# Scanless herramienta para pentesting de puertos en sitios webs

URL: https://www.blogueroinformatico.net/scanless-herramienta-pentesting-puertos-sitios-webs/
Published: 2018-03-24

Si eres amante y curioso en la seguridad Informática esta herramienta te va a encantar les presento a Scanless la cual es una utilidad de línea de comandos para usar sitios web que pueden realizar escaneos de puertos en su nombre. Útil para las primeras etapas de una prueba de penetración o si desea ejecutar un escaneo de puertos en un host y que no provenga de su dirección IP.
Puedes descargarlo desde el repositorio en Github
Esta herramienta usa los servicios de las siguientes urls:

yougetsignal
viewdns
hackertarget
ipfingerprints
pingeu
spiderip
t1shopper

&nbsp;
Instalar
Para instalar, simplemente ejecuta:
$ sudo pip install scanless

Uso
$ scanless &#8211;help
usage: scanless [-h] [-t TARGET] [-s SCANNER] [-l] [-a]
&nbsp;
scanless, public port scan scrapper
&nbsp;
optional arguments:
-h, &#8211;help            show this help message and exit
-t TARGET, &#8211;target TARGET
ip or domain to scan
-s SCANNER, &#8211;scanner SCANNER
scanner to use (default: hackertarget)
-r, &#8211;random          use a random scanner
-l, &#8211;list            list scanners
-a, &#8211;all             use all the scanners
&nbsp;
$ scanless &#8211;list
Scanner Name   | Website
&#8212;&#8212;&#8212;&#8212;&#8212;|&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;
yougetsignal   | http://www.yougetsignal.com
viewdns        | http://viewdns.info
hackertarget   | https://hackertarget.com
ipfingerprints | http://www.ipfingerprints.com
pingeu         | http://ping.eu
spiderip       | https://spiderip.com
t1shopper      | http://www.t1shopper.com
&nbsp;
$ scanless -t scanme.nmap.org -s ipfingerprints
Running scanless&#8230;
&nbsp;
&#8212;&#8212;- ipfingerprints &#8212;&#8212;-
Host is up (0.16s latency).
Not shown: 491 closed ports
PORT   STATE SERVICE
22/tcp open  ssh
80/tcp open  http
Device type: general purpose
Running: Linux 3.X|4.X
OS CPE: cpe:/o:linux:linux_kernel:3 cpe:/o:linux:linux_kernel:4
OS details: Linux 3.2 &#8211; 4.6
Network Distance: 7 hops
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;
&nbsp;
$ scanless -a -t scanme.nmap.org
Running scanless&#8230;
&nbsp;
&#8212;&#8212;- yougetsignal &#8212;&#8212;-
PORT     STATE  SERVICE
21/tcp   closed ftp
22/tcp   open   ssh
23/tcp   closed telnet
25/tcp   closed smtp
53/tcp   closed dns
80/tcp   open   http
110/tcp  closed pop3
115/tcp  closed sftp
135/tcp  closed msrpc
139/tcp  closed netbios
143/tcp  closed imap
194/tcp  closed irc
443/tcp  closed https
445/tcp  closed smb
1433/tcp closed mssql
3306/tcp closed mysql
3389/tcp closed rdp
5632/tcp closed pcanywhere
5900/tcp closed vnc
6112/tcp closed wc3
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-
&nbsp;
&#8212;&#8212;- viewdns &#8212;&#8212;-
PORT     STATE  SERVICE
21/tcp   closed ftp
22/tcp   open   ssh
23/tcp   closed telnet
25/tcp   closed smtp
53/tcp   closed dns
80/tcp   open   http
110/tcp  closed pop3
139/tcp  closed netbios
143/tcp  closed imap
443/tcp  closed https
445/tcp  closed smb
1433/tcp closed mssql
1521/tcp closed oracle
3306/tcp closed mysql
3389/tcp closed rdp
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;
&nbsp;
&#8212;&#8212;- hackertarget &#8212;&#8212;-
Starting Nmap 7.01 ( https://nmap.org ) at 2017-05-14 16:46 UTC
Nmap scan report for scanme.nmap.org (45.33.32.156)
Host is up (0.066s latency).
Other addresses for scanme.nmap.org (not scanned): 2600:3c01::f03c:91ff:fe18:bb2f
PORT     STATE  SERVICE       VERSION
21/tcp   closed ftp
22/tcp   open   ssh           OpenSSH 6.6.1p1 Ubuntu 2ubuntu2.8 (Ubuntu Linux; protocol 2.0)
23/tcp   closed telnet
25/tcp   closed smtp
80/tcp   open   http          Apache httpd 2.4.7 ((Ubuntu))
110/tcp  closed pop3
143/tcp  closed imap
443/tcp  closed https
445/tcp  closed microsoft-ds
3389/tcp closed ms-wbt-server
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
&nbsp;
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 6.94 seconds
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-
&nbsp;
&#8212;&#8212;- ipfingerprints &#8212;&#8212;-
Host is up (0.16s latency).
Not shown: 491 closed ports
PORT   STATE SERVICE
22/tcp open  ssh
80/tcp open  http
Device type: general purpose
Running: Linux 3.X|4.X
OS CPE: cpe:/o:linux:linux_kernel:3 cpe:/o:linux:linux_kernel:4
OS details: Linux 3.2 &#8211; 4.6
Network Distance: 7 hops
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;
&nbsp;
&#8212;&#8212;- pingeu &#8212;&#8212;-
PORT     STATE  SERVICE
21/tcp   closed ftp
22/tcp   open   ssh
23/tcp   closed telnet
25/tcp   closed smtp
53/tcp   closed dns
80/tcp   open   http
139/tcp  closed netbios
443/tcp  closed https
445/tcp  closed smb
3389/tcp closed rdp
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-
&nbsp;
&#8212;&#8212;- spiderip &#8212;&#8212;-
PORT     STATE  SERVICE
21/tcp   closed ftp
22/tcp   open   ssh
25/tcp   closed smtp
80/tcp   open   http
110/tcp  closed pop3
143/tcp  closed imap
443/tcp  closed https
465/tcp  closed smtps
993/tcp  closed imaps
995/tcp  closed pop3s
1433/tcp closed mssql
3306/tcp closed mysql
3389/tcp closed rdp
5900/tcp closed vnc
8080/tcp closed http-alt
8443/tcp closed https-alt
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;
&nbsp;
&#8212;&#8212;- t1shopper &#8212;&#8212;-
PORT     STATE  SERVICE
21/tcp   closed ftp
23/tcp   closed telnet
25/tcp   closed smtp
80/tcp   open   http
110/tcp  closed pop3
139/tcp  closed netbios
445/tcp  closed smb
1433/tcp closed mssql
1521/tcp closed oracle
1723/tcp closed pptp
3306/tcp closed mysql
3389/tcp closed rdp
5900/tcp closed vnc
8080/tcp closed http-alt
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-
Aqui te dejamos un video demostrativo gracias a pentesttoolz.com
https://www.youtube.com/watch?v=F2af8VK5_WM