(<span class="pl-s"><span class="pl-pds">'</span>Collector Path/lib/bin/<span class="pl-pds">'</span></span>);</span>

1

2

3

4

5

6

7

8

9

10

11

12

13

14

15

16

17

18

19

<span class="pl-s1"><span class="pl-k">&lt;</span>?<span class="pl-c1">php</span></span>

<span class="pl-s1"><span class="pl-k">namespace</span> <span class="pl-en">SquidApp\Core</span>;</span>

 

<span class="pl-s1"><span class="pl-k">require</span> <span class="pl-c1">dirname</span>(<span class="pl-c1">__DIR__</span>) <span class="pl-k">.</span> <span class="pl-s"><span class="pl-pds">'</span>/lib/vendor/autoload.php<span class="pl-pds">'</span></span>;</span>

 

<span class="pl-s1"><span class="pl-smi">$banner</span> <span class="pl-k">=</span> <span class="pl-k">new</span> <span class="pl-c1">\SquidApp\</span><span class="pl-c1">Squid</span>();</span>

<span class="pl-s1"><span class="pl-smi">$squidmagic</span> <span class="pl-k">=</span> <span class="pl-k">new</span> <span class="pl-c1">FileSystem</span>();</span>

 

<span class="pl-s1"><span class="pl-c">// output banner</span></span>

<span class="pl-s1"><span class="pl-c1">echo</span> <span class="pl-smi">$banner</span><span class="pl-k">-&gt;</span>bannerAction();</span>

 

<span class="pl-s1"><span class="pl-c">// Scans a directory for files</span></span>

<span class="pl-s1"><span class="pl-smi">$squidmagic</span><span class="pl-k">-&gt;</span>scandirs(<span class="pl-s"><span class="pl-pds">'</span>squidmagic/Collector path<span class="pl-pds">'</span></span>);</span>

 

<span class="pl-s1"><span class="pl-c">// Checks if file exists in certain location </span></span>

<span class="pl-s1"><span class="pl-smi">$squidmagic</span><span class="pl-k">-&gt;</span>fileExists(<span class="pl-s"><span class="pl-pds">'</span>Collector Path/server.php<span class="pl-pds">'</span></span>);</span>

 

<span class="pl-s1"><span class="pl-c">// run server</span></span>

<span class="pl-s1"><span class="pl-smi">$squidmagic</span><span class="pl-k">-&gt;</span>openInBackground(<span class="pl-s"><span class="pl-pds">'</span>Collector Path/lib/bin/<span class="pl-pds">'</span></span>);</span>

 

squidmagic/lib # php squidmagic.php | | ___ __ _ _ _ _ __| |_ __ ___ __ _ __ _ _ ___ / __|/ _` | | | | |/ _` | '_ ` _ \ / _` |/ _` | |/ __| \__ \ (_| | |_| | | (_| | | | | | | (_| | (_| | | (__ |___/\__, |\__,_|_|\__,_|_| |_| |_|\__,_|\__, |_|\___| | | __/ | |_| |___/ squidmagic collector started

1

2

3

4

5

6

7

8

9

10

11

squidmagic/lib # php squidmagic.php

 

                                                            

                              | |                          

         ___  __ _ _   _ _  __| |_ __ ___   __ _  __ _ _  ___

        / __|/ _` | | | | |/ _` | '_ ` _ \ / _` |/ _` | |/ __|

        \__ \ (_| | |_| | | (_| | | | | | | (_| | (_| | | (__

        |___/\__, |\__,_|_|\__,_|_| |_| |_|\__,_|\__, |_|\___|

                | |                               __/ |      

                |_|                              |___/

                    squidmagic collector started  

阿布云高速代理IP,分布式动态代理IP,高质量IP代理,全国高匿代理ip,爬虫代理,私密代理IP,国内极速代理IP,优质代理IP