Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Ingram — 网络摄像头漏洞扫描工具 | Webcam vulnerability scanning tool | Kitploit
Tools/GitHubGitHub/jorhelp/ingram
Vulnerability ScannersIoT SecurityExploitationInformation Gathering
GitHubjorhelp/ingram

Ingram

网络摄像头漏洞扫描工具 | Webcam vulnerability scanning tool

View Repository
2.3k37312 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Ingram
Platform Python Version GitHub Github Checks GitHub Last Commit (master) Languages Count

English | 简体中文

Intro

This is a web camera device vulnerability scanning tool, which already supports Hikvision, Dahua and other devices

run

Installation

Please run it under Linux or Mac. Please make sure you have installed Python >= 3.8, but 3.11 is not recommended.

  • Firstly, clone this repo:
root@kitploit:~
git clone https://github.com/jorhelp/Ingram.git
  • Then, go to the repo dir, create a virtual environment and activate it:
root@kitploit:~
cd Ingram
pip3 install virtualenv
python3 -m virtualenv venv
source venv/bin/activate
  • After that, install dependencies:
root@kitploit:~
pip3 install -r requirements.txt

So far, it has been installed!

Run

  • Since it is configured in a virtual environment, pls activate the virtual environment before each running

  • You need to prepare an target file, let's name it input, which contains the targets that will be scanned. The content of input file can be:

root@kitploit:~
# use '#' to comment

# single ip
192.168.0.1

# ip with a port
192.168.0.2:80

# ip segment ('/')
192.168.0.0/16

# ip segment ('-')
192.168.0.0-192.168.255.255
  • With the input file, let's start scanning:
root@kitploit:~
python3 run_ingram.py -i input -o output
  • If you specified the port like: x.x.x.x:80, then the port 80 will be scanned, otherwise common ports will be scanned(defined in Ingram/config.py). And you can also override it with the -p argument such as:
root@kitploit:~
python3 run_ingram.py -i input -o output -p 80 81 8000
  • The number of coroutines can be controlled by the -t argument:
root@kitploit:~
python3 run_ingram.py -i input -o output -t 500
  • all arguments:
root@kitploit:~
optional arguments:
  -h, --help            show this help message and exit
  -i IN_FILE, --in_file IN_FILE
                        the targets will be scan
  -o OUT_DIR, --out_dir OUT_DIR
                        the dir where results will be saved
  -p PORTS [PORTS ...], --ports PORTS [PORTS ...]
                        the port(s) to detect
  -t TH_NUM, --th_num TH_NUM
                        the processes num
  -T TIMEOUT, --timeout TIMEOUT
                        requests timeout
  -D, --disable_snapshot
                        disable snapshot
  --debug

Port scanner

  • We can use powerful port scanner to obtain active hosts, thereby reducing the scanning range of Ingram and improving the running speed. The specific method is to organize the result file of the port scanner into the format of ip:port and use it as the input file of Ingram

  • Here is a brief demonstration of masscan as an example (the detailed usage of masscan will not be repeated here).

  • First, use masscan to scan the surviving host on port 80 or 8000-8008 (you sure can change the port anything else if you want): masscan -p80,8000-8008 -iL INPUT -oL OUTPUT --rate 8000

  • After masscan is done, sort out the result file: grep 'open' OUTPUT | awk '{printf"%s:%s\n", $4, $3}' > input

  • Then: python run_ingram.py -i input -o output

Output

root@kitploit:~
.
├── not_vulnerable.csv
├── results.csv
├── snapshots
└── log.txt
  • results.csv contains the vulnerable devices: ip,port,device-type,user,password,vul:
Ingram
  • not_vulnerable.csv contains the not vulnerable devices

  • snapshots contains some snapshots of a part of devices (not all device can have a snapshot!!!):

Ingram

Warning

This tool is for security testing only, it is strictly prohibited to use it for illegal purposes, and the consequences have nothing to do with this team.

Thanks & Reference

Thanks to Aiminsun for CVE-2021-36260
Thanks to chrisjd20 for hidvision config file decryptor
Thanks to mcw0 for DahuaConsole

Download Tool