Shodanwave is a tool for exploring and obtaining information from cameras specifically Netwave IP Camera. The tool uses a search engine called shodan that makes it easy to search for cameras online.
What does the tool to? Look, a list!
SSID and WPAPSK Password Disclosure
E-mail, FTP, DNS, MSN Password Disclosure
This is an example of shodan wave running, the password was not found through raw force so the tool tries to leak the camera’s memory. If the tool finds the password it does not try to leak the memory.
$ cd /opt/
$ git clone http://ift.tt/2uUjMS2
$ cd shodanwave
$ pip install -r requirements.txt
Usage: python shodanwave.py -u usernames.txt -w passwords.txt -k Shodan API key
python shodanwave.py –help
_____/ /_ ____ ____/ /___ _____ _ ______ __ _____
/ ___/ __ \/ __ \/ __ / __ `/ __ \ | /| / / __ `/ | / / _ \
(__ ) / / / /_/ / /_/ / /_/ / / / / |/ |/ / /_/ /| |/ / __/
/____/_/ /_/\____/\__,_/\__,_/_/ /_/|__/|__/\__,_/ |___/\___/
This tool is successfully connected to shodan service
Information the use of this tool is illegal, not bad.
usage: shodanwave.py [-h] [-s SEARCH] [-u USERNAME] [-w PASSWORD] [-k ADDRESS]
-h, –help show this help message and exit
-s SEARCH, –search SEARCH
Default Netwave IP Camera
-u USERNAME, –username USERNAME
Select your usernames wordlist
-w PASSWORD, –wordlist PASSWORD
Select your passwords wordlist
-k ADDRESS, –shodan ADDRESS
Shodan API key
The post Shodanwave – Netwave IP Camera appeared first on Penetration Testing.