如何实现Bash脚本中多扫描步骤并发执行以缩短耗时?
问题解决:Bash脚本中端口扫描、漏洞检测、目录爆破的并发优化与提速方案
一、当前脚本的并发问题根源
你现在写的(portscan; execute_nuclei_command; run_ffuf) &是把三个函数塞进同一个子shell里串行执行,只是整个子shell后台运行而已——三个步骤还是按顺序走完,根本没做到真正的并发。要让三个任务同时跑,得把每个函数单独丢到后台。
二、修复并发执行的核心调整
1. 修正并发启动逻辑
把原来的后台执行代码改成下面这样,让三个函数各自独立后台运行:
# 三个任务分别后台启动,真正实现并行 portscan & execute_nuclei_command & run_ffuf & # 等待所有后台任务完成后再继续 wait
2. 优化每个函数内部的并行效率
你原来的while循环是逐行处理目标,速度慢得离谱。直接利用工具本身的并发参数,或者用xargs/parallel批量并行处理,能大幅提速:
(1)Nuclei漏洞扫描优化
Nuclei自带批量输入和并发功能,没必要自己写while循环,直接用-l读目标文件,加上-c指定并发数:
execute_nuclei_command() { timeout "${timeout_duration}s" nuclei -l "fuzz_$$.txt" -t ~/nuclei-templates/ -es info -no-stdin -etags ssl -o "result_$$.txt" -c 50 | notify }
-c 50是并发扫描数,根据你机器的CPU和带宽调整,一般20-100之间合适。
(2)FFuf目录爆破优化
用xargs并行启动多个ffuf进程,同时调整-rate控制每秒请求数,避免被目标封禁:
run_ffuf() { # xargs -P 10 表示同时启动10个ffuf进程,按需调整 cat "fuzz_$$.txt" | xargs -P 10 -I {} ffuf -c -u "{}/FUZZ" -w wordlist.txt -ac -fs 0 -fc 500 -fr 'Whitelabel Error Page|Allowlist|The request could not be satisfied|Internal Server Error|This website is reserved for Samsung Service|invalid_grant|This application has no explicit mapping for /error' -maxtime 1800 -o "second_{}.txt" # 统一收集有效结果并通知 for file in second_*.txt; do if [[ -f "$file" && $(stat -c %s "$file") -lt 31200 ]]; then cat "$file" | jq -r '.results[] | [.url, .status] | @tsv' | notify fi rm -f "$file" done }
(3)Naabu端口扫描优化
Naabu本身就是并发扫描工具,加上-c指定并发数,提升扫描速度:
portscan() { cat "$new_ips_file" | naabu -p 2075,2076,6443,3868,3366,8080,9443,9091,4080,3000,8000,5900,8081,6000,51820,10000,8181,7001,3306,65455,5000,4000,8888,5432,15672,9999,161,4044,7077,4040,9000,8089,7447,7080,8880,8983,5673,7443,19000,19080,9200,27017,5985,9042,6984,6379,2375,8983,8383,554,4990,9000,8500,6066,9160,3389,5900,23,10250,10255,30000,32767,8088,6389,4444 -c 100 | notify }
-c 100是并发端口数,根据网络情况调整,别太高导致丢包。
三、全局提速的额外方案
- 字典精简:10万条字典太冗余,优先用SecLists里的常用目录子集,或者根据目标行业定制字典,砍掉无效请求。
- 目标过滤:httpx筛选存活主机时,加上
-mc 200,301,302只保留有效状态码的目标,减少后续扫描的无效任务。 - 分批处理:如果Shodan返回的IP太多,分成小批次处理,每批次启动一组并发任务,避免单进程负载过高。
- 工具参数调优:
- Nuclei:只扫描和目标相关的模板(比如指定子目录
-t ~/nuclei-templates/http/vulnerabilities),减少不必要的扫描量。 - FFuf:用
-mc指定只关注200、403等有价值的状态码,减少结果处理时间。
- Nuclei:只扫描和目标相关的模板(比如指定子目录
四、完整修正后的脚本
#!/bin/bash timeout_duration=1400 ssl_queries=( "queries" ) output_file="ips.txt" timestamp=$(date +"%Y%m%d%H") new_ips_file="/home/momo/monitor/new_ips_${timestamp}.txt" echo "start scan" | notify monitor_ips() { for query in "${ssl_queries[@]}"; do echo "Monitoring $query" shodan download "$query" ssl:"$query" gunzip -f "$query.json.gz" jq -r '.ip_str' "$query.json" | anew "$output_file" | tee -a "$new_ips_file" # 筛选有效存活主机,减少后续任务量 cat "$new_ips_file" | httpx --title --status-code -mc 200,301,302 | cut -d " " -f 1 | tee "fuzz_$$.txt" rm "$query.json" # 三个任务并行启动 portscan & execute_nuclei_command & run_ffuf & # 等待所有任务完成后处理下一个query wait # 清理临时文件 rm -f "fuzz_$$.txt" "result_$$.txt" done } execute_nuclei_command() { timeout "${timeout_duration}s" nuclei -l "fuzz_$$.txt" -t ~/nuclei-templates/ -es info -no-stdin -etags ssl -o "result_$$.txt" -c 50 | notify } run_ffuf() { cat "fuzz_$$.txt" | xargs -P 10 -I {} ffuf -c -u "{}/FUZZ" -w wordlist.txt -ac -fs 0 -fc 500 -fr 'Whitelabel Error Page|Allowlist|The request could not be satisfied|Internal Server Error|This website is reserved for Samsung Service|invalid_grant|This application has no explicit mapping for /error' -maxtime 1800 -o "second_{}.txt" for file in second_*.txt; do if [[ -f "$file" && $(stat -c %s "$file") -lt 31200 ]]; then cat "$file" | jq -r '.results[] | [.url, .status] | @tsv' | notify fi rm -f "$file" done } portscan() { cat "$new_ips_file" | naabu -p 2075,2076,6443,3868,3366,8080,9443,9091,4080,3000,8000,5900,8081,6000,51820,10000,8181,7001,3306,65455,5000,4000,8888,5432,15672,9999,161,4044,7077,4040,9000,8089,7447,7080,8880,8983,5673,7443,19000,19080,9200,27017,5985,9042,6984,6379,2375,8983,8383,554,4990,9000,8500,6066,9160,3389,5900,23,10250,10255,30000,32767,8088,6389,4444 -c 100 | notify } monitor_ips
内容的提问来源于stack exchange,提问作者ELMO
相关产品推荐
相关产品推荐

