Shodanwave 是一款用于探索和获取摄像头信息(特别是 Netwave IP 摄像头)的工具。该工具利用名为 Shodan 的搜索引擎,可以轻松地在网络上搜索摄像头。
该工具能做什么?看,列表在这里!
这是 Shodanwave 运行的一个示例,密码未通过暴力破解找到,因此工具尝试泄露摄像头内存。如果工具找到了密码,就不会尝试泄露内存。
要使用 Shodanwave,您需要一个 API 密钥,该密钥可在 https://www.shodan.io/ 免费获取,然后您需要按照以下步骤操作。
$ cd /opt/
$ git clone https://github.com/fbctf/shodanwave.git
$ cd shodanwave
$ pip install -r requirements.txt
Usage: python shodanwave.py -u usernames.txt -w passwords.txt -k Shodan API key --t OUTPUT
python shodanwave.py --help
__ __
_____/ /_ ____ ____/ /___ _____ _ ______ __ _____
/ ___/ __ \/ __ \/ __ / __ `/ __ \ | /| / / __ `/ | / / _ \
(__ ) / / / /_/ / /_/ / /_/ / / / / |/ |/ / /_/ /| |/ / __/
/____/_/ /_/\____/\__,_/\__,_/_/ /_/|__/|__/\__,_/ |___/\___/
该工具已成功连接到 Shodan 服务
请注意,使用此工具进行非法活动是不被允许的。
usage: shodanwave.py [-h] [-s SEARCH] [-u USERNAME] [-w PASSWORD] [-k ADDRESS]
optional arguments:
-h, --help show this help message and exit
-s SEARCH, --search SEARCH
Default Netwave IP Camera
-u USERNAME, --username USERNAME
Select your usernames wordlist
-w PASSWORD, --wordlist PASSWORD
Select your passwords wordlist
-k ADDRESS, --shodan ADDRESS
Shodan API key
-l LIMIT, --limit LIMIT
Limit the number of registers responsed by Shodan
-o OFFSET, --offset OFFSET
Shodan skips this number of registers from response
-t OUTPUT, --output OUTPUT
Save the results
-p, --tor
All Requests/Wgets go through Tor
请明智地使用此工具,不要用于恶意目的。要获得此工具的最佳性能,您需要付费获取 Shodan 的完整 API 访问权限。选项 --limit 和 --offset 可能需要付费的 API 密钥,并且会消耗您的 Shodan 账户的查询额度。
代码示例仅供教育目的提供。只有研究攻击者使用的攻击技术,才能构建充分的防御。未经事先许可,针对目标系统使用此代码在大多数司法管辖区是违法的。作者不对因滥用此信息或代码造成的任何损害承担责任。
修改你的 Tsocks 配置!!
49m12JEEC6HPCHkLMX5QL4SrDQdKwh6eb4Muu8Z9CwA9MwemhzFQ3VcgHwyuR73rC22WCymTUyep7DVrfN3GPt5JBCekPrR