Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
shodan-favicon-preimage — 生成一个在 Shodan 上可得到任意目标哈希的 favicon | Kitploit
工具/GitHubGitHub/jorianwoltjer/shodan-favicon-preimage
OSINT (开源情报)侦察信息收集密码学实用工具与框架指纹欺骗
GitHubjorianwoltjer/shodan-favicon-preimage

shodan-favicon-preimage

生成一个在 Shodan 上可得到任意目标哈希的 favicon

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
查看仓库网站
32年前尚未审核

Shodan Favicon 原像生成器

生成一个在 Shodan 上产生任意目标哈希的 favicon

该工具实现了一种暴力破解方法,用于为 Shodan http.favicon.hash 算法生成任意原像。例如,你可以让搜索你选择的特定哈希时显示你的网站:

Shodan search result for `http.favicon.hash:1337` showing only jorianwoltjer.com

在我的博客文章中阅读更多关于该方法和实现的内容:
"How I got a Shodan Favicon Hash = 1337"

安装

首先,安装 Rust,这是本项目所使用的编程语言,以便从源代码构建它。然后这些命令会将其转换为优化的可执行文件:

git clone https://github.com/JorianWoltjer/shodan-favicon-preimage.git && cd shodan-favicon-preimage
cargo build --release
./target/release/shodan-favicon-preimage --help

用法

Usage: shodan-favicon-preimage [OPTIONS] <INPUT> [TARGET]

Arguments:
  <INPUT>   File to compute hash on
  [TARGET]  The target hash to find (32 bits) [default: 1337]

Options:
  -o, --output <OUTPUT>  Output file to store the base64 encoded content [default: output.b64]
  -h, --help             Print help

取任意现有的 .ico 文件,并将其作为第一个参数传入。可选地,选择一个不同于默认值 1337 的目标哈希:

$ shodan-favicon-preimage favicon.ico 31337
Aligning input...
State: 2363324422 @ 20948 bytes
Starting search...
SUCCESS: Found hash=31337 for input 4107189463 ("17zO9A==\n")
Wrote result to "output.b64"
Decode it using `base64 -di "output.b64" > output.ico`

output.b64 文件将是经 MurmurHash3 计算后得到你的目标哈希的编码形式,但你也可以将其解码为常规的 .ico 文件。然后可以使用 verify.py 来检查哈希是否确实正确:

$ base64 -di "output.b64" > output.ico
$ ./verify.py output.ico 
31337
下载工具