You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何实现Bash脚本中多扫描步骤并发执行以缩短耗时?

问题解决:Bash脚本中端口扫描、漏洞检测、目录爆破的并发优化与提速方案

一、当前脚本的并发问题根源

你现在写的(portscan; execute_nuclei_command; run_ffuf) &是把三个函数塞进同一个子shell里串行执行,只是整个子shell后台运行而已——三个步骤还是按顺序走完,根本没做到真正的并发。要让三个任务同时跑,得把每个函数单独丢到后台。

二、修复并发执行的核心调整

1. 修正并发启动逻辑

把原来的后台执行代码改成下面这样,让三个函数各自独立后台运行:

# 三个任务分别后台启动,真正实现并行
portscan &
execute_nuclei_command &
run_ffuf &
# 等待所有后台任务完成后再继续
wait

2. 优化每个函数内部的并行效率

你原来的while循环是逐行处理目标,速度慢得离谱。直接利用工具本身的并发参数,或者用xargs/parallel批量并行处理,能大幅提速:

(1)Nuclei漏洞扫描优化

Nuclei自带批量输入和并发功能,没必要自己写while循环,直接用-l读目标文件,加上-c指定并发数:

execute_nuclei_command() {
    timeout "${timeout_duration}s" nuclei -l "fuzz_$$.txt" -t ~/nuclei-templates/ -es info -no-stdin -etags ssl -o "result_$$.txt" -c 50 | notify
}

-c 50是并发扫描数,根据你机器的CPU和带宽调整,一般20-100之间合适。

(2)FFuf目录爆破优化

用xargs并行启动多个ffuf进程,同时调整-rate控制每秒请求数,避免被目标封禁:

run_ffuf() {
    # xargs -P 10 表示同时启动10个ffuf进程,按需调整
    cat "fuzz_$$.txt" | xargs -P 10 -I {} ffuf -c -u "{}/FUZZ" -w wordlist.txt -ac -fs 0 -fc 500 -fr 'Whitelabel Error Page|Allowlist|The request could not be satisfied|Internal Server Error|This website is reserved for Samsung Service|invalid_grant|This application has no explicit mapping for /error' -maxtime 1800 -o "second_{}.txt"
    
    # 统一收集有效结果并通知
    for file in second_*.txt; do
        if [[ -f "$file" && $(stat -c %s "$file") -lt 31200 ]]; then
            cat "$file" | jq -r '.results[] | [.url, .status] | @tsv' | notify
        fi
        rm -f "$file"
    done
}

(3)Naabu端口扫描优化

Naabu本身就是并发扫描工具,加上-c指定并发数,提升扫描速度:

portscan() {
    cat "$new_ips_file" | naabu -p 2075,2076,6443,3868,3366,8080,9443,9091,4080,3000,8000,5900,8081,6000,51820,10000,8181,7001,3306,65455,5000,4000,8888,5432,15672,9999,161,4044,7077,4040,9000,8089,7447,7080,8880,8983,5673,7443,19000,19080,9200,27017,5985,9042,6984,6379,2375,8983,8383,554,4990,9000,8500,6066,9160,3389,5900,23,10250,10255,30000,32767,8088,6389,4444 -c 100 | notify
}

-c 100是并发端口数,根据网络情况调整,别太高导致丢包。

三、全局提速的额外方案

  • 字典精简:10万条字典太冗余,优先用SecLists里的常用目录子集,或者根据目标行业定制字典,砍掉无效请求。
  • 目标过滤:httpx筛选存活主机时,加上-mc 200,301,302只保留有效状态码的目标,减少后续扫描的无效任务。
  • 分批处理:如果Shodan返回的IP太多,分成小批次处理,每批次启动一组并发任务,避免单进程负载过高。
  • 工具参数调优:
    • Nuclei:只扫描和目标相关的模板(比如指定子目录-t ~/nuclei-templates/http/vulnerabilities),减少不必要的扫描量。
    • FFuf:用-mc指定只关注200、403等有价值的状态码,减少结果处理时间。

四、完整修正后的脚本

#!/bin/bash

timeout_duration=1400
ssl_queries=(
    "queries"
)

output_file="ips.txt"
timestamp=$(date +"%Y%m%d%H")
new_ips_file="/home/momo/monitor/new_ips_${timestamp}.txt"

echo "start scan" | notify

monitor_ips() {
    for query in "${ssl_queries[@]}"; do
        echo "Monitoring $query"
        shodan download "$query" ssl:"$query"
        gunzip -f "$query.json.gz"
        jq -r '.ip_str' "$query.json" | anew "$output_file" | tee -a "$new_ips_file"
        
        # 筛选有效存活主机,减少后续任务量
        cat "$new_ips_file" | httpx --title --status-code -mc 200,301,302 | cut -d " " -f 1 | tee "fuzz_$$.txt"
        
        rm "$query.json"
        
        # 三个任务并行启动
        portscan &
        execute_nuclei_command &
        run_ffuf &
        
        # 等待所有任务完成后处理下一个query
        wait
        
        # 清理临时文件
        rm -f "fuzz_$$.txt" "result_$$.txt"
    done
}

execute_nuclei_command() {
    timeout "${timeout_duration}s" nuclei -l "fuzz_$$.txt" -t ~/nuclei-templates/ -es info -no-stdin -etags ssl -o "result_$$.txt" -c 50 | notify
}

run_ffuf() {
    cat "fuzz_$$.txt" | xargs -P 10 -I {} ffuf -c -u "{}/FUZZ" -w wordlist.txt -ac -fs 0 -fc 500 -fr 'Whitelabel Error Page|Allowlist|The request could not be satisfied|Internal Server Error|This website is reserved for Samsung Service|invalid_grant|This application has no explicit mapping for /error' -maxtime 1800 -o "second_{}.txt"
    
    for file in second_*.txt; do
        if [[ -f "$file" && $(stat -c %s "$file") -lt 31200 ]]; then
            cat "$file" | jq -r '.results[] | [.url, .status] | @tsv' | notify
        fi
        rm -f "$file"
    done
}

portscan() {
    cat "$new_ips_file" | naabu -p 2075,2076,6443,3868,3366,8080,9443,9091,4080,3000,8000,5900,8081,6000,51820,10000,8181,7001,3306,65455,5000,4000,8888,5432,15672,9999,161,4044,7077,4040,9000,8089,7447,7080,8880,8983,5673,7443,19000,19080,9200,27017,5985,9042,6984,6379,2375,8983,8383,554,4990,9000,8500,6066,9160,3389,5900,23,10250,10255,30000,32767,8088,6389,4444 -c 100 | notify
}

monitor_ips

内容的提问来源于stack exchange,提问作者ELMO

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.10 20:14:57