
CVE-2026-33017 - Langflow < 1.9.0 إثبات المفهوم لثغرة RCE بدون مصادقة
██╗ ██╗ ██████╗ ███████╗███████╗ ██████╗ ██████╗ ██████╗ ███████╗
██║ ██║██╔═══██╗██╔════╝██╔════╝██╔═══██╗██╔══██╗██╔═══██╗██╔════╝
██║ ██║██║ ██║███████╗███████╗██║ ██║██║ ██║██║ ██║███████╗
╚██╗ ██╔╝██║ ██║╚════██║╚════██║██║ ██║██║ ██║██║ ██║╚════██║
╚████╔╝ ╚██████╔╝███████║███████║╚██████╔╝██████╔╝╚██████╔╝███████║
╚═══╝ ╚═════╝ ╚══════╝╚══════╝ ╚═════╝ ╚═════╝ ╚═════╝ ╚══════╝
███████╗██╗ ██╗███████╗███╗ ██╗████████╗██╗
██╔════╝██║ ██║██╔════╝████╗ ██║╚══██╔══╝██║
███████╗██║ ██║█████╗ ██╔██╗ ██║ ██║ ██║
╚════██║██║ ██║██╔══╝ ██║╚██╗██║ ██║ ╚═╝
███████║╚██████╔╝███████╗██║ ╚████║ ██║ ██╗
╚══════╝ ╚═════╝ ╚══════╝╚═╝ ╚═══╝ ╚═╝ ╚═╝
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░
░ ماسح متزامن × Nuclei × استكشاف ░
░ التقاط الشعار · تعريف الخدمة · كشف الثغرات░
░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
┌──────────────────────────────────────────────────────────────┐
│ │
│ مسح عناوين IP عشوائي ← التقاط الشعارات ← تعريف الخدمات │
│ ← إدخالها في Nuclei ← اكتشاف الثغرات ← الربح │
│ │
└──────────────────────────────────────────────────────────────┘
ماسح منافذ متزامن عالي الأداء مع التقاط الشعارات، وبصمة الخدمة، وتكامل Nuclei للاكتشاف الآلي للثغرات على نطاق واسع.
المحرك الأساسي
|
خط أنابيب Nuclei
|
# 1. Clone the beast
git clone https://github.com/Usman0220/port-scanner.git && cd port-scanner
# 2. Build
go build -o port-scanner main.go
# 3. Unleash — scan port 5678 with 500 workers, 10k IPs
./port-scanner -port 5678 -w 500 -n 10000
# 4. Full pipeline — scan → filter → nuclei
./port-scanner -port 80 -w 1000 -n 50000 -o http-open.txt
awk -F'[|]' '{print $1}' http-open.txt | sed 's/\[OPEN\] //' | cut -d: -f1 | sort -u > http-targets.txt
nuclei -l http-targets.txt -tags http -severity critical,high -o findings.txt
╔═══════════════════════════════════╗
║ محرك ماسح المنافذ ║
╚═══════════════════════════════════╝
│
┌───────────────┼───────────────┐
▼ ▼ ▼
┌──────────────┐ ┌──────────────┐ ┌──────────────┐
│ مولد IP │ │ مجموعة │ │ جامع │
│ │ │ goroutines │ │ النتائج │
│ IP عشوائي │ │ │ │ │
│ تخطي الخاص │ │ N عاملاً │ │ قناة │
│ 1-223.x.x.x │ │ متزامن │ │ مخزنة مؤقتاً│
└──────┬───────┘ └──────┬───────┘ └──────┬───────┘
│ │ │
▼ ▼ ▼
┌──────────────┐ ┌──────────────┐ ┌──────────────┐
│ اتصال TCP │ │ إرسال │ │ قراءة │
│ │ │ استقصاء │ │ الشعار │
│ مهلة الاتصال│ │ │ │ │
│ 2s افتراضي │ │ واعي │ │ بصمة الخدمة │
│ │ │ بالبروتوكول │ │ │
└──────────────┘ └──────────────┘ └──────────────┘
│
╔═══════════════╧═══════════════╗
║ الإخراج: results.txt ║
╚═══════════════╤═══════════════╝
│
┌───────────────┼───────────────┐
▼ ▼ ▼
┌──────────────┐ ┌──────────────┐ ┌──────────────┐
│ awk / grep │ │ sort -u │ │ nuclei -l │
│ استخراج IPs │ │ إزالة │ │ مسح الثغرات │
│ │ │ التكرار │ │ │
└──────────────┘ └──────────────┘ └──────────────┘
│
╔═══════════════╧═══════════════╗
║ النتائج: nuclei-*.txt ║
╚═══════════════════════════════╝
# ┌─────────────────────────────────────────────────────────────┐
# │ STEP 1: SCAN — Find live services │
# │ STEP 2: EXTRACT — Pull IPs from results │
# │ STEP 3: AUDIT — Nuclei vulnerability scan │
# └─────────────────────────────────────────────────────────────┘
# Scan
./port-scanner -port 21 -w 1000 -n 50000 -o ftp-open.txt
