
Shodanwave è uno strumento per esplorare e ottenere informazioni da Netwave IP Camera.
Shodanwave è uno strumento per esplorare e ottenere informazioni da telecamere, in particolare Netwave IP Camera. Lo strumento utilizza un motore di ricerca chiamato shodan che semplifica la ricerca di telecamere online.
Cosa fa lo strumento? Guarda, una lista!
Questo è un esempio di shodan wave in esecuzione, la password non è stata trovata tramite forza bruta, quindi lo strumento tenta di estrarre la memoria della telecamera. Se lo strumento trova la password, non tenta di estrarre la memoria.
Per usare shodanwave hai bisogno di una chiave API che puoi ottenere gratuitamente su https://www.shodan.io/, poi devi seguire i passaggi successivi.
$ cd /opt/
$ git clone https://github.com/fbctf/shodanwave.git
$ cd shodanwave
$ pip install -r requirements.txt
Usage: python shodanwave.py -u usernames.txt -w passwords.txt -k Shodan API key --t OUTPUT
python shodanwave.py --help
__ __
_____/ /_ ____ ____/ /___ _____ _ ______ __ _____
/ ___/ __ \/ __ \/ __ / __ `/ __ \ | /| / / __ `/ | / / _ \
(__ ) / / / /_/ / /_/ / /_/ / / / / |/ |/ / /_/ /| |/ / __/
/____/_/ /_/\____/\__,_/\__,_/_/ /_/|__/|__/\__,_/ |___/\___/
This tool is successfully connected to shodan service
Information the use of this tool is illegal, not bad.
usage: shodanwave.py [-h] [-s SEARCH] [-u USERNAME] [-w PASSWORD] [-k ADDRESS]
optional arguments:
-h, --help show this help message and exit
-s SEARCH, --search SEARCH
Default Netwave IP Camera
-u USERNAME, --username USERNAME
Select your usernames wordlist
-w PASSWORD, --wordlist PASSWORD
Select your passwords wordlist
-k ADDRESS, --shodan ADDRESS
Shodan API key
-l LIMIT, --limit LIMIT
Limit the number of registers responsed by Shodan
-o OFFSET, --offset OFFSET
Shodan skips this number of registers from response
-t OUTPUT, --output OUTPUT
Save the results
-p, --tor
All Requests/Wgets go through Tor
Usa questo strumento con saggezza e non per scopi malvagi. Per ottenere le migliori prestazioni di questo strumento, devi pagare per shodan per ottenere accesso completo all'API. Le opzioni --limit e --offset potrebbero richiedere una chiave API a pagamento e consumare crediti di query dal tuo account Shodan.
I codici di esempio sono forniti a scopo educativo. Difese adeguate possono essere costruite solo ricercando le tecniche di attacco disponibili agli attori malintenzionati. L'uso di questo codice contro sistemi target senza autorizzazione preventiva è illegale nella maggior parte delle giurisdizioni. Gli autori non sono responsabili per eventuali danni derivanti dall'uso improprio di queste informazioni o di questo codice.
Modifica la tua configurazione Tsocks!!
49m12JEEC6HPCHkLMX5QL4SrDQdKwh6eb4Muu8Z9CwA9MwemhzFQ3VcgHwyuR73rC22WCymTUyep7DVrfN3GPt5JBCekPrR