Automic VaultAutomic Vault

brew

ike-scan を Homebrew, apt, MacPorts, Nix でインストール

ike-scan のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

インストール

追加のインストールコマンド

macOS

Homebrew確認済み · 100%
brew install ike-scan

local Homebrew formula metadata

MacPorts確認済み · 94%
sudo port install ike-scan

MacPorts ports tree · security/ike-scan/Portfile · ソース: api.github.com

Linux

Debian apt確認済み · 92%
sudo apt install ike-scan

Debian stable package indexes · ike-scan · ソース: deb.debian.org

Nix確認済み · 92%
nix profile install nixpkgs#ike-scan

nixpkgs package indexes · pkgs/by-name/ik/ike-scan/package.nix · ソース: api.github.com

概要

パッケージ概要

Discover and fingerprint IKE hosts

コマンドとエイリアス

  • ike-scan
  • psk-crack

履歴

プロジェクトの歴史と使われ方

ike-scan is Roy Hills' command-line scanner for discovering IPsec VPN endpoints that speak IKE and fingerprinting their implementations. The README frames its core jobs as discovery, fingerprinting, transform enumeration, user enumeration for some VPN systems, and offline pre-shared-key cracking through the bundled psk-crack program.

プロジェクトの歴史

The project grew out of NTA Monitor research into UDP retransmission backoff fingerprinting. Roy Hills' 2003 white paper explains the observation that many UDP services, including IKE, leave retransmission timing decisions to implementers, creating measurable patterns that can identify VPN products.

ike-scan v1.0 was the initial public release in the project's NEWS file. Subsequent releases expanded platform support, added Windows binaries, accumulated vendor ID and backoff fingerprints, and added psk-crack for aggressive-mode pre-shared-key material captured by ike-scan.

Version 1.9 marked a major feature expansion: IKEv2 packet support, NAT traversal, source IP spoofing on raw-socket systems, stdin dictionaries for psk-crack, Vendor ID fingerprinting, and improved pseudo-random packet generation. Version 1.9.4 moved development from an internal SVN repository to GitHub.

採用の歴史

ike-scan became a standard package for VPN assessment work because it targets the exposed UDP/500 and UDP/4500 surfaces that often sit at network borders. The input metadata shows packaging in Homebrew, Debian, Ubuntu, MacPorts, and Nix, and the README documents builds on Linux, BSDs, Solaris, macOS, Cygwin, and several older Unix systems.

使われ方

Operators use ike-scan to send IKE phase-1 probes to one or many targets, list responding hosts, inspect transform support, collect Vendor ID payloads, and optionally measure retransmission backoff with --showbackoff. In aggressive mode, --pskcrack output can feed psk-crack for dictionary or brute-force testing of captured pre-shared-key hashes.

パッケージ好きにとっての重要性

The package is significant because it packages a specific security-research technique, not just a generic network scanner. Its data files, including ike-backoff-patterns and ike-vendor-ids, are part of the value: they turn timing behavior and vendor payloads into repeatable fingerprints that can be updated as products change.

タイムライン

  • 2003: UDP backoff fingerprinting white paper describes ike-scan as the example program.
  • v1.0: Initial public release supports Debian, FreeBSD, and OpenBSD builds.
  • v1.7: psk-crack and aggressive-mode PSK capture support are added.
  • v1.8: Vendor ID and UDP backoff pattern databases expand to 135 vendor IDs and 29 backoff patterns.
  • v1.9: IKEv2, NAT traversal, Vendor ID fingerprinting, and stdin dictionaries for psk-crack are added.
  • 2013: v1.9.4 moves development from internal SVN to GitHub.

Related projects

  • ike-scan sits beside packet tools such as tcpdump and broader scanners such as Nmap, but its closest related artifact is its own UDP backoff fingerprinting paper. Its psk-crack companion makes it part scanner and part focused IPsec assessment toolkit.

ソース

  • Project README, NEWS file, UDP backoff fingerprinting paper, vendor ID database, GitHub repository metadata, and Homebrew formula metadata.

セキュリティ状態

リスクレベル: グリーン

narrow executable package without higher-risk signals.

