如何编写Bash脚本解析Nmap多段扫描结果,筛选特定加密算法与密码
Got it, let's work through this step by step. You need to split your Nmap scan output into individual IP sections (using "Nmap scan report" as the delimiter) and then flag any instances of RC4 ciphers or CBC algorithms tied to their respective IPs. Since we're sticking to Bash standard tools, awk is perfect for this—it handles custom record delimiters and pattern matching seamlessly.
Core Script Implementation
Here's a ready-to-use script that takes your Nmap output file (or reads from standard input) and outputs the IPs associated with your target issues:
#!/bin/bash # Optional: Define your input file (comment out if using pipe input) INPUT_FILE="nmap_scan_output.txt" # Use awk to split records by "Nmap scan report" and analyze each section awk -v RS="Nmap scan report" ' { # Skip the empty first record created by the leading delimiter if ($0 == "") next # Extract the target IP address from the section header if (match($0, /for ([0-9]+\.[0-9]+\.[0-9]+\.[0-9]+)/, ip_match)) { target_ip = ip_match[1] } else { target_ip = "Unknown IP (check scan output format)" } # Check for RC4 ciphers if ($0 ~ /RC4/) { printf "[CRITICAL] Weak cipher detected: IP %s has RC4 enabled\n", target_ip } # Check for CBC mode algorithms if ($0 ~ /CBC/) { printf "[NOTE] Algorithm found: IP %s uses CBC encryption mode\n", target_ip } }' "${INPUT_FILE:-/dev/stdin}"
How It Works
Let's break down the key parts:
- Record Splitting: The
-v RS="Nmap scan report"tells awk to treat each "Nmap scan report" block as a separate record—this is exactly how we split the output into per-IP sections. - IP Extraction: The
match()function uses a regex to pull the IP address from the "Nmap scan report for X.X.X.X" line. - Pattern Matching: We use simple regex checks (
$0 ~ /RC4/and$0 ~ /CBC/) to detect the target content in each IP's scan section, then print a formatted message with the associated IP.
Usage Options
From a saved output file:
Save your Nmap scan results to a file first (e.g.,nmap --script ssl-enum-ciphers -p443 192.168.0.0/24 > nmap_scan_output.txt), then run the script with the file defined.Directly from Nmap output pipe:
Skip saving to a file and pipe Nmap's output straight into the script:nmap --script ssl-enum-ciphers -p443 192.168.0.0/24 | ./your_script_name.shCombine both scan types:
Merge your SSL and SSH scan outputs into one file first, then run the script—it will process all IPs from both scans:cat ssl_scan.txt ssh_scan.txt > combined_scan.txt ./your_script_name.sh
Customization Tips
- Add more checks: Want to look for other weak algorithms (like 3DES)? Just add another block like:
if ($0 ~ /3DES/) { printf "[CRITICAL] Weak cipher detected: IP %s has 3DES enabled\n", target_ip } - Adjust IP regex: If your scan includes hostnames alongside IPs, update the regex to handle both:
match($0, /for ([0-9]+\.[0-9]+\.[0-9]+\.[0-9]+|[-a-zA-Z0-9.]+)/, ip_match) - Output to a file: Redirect the script's output to a report file for later review:
./your_script_name.sh > weak_cipher_report.txt
内容的提问来源于stack exchange,提问作者David W

