Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
ike-scan — IKE扫描器 | Kitploit
工具/GitHubGitHub/royhills/ike-scan
密码破解侦察漏洞扫描器漏洞分析信息收集网络安全渗透测试
GitHubroyhills/ike-scan

ike-scan

IKE扫描器

查看仓库
42063242年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

ike-scan

Build Coverage Status CodeQL

发现并识别 IKE 主机(IPsec VPN 服务器)

目录

  • 构建与安装
  • 概述
  • 使用说明
  • 实现细节
    • 主机输入与内存需求
    • 速率限制
    • Cookie 生成与远程主机识别
    • IKE 数据包细节
    • 后退指纹识别
  • 程序输出
  • 示例
  • 支持的平台
  • 进一步阅读与 RFC
  • 联系方式

构建与安装

ike-scan 使用标准的 GNU autoconf 和 automake 工具,因此安装过程如下:

  • 运行 git clone https://github.com/royhills/ike-scan.git 获取项目源码
  • 运行 cd ike-scan 进入源码目录
  • 运行 autoreconf --install 生成可用的 ./configure 文件
  • 运行 ./configure 或 ./configure --with-openssl 以使用 OpenSSL 库
  • 运行 make 构建项目
  • 运行 make check 验证一切正常
  • 运行 make install 进行安装(此步骤需要 root 或 sudo 权限)

如果你计划进行预共享密钥破解,建议配置 ike-scan 使用 OpenSSL 的哈希函数(而非内置函数),因为 OpenSSL 通常速度更快。为此,请确保已安装 OpenSSL 的头文件和库,并运行 ./configure --with-openssl。是否使用 OpenSSL 不会影响 ike-scan 的功能,仅会影响 psk-crack 进行预共享密钥破解的速度。

某些操作系统默认安装了 OpenSSL 头文件和库;其他系统则需要安装可选软件包,例如在 Debian Linux 上你需要安装 libssl-dev 包。或者,你也可以从 http://www.openssl.org/ 下载并安装 OpenSSL 的 tarball。

该项目应在大多数现代类 Unix 操作系统上构建。在 Windows 上可通过 Cygwin 运行,当存在 cygwin1.dll 时也可作为独立的 Windows 可执行程序使用。

如果你使用的是 Windows-32 二进制包,请同时阅读 README-WIN32 文件,其中详细说明了在 Windows 平台上的差异。

该程序已知可在 Linux、FreeBSD、OpenBSD、NetBSD、Win32/Cygwin、Solaris、MacOS X、HP Tru64、HP-UX 和 SCO OpenServer 上构建并运行。更多详情请参见下方“支持的平台”部分。

概述

ike-scan 能够发现 IKE 主机,并可通过重传后退模式对其进行指纹识别。

ike-scan 可以执行以下功能:

  • 发现 确定给定 IP 范围内哪些主机正在运行 IKE。通过显示对 ike-scan 发送的 IKE 请求作出响应的主机来实现。
  • 指纹识别 确定主机使用的 IKE 实现,并在某些情况下确定其运行的软件版本。这通过两种方式实现:一是 UDP 后退指纹识别,记录目标主机的 IKE 响应数据包时间,并将观察到的重传后退模式与已知模式进行比较;二是 Vendor ID 指纹识别,将 VPN 服务器的 Vendor ID 载荷与已知的 Vendor ID 模式进行比较。
  • 转换枚举 发现 VPN 服务器支持的 IKE 阶段 1 转换属性(例如加密算法、哈希算法等)。
  • 用户枚举 对于某些 VPN 系统,发现有效的 VPN 用户名。
  • 预共享密钥破解 对使用预共享密钥认证的 IKE 积极模式进行离线字典或暴力密码破解。首先使用 ike-scan 获取哈希和其他参数,然后使用 psk-crack(属于 ike-scan 软件包的一部分)进行破解。

重传后退指纹识别的概念在 UDP 后退指纹识别论文中有更详细的讨论,该论文应包含在 ike-scan 套件中,文件名为 UDP Backoff Fingerprinting Paper。

该程序向指定主机发送 IKE 阶段 1(主模式或积极模式)请求,并显示接收到的任何响应。它处理带有后退的重试和重传,以应对数据包丢失。它还限制了出站 IKE 数据包所使用的带宽。

IKE 是互联网密钥交换协议,是 IPsec 使用的密钥交换和认证机制。几乎所有现代 VPN 系统都实现 IPsec,而绝大多数 IPsec VPN 使用 IKE 进行密钥交换。主模式是 IKE 交换阶段 1 定义的两种模式之一(另一种是积极模式)。RFC 2409 第 5 节规定必须实现主模式,因此所有 IKE 实现都应支持主模式。许多实现也支持积极模式。

使用说明

要查看当前使用信息,请按如下方式运行 ike-scan 二进制程序:ike-scan -h

Additional documentation is provided on the NTA Monitor Wiki

To report bugs or suggest new features, please create a GitHub issue.

