Update README.md
This commit is contained in:
@@ -9,51 +9,143 @@
|
||||
██╔════╝██║ ██╔═══██╗██╔════╝██║ ██╔╝ ██╔════╝██╔════╝██╔══██╗████╗ ██║
|
||||
█████╗ ██║ ██║ ██║██║ █████╔╝ ███████╗██║ ███████║██╔██╗ ██║
|
||||
██╔══╝ ██║ ██║ ██║██║ ██╔═██╗ ╚════██║██║ ██╔══██║██║╚██╗██║
|
||||
██║ ███████╗╚██████╔╝██████╗██║ ██╗ ███████║╚██████╗██║ ██║██║ ╚████║
|
||||
╚═╝ ╚══════╝ ╚═════╝ ╚═════╝╚═╝ ╚═╝ ╚══════╝ ╚═════╝╚═╝ ╚═╝╚═╝ ╚═══╝
|
||||
██║ ███████╗╚██████╔╝╚██████╗██║ ██╗ ███████║╚██████╗██║ ██║██║ ╚████║
|
||||
╚═╝ ╚══════╝ ╚═════╝ ╚═════╝╚═╝ ╚═╝ ╚══════╝ ╚═════╝╚═╝ ╚═╝╚═╝ ╚═══╝
|
||||
```
|
||||
|
||||
Multi-mode Flock Safety security assessment tool.
|
||||
|
||||
---
|
||||
|
||||
## Capabilities
|
||||
## Capabilities
|
||||
|
||||
### CVE Scanning (v1)
|
||||
### 1) CVE Scanning
|
||||
| CVE | Score | Description |
|
||||
|-----|-------|-------------|
|
||||
| **CVE-2025-59403** | 9.8 | Unauthenticated admin API / ADB RCE |
|
||||
| **CVE-2025-59403** | 9.8 | Unauthenticated admin API / ADB RCE |
|
||||
| **CVE-2025-59407** | CRIT | Hardcoded keystore crypto key |
|
||||
| **CVE-2025-47818** | HIGH | Hardcoded fallback hotspot credentials |
|
||||
| **CVE-2025-47823** | HIGH | Hardcoded system password on ALPR firmware |
|
||||
|
||||
### Flock Instance Discovery (v2 — NEW)
|
||||
Disclaimer: For authorized security testing only.
|
||||
|
||||
### 2) Flock Instance Discovery
|
||||
Scans any subnet for all known Flock camera fingerprints.
|
||||
|
||||
| Fingerprint | Port | Detection |
|
||||
|-------------|------|-----------|
|
||||
| **ADB shell** | 5555 | `getprop ro.product.model` → Flock/Falcon/Sparrow |
|
||||
| **ADB shell** | 5555 | `getprop ro.product.model` -> Flock/Falcon/Sparrow |
|
||||
| **Admin web UI** | 80/443 | GainSec's `admin_page_template.html` in HTTP body |
|
||||
| **ONVIF device** | 80/443/8899 | SOAP `GetDeviceInformation` → manufacturer string |
|
||||
| **ONVIF device** | 80/443/8899 | SOAP `GetDeviceInformation` -> manufacturer string |
|
||||
| **SpeedPourer** | 21 | FTP banner / admin page references |
|
||||
| **FRP tunnel** | 7000-7500 | Fast Reverse Proxy banner grab |
|
||||
| **Cloud DNS** | — | Admin UI contains `*.flocksafety.com` URLs |
|
||||
| **All 4 CVEs** | — | Per-host exploit checks run automatically |
|
||||
| **Cloud DNS** | -- | Admin UI contains `*.flocksafety.com` URLs |
|
||||
| **All 4 CVEs** | -- | Per-host exploit checks run automatically |
|
||||
|
||||
### Traffic Analysis (v2 — NEW)
|
||||
### 3) Traffic Analysis
|
||||
Determines if a Flock camera sends data to **the cloud** or a **local station**.
