
POC-Scanner für CVE-2024-47176
Dienstprogramm zum schnellen Scannen einer einzelnen IP / eines CIDR-Bereichs, um nach OpenPrinting CVE 2024-47176 auf UDP 631 zu suchen.
Dieses Dienstprogramm ist schnell und hässlich – könnte aber für manche nützlich sein.
Der Exploit wurde bewusst weggelassen, da dies eher dazu dient, zu scannen und Benutzer zu sensibilisieren.
go build .
Usage:
-dest string
IP address for callbacks
-destport string
TCP port to listen on for HTTP callbacks (default "12345")
-port string
Target UDP port (default "631")
-target string
Target IP address, CIDR network, or filename to scan
go run main.go -ip <target-ip> -port 631 -dest <your listening ip> -destport <your listening port>
OR
./spill -ip <target-ip> -port 631 -dest <your listening ip> -destport <your listening port>
go run main.go -target <target-range> -port 631 -dest <your listening ip> -destport <your listening port>
OR
./spill -target <target-range> -port 631 -dest <your listening ip> -destport <your listening port>
go run main.go -target <path/to/target/file> -port 631 -dest <your listening ip> -destport <your listening port>
OR
./spill -target <path/to/target/file> -port 631 -dest <your listening ip> -destport <your listening port>
┌──(kali㉿kali-raspberry-pi)-[~/spill]
└─$ ./spill -target 10.1.80.0/24 -dest 10.110.123.74 -destport 9003
. .
.. . *.
- -_ _-__-0oOo
_-_ -__ -||||)
______||||______
~~~~~~~~~~^""' Spill
2024/09/27 13:55:37 Starting HTTP server on port 9003...
Packet Progress 100% |████████████████████████████████████████|
2024/09/27 13:55:37 Received POST request: 10.1.80.89:56952
2024/09/27 13:55:37 Received POST request: 10.1.80.85:37606