# Extract
awk -F'[|]' '{print $1}' ftp-open.txt | sed 's/\[OPEN\] //' | cut -d: -f1 | sort -u > ftp-targets.txt
# Audit
nuclei -l ftp-targets.txt -tags ftp -severity critical,high -o ftp-findings.txt
#!/bin/bash
# ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
# FULL RECON PIPELINE — Scan → Extract → Nuclei → Report
# ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
PORTS=(21 22 23 25 80 110 143 443 3306 5432 6379 8080 8443 9090 27017 5678)
WORKERS=1000
IPS=30000
SEVERITY="critical,high,medium"
TEMPLATES="$HOME/.local/nuclei-templates"
echo "╔══════════════════════════════════════════════════════════╗"
echo "║ FULL RECON PIPELINE STARTED ║"
echo "╚══════════════════════════════════════════════════════════╝"
for port in "${PORTS[@]}"; do
echo ""
echo "┌──────────────────────────────────────────────────────┐"
echo "│ [*] SCANNING PORT $port"
echo "│ Workers: $WORKERS | Targets: $IPS"
echo "└──────────────────────────────────────────────────────┘"
# Scan
./port-scanner -port $port -w $WORKERS -n $IPS -o "scan-port${port}.txt"
# Extract targets
awk -F'[|]' '{print $1}' "scan-port${port}.txt" | \
sed 's/\[OPEN\] //' | cut -d: -f1 | sort -u > "targets-port${port}.txt"
count=$(wc -l < "targets-port${port}.txt")
echo "[+] Found $count live hosts on port $port"
# Nuclei audit
if [ "$count" -gt 0 ]; then
echo "[*] Running Nuclei templates for port $port..."
nuclei -l "targets-port${port}.txt" \
-p-port $port \
-t "$TEMPLATES" \
-severity $SEVERITY \
-o "nuclei-port${port}.txt" \
-silent -stats
vulns=$(wc -l < "nuclei-port${port}.txt" 2>/dev/null || echo "0")
echo "[!] $vulns vulnerabilities found on port $port"
fi
done
# Merge all findings
echo ""
echo "┌──────────────────────────────────────────────────────┐"
echo "│ [*] MERGING ALL FINDINGS"
echo "└──────────────────────────────────────────────────────┘"
cat nuclei-port*.txt 2>/dev/null | sort -u > all-findings.txt
total=$(wc -l < "all-findings.txt" 2>/dev/null || echo "0")
echo ""
echo "╔══════════════════════════════════════════════════════════╗"
echo "║ PIPELINE COMPLETE ║"
echo "║ Total vulnerabilities: $total"
echo "║ Report: all-findings.txt"
echo "╚══════════════════════════════════════════════════════════╝"
# ┌─────────────────────────────────────────────────────────────┐
# │ SERVICE-SPECIFIC NUCLEI SCANS │
# └─────────────────────────────────────────────────────────────┘
# FTP — anonymous login, brute force, known CVEs
nuclei -l targets.txt -tags ftp -severity critical,high
# SSH — weak ciphers, user enumeration, CVEs
nuclei -l targets.txt -tags ssh -severity critical,high,medium
# HTTP — full web audit (XSS, SQLi, LFI, RCE, misconfigs)
nuclei -l targets.txt -tags http -severity critical,high,medium,low
# MySQL — weak auth, CVEs, misconfigs
nuclei -l targets.txt -tags mysql -severity critical,high
# Redis — unauthorized access, module loading
nuclei -l targets.txt -tags redis -severity critical,high
# MongoDB — no-auth, CVEs
nuclei -l targets.txt -tags mongodb -severity critical,high
# PostgreSQL — weak auth, CVEs
nuclei -l targets.txt -tags postgresql -severity critical,high
