██╗ ██╗ ██████╗ ███████╗███████╗ ██████╗ ██████╗ ██████╗ ███████╗
██║ ██║██╔═══██╗██╔════╝██╔════╝██╔═══██╗██╔══██╗██╔═══██╗██╔════╝
██║ ██║██║ ██║███████╗███████╗██║ ██║██║ ██║██║ ██║███████╗
╚██╗ ██╔╝██║ ██║╚════██║╚════██║██║ ██║██║ ██║██║ ██║╚════██║
╚████╔╝ ╚██████╔╝███████║███████║╚██████╔╝██████╔╝╚██████╔╝███████║
╚═══╝ ╚═════╝ ╚══════╝╚══════╝ ╚═════╝ ╚═════╝ ╚═════╝ ╚══════╝
███████╗██╗ ██╗███████╗███╗ ██╗████████╗██╗
██╔════╝██║ ██║██╔════╝████╗ ██║╚══██╔══╝██║
███████╗██║ ██║█████╗ ██╔██╗ ██║ ██║ ██║
╚════██║██║ ██║██╔══╝ ██║╚██╗██║ ██║ ╚═╝
███████║╚██████╔╝███████╗██║ ╚████║ ██║ ██╗
╚══════╝ ╚═════╝ ╚══════╝╚═╝ ╚═══╝ ╚═╝ ╚═╝
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░
░ 并发扫描器 × Nuclei × 侦察 ░
░ 横幅抓取 · 服务识别 · 漏洞检测 ░
░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
┌──────────────────────────────────────────────────────────────┐
│ │
│ 扫描随机IP → 抓取横幅 → 识别服务 │
│ → 输入Nuclei → 发现漏洞 → 获利 │
│ │
└──────────────────────────────────────────────────────────────┘
高性能并发端口扫描器,支持横幅抓取、服务指纹识别,并集成Nuclei以实现自动化的规模化漏洞发现。
核心引擎
|
Nuclei 流水线
|
# 1. 克隆巨兽
git clone https://github.com/Usman0220/port-scanner.git && cd port-scanner
# 2. 构建
go build -o port-scanner main.go
# 3. 释放 — 扫描端口5678,500个worker,10000个IP
./port-scanner -port 5678 -w 500 -n 10000
# 4. 完整流水线 — 扫描 → 过滤 → nuclei
./port-scanner -port 80 -w 1000 -n 50000 -o http-open.txt
awk -F'[|]' '{print $1}' http-open.txt | sed 's/\[OPEN\] //' | cut -d: -f1 | sort -u > http-targets.txt
nuclei -l http-targets.txt -tags http -severity critical,high -o findings.txt
╔═══════════════════════════════════╗
║ PORT SCANNER ENGINE ║
╚═══════════════════════════════════╝
│
┌───────────────┼───────────────┐
▼ ▼ ▼
┌──────────────┐ ┌──────────────┐ ┌──────────────┐
│ IP 生成器 │ │ Goroutine │ │ 结果收集器 │
│ │ │ 池 │ │ │
│ 随机 IP │ │ │ │ 通道 │
│ 跳过私有 │ │ N 个 worker │ │ 缓冲 │
│ 1-223.x.x.x│ │ 并发 │ │ │
└──────┬───────┘ └──────┬───────┘ └──────┬───────┘
│ │ │
▼ ▼ ▼
┌──────────────┐ ┌──────────────┐ ┌──────────────┐
│ TCP 连接 │ │ 发送探测包 │ │ 读取横幅 │
│ │ │ │ │ │
│ Dial 超时 │ │ 协议感知 │ │ 服务指纹 │
│ 默认 2s │ │ │ │ │
└──────────────┘ └──────────────┘ └──────────────┘
│
╔═══════════════╧═══════════════╗
║ 输出: results.txt ║
╚═══════════════╤═══════════════╝
│
┌───────────────┼───────────────┐
▼ ▼ ▼
┌──────────────┐ ┌──────────────┐ ┌──────────────┐
│ awk / grep │ │ sort -u │ │ nuclei -l │
│ 提取 IP │ │ 去重 │ │ 漏洞扫描 │
└──────────────┘ └──────────────┘ └──────────────┘
│
╔═══════════════╧═══════════════╗
║ 发现结果: nuclei-*.txt ║
╚═══════════════════════════════╝
# ┌─────────────────────────────────────────────────────────────┐
# │ 步骤 1: 扫描 — 发现活跃服务 │
# │ 步骤 2: 提取 — 从结果中提取 IP │
# │ 步骤 3: 审计 — Nuclei 漏洞扫描 │
# └─────────────────────────────────────────────────────────────┘
# 扫描
./port-scanner -port 21 -w 1000 -n 50000 -o ftp-open.txt
# 提取
awk -F'[|]' '{print $1}' ftp-open.txt | sed 's/\[OPEN\] //' | cut -d: -f1 | sort -u > ftp-targets.txt
# 审计
nuclei -l ftp-targets.txt -tags ftp -severity critical,high -o ftp-findings.txt
#!/bin/bash
# ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
# 完整侦察流水线 — 扫描 → 提取 → Nuclei → 报告
# ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
PORTS=(21 22 23 25 80 110 143 443 3306 5432 6379 8080 8443 9090 27017 5678)
WORKERS=1000
IPS=30000
SEVERITY="critical,high,medium"
TEMPLATES="$HOME/.local/nuclei-templates"
echo "╔══════════════════════════════════════════════════════════╗"
echo "║ 完整侦察流水线已启动 ║"
echo "╚══════════════════════════════════════════════════════════╝"
for port in "${PORTS[@]}"; do
echo ""
echo "┌──────────────────────────────────────────────────────┐"
echo "│ [*] 正在扫描端口 $port"
echo "│ Workers: $WORKERS | 目标数: $IPS"
echo "└──────────────────────────────────────────────────────┘"
# 扫描
./port-scanner -port $port -w $WORKERS -n $IPS -o "scan-port${port}.txt"
# 提取目标
awk -F'[|]' '{print $1}' "scan-port${port}.txt" | \
sed 's/\[OPEN\] //' | cut -d: -f1 | sort -u > "targets-port${port}.txt"
count=$(wc -l < "targets-port${port}.txt")
echo "[+] 在端口 $port 上发现 $count 个活跃主机"
# Nuclei 审计
if [ "$count" -gt 0 ]; then
echo "[*] 正在对端口 $port 运行 Nuclei 模板..."
nuclei -l "targets-port${port}.txt" \
-p-port $port \
-t "$TEMPLATES" \
-severity $SEVERITY \
-o "nuclei-port${port}.txt" \
-silent -stats
vulns=$(wc -l < "nuclei-port${port}.txt" 2>/dev/null || echo "0")
echo "[!] 在端口 $port 上发现 $vulns 个漏洞"
fi
done
# 合并所有发现结果
echo ""
echo "┌──────────────────────────────────────────────────────┐"
echo "│ [*] 正在合并所有发现结果 │"
echo "└──────────────────────────────────────────────────────┘"
cat nuclei-port*.txt 2>/dev/null | sort -u > all-findings.txt
total=$(wc -l < "all-findings.txt" 2>/dev/null || echo "0")
echo ""
echo "╔══════════════════════════════════════════════════════════╗"
echo "║ 流水线完成 ║"
echo "║ 漏洞总数: $total"
echo "║ 报告: all-findings.txt"
echo "╚══════════════════════════════════════════════════════════╝"