這幾天做ASP.Net追捕,也算是我入門。想法很簡單,主要就是辨識遠端主機傳回的Banner,判斷遠端主機伺服器。這可能不夠準確,因為合格的管理員可能會去修改Banner。
程式碼如下(從我的Web追捕裡找出來的,用VB.Net)
Dim swWriter As StreamWriter
'用以傳送資料流至網路基礎資料流
Dim nsStream As NetworkStream
'建立發送資料的網路基礎資料流
Dim tcpClient2 As TcpClient
'透過它實現向遠端主機提出TCP連線申請
Dim sHostName As String
Dim srRead As StreamReader
'從網路基礎資料流讀取數據
'HTTP服務追捕
If TcpConnect(ZSIP, 80) = "CG" Then
OppHTTP.Text = "HTTP服務已開啟!服務軟體類型:未知"
Try
'tcpClient = New TcpClient(IPAddress, Port)
tcpClient2 = New TcpClient(ZSIP.ToString(), 80)
tcpClient2.ReceiveTimeout = 1000000
tcpClient2.SendTimeout = 1000000
'對遠端主機的8000埠提出TCP連線申請
nsStream = tcpClient2.GetStream()
'透過申請,並取得傳送資料的網路基礎資料流
swWriter = New StreamWriter(nsStream)
swWriter.WriteLine("Get /index.htm HTTP/1.1")
swWriter.WriteLine("Host:" & IP.Text)
swWriter.WriteLine("Accept:*/*")
swWriter.WriteLine("Referer:")
swWriter.WriteLine()
'刷新當前資料流中的數據
swWriter.Flush()
srRead = New StreamReader(nsStream, Encoding.Default)
'以得到的網路基礎資料流來初始化StreamReader實例
Dim L As Integer = 0
Do While Not srRead.Peek = -1 And L < 20
StrHttp = StrHttp & srRead.ReadLine()
L = L + 1
Loop
If InStr(StrHttp, "IIS") > 0 Then
OppHTTP.Text = "HTTP服務已開啟!服務軟體類型:IIS 版本未知"
SystemFW = "WindowsNT/2000/XP/2003"
End If
If InStr(StrHttp, "Apache") > 0 Then
OppHTTP.Text = "HTTP服務已開啟!服務軟體類型:Apache 版本未知"
End If
If InStr(StrHttp, "Netscape-Enterprise") > 0 Then
OppHTTP.Text = "HTTP服務已開啟!服務軟體類型:Netscape-Enterprise 版本未知"
End If
If InStr(StrHttp, "Microsoft-IIS/5.0") > 0 Then
OppHTTP.Text = "HTTP服務已開啟!服務軟體類型:IIS 5.0"
SystemFW = "Windows2000"
End If
If InStr(StrHttp, "Microsoft-IIS/5.1") > 0 Then
OppHTTP.Text = "HTTP服務已開啟!服務軟體類型:IIS 5.1"
SystemFW = "Windows2000/XP"
End If
If InStr(StrHttp, "Microsoft-IIS/6.0") > 0 Then
OppHTTP.Text = "HTTP服務已開啟!服務軟體類型:IIS 6.0"
SystemFW = "Windows2003"
End If
If InStr(StrHttp, "Apache/2") > 0 Then
OppHTTP.Text = "HTTP服務已開啟!服務軟體類型:Apache 2.x"
End If
If InStr(StrHttp, "Apache/2.0.54") > 0 Then
OppHTTP.Text = "HTTP服務已開啟!服務軟體類型:Apache 2.0.54"
End If
If InStr(StrHttp, "Apache/2.0.52") > 0 Then
OppHTTP.Text = "HTTP服務已開啟!服務軟體類型:Apache 2.0.52"
End If
If InStr(StrHttp, "Apache/2.1.6") > 0 Then
OppHTTP.Text = "HTTP服務已開啟!服務軟體類型:Apache 2.1.6"
End If
If InStr(StrHttp, "Apache/1.3.2") > 0 Then
OppHTTP.Text = "HTTP服務已開啟!服務軟體類型:Apache 1.3.x"
End If
If InStr(StrHttp, "Apache/1.3.20") > 0 Then
OppHTTP.Text = "HTTP服務已開啟!服務軟體類型:Apache 1.3.20"
End If
If InStr(StrHttp, "Apache/1.3.23") > 0 Then
OppHTTP.Text = "HTTP服務已開啟!服務軟體類型:Apache 1.3.23"
End If
If InStr(StrHttp, "Apache/1.3.26") > 0 Then
OppHTTP.Text = "HTTP服務已開啟!服務軟體類型:Apache 1.3.26"
End If
If InStr(StrHttp, "Apache/1.3.27") > 0 Then
OppHTTP.Text = "HTTP服務已開啟!服務軟體類型:Apache 1.3.27"
End If
If InStr(StrHttp, "Apache/1.3.33") > 0 Then
OppHTTP.Text = "HTTP服務已開啟!服務軟體類型:Apache 1.3.33"
End If
If InStr(StrHttp, "Netscape-Enterprise/4.1") > 0 Then
OppHTTP.Text = "HTTP服務已開啟!服務軟體類型:Netscape-Enterprise 4.1"
End If
If InStr(StrHttp, "Unix") > 0 Then
SystemFW = "類Unix/Linux系統"
End If
Catch
End Try
因為是摘出來的,所以有的變數沒有定義,大家自己去琢磨吧。
ZSIP:分析出的真實IP