如何通过Shodan Python API获取SSL证书的通用名称(CN)
获取Shodan搜索结果中的SSL证书通用名称
嘿,我明白你想在Shodan搜索abc1234的同时,提取目标IP对应的SSL证书通用名称(Common Name)。其实Shodan的API返回结果里已经包含了SSL相关的元数据,咱们只需要正确访问对应的字段就行。
修改后的完整脚本
#!/usr/bin/env python import shodan import sys SHODAN_API_KEY = "your_api_key_here" # 记得替换成你的真实API密钥 api = shodan.Shodan(SHODAN_API_KEY) try: # 执行Shodan搜索,关键词为abc1234 results = api.search('abc1234') # 打印搜索到的总结果数 print('Results found: %s' % results['total']) for result in results['matches']: # 提取并打印IP地址 ip = result['ip_str'] print('\nIP: %s' % ip) # 安全提取SSL证书的通用名称(Common Name) # 先逐层判断字段是否存在,避免无SSL证书时抛出KeyError if 'ssl' in result and 'cert' in result['ssl'] and 'subject' in result['ssl']['cert']: common_name = result['ssl']['cert']['subject'].get('CN', '未找到通用名称') print('SSL证书通用名称: %s' % common_name) else: print('该IP未提供SSL证书或无法获取证书信息') except shodan.APIError as e: print('API调用出错: %s' % e) sys.exit(1)
核心要点说明
- SSL字段层级:Shodan返回的搜索结果中,每个匹配项的
ssl字段存储了所有SSL相关数据,证书详情在ssl.cert路径下,而通用名称(CN)具体存放在ssl.cert.subject.CN中。 - 安全取值:不是所有目标IP都部署了SSL证书,所以必须先逐层判断
ssl、cert、subject字段是否存在;用.get('CN', '默认值')的方式,即使CN字段缺失也不会触发报错,而是返回预设的提示文本。 - 密钥替换:一定要把
SHODAN_API_KEY替换成你自己的Shodan API密钥,否则脚本无法正常调用接口。
这样修改后,你就能在输出IP地址的同时,同步获取到对应的SSL证书通用名称啦!
内容的提问来源于stack exchange,提问作者Me Myself
相关产品推荐
相关产品推荐

