Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
OllamaHound — Mass reconnaissance, version fingerprinting, CVE tester and live exploitation framework for Ollama open instances. | Kitploit
Tools/GitHubGitHub/7h30th3r0n3/ollamahound
OSINT (Open Source Intelligence)ReconnaissanceVulnerability ScannersExploitationInformation GatheringWeb SecurityPenetration TestingCommand and ControlRed Teaming
GitHub7h30th3r0n3/ollamahound

OllamaHound

Mass reconnaissance, version fingerprinting, CVE tester and live exploitation framework for Ollama open instances.

623128 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

OllamaHound

Modular toolkit for discovering exposed Ollama servers, fingerprinting versions, and validating model access.

Python Status License

OllamaHound is a modular, RedTeam oriented toolkit for discovering publicly exposed Ollama servers, fingerprinting versions, classifying CVE exposure, validating whether text generation is possible, and (optionally) enabling an interactive CLI session for controlled testing.

@@@@@@@@@@@@@@@@@@@@@@@@@@@#*#@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@%.-+-:#@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@+--=%@@@@@@@@-.@@@+ #@@@@@@@@@@@@@@@@@
@@@@@@@@@@@= %%+.=@@@%###-.@@@@= %@@@@@@@@@@@@@@@@
@@@@@@@@@@@-.@@@@..--====-.=@@@@.-@@@@@@@@@@@@@@@@
@@@@@@@@@@@# +#+-:*%@@@@@@@@@@@@- +@@@@@@@@@@@@@@@
@@*@@@@@#*+=:::.-*%@@@@@@@@@@@@@@%::%@@@@@@@@@@@@@
@+:-@@*----=***+==-=#@@@@@@@@@@@@@@::@@@@@@@@@@@@@
@*+#@=-==+=%@@@@%#=+:*%%%@@@@#++%@@+ %@@@@@@@@@@@@
+:=@#.+-@#=#@%+++%@:* =++==*@-  *@@-.@@@@@@@@@@@@@
%=+@+--*@@*=##+++%#.+::=@#%:+@%@@@@%.=@@@@@@@@@@@@
@@@@#.+-@@%=*@@@@@+.* =-:*@-=@@@@@@@* %@@@@@@@@@@@
@@@@@+:==#*=%@@@@*-=.:--+*-=@@@@@@@@+ %@@@@@@@@@@@
@@@@@@#=----+*++=--=**++*#%@@@@@@@@% =@@@@@@@@@@@@
@@@@@@@@%*-:---.+*%@@@@@@@@@@@@@@@@+-:+@@@@@@@@@@@
@@@@@@@@@@# ==:.%@@@@@@@@@@@@@@@@@@@@%.-@@@@@@@@@@
@@@@@@@@@@#.@@:.#@@@@@@@@@@@@@@#@@@@@@% *@@@@@@@@@
@@@@@@@@@*::--::=%@@@@@@@@@@@@::@@@@@@@ =@@@@@@@@@
@@@@@@@@-.#@@@@@-.@@@@@@@@@@#.-@@@@@@@@*.-@@@@@@@@
@@@@@@@@.-@@@@@%::@@@@@@@@%=.+@@@@@@@@@@%.-@@@@@@@
@@@@@@@@#::++=::+@@@@@@@%=:=%@@@@@%%@@@@@+ @@@@@@@
@@@@@@@@@@=.:: #@@@@@@@=.+@@@@@@%=:*@@@@@= @@@@@@@
@@@@@@@@@@@@%-.%@@@@@@# *@@@@@#-:+@@@@@@% +@@@@@@@
@@@@@@@@@@@@@.=@@@@@@@@=:===---*@@@@@@@@@.=@@@@@@@
@@@@@@@@@@@@@=.%@@@@@@@@#-##%@@@@@@@@@@@@.-@@@@@@@
@@@@@@@@@@@@@@= -%@@@@@@# #@@@@@@@@@@@@@# #@@@@@@@
@@@@@@@@@@@@@@@ .:=*%%@%#..*@@@@@@@@@@@+.+@@@@@@@@
@@@@@@@@@@@@@@@.=@*==- -=*. --==+*#**=:-#@@@@@@@@@
@@@@@@@@@@@@@@@:-@@@@# #@@+ %%##*..++#%@@@@@@@@@@@
@@@@@@@@@@@@@@@::@@@@-.@@@% *@@@@-:@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@*.=++::%@@@@::%@%+ *@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@%***%@@@@@@%=---=%@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@---OllamaHound---@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@---By 7h30th3r0n3---@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@

!!! WARNING !!!