# n8n — God Mode exploit, CVE-2025-68613
nuclei -l targets.txt -tags n8n -severity critical
# Jenkins — script console, CVEs
nuclei -l targets.txt -tags jenkins -severity critical,high
# Grafana — path traversal, CVEs
nuclei -l targets.txt -tags grafana -severity critical,high
# FULL AUDIT — everything
nuclei -l targets.txt -t ~/.local/nuclei-templates/ -severity critical,high,medium,low
./port-scanner -port 443 -w 500 -n 10000 -o results.txt
./port-scanner -port 80 -w 2000 -n 100000 -o results.txt
./port-scanner -port 5678 -w 100 -n 5000 -timeout 1s
./port-scanner -port 22 -w 200 -n 50000 -timeout 5s -o deep-scan.txt
┌──────────────────────────────────────────────────────────────────────┐
│ [*] 15234/30000 scanned | 847 open | 847 verified │
│ │
│ [OPEN] 103.21.244.12:80 | HTTP/Apache | HTTP/1.1 200 OK │
│ [OPEN] 198.51.100.45:22 | SSH | SSH-2.0-OpenSSH_8.9p1 │
│ [OPEN] 203.0.113.88:3306 | MySQL | 5.7.42-0ubuntu0.18.04.1 │
│ [OPEN] 192.0.2.15:6379 | Redis | Redis server version 7.0.11 │
│ [OPEN] 198.51.100.200:5678 | n8n | n8n v1.19.0 │
│ [OPEN] 203.0.113.55:27017 | MongoDB | MongoDB 6.0.4 │
│ [OPEN] 103.21.244.90:8080 | HTTP/Nginx | HTTP/1.1 200 OK │
│ [OPEN] 198.51.100.120:5432 | PostgreSQL | PostgreSQL 15.3 │
│ │
│ [+] Done. Scanned: 30000 | Open: 847 | Verified: 847 │
└──────────────────────────────────────────────────────────────────────┘
| العلم | القيمة الافتراضية | الوصف |
|---|---|---|
-port | 5678 | المنفذ الهدف للمسح |
-w | 500 | عدد عمال goroutine (أكثر = أسرع) |
-timeout | 2s | مهلة اتصال TCP |
-n | 10000 | عدد عناوين IP العشوائية للمسح |
-o | "" | مسار ملف الإخراج |
| المنفذ/المنافذ | الخدمة | الاستقصاء | البصمة |
|---|---|---|---|
| 21 | FTP | Banner | ProFTPD, vsftpd, Pure-FTPd |
| 22 | SSH | Banner | OpenSSH, Dropbear |
| 23 | Telnet | Banner | Generic telnetd |
| 25, 587 | SMTP | EHLO test | Postfix, Exim, Sendmail |
| 80, 8080, 8443, 443, 5678, 3000, 8000, 8888, 9090 | HTTP | GET / | Nginx, Apache, IIS, Cloudflare, n8n, Grafana, Jenkins, Kibana |
| 110 | POP3 | Banner | Dovecot, Courier |
| 143 | IMAP | Banner | Dovecot, Courier |
| 3306 | MySQL | Handshake | MySQL 5.x, 8.x |
| 5432 | PostgreSQL | Startup | PostgreSQL 12-16 |
| 6379 | Redis | INFO | Redis 6.x, 7.x |
| 27017 | MongoDB | Hello | MongoDB 5.x, 6.x, 7.x |
| المقياس | القيمة |
|---|---|
| سرعة المسح (500 عاملاً) | ~2,500 IPs/sec |
| سرعة المسح (2000 عاملاً) | ~10,000 IPs/sec |
| استخدام الذاكرة | ~50MB أساسي + مجموعة العمال |
| مهلة الاتصال | قابلة للتكوين (افتراضي 2s) |
| أقصى اتصالات متزامنة | غير محدود (محدود بعلم العمال) |
# Go
go version # >= 1.20
# Nuclei (اختياري — لمسح الثغرات)
go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest
# تحديث قوالب Nuclei
nuclei -update-templates
┌──────────────────────────────────────────────────────────────────────┐
│ │
│ ⚠️ تحذير │
│ │
│ هذه الأداة مخصصة للاختبارات الأمنية المصرح بها والبحث فقط. │
│ │
│ مسح الشبكات دون إذن صريح هو أمر غير قانوني. │
│ استخدم هذه الأداة بمسؤولية وفقط على الأنظمة التي تمتلكها أو لديك │
│ تفويض كتابي لاختبارها. │
│ │
│ المؤلف غير مسؤول عن أي إساءة استخدام أو ضرر ناتج عن هذه الأداة. │
│ │
└──────────────────────────────────────────────────────────────────────┘