リスク分類器

リスク グリーン · 信頼度 低 · appliance

理由

  • narrow executable package without higher-risk signals

信号

  • metadata:no-higher-risk-signals

インストール挙動

  • formula メタデータに Homebrew post-install フックは記録されていません。
  • Homebrew bottle メタデータは 13 個のプラットフォームターゲットで利用できます。
  • 1 件の実行時依存関係とともにインストールされます。
  • ビルドメタデータには 3 件のビルド依存関係があります。

推奨レビュー

エージェントに無人実行させる前に、このツールが平文の認証情報を読むか、リモート状態を書き込むか、成果物を公開するか、プラグインを起動するかを確認してください。

実行可能ファイル

インストールされる実行可能ファイル

コマンド種類公開範囲メモ
ike-scancliグローバル実行可能ファイル
psk-crackcliグローバル実行可能ファイル

鮮度

バージョンと鮮度

これらの信号は、ページ生成時期、パッケージマネージャの活動、上流リリース比較を分けて示します。バージョン遅れは、証拠 URL と比較可能なバージョンがある場合だけ警告されます。

ページ生成日2026-07-26
マネージャ版1.9.5
マネージャ更新日2026-06-22
ローカルデータOK
上流最新
検出された最新1.9.5

https://github.com/royhills/ike-scan

  • OK鮮度警告は生成されていません。

インストールメタデータ

パッケージメタデータ

パッケージキーbrew:ike-scan
バージョン1.9.5
パッケージマネージャHomebrew
パッケージマネージャページhttps://formulae.brew.sh/formula/ike-scan
ホームページhttps://github.com/royhills/ike-scan
リポジトリhttps://github.com/royhills/ike-scan
上流ドキュメントhttps://github.com/royhills/ike-scan#readme
ライセンスGPL-3.0-or-later WITH openvpn-openssl-exception
ソースアーカイブhttps://github.com/royhills/ike-scan/archive/refs/tags/1.9.5.tar.gz
最終更新2026-06-22T14:03:45-07:00
Pulseupdated
依存関係openssl@3
ビルド依存関係autoconf, automake, libtool
Bottle利用可能 (対象 arm64_big_sur, arm64_linux, arm64_monterey, arm64_sequoia, arm64_sonoma, arm64_tahoe, arm64_ventura, big_sur, catalina, monterey, sonoma, ventura, x86_64_linux)
Homebrew post-install未定義
サービス宣言なし

レジストリ情報

ソースデータベース詳細

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Nameike-scan
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

ソースデータベース一致

他のパッケージマネージャ記録

一致は外部パッケージマネージャインデックスから取得され、ローカルの Automic Vault パッケージリンクとは分けて表示されます。

Debian apt95%

ike-scan 1.9.5-2

discover and fingerprint IKE hosts (IPsec VPN Servers)

https://github.com/royhills/ike-scan

sudo apt install ike-scan
  • Section: net
  • Architecture: amd64
  • 2 依存関係
  • normalized package name match
  • 一致条件: Ike Scan
Debian stable package indexes · deb.debian.org · Debian stable package indexes: ike-scan from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz
Nix95%

ike-scan

nix profile install nixpkgs#ike-scan
  • normalized package name match
  • 一致条件: Ike Scan
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/ik/ike-scan/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
Ubuntu apt95%

ike-scan 1.9.5-1ubuntu1

discover and fingerprint IKE hosts (IPsec VPN Servers)

https://github.com/royhills/ike-scan

sudo apt install ike-scan
  • Section: universe/net
  • Architecture: amd64
  • 2 依存関係
  • normalized package name match
  • 一致条件: Ike Scan
Ubuntu 24.04 LTS package indexes · archive.ubuntu.com · Ubuntu 24.04 LTS package indexes: ike-scan from https://archive.ubuntu.com/ubuntu/dists/noble/universe/binary-amd64/Packages.gz
MacPorts95%

ike-scan

sudo port install ike-scan
  • normalized package name match
  • 一致条件: Ike Scan
MacPorts ports tree · api.github.com · MacPorts ports tree: security/ike-scan/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1

ソース経路

リポジトリデータから生成

このページは scripts/generate-pkg-sqlite.py が生成した非公開のパッケージ SQLite アーティファクトから av-web によって提供されます。

使用ソース

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment