Skip to content
KitploitKITPLOIT
ИнструментыБлог
Отправить
ИнструментыБлог
Отправить

Инструменты для хакинга, пентеста и кибербезопасности — ваш арсенал защиты!

Kitploit — это каталог инструментов для хакинга, кибербезопасности и пентестинга. Находите последние обновления проектов для поиска уязвимостей, анализа систем, автоматизации тестирования и усиления вашей безопасности.

··Ленты·Контакты·Конфиденциальность·© 2026 Kitploit

Каталог инструментов

Категории

Все категории
Loading categories
canTot — быстрый и грязный фреймворк для х4кинга canbus | Kitploit
Инструменты/GitHubGitHub/shipcod3/cantot
Фреймворки для эксплойтовФаззингТестирование на Проникновение
GitHubshipcod3/cantot

canTot

быстрый и грязный фреймворк для х4кинга canbus

Репозиторий
150272 лет назадПроверено Kitploit

Популярное

Смотреть все →

Откройте для себя самые используемые инструменты нашего сообщества.

Изучить все инструменты

Просмотрите нашу коллекцию инструментов

Смотреть все инструменты →
Поделиться

canTot

canTot — это CLI-фреймворк на Python, основанный на sploitkit, который прост в использовании, так как напоминает работу с Metasploit. Он похож на эксплойт-фреймворк, но сосредоточен на известных уязвимостях CAN-шины или забавных хаках CAN-шины. Его также можно использовать как руководство по пентесту автомобилей и изучению Python для более лёгкого пути в автовзломе. Это не попытка изобрести заново известные CAN-фаззеры, инструменты для исследования автомобилей вроде caring caribou или другие отличные анализаторы CAN. Скорее, это объединение всех известных уязвимостей и забавных хаков CAN-шины в области автомобильной безопасности.

Проект, созданный Car Hacking Village Philippines.

Установка

root@kitploit:~
git clone https://github.com/shipcod3/canTot
cd canTot
pip3 install -r requirements.txt

Примечание: Лучше работает с Kali и Ubuntu.

Пример использования фреймворка:

root@kitploit:~
─$ python3 main.py 

                                                                                                                                                                                                                  
                                                                             @@@@@@@   @@@@@@   @@@  @@@  @@@@@@@   @@@@@@   @@@@@@@                                                                              
                                                                            @@@@@@@@  @@@@@@@@  @@@@ @@@  @@@@@@@  @@@@@@@@  @@@@@@@                                                                              
                                                                            !@@       @@!  @@@  @@!@!@@@    @@!    @@!  @@@    @@!                                                                                
                                                                            !@!       !@!  @!@  !@!!@!@!    !@!    !@!  @!@    !@!                                                                                
                                                                            !@!       @!@!@!@!  @!@ !!@!    @!!    @!@  !@!    @!!                                                                                
                                                                            !!!       !!!@!!!!  !@!  !!!    !!!    !@!  !!!    !!!                                                                                
                                                                            :!!       !!:  !!!  !!:  !!!    !!:    !!:  !!!    !!:                                                                                
                                                                            :!:       :!:  !:!  :!:  !:!    :!:    :!:  !:!    :!:                                                                                
                                                                             ::: :::  ::   :::   ::   ::     ::    ::::: ::     ::                                                                                
                                                                             :: :: :   :   : :  ::    :      :      : :  :      :                                                                                 
                                                                                                                                                                                                                  
                                                                                                                                                                                                                  
                                                                                                         ███████████           █████                                                                              
                                                                                                        ░█░░░███░░░█          ░░███                                                                               
                                                                            ██████   ██████   ████████  ░   ░███  ░   ██████  ███████                                                                             
                                                                           ███░░███ ░░░░░███ ░░███░░███     ░███     ███░░███░░░███░                                                                              
                                                                          ░███ ░░░   ███████  ░███ ░███     ░███    ░███ ░███  ░███                                                                               
                                                                          ░███  ███ ███░░███  ░███ ░███     ░███    ░███ ░███  ░███ ███                                                                           
                                                                          ░░██████ ░░████████ ████ █████    █████   ░░██████   ░░█████                                                                            
                                                                           ░░░░░░   ░░░░░░░░ ░░░░ ░░░░░    ░░░░░     ░░░░░░     ░░░░░                                                                             
                                                                                                                                                                                                                  
                                                                                                                                                                                                                  
                                                                                    >> quick and dirty canbus h4xing framework                                                                                    
                                                                                                   >> @shipcod3                                                                                                   
                                                                                                                                                                                                                  
                                                                                                                                                                                                                  
 
        -=[ 13 uncategorized ]=-                                                                                                                                                                                   
                                                                                                                                                                                                                  
cantot > show modules                                                                                                                                                                                             

Uncategorized modules
=====================

   Name                         Path  Enabled  Description                                                                                                                                                     
   ----                         ----  -------  -----------                                                                                                                                                     
   cherokee_kill_brakes         .     Y        This module will bleed all the brakes on the 2014 Jeep Cherokee while the car is moving. This has the result that the brakes will not work during this time and 
                                               has significant safety issues, even if it only works if you are driving slowly.                                                                                 
   cherokee_kill_engine         .     Y        This module will kill the engine on the 2014 Jeep Cherokee while the car is moving at low speed by killing a particular fuel injector.                          
   cherokee_turn_steering       .     Y        This module will put the Parking Assist Module(PAM) in diagnostic session and send a CAN message to tell the power steering ECU to turn the wheel for the Jeep  
                                               Cherokee 2014.                                                                                                                                                  
   diagnostic_state             .     Y        This module will keep the vehicle in a diagnostic state on loop by sending tester present packet.                                                               
   ecu_hard_reset               .     Y        This module performs hard reset in the ECU Reset Service Identifier (0x11).                                                                                     
   ford_escape_door_ajar_spoof  .     Y        This module will indicate that the door is ajar (open) from the instrument panel despite not opened.                                                            
   ford_escape_kill_engine      .     Y        This module will kill the engine for Ford Escape 2010 without establishing a diagnostic session and works at any speed.                                         
   jeep_wrangler_evicsend       .     Y        This module allows you to display the word Hacked on a 2012 Jeep Wrangler EVIC.                                                                                 
   kill_bus                     .     Y        This module will perform a known denial of service via the CAN bus called Firehose attack.                                                                      
   malibu_overheat              .     Y        This module will flood temp gauge on a 2006 Malibu.                                                                                                             
   mazda_ic_mover               .     Y        This module moves the needle of the accelorometer and speedometer of the Mazda 2 instrument cluster.                                                            
   prius_park_kill_engine       .     Y        This module will kill the fuel to individual or all cylinders in the internal combustion engine of a Toyota Prius 2010 but requires it to be parked.            
   reset_mileage                .     Y        This module clears diagnostic trouble codes and resets the mileage.

cantot > use diagnostic_state                                                                                                                                                                                     
cantot (diagnostic_state) > show options                                                                                                                                                                          

Module options
==============

   Name       Value  Required  Description                     
   ----       -----  --------  -----------                     
   ARBID      2015   Y         Arbitration ID (Default: 0x7DF) 
   INTERFACE  vcan0  Y         CAN interface                   

cantot (diagnostic_state) > run                                                                                                                                                                                    
[*] Putting the vehicle in a diagnostic state...
Press Ctrl+C to stop or cancel

Автор

Jay Turla

Если вам нравится canTot, вы можете угостить меня кофе в поддержку этого проекта :)

Купи мне кофе

Участники

  • superuserx

Благодарности

  • Nikhil Bogam за CVE-2022-26269 и разрешение портировать его находки.
  • Charlie Miller и Chris Valasek за их исследования и статьи.
  • Ian Tabor (mintynet) за советы и наставничество.
  • Car Hacking Village
  • Eric Evenchick за pyvit
  • Alexandre D'Hondt за sploitkit
  • carfucar за вдохновение для canfuzz_sids.py
  • Craig Smith за «Car Hacker's Handbook» и вдохновение для hwbridge
  • ps1337 за udsSecAccess.py для сканирования UDS-сервисов через Security Access
  • Keen Security Lab от Tencent за их хаки Tesla
  • superuserx за исправление логической ошибки в uds_sec_access.py
Скачать инструмент