
Descubra e identifique anfitriões IKE (Servidores VPN IPsec)
O ike-scan utiliza as ferramentas padrão GNU autoconf e automake, portanto a instalação é o processo normal:
git clone https://github.com/royhills/ike-scan.git para obter o código fonte do projetocd ike-scan para entrar no diretório fonteautoreconf --install para gerar um arquivo ./configure viável./configure ou ./configure --with-openssl para usar as bibliotecas OpenSSLmake para compilar o projetomake check para verificar se tudo funciona como esperadomake install para instalar (você precisará de root ou sudo para esta parte)Se você planeja realizar quebra de chave pré-compartilhada, então deve configurar o ike-scan para usar as funções de hash do OpenSSL em vez das funções internas, pois as do OpenSSL são normalmente mais rápidas. Para fazer isso, certifique-se de ter os arquivos de inclusão e bibliotecas do OpenSSL instalados e execute o configure como ./configure --with-openssl. Usar ou não o OpenSSL não afetará a funcionalidade do ike-scan, apenas a velocidade da quebra de chave pré-compartilhada com o psk-crack.
Alguns sistemas operacionais instalam os cabeçalhos e bibliotecas do OpenSSL por padrão; outros exigem que você instale um pacote opcional, por exemplo no Debian Linux você precisa instalar o pacote libssl-dev. Alternativamente, você pode baixar e instalar o tarball do OpenSSL em http://www.openssl.org/
Deve compilar na maioria dos sistemas operacionais modernos do tipo Unix. Funciona no Windows com Cygwin e pode ser usado como um executável Windows autônomo quando o cygwin1.dll estiver presente.
Se você estiver usando o pacote binário Windows-32, leia também o arquivo README-WIN32 que detalha as diferenças ao executar na plataforma Windows.
Sabe-se que o programa compila e funciona em Linux, FreeBSD, OpenBSD, NetBSD, Win32/Cygwin, Solaris, MacOS X, HP Tru64, HP-UX e SCO OpenServer. Para mais detalhes, veja a seção "PLATAFORMAS SUPORTADAS" abaixo.
O ike-scan descobre anfitriões IKE e também pode identificá-los usando o padrão de backoff de retransmissão.
O ike-scan pode realizar as seguintes funções:
O conceito de fingerprinting de backoff de retransmissão é discutido em mais detalhes no artigo sobre fingerprinting de backoff UDP, que deve estar incluído no kit ike-scan como Artigo sobre Fingerprinting de Backoff UDP.
O programa envia solicitações de fase 1 IKE (Modo Principal ou Modo Agressivo) para os anfitriões especificados e exibe quaisquer respostas que sejam recebidas. Ele lida com repetição e retransmissão com backoff para lidar com perda de pacotes. Também limita a quantidade de largura de banda usada pelos pacotes IKE de saída.
IKE é o protocolo Internet Key Exchange, que é o mecanismo de troca de chaves e autenticação usado pelo IPsec. Quase todos os sistemas VPN modernos implementam IPsec, e a grande maioria das VPNs IPsec usa IKE para troca de chaves. O Modo Principal é um dos modos definidos para a fase 1 da troca IKE (o outro modo definido é o modo agressivo). A RFC 2409 seção 5 especifica que o modo principal deve ser implementado, portanto, todas as implementações IKE podem ser esperadas para suportar o modo principal. Muitas também suportam o Modo Agressivo.
Para ver as informações de uso atuais, execute o binário ike-scan da seguinte forma:ike-scan -h
Additional documentation is provided on the NTA Monitor Wiki
To report bugs or suggest new features, please create a GitHub issue.
The hosts to scan can be specified on the command line or read from an input file using the --file=<fn> option. The program can cope with large numbers of hosts limited only by the amount of memory needed to store the list of host_entry structures. Each host_entry structure requires 45 bytes on a 32-bit system, so a class B network (65534 hosts) would require about 2.8 MB for the list. The hosts can be specified as either IP addresses or hostnames, however the program will store all hosts internally as IP addresses and will only display IP addresses in the output (ike-scan calls gethostbyname(3) to determine the IP address of each host, but this can be disabled with the --nodns option).
The program limits the rate at which it sends IKE packets to ensure that it does not overload the network connection. By default it uses an outbound data rate of 56000 bits per second. This can be changed with the --bandwidth option.
If you want to send packets at a specific rate, you can use the --interval option.
ike-scan generates unique IKE cookies for each host, and it uses these cookies to determine which host the response packets belong to. Note that it does not rely on the source IP address of the response packets because it is possible for a response packet to be sent from a different IP address than it was originally sent to. See the PROGRAM OUTPUT section for an example of this.