|
||||
|
||||
```
|
||||
CLOUD → Sends data to api.flocksafety.com / Flock infrastructure
|
||||
LOCAL_STATION → Data stays on-prem (no cloud contact detected)
|
||||
INDETERMINATE → Unable to determine (camera may be offline)
|
||||
CLOUD -> Sends data to api.flocksafety.com / Flock infrastructure
|
||||
LOCAL_STATION -> Data stays on-prem (no cloud contact detected)
|
||||
INDETERMINATE -> Unable to determine (camera may be offline)
|
||||
```
|
||||
|
||||
Detection methods:
|
||||
- **DNS resolution** of `api.flocksafety.com` and other Flock domains
|
||||
- **Admin UI inspection** — `/metadata`, `/config` endpoints checked for cloud URLs vs internal IPs
|
||||
- **FRP tunnel detection** — Reverse Proxy tunnel on ports 7000/7500
|
||||
- **ADB network config** — reads gateway and DNS from camera shell
|
||||
- **Admin UI inspection** -- `/metadata`, `/config` endpoints checked for cloud URLs vs internal IPs
|
||||
- **FRP tunnel detection** -- Reverse Proxy tunnel on ports 7000/7500
|
||||
- **ADB network config** -- reads gateway and DNS from camera shell
|
||||
|
||||
### 4) Traffic Tap -- Passive Monitoring (NEW)
|
||||
|
||||
Watch live camera traffic or analyze a PCAP file to see exactly what Flock cameras are communicating with. No decryption needed.
|
||||
|
||||
#### What it detects
|
||||
|
||||
| Signal | What it reveals |
|
||||
|--------|----------------|
|
||||
| **DNS queries** | Every domain the camera resolves -- `api.flocksafety.com`, `flock-hibiki-inbox.s3...`, etc. |
|
||||
| **TLS SNI** | HTTPS destinations **without decryption** -- just the hostname |
|
||||
| **FRP tunnels** | Outbound connections on ports 7000-7500 (Fast Reverse Proxy) |
|
||||
| **TCP connections** | Full connection map -- who talks to whom, how much data flows |
|
||||
| **Cloud vs Local** | Classification per IP: `CLOUD_CONNECTED`, `LOCAL_STATION`, `UNKNOWN` |
|
||||
|
||||
#### Callback Architecture
|
||||
|
||||
The tap fires three callbacks for every packet, matching the pseudocode design:
|
||||
|
||||
```python
|
||||
def on_dns_query(self, hostname, src_ip, resolved_ips, timestamp):
|
||||
if "flocksafety" in hostname:
|
||||
self.flow_stats[src_ip]["cloud_dns"] += 1
|
||||
|
||||
def on_tcp_connect(self, src, dst, sport, dport, timestamp):
|
||||
if dport in [7000, 7500, 7001, 7002]:
|
||||
self.flow_stats[src]["frp_tunnel"] = True
|
||||
|
||||
def on_tls_sni(self, sni, src_ip, dst_ip, timestamp):
|
||||
cat = self._categorize_sni(sni) # "auth" | "s3_upload" | "cloud_api"
|
||||
self.flow_stats[src_ip][f"{cat} += 1
|
||||
```
|
||||
|
||||
#### Zeek-Equivalent FRP Signature
|
||||
|
||||
```python
|
||||
# signature frp-tunnel {
|
||||
# ip-proto == tcp
|
||||
# dst-port in [7000, 7500, 7001, 7002]
|
||||
# payload /frp|auth|proxy_type/
|
||||
# event "FRP TUNNEL DETECTED"
|
||||
# }
|
||||
```
|
||||
|
||||
#### SNI Traffic Categorization
|
||||
|
||||
| Category | Matches | Example |
|
||||
|----------|---------|---------|
|
||||
| `auth` | auth0, login | `login.flocksafety.com`, `prod-flock.auth0.com` |
|
||||
| `s3_upload` | s3.amazonaws | `flock-hibiki-inbox.s3.us-east-1.amazonaws.com` |
|
||||
| `cloud_api` | flocksafety, flock | `api.flocksafety.com`, `websockets.flocksafety.com` |
|
||||
|
||||
#### Report Output
|
||||
|
||||
```
|
||||
============================================================
|
||||
FLOCK TRAFFIC TAP REPORT
|
||||
============================================================
|
||||
|
||||
Capture:
|
||||
Interface: eth0
|
||||
Duration: 300.5s
|
||||
Packets: 142,931
|
||||
|
||||
Classification:
|
||||
Cloud-connected: 3
|
||||
Local station: 12
|
||||
Unknown: 5
|
||||
|
||||
Cloud-Connected Cameras:
|
||||
192.168.1.104 DNS(api.flocksafety.com)
|
||||
192.168.1.107 SNI(login.flocksafety.com)
|
||||
192.168.1.110 FRP(2 tunnels)
|
||||
|
||||
FRP Tunnels: 2
|
||||
192.168.1.110 -> 10.0.0.50:7500 [frp_tunnel]
|
||||
192.168.1.110 -> 10.0.0.50:7000 [frp_auth_payload]
