Kang Asu
GoGhost - High Performance, Lightweight, Portable Open Source Tool For Mass SMBGhost Scan
GoGhost is a High Performance, lightweight, portable Open Source tool for mass SMBGhost Scan.
Installation
You can download Windows Binary or Linux Binary. Alternatively, GoGhost uses native Golang libraries so the line above would be fine to compile it:
go build GoGhost.go
Usage Options
GoGhost Scanned 25,000 IP addresses in less than 3 seconds, NMAP took more than 600.
-iL [FILE]
By using the -iL option you're able to specify a list file with CIDRs in file.
-iR [CIDR]
By using the -iR option you're able to specify an IP Range.
False Positive & False Negative
If the Windows is patched with KB4551762, GoGhost will still flag it as vulnerable. If the list of CIDRs in the file is bigger than 500k IP Addresses it may flag some vulnerable as Timeout.
The Results
Timeout => Closed Port
Not Vulnerable => Does not has compression
Vulnerable => LZNT1 compression on SMB.
Disclaimer
This tool was coded to measure the impact of SMBGhost in Latin America and Deepsecurity is not responsible for the use of this tool.
Regards
Kang Asu
No comments:
Post a Comment
# Silahkan berkomentar, bertanya dan kritik dengan sopan
# Disini anda boleh menyisipkan Link di kolom komentar
# Tetapi akan saya moderasi atau Review terlebih dahulu tiap komentar
# Jangan sampai komentar anda mengandung SPAM.
# Terima Kasih - Regards Muhammad Sobri Maulana