Implementation Details

Host Input and Memory Requirements

The hosts to scan can be specified on the command line or read from an input file using the --file=<fn> option. The program can cope with large numbers of hosts limited only by the amount of memory needed to store the list of host_entry structures. Each host_entry structure requires 45 bytes on a 32-bit system, so a class B network (65534 hosts) would require about 2.8 MB for the list. The hosts can be specified as either IP addresses or hostnames, however the program will store all hosts internally as IP addresses and will only display IP addresses in the output (ike-scan calls gethostbyname(3) to determine the IP address of each host, but this can be disabled with the --nodns option).

Rate Limiting

The program limits the rate at which it sends IKE packets to ensure that it does not overload the network connection. By default it uses an outbound data rate of 56000 bits per second. This can be changed with the --bandwidth option.

If you want to send packets at a specific rate, you can use the --interval option.

Cookie Generation and Remote Host Identification

ike-scan generates unique IKE cookies for each host, and it uses these cookies to determine which host the response packets belong to. Note that it does not rely on the source IP address of the response packets because it is possible for a response packet to be sent from a different IP address than it was originally sent to. See the PROGRAM OUTPUT section for an example of this.

The cookies are generated by taking the first 64 bits of an MD5 hash of the current time in seconds and microseconds as returned by gettimeofday(), the unique host number, and the host IP address. This ensures that the cookies are unique with a reasonable degree of certainty.

If --verbose is in effect, any packets that are received with cookies that do not match will result in a message like:

Ignoring 84 bytes from 172.16.2.2 with unknown cookie 195c837e5a39f657 如果未启用 --verbose,这些数据包将被静默忽略。

此类cookie不匹配可能由以下原因引起:

  • 主机仍在返回对先前 ike-scan 运行的 IKE 响应;
  • 数据包不是 IKE 数据包或已损坏;或
  • 已收到与 ike-scan 无关的 IKE 数据包。

IKE 数据包详情

发送的主模式数据包包含一个 ISAKMP 头部和一个 SA 载荷。SA 载荷包含一个单一提议,并且该提议可以包含可变数量的变换,如下所述。

默认情况下,SA 提议包含 8 个变换。这 8 个变换代表了以下所有可能组合:

  • 加密算法:DES-CBC 和 3DES-CBC;
  • 哈希算法:MD5 和 SHA-1;以及
  • DH 组:1(MODP 768)和 2(MODP 1024)。

以下是使用默认变换集时,ike-scan 发送的主模式数据包的示例 tcpdump 输出。显示了这 8 个变换以及它们的发送顺序:

16:57:16.024536 192.168.124.8.500 > 172.16.2.2.500:  [udp sum ok]isakmp 1.0 msgid 00000000: phase 1 I ident:
  (sa: doi=ipsec situation=identity
    (p: #1 protoid=isakmp transform=8
      (t: #1 id=ike (type=enc value=3des)(type=hash value=sha1)(type=auth value=preshared)(type=group desc value=modp1024)(type=lifetype value=sec)(type=lifeduration len=4 value=00007080))
      (t: #2 id=ike (type=enc value=3des)(type=hash value=md5)(type=auth value=preshared)(type=group desc value=modp1024)(type=lifetype value=sec)(type=lifeduration len=4 value=00007080))
      (t: #3 id=ike (type=enc value=1des)(type=hash value=sha1)(type=auth value=preshared)(type=group desc value=modp1024)(type=lifetype value=sec)(type=lifeduration len=4 value=00007080))
      (t: #4 id=ike (type=enc value=1des)(type=hash value=md5)(type=auth value=preshared)(type=group desc value=modp1024)(type=lifetype value=sec)(type=lifeduration len=4 value=00007080))
      (t: #5 id=ike (type=enc value=3des)(type=hash value=sha1)(type=auth value=preshared)(type=group desc value=modp768)(type=lifetype value=sec)(type=lifeduration len=4 value=00007080))
      (t: #6 id=ike (type=enc value=3des)(type=hash value=md5)(type=auth value=preshared)(type=group desc value=modp768)(type=lifetype value=sec)(type=lifeduration len=4 value=00007080))
      (t: #7 id=ike (type=enc value=1des)(type=hash value=sha1)(type=auth value=preshared)(type=group desc value=modp768)(type=lifetype value=sec)(type=lifeduration len=4 value=00007080))
      (t: #8 id=ike (type=enc value=1des)(type=hash value=md5)(type=auth value=preshared)(type=group desc value=modp768)(type=lifetype value=sec)(type=lifeduration len=4 value=00007080)))) (DF) (ttl 64, id 0, len 364)```

此默认变换集旨在被大多数 IKE 实现所接受——大多数会接受至少一个提供的变换。然而,有时需要使用不同的身份验证方法(预共享密钥是最常见的,但并非总是支持),偶尔也需要指定不同的密码,例如 256 位 AES。更罕见的情况可能需要更改生命周期。最后,一些实现要求客户端发送特定的“供应商 ID”字符串才能响应。这可以通过 --vendor 选项指定。

默认变换集产生的数据包数据长度为 336 字节,加上 IP 和 UDP 头部后,总数据包大小为 364 字节。

下载工具