
ماسح IKE
اكتشف وتحقق من مضيفات IKE (خوادم VPN باستخدام IPsec)
يستخدم ike-scan أدوات GNU autoconf و automake القياسية، لذا فإن التثبيت هو العملية العادية:
git clone https://github.com/royhills/ike-scan.git للحصول على الكود المصدري للمشروعcd ike-scan للدخول إلى دليل المصدرautoreconf --install لإنشاء ملف ./configure قابل للتشغيل./configure أو ./configure --with-openssl لاستخدام مكتبات OpenSSLmake لبناء المشروعmake check للتحقق من أن كل شيء يعمل كما هو متوقعmake install للتثبيت (ستحتاج إلى صلاحيات الجذر أو sudo لهذا الجزء)إذا كنت تخطط لتنفيذ اختراق المفاتيح المشتركة مسبقاً (Pre-Shared Key cracking)، فيجب عليك تهيئة ike-scan لاستخدام دوال التجزئة (hash functions) الخاصة بـ OpenSSL بدلاً من الدوال المدمجة، لأن دوال OpenSSL عادةً ما تكون أسرع. للقيام بذلك، تأكد من تثبيت ملفات الرأس ومكتبات OpenSSL، ثم قم بتشغيل configure كـ ./configure --with-openssl. سواء استخدمت OpenSSL أم لا، فلن يؤثر ذلك على وظائف ike-scan، بل فقط على سرعة اختراق المفاتيح المشتركة مسبقاً باستخدام psk-crack.
تقوم بعض أنظمة التشغيل بتثبيت ملفات الرأس (headers) ومكتبات OpenSSL بشكل افتراضي؛ بينما تتطلب أخرى تثبيت حزمة اختيارية، على سبيل المثال في Debian Linux تحتاج إلى تثبيت حزمة libssl-dev. بدلاً من ذلك، يمكنك تنزيل وتثبيت حزمة OpenSSL المضغوطة من http://www.openssl.org/
يجب أن يعمل البناء على معظم أنظمة التشغيل الحديثة الشبيهة بـ Unix. يعمل على Windows مع Cygwin ويمكن استخدامه كملف تنفيذي مستقل على Windows عند وجود cygwin1.dll.
إذا كنت تستخدم حزمة Windows-32 الثنائية، فيرجى قراءة ملف README-WIN32 الذي يوضح الاختلافات عند التشغيل على منصة Windows.
يُعرف أن البرنامج يُبنى ويُشغل على Linux، FreeBSD، OpenBSD، NetBSD، Win32/Cygwin، Solaris، MacOS X، HP Tru64، HP-UX، و SCO OpenServer. لمزيد من التفاصيل، راجع القسم "المنصات المدعومة" أدناه.
يقوم ike-scan باكتشاف مضيفات IKE ويمكنه أيضًا بصمتها (fingerprint) باستخدام نمط التباطؤ في إعادة الإرسال (retransmission backoff pattern).
يمكن لـ ike-scan القيام بالوظائف التالية:
تتم مناقشة مفهوم بصمة التباطؤ في إعادة الإرسال بمزيد من التفصيل في ورقة بصمة التباطؤ في UDP (UDP backoff fingerprinting paper) والتي يجب تضمينها في حزمة ike-scan كـ UDP Backoff Fingerprinting Paper.
يقوم البرنامج بإرسال طلبات المرحلة الأولى من IKE (الوضع الرئيسي أو الوضع العدواني) إلى المضيفات المحددة ويعرض أي ردود يتم استلامها. يتعامل مع إعادة المحاولة وإعادة الإرسال مع التباطؤ لمواجهة فقدان الحزم. كما يحد من عرض النطاق الترددي المستخدم في حزم IKE الصادرة.
IKE هو بروتوكول تبادل المفاتيح عبر الإنترنت (Internet Key Exchange) وهو آلية تبادل المفاتيح والمصادقة المستخدمة بواسطة IPsec. تقريبًا جميع أنظمة VPN الحديثة تنفذ IPsec، والغالبية العظمى من شبكات VPN باستخدام IPsec تستخدم IKE لتبادل المفاتيح. الوضع الرئيسي هو أحد الأوضاع المحددة للمرحلة الأولى من تبادل IKE (الوضع الآخر المحدد هو الوضع العدواني). تحدد RFC 2409 القسم 5 أن الوضع الرئيسي يجب تنفيذه، لذلك يمكن توقع أن تدعم جميع تطبيقات IKE الوضع الرئيسي. العديد منها يدعم أيضًا الوضع العدواني.
لعرض معلومات الاستخدام الحالية، قم بتشغيل الملف الثنائي ike-scan كما يلي:ike-scan -h
Additional documentation is provided on the NTA Monitor Wiki
To report bugs or suggest new features, please create a GitHub issue.
The hosts to scan can be specified on the command line or read from an input file using the --file=<fn> option. The program can cope with large numbers of hosts limited only by the amount of memory needed to store the list of host_entry structures. Each host_entry structure requires 45 bytes on a 32-bit system, so a class B network (65534 hosts) would require about 2.8 MB for the list. The hosts can be specified as either IP addresses or hostnames, however the program will store all hosts internally as IP addresses and will only display IP addresses in the output (ike-scan calls gethostbyname(3) to determine the IP address of each host, but this can be disabled with the --nodns option).
The program limits the rate at which it sends IKE packets to ensure that it does not overload the network connection. By default it uses an outbound data rate of 56000 bits per second. This can be changed with the --bandwidth option.
If you want to send packets at a specific rate, you can use the --interval option.
ike-scan generates unique IKE cookies for each host, and it uses these cookies to determine which host the response packets belong to. Note that it does not rely on the source IP address of the response packets because it is possible for a response packet to be sent from a different IP address than it was originally sent to. See the PROGRAM OUTPUT section for an example of this.
The cookies are generated by taking the first 64 bits of an MD5 hash of the current time in seconds and microseconds as returned by gettimeofday(), the unique host number, and the host IP address. This ensures that the cookies are unique with a reasonable degree of certainty.
If --verbose is in effect, any packets that are received with cookies that do not match will result in a message like:
Ignoring 84 bytes from 172.16.2.2 with unknown cookie 195c837e5a39f657
إذا لم يكن --verbose مفعّلاً، فسيتم تجاهل هذه الحزم بصمت.
قد يكون سبب عدم تطابق ملف تعريف الارتباط هذا هو: