
Mass reconnaissance, version fingerprinting, CVE tester and live exploitation framework for Ollama open instances.
Modular toolkit for discovering exposed Ollama servers, fingerprinting versions, and validating model access.
OllamaHound is a modular, RedTeam oriented toolkit for discovering publicly exposed Ollama servers, fingerprinting versions, classifying CVE exposure, validating whether text generation is possible, and (optionally) enabling an interactive CLI session for controlled testing.
@@@@@@@@@@@@@@@@@@@@@@@@@@@#*#@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@%.-+-:#@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@+--=%@@@@@@@@-.@@@+ #@@@@@@@@@@@@@@@@@ @@@@@@@@@@@= %%+.=@@@%###-.@@@@= %@@@@@@@@@@@@@@@@ @@@@@@@@@@@-.@@@@..--====-.=@@@@.-@@@@@@@@@@@@@@@@ @@@@@@@@@@@# +#+-:*%@@@@@@@@@@@@- +@@@@@@@@@@@@@@@ @@*@@@@@#*+=:::.-*%@@@@@@@@@@@@@@%::%@@@@@@@@@@@@@ @+:-@@*----=***+==-=#@@@@@@@@@@@@@@::@@@@@@@@@@@@@ @*+#@=-==+=%@@@@%#=+:*%%%@@@@#++%@@+ %@@@@@@@@@@@@ +:=@#.+-@#=#@%+++%@:* =++==*@- *@@-.@@@@@@@@@@@@@ %=+@+--*@@*=##+++%#.+::=@#%:+@%@@@@%.=@@@@@@@@@@@@ @@@@#.+-@@%=*@@@@@+.* =-:*@-=@@@@@@@* %@@@@@@@@@@@ @@@@@+:==#*=%@@@@*-=.:--+*-=@@@@@@@@+ %@@@@@@@@@@@ @@@@@@#=----+*++=--=**++*#%@@@@@@@@% =@@@@@@@@@@@@ @@@@@@@@%*-:---.+*%@@@@@@@@@@@@@@@@+-:+@@@@@@@@@@@ @@@@@@@@@@# ==:.%@@@@@@@@@@@@@@@@@@@@%.-@@@@@@@@@@ @@@@@@@@@@#.@@:.#@@@@@@@@@@@@@@#@@@@@@% *@@@@@@@@@ @@@@@@@@@*::--::=%@@@@@@@@@@@@::@@@@@@@ =@@@@@@@@@ @@@@@@@@-.#@@@@@-.@@@@@@@@@@#.-@@@@@@@@*.-@@@@@@@@ @@@@@@@@.-@@@@@%::@@@@@@@@%=.+@@@@@@@@@@%.-@@@@@@@ @@@@@@@@#::++=::+@@@@@@@%=:=%@@@@@%%@@@@@+ @@@@@@@ @@@@@@@@@@=.:: #@@@@@@@=.+@@@@@@%=:*@@@@@= @@@@@@@ @@@@@@@@@@@@%-.%@@@@@@# *@@@@@#-:+@@@@@@% +@@@@@@@ @@@@@@@@@@@@@.=@@@@@@@@=:===---*@@@@@@@@@.=@@@@@@@ @@@@@@@@@@@@@=.%@@@@@@@@#-##%@@@@@@@@@@@@.-@@@@@@@ @@@@@@@@@@@@@@= -%@@@@@@# #@@@@@@@@@@@@@# #@@@@@@@ @@@@@@@@@@@@@@@ .:=*%%@%#..*@@@@@@@@@@@+.+@@@@@@@@ @@@@@@@@@@@@@@@.=@*==- -=*. --==+*#**=:-#@@@@@@@@@ @@@@@@@@@@@@@@@:-@@@@# #@@+ %%##*..++#%@@@@@@@@@@@ @@@@@@@@@@@@@@@::@@@@-.@@@% *@@@@-:@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@*.=++::%@@@@::%@%+ *@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@%***%@@@@@@%=---=%@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@---OllamaHound---@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@---By 7h30th3r0n3---@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
!!! WARNING !!!
⚠️ Legal & Ethics Notice
This project is intended for authorized security assessments (internal networks, scoped engagements, lab environments).
Use only on systems you own or where you have explicit written permission.
By using this software, you agree that you are solely responsible for your actions.
The author(s) and contributors provide this software "as is" and disclaim all liability
for any misuse, damage, or legal consequences arising from its use.
ScannerHigh‑scale async discovery, version fingerprinting, CVE classification, model probing.
|
ConnectorRich‑UI interactive CLI client to talk to a discovered Ollama instance.
|
ScraperShodan-backed target harvester that builds
|
NavigatorSearch/filter helper for scanner CSVs with exports + interactive menu.
|
OrchestratorChains scraper → scanner → connector, handing each output to the next.
|
ResultsOutputs live under |
/api/tags and /api/generateresults/scraper/targets.txtresults/scanner/<prefix>_YYYYMMDD_HHMMSS.csvYou can do this step-by-step or run the Orchestrator to chain the first three stages.
asyncio + aiohttp (thousands of sockets in flight)rich<prefix>_YYYYMMDD_HHMMSS.csvGET /api/version → fallback GET /version → fallback Server header< 0.1.47<= 0.3.14GET /api/tagsPOST /api/generate/api/generate returns HTTP 200 bubble to the top--gen-ok-only keeps only hosts with working /api/generate--vuln-only keeps only hosts classified RCE/DoS--show-unknown includes hosts with unknown/unparseable versionsaiohttprichpackagingrequestsshodanInstall dependencies:
python3 -m pip install -U aiohttp rich packaging requests shodan
Use Docker:
docker build -t ollamahound .
docker run -it --rm ollamahound <ollamahound scripts>
Option A (fastest): scrape → scan → connect
python3 ollamaScraper.py
python3 ollamaScanner.py results/scraper/targets.txt --gen-ok-only
python3 ollamaConnector.py --scan-csv results/scanner/ollama_scan_*.csv
Option B (one-shot): orchestrator pipeline
python3 ollamaOrchestrator.py --scan-gen-ok-only
ollamaOrchestrator.py simply runs the scraper, scanner, then connector so you can move from Shodan harvesting to an interactive CLI in a single command. The scraper and connector remain interactive, but the orchestrator wires their outputs together for you.
python3 ollamaOrchestrator.py --scan-gen-ok-only --scan-vuln-only