|
||||
|
||||
Flock Domains Resolved:
|
||||
- api.flocksafety.com
|
||||
- flock-hibiki-inbox.s3.us-east-1.amazonaws.com
|
||||
- login.flocksafety.com
|
||||
- prod-flock.auth0.com
|
||||
- websockets.flocksafety.com
|
||||
|
||||
TLS Traffic Categories:
|
||||
auth: 47 connections
|
||||
s3_upload: 1887 connections
|
||||
cloud_api: 2341 connections
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
@@ -66,34 +158,39 @@ python3 scanner.py
|
||||
|
||||
### CVE Scanning
|
||||
```bash
|
||||
# Single target
|
||||
python3 scanner.py -t 192.168.1.100
|
||||
|
||||
# From file
|
||||
python3 scanner.py -f targets.txt --exploit
|
||||
|
||||
# Save results
|
||||
python3 scanner.py --output results.json -v
|
||||
```
|
||||
|
||||
### Instance Discovery
|
||||
```bash
|
||||
# Scan a /24 subnet
|
||||
python3 scanner.py --discover 192.168.1.0/24
|
||||
|
||||
# Scan a /16, save findings
|
||||
python3 scanner.py --discover 10.0.0.0/16 --output found.json
|
||||
```
|
||||
|
||||
### Traffic Analysis
|
||||
```bash
|
||||
# Check if a camera phones home
|
||||
python3 scanner.py --analyze-traffic 192.168.1.100
|
||||
|
||||
# Save flow analysis
|
||||
python3 scanner.py --analyze-traffic 10.0.0.50 --output flow.json
|
||||
```
|
||||
|
||||
### Traffic Tap (Live Capture)
|
||||
```bash
|
||||
# Requires scapy: pip install scapy
|
||||
python3 scanner.py --tap-interface eth0 --tap-output report.json
|
||||
```
|
||||
|
||||
### Traffic Tap (PCAP Analysis)
|
||||
```bash
|
||||
python3 scanner.py --tap-pcap capture.pcap --tap-output report.json
|
||||
```
|
||||
|
||||
### Traffic Tap (Pipe from tcpdump)
|
||||
```bash
|
||||
tcpdump -i eth0 -l -nn | python3 scanner.py --tap-pipe -v
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Interactive Menu
|
||||
@@ -102,7 +199,18 @@ python3 scanner.py --analyze-traffic 10.0.0.50 --output flow.json
|
||||
python3 scanner.py
|
||||
```
|
||||
|
||||
<img width="543" height="648" alt="IMG_5603" src="https://github.com/user-attachments/assets/85ebf61b-789e-4c81-ae98-9ad8c9092fed" />
|
||||
```
|
||||
1. Single IP
|
||||
2. IP Range (CIDR)
|
||||
3. From File
|
||||
4. Shodan Query
|
||||
5. Falcon/Sparrow Signatures
|
||||
6. Flock Instance Discovery
|
||||
7. Traffic Analysis
|
||||
8. Traffic Tap -- live monitor
|
||||
9. Traffic Tap -- analyze PCAP
|
||||
0. Return
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
@@ -125,11 +233,12 @@ Includes dedicated `FLOCK_DISCOVERY` queries:
|
||||
|
||||
---
|
||||
|
||||
## Safety
|
||||
## Safety
|
||||
|
||||
- **Exploitation disabled by default** — requires explicit `--exploit` flag
|
||||
- **Rate-limited threads** — default 10, configurable with `-T`
|
||||
- **Discovery mode is passive** — only sends probe/identification packets
|
||||
- **Exploitation disabled by default** -- requires explicit `--exploit` flag
|
||||
- **Rate-limited threads** -- default 10, configurable with `-T`
|
||||
- **Discovery mode is passive** -- only sends probe/identification packets
|
||||
- **Tap mode is read-only** -- never sends packets, only listens
|
||||
- **User confirmation** required before any exploit execution
|
||||
|
||||
```bash
|
||||
@@ -140,7 +249,21 @@ python3 scanner.py -t 192.168.1.100
|
||||
python3 scanner.py -t 192.168.1.100 --exploit
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## File Layout
|
||||
|
||||
```
|
||||
FLOCK_scan/
|
||||
├── scanner.py # Main tool (CVE scan + discovery + traffic analysis)
|
||||
├── flock_tap.py # Passive traffic monitor (callbacks, FRP, SNI, DNS)
|
||||
├── shodan_queries.py # Shodan dork generator
|
||||
├── run_scanner.sh # Quick-launch script
|
||||
├── masscan_wrapper.sh # Masscan integration
|
||||
└── README.md
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
<p align="center">
|
||||
<sub>Authorized security testing only. Use on systems you own or have written permission to test.</sub>
|
||||
|
||||
Reference in New Issue
Block a user