You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Shodan Python API获取SSL证书的通用名称(CN)

获取Shodan搜索结果中的SSL证书通用名称

嘿,我明白你想在Shodan搜索abc1234的同时,提取目标IP对应的SSL证书通用名称(Common Name)。其实Shodan的API返回结果里已经包含了SSL相关的元数据,咱们只需要正确访问对应的字段就行。

修改后的完整脚本

#!/usr/bin/env python
import shodan
import sys

SHODAN_API_KEY = "your_api_key_here"  # 记得替换成你的真实API密钥
api = shodan.Shodan(SHODAN_API_KEY)

try:
    # 执行Shodan搜索,关键词为abc1234
    results = api.search('abc1234')
    
    # 打印搜索到的总结果数
    print('Results found: %s' % results['total'])
    
    for result in results['matches']:
        # 提取并打印IP地址
        ip = result['ip_str']
        print('\nIP: %s' % ip)
        
        # 安全提取SSL证书的通用名称(Common Name)
        # 先逐层判断字段是否存在,避免无SSL证书时抛出KeyError
        if 'ssl' in result and 'cert' in result['ssl'] and 'subject' in result['ssl']['cert']:
            common_name = result['ssl']['cert']['subject'].get('CN', '未找到通用名称')
            print('SSL证书通用名称: %s' % common_name)
        else:
            print('该IP未提供SSL证书或无法获取证书信息')

except shodan.APIError as e:
    print('API调用出错: %s' % e)
    sys.exit(1)

核心要点说明

  • SSL字段层级:Shodan返回的搜索结果中,每个匹配项的ssl字段存储了所有SSL相关数据,证书详情在ssl.cert路径下,而通用名称(CN)具体存放在ssl.cert.subject.CN中。
  • 安全取值:不是所有目标IP都部署了SSL证书,所以必须先逐层判断ssl、cert、subject字段是否存在;用.get('CN', '默认值')的方式,即使CN字段缺失也不会触发报错,而是返回预设的提示文本。
  • 密钥替换:一定要把SHODAN_API_KEY替换成你自己的Shodan API密钥,否则脚本无法正常调用接口。

这样修改后,你就能在输出IP地址的同时,同步获取到对应的SSL证书通用名称啦!

内容的提问来源于stack exchange,提问作者Me Myself

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 08:14:52