10.3.1 网络嗅探器
网络嗅探器可以检测本机所在局域网内的网络流量和数据包收发情况。
import socket
import threading
import time
activeDegree = dict()
flag = 1
def main():
global activeDegree
global flag
# 获取 IP 地址
HOST = socket.gethostbyname(socket.gethostname())
print('HOST:', HOST)
#
s = socket.socket(socket.AF_INET, socket.SOCK_RAW, socket.IPPROTO_IP)
s.bind((HOST, 0)) # 0 表示所有端口
#
s.setsockopt(socket.IPPROTO_IP, socket.IP_HDRINCL, 1)
# 打开混杂模式,接收所有包
s.ioctl(socket.SIO_RCVALL, socket.RCVALL_ON)
#
while flag:
c = s.recvfrom(65565) # 接收一个数据包
print(type(c))
host = c[1][0]
activeDegree[host] = activeDegree.get(host, 0) + 1
print(c)
s.ioctl(socket.SIO_RCVALL, socket.RCVALL_OFF) # 关闭混杂模式
s.close()
t = threading.Thread(target = main) # 创建线程
t.start() # 启动线程,开始嗅探
time.sleep(60)
flag = 0
t.join() # 等待子线程
for item in activeDegree.items():
print(item)
10.3.2 多进程端口扫描器
import socket
import multiprocessing
import sys
def ports(ports_service):
# 获取常用端口对应的服务名称
for port in list(range(1, 100)) + [143, 145, 133, 443, 445, 3389, 8080]:
try:
ports_service[port] = socket.getservbyport(port)
except socket.error:
pass
def ports_scan(host, ports_service):
ports_open = []
try:
sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
# 超时时间的不同会影响扫描结果的精确度
sock.settimeout(0.01)
except socket.error:
print('socket creaation error')
sys.exit()
for port in ports_service:
try:
# 尝试连接指定端口
sock.connect((host, port))
# 记录打开端口
ports_open.append(port)
sock.close()
except socket.error:
pass
return ports_open
if __name__ == '__main__':
m = multiprocessing.Manager()
ports_service = dict()
results = dict()
ports(ports_service)
# 创建线程池,允许 8 个线程同时运行
pool = multiprocessing.Pool(processes = 8)
net = '169.254.143.'
for host_number in map(str, range(200, 256)):
host = net + host_number
# 创建一个新进程,同时记录运行结果
results[host] = pool.apply_async(ports_scan, (host, ports_service))
print('starting ' + host + '...')
# 关闭进程池,close() 必须在 join() 之前调用
pool.close()
# 等待进程池的进程全部执行结束
pool.join()
# 打印输出结果
for host in results:
print('=' * 30)
print(host, '.'*10)
for port in results[host].get():
print(port, ':', ports_service[port])