提交时间:2007-12-07 更新时间:2008-05-07
工具大小:103675 Bytes
文件MD5 :2925a3366345bc656ff21d4a6cf5ab6a

spcrk(Services Password Crack)用于在Linux系统下探测网络服务登陆口令的工具,现支持telnet ftp pop3 mssql mysql postgres sybase vnc socks5 snmp cvs smtp-auth;

imap smb smbnt http cisco ldap nntp rexec rlogin rsh icq pcnfs sapr3 ssh2 teamspeak

$./crk -L LOGINFILE -P PASSFILE telnet
$./crk -L 用户名字典 -P 密码字典 目标地址 服务名

crk v0.0.1 [mailto:yearnx@yeah.net] (c) 2007 by yearnx  <yearnx@yeah.net>

Syntax: crk [[[-l LOGIN|-L FILE] [-p PASS|-P FILE]] | [-C FILE]] [-e ns]
[-o FILE] [-t TASKS] [-M FILE [-T TASKS]] [-w TIME] [-f] [-s PORT] [-S] [-vV]
server service [OPT]
  -S        connect via SSL
  -s PORT   if the service is on a different default port, define it here
  -l LOGIN or -L FILE login with LOGIN name, or load several logins from FILE
  -p PASS  or -P FILE try password PASS, or load several passwords from FILE
  -e ns     additional checks, "n" for null password, "s" try login as pass
  -C FILE   colon seperated "login:pass" format, instead of -L/-P options
  -M FILE   server list for parallel attacks, one entry per line
  -r IPRANGE    target server ip address range, like 192.168.X.1-192.168.X.254, Just support '192.168.X.X'type address
  -o FILE   write found login/password pairs to FILE instead of stdout
  -f        exit after the first found login/password pair (per host if -M)
  -t TASKS  run TASKS number of connects in parallel (default: 16)
  -w TIME   defines the max wait time in seconds for responses (default: 30)
  -v / -V   verbose mode / show login+pass combination for each attempt
  server    the target server (use either this OR the -M option)
  service   the service to crack. Supported protocols: [telnet ftp pop3 mssql mysql postgres sybase vnc socks5 snmp cvs smtp-auth]
  :-)       I will add some familiar services modules to it , like: [imap smb smbnt http-head http-get https-head https-get http-proxy cisco cisco-enable ldap2 ldap3 nntp rexec rlogin rsh icq pcnfs sapr3 ssh2 teamspeak]
  OPT       some service modules need special input (see README!)

Use crk_PROXY_HTTP/crk_PROXY_CONNECT and crk_PROXY_AUTH env for a proxy.
crk is a tool to guess/crack valid login/password pairs - use allowed only
for legal purposes! If used commercially, tool name, version and web address
must be mentioned in the report. Find the newest version from mailto:yearnx@yeah.net

注:本文件为网友上传,XFOCUS 未对其进行安全检查。XFOCUS 不对下载、查看、执行其该文件及其包含内容所可能导致的后果做任何暗示和保证。

>> 下载 <<