
CVE-2026-33017 - Langflow < 1.9.0 인증되지 않은 RCE PoC
██╗ ██╗ ██████╗ ███████╗███████╗ ██████╗ ██████╗ ██████╗ ███████╗
██║ ██║██╔═══██╗██╔════╝██╔════╝██╔═══██╗██╔══██╗██╔═══██╗██╔════╝
██║ ██║██║ ██║███████╗███████╗██║ ██║██║ ██║██║ ██║███████╗
╚██╗ ██╔╝██║ ██║╚════██║╚════██║██║ ██║██║ ██║██║ ██║╚════██║
╚████╔╝ ╚██████╔╝███████║███████║╚██████╔╝██████╔╝╚██████╔╝███████║
╚═══╝ ╚═════╝ ╚══════╝╚══════╝ ╚═════╝ ╚═════╝ ╚═════╝ ╚══════╝
███████╗██╗ ██╗███████╗███╗ ██╗████████╗██╗
██╔════╝██║ ██║██╔════╝████╗ ██║╚══██╔══╝██║
███████╗██║ ██║█████╗ ██╔██╗ ██║ ██║ ██║
╚════██║██║ ██║██╔══╝ ██║╚██╗██║ ██║ ╚═╝
███████║╚██████╔╝███████╗██║ ╚████║ ██║ ██╗
╚══════╝ ╚═════╝ ╚══════╝╚═╝ ╚═══╝ ╚═╝ ╚═╝
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░
░ CONCURRENT SCANNER × NUCLEI × RECON ░
░ Banner Grab · Service ID · Vuln Detection ░
░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
┌──────────────────────────────────────────────────────────────┐
│ │
│ Scan random IPs → Grab banners → Identify services │
│ → Feed into Nuclei → Find vulnerabilities → Profit │
│ │
└──────────────────────────────────────────────────────────────┘
배너 그래빙, 서비스 핑거프린팅, 대규모 자동 취약점 발견을 위한 Nuclei 통합을 갖춘 고성능 동시성(concurrent) 포트 스캐너입니다.
핵심 엔진
|
Nuclei 파이프라인
|
# 1. Clone the beast
git clone https://github.com/Usman0220/port-scanner.git && cd port-scanner
# 2. Build
go build -o port-scanner main.go
# 3. Unleash — scan port 5678 with 500 workers, 10k IPs
./port-scanner -port 5678 -w 500 -n 10000
# 4. Full pipeline — scan → filter → nuclei
./port-scanner -port 80 -w 1000 -n 50000 -o http-open.txt
awk -F'[|]' '{print $1}' http-open.txt | sed 's/\[OPEN\] //' | cut -d: -f1 | sort -u > http-targets.txt
nuclei -l http-targets.txt -tags http -severity critical,high -o findings.txt
╔═══════════════════════════════════╗
║ PORT SCANNER ENGINE ║
╚═══════════════════════════════════╝
│
┌───────────────┼───────────────┐
▼ ▼ ▼
┌──────────────┐ ┌──────────────┐ ┌──────────────┐
│ IP Generator│ │ Goroutine │ │ Result │
│ │ │ Pool │ │ Collector │
│ Random IPs │ │ │ │ │
│ Skip Private│ │ N workers │ │ Channel │
│ 1-223.x.x.x│ │ Concurrent │ │ Buffered │
└──────┬───────┘ └──────┬───────┘ └──────┬───────┘
│ │ │
▼ ▼ ▼
┌──────────────┐ ┌──────────────┐ ┌──────────────┐
│ TCP Connect │ │ Probe Send │ │ Banner Read │
│ │ │ │ │ │
│ Dial timeout│ │ Protocol │ │ Service │
│ 2s default │ │ aware │ │ fingerprint │
└──────────────┘ └──────────────┘ └──────────────┘
│
╔═══════════════╧═══════════════╗
║ OUTPUT: results.txt ║
╚═══════════════╤═══════════════╝
│
┌───────────────┼───────────────┐
▼ ▼ ▼
┌──────────────┐ ┌──────────────┐ ┌──────────────┐
│ awk / grep │ │ sort -u │ │ nuclei -l │
│ Extract IPs │ │ Deduplicate │ │ Vuln Scan │
└──────────────┘ └──────────────┘ └──────────────┘
│
╔═══════════════╧═══════════════╗
║ FINDINGS: nuclei-*.txt ║
╚═══════════════════════════════╝
# ┌─────────────────────────────────────────────────────────────┐
# │ STEP 1: SCAN — Find live services │
# │ STEP 2: EXTRACT — Pull IPs from results │
# │ STEP 3: AUDIT — Nuclei vulnerability scan │
# └─────────────────────────────────────────────────────────────┘
# Scan
./port-scanner -port 21 -w 1000 -n 50000 -o ftp-open.txt
# Extract
awk -F'[|]' '{print $1}' ftp-open.txt | sed 's/\[OPEN\] //' | cut -d: -f1 | sort -u > ftp-targets.txt
# Audit
nuclei -l ftp-targets.txt -tags ftp -severity critical,high -o ftp-findings.txt
#!/bin/bash
# ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
# FULL RECON PIPELINE — Scan → Extract → Nuclei → Report
# ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
PORTS=(21 22 23 25 80 110 143 443 3306 5432 6379 8080 8443 9090 27017 5678)
WORKERS=1000
IPS=30000
SEVERITY="critical,high,medium"
TEMPLATES="$HOME/.local/nuclei-templates"
echo "╔══════════════════════════════════════════════════════════╗"
echo "║ FULL RECON PIPELINE STARTED ║"
echo "╚══════════════════════════════════════════════════════════╝"
for port in "${PORTS[@]}"; do
echo ""
echo "┌──────────────────────────────────────────────────────┐"
echo "│ [*] SCANNING PORT $port"
echo "│ Workers: $WORKERS | Targets: $IPS"
echo "└──────────────────────────────────────────────────────┘"
# Scan
./port-scanner -port $port -w $WORKERS -n $IPS -o "scan-port${port}.txt"
# Extract targets
awk -F'[|]' '{print $1}' "scan-port${port}.txt" | \
sed 's/\[OPEN\] //' | cut -d: -f1 | sort -u > "targets-port${port}.txt"
count=$(wc -l < "targets-port${port}.txt")
echo "[+] Found $count live hosts on port $port"
# Nuclei audit
if [ "$count" -gt 0 ]; then
echo "[*] Running Nuclei templates for port $port..."
nuclei -l "targets-port${port}.txt" \
-p-port $port \
-t "$TEMPLATES" \
-severity $SEVERITY \
-o "nuclei-port${port}.txt" \
-silent -stats
vulns=$(wc -l < "nuclei-port${port}.txt" 2>/dev/null || echo "0")
echo "[!] $vulns vulnerabilities found on port $port"
fi
done
# Merge all findings
echo ""
echo "┌──────────────────────────────────────────────────────┐"
echo "│ [*] MERGING ALL FINDINGS"
echo "└──────────────────────────────────────────────────────┘"
cat nuclei-port*.txt 2>/dev/null | sort -u > all-findings.txt
total=$(wc -l < "all-findings.txt" 2>/dev/null || echo "0")