⚠️ Legal & Ethics Notice

This project is intended for authorized security assessments (internal networks, scoped engagements, lab environments).
Use only on systems you own or where you have explicit written permission.
By using this software, you agree that you are solely responsible for your actions.
The author(s) and contributors provide this software "as is" and disclaim all liability
for any misuse, damage, or legal consequences arising from its use.


Table of contents

  • Modules
  • Typical flow
  • Key features (Scanner)
  • Requirements
  • Quick start
  • Command cheat sheet
  • Scanner output
  • Navigator (scanner CSV helper)
  • Connector (interactive CLI)
  • Scraper (Shodan helper)
  • Orchestrator flags (high-level)
  • Output files (summary)
  • Notes on model size parsing
  • Safety, ethics, and scope
  • Author

Modules

Scanner

High‑scale async discovery, version fingerprinting, CVE classification, model probing.

ollamaScanner.py

Connector

Rich‑UI interactive CLI client to talk to a discovered Ollama instance.

ollamaConnector.py

Scraper

Shodan-backed target harvester that builds targets.txt interactively.

ollamaScraper.py

Navigator

Search/filter helper for scanner CSVs with exports + interactive menu.

ollamaNavigator.py

Orchestrator

Chains scraper → scanner → connector, handing each output to the next.

ollamaOrchestrator.py

Results

Outputs live under results/ for easy reuse across modules.


Features

  • ⚡ High‑scale scanning with async sockets and rich progress UI
  • 🧠 Version + CVE classification for RCE/DoS exposure
  • ✅ Model validation via /api/tags and /api/generate
  • 🧭 Navigator filters for dedupe, sorting, and export
  • 💬 Interactive connector to test prompts safely

Typical flow

  1. Scrape targets (optional) → results/scraper/targets.txt
  2. Scan targets → results/scanner/<prefix>_YYYYMMDD_HHMMSS.csv
  3. Navigate + filter results → optional JSON/CSV exports
  4. Connect to a chosen host/model → interactive CLI

You can do this step-by-step or run the Orchestrator to chain the first three stages.


Key features (Scanner)

  • Fast, asynchronous scanning using asyncio + aiohttp (thousands of sockets in flight)
  • Progress UI (ETA, throughput, completion) via rich
  • Timestamped CSV reporting: <prefix>_YYYYMMDD_HHMMSS.csv
  • Colorized table output
    • RCE: red
    • DoS: yellow
    • Patched: green
  • Version parsing
    • GET /api/version → fallback GET /version → fallback Server header
  • CVE classification
    • CVE-2024-7773 (RCE): version < 0.1.47
    • CVE-2025-0317 (DoS): version <= 0.3.14
  • Model discovery & validation
    • Enumerates models via GET /api/tags
    • Tests generation via POST /api/generate
  • Smart sorting
    • Hosts where /api/generate returns HTTP 200 bubble to the top
  • Powerful filters
    • --gen-ok-only keeps only hosts with working /api/generate
    • --vuln-only keeps only hosts classified RCE/DoS
    • --show-unknown includes hosts with unknown/unparseable versions
  • Tunable
    • multi‑port, timeouts, concurrency, CSV prefix

Requirements

  • Python 3.10+
  • Packages:
    • aiohttp
    • rich
    • packaging
    • requests
    • shodan

Install dependencies:

python3 -m pip install -U aiohttp rich packaging requests shodan

Use Docker:

docker build -t ollamahound .
docker run -it --rm ollamahound <ollamahound scripts>

Quick start

Quick start minimal (2–3 commands)

Option A (fastest): scrape → scan → connect

python3 ollamaScraper.py
python3 ollamaScanner.py results/scraper/targets.txt --gen-ok-only
python3 ollamaConnector.py --scan-csv results/scanner/ollama_scan_*.csv

Option B (one-shot): orchestrator pipeline

python3 ollamaOrchestrator.py --scan-gen-ok-only

Orchestrator (one-shot scrape → scan → connect)

ollamaOrchestrator.py simply runs the scraper, scanner, then connector so you can move from Shodan harvesting to an interactive CLI in a single command. The scraper and connector remain interactive, but the orchestrator wires their outputs together for you.

python3 ollamaOrchestrator.py --scan-gen-ok-only --scan-vuln-only
Download Tool