
IKE 호스트(IPsec VPN 서버)를 탐색하고 지문을 식별합니다.
ike-scan은 표준 GNU autoconf 및 automake 도구를 사용하므로 설치 절차는 일반적입니다:
git clone https://github.com/royhills/ike-scan.git를 실행하여 프로젝트 소스 코드를 가져옵니다.cd ike-scan을 실행하여 소스 디렉터리로 이동합니다.autoreconf --install을 실행하여 사용 가능한 ./configure 파일을 생성합니다../configure 또는 OpenSSL 라이브러리를 사용하려면 ./configure --with-openssl을 실행합니다.make를 실행하여 프로젝트를 빌드합니다.make check를 실행하여 모든 것이 정상적으로 작동하는지 확인합니다.make install을 실행하여 설치합니다(이 부분에는 root 또는 sudo 권한이 필요합니다).사전 공유 키 크래킹을 수행할 계획이라면 ike-scan이 내장 함수 대신 OpenSSL 해시 함수를 사용하도록 구성하는 것이 좋습니다. OpenSSL 함수가 일반적으로 더 빠르기 때문입니다. 이를 위해 OpenSSL include 파일과 라이브러리가 설치되어 있는지 확인하고 ./configure --with-openssl로 configure를 실행하십시오. OpenSSL 사용 여부는 ike-scan의 기능에 영향을 미치지 않으며, psk-crack을 이용한 사전 공유 키 크래킹 속도에만 영향을 줍니다.
일부 운영 체제는 OpenSSL 헤더와 라이브러리를 기본적으로 설치합니다. 다른 운영 체제는 선택적 패키지를 설치해야 합니다. 예를 들어 Debian Linux에서는 libssl-dev 패키지를 설치해야 합니다. 또는 http://www.openssl.org/ 에서 OpenSSL tarball을 다운로드하여 설치할 수 있습니다.
대부분의 최신 Unix 계열 OS에서 빌드되어야 합니다. Cygwin이 설치된 Windows에서도 작동하며, cygwin1.dll이 있는 경우 독립 실행형 Windows 실행 파일로 사용할 수 있습니다.
Windows-32 바이너리 패키지를 사용하는 경우, Windows 플랫폼에서 실행할 때의 차이점을 설명하는 README-WIN32 파일도 함께 읽어 주시기 바랍니다.
이 프로그램은 Linux, FreeBSD, OpenBSD, NetBSD, Win32/Cygwin, Solaris, MacOS X, HP Tru64, HP-UX, SCO OpenServer에서 빌드 및 실행되는 것으로 알려져 있습니다. 자세한 내용은 아래 "지원 플랫폼" 섹션을 참조하십시오.
ike-scan은 IKE 호스트를 탐색하고 재전송 백오프 패턴을 사용하여 지문을 식별할 수도 있습니다.
ike-scan은 다음 기능을 수행할 수 있습니다:
재전송 백오프 지문 식별 개념은 ike-scan 키트에 포함된 UDP 백오프 지문 식별 논문에서 더 자세히 설명됩니다.
이 프로그램은 지정된 호스트에 IKE phase-1(Main Mode 또는 Aggressive Mode) 요청을 보내고 수신된 모든 응답을 표시합니다. 패킷 손실에 대처하기 위해 재시도 및 백오프를 통한 재전송을 처리합니다. 또한 나가는 IKE 패킷에 사용되는 대역폭을 제한합니다.
IKE는 IPsec에서 사용하는 키 교환 및 인증 메커니즘인 인터넷 키 교환(Internet Key Exchange) 프로토콜입니다. 거의 모든 최신 VPN 시스템은 IPsec을 구현하며, 대부분의 IPsec VPN은 키 교환에 IKE를 사용합니다. Main Mode는 IKE 교환의 phase-1에 대해 정의된 모드 중 하나입니다(다른 정의된 모드는 Aggressive Mode입니다). RFC 2409 섹션 5는 main mode를 구현해야 한다고 명시하므로 모든 IKE 구현이 main mode를 지원할 것으로 예상됩니다. 많은 구현에서 Aggressive Mode도 지원합니다.
현재 사용법 정보를 보려면 다음과 같이 ike-scan 바이너리를 실행하십시오:ike-scan -h
Additional documentation is provided on the NTA Monitor Wiki
To report bugs or suggest new features, please create a GitHub issue.
The hosts to scan can be specified on the command line or read from an input file using the --file=<fn> option. The program can cope with large numbers of hosts limited only by the amount of memory needed to store the list of host_entry structures. Each host_entry structure requires 45 bytes on a 32-bit system, so a class B network (65534 hosts) would require about 2.8 MB for the list. The hosts can be specified as either IP addresses or hostnames, however the program will store all hosts internally as IP addresses and will only display IP addresses in the output (ike-scan calls gethostbyname(3) to determine the IP address of each host, but this can be disabled with the --nodns option).
The program limits the rate at which it sends IKE packets to ensure that it does not overload the network connection. By default it uses an outbound data rate of 56000 bits per second. This can be changed with the --bandwidth option.
If you want to send packets at a specific rate, you can use the --interval option.
ike-scan generates unique IKE cookies for each host, and it uses these cookies to determine which host the response packets belong to. Note that it does not rely on the source IP address of the response packets because it is possible for a response packet to be sent from a different IP address than it was originally sent to. See the PROGRAM OUTPUT section for an example of this.
The cookies are generated by taking the first 64 bits of an MD5 hash of the current time in seconds and microseconds as returned by gettimeofday(), the unique host number, and the host IP address. This ensures that the cookies are unique with a reasonable degree of certainty.
If --verbose is in effect, any packets that are received with cookies that do not match will result in a message like:
Ignoring 84 bytes from 172.16.2.2 with unknown cookie 195c837e5a39f657
If --verbose 옵션이 활성화되지 않은 경우, 이러한 패킷은 자동으로 무시됩니다.
이러한 쿠키 불일치는 다음과 같은 이유로 발생할 수 있습니다:
전송되는 메인 모드 패킷에는 ISAKMP 헤더와 SA 페이로드가 포함됩니다. SA 페이로드는 단일 제안을 포함하며, 제안은 아래에 설명된 대로 가변적인 수의 변환(transform)을 포함할 수 있습니다.
기본적으로 SA 제안은 8개의 변환을 포함합니다. 이 8개의 변환은 다음의 모든 가능한 조합을 나타냅니다:
기본 변환 세트를 사용하여 ike-scan이 전송한 메인 모드 패킷의 예시 tcpdump 출력은 아래와 같습니다. 이는 8개의 변환과 전송 순서를 보여줍니다: