IKE Enumeration with Patator: Extracting VPN Transform Sets and Security Parameters
Patator's IKE_enum module extracts the four critical components of IKEv1 VPN transform sets—encryption algorithm, hash algorithm, authentication method, and Diffie-Hellman group—by wrapping and parsing the output of the external ike-scan tool.
The lanjelot/patator framework includes a dedicated IKE enumeration module that automates the discovery of VPN security policies. By systematically testing combinations of cryptographic parameters against IKEv1 endpoints, security professionals can identify supported transform sets and determine whether a VPN gateway accepts aggressive mode connections.
What Information Does Patator Reveal During IKE Enumeration?
When targeting an IKEv1 VPN gateway, Patator specifically harvests the four numeric identifiers that define a transform set. These components are mapped to human-readable names using static lookup tables defined in src/patator/patator.py (lines 4164–4175):
- Encryption algorithms (
IKE_ENC): DES, 3DES, AES-128/192/256, Camellia, and others - Hash algorithms (
IKE_HASH): MD5, SHA-1, SHA-2-256/384/512, Tiger - Authentication methods (
IKE_AUTH): PSK (Pre-Shared Key), RSA-Sig, XAUTH with PSK, and Harkins-CRACK - Diffie-Hellman groups (
IKE_GROUP): modp768, modp1024, modp1536, modp2048, and higher
Patator does not retrieve credentials or configuration files; it only enumerates which cryptographic combinations the target endpoint will accept for establishing a Security Association (SA).
How the IKE_enum Module Works
The IKE_enum class serves as a thin orchestration layer around the ike-scan binary. It handles transform generation, command execution, and response parsing through several internal mechanisms.
Transform Generation and Cartesian Product
The generate_transforms() function (located around line 4180 in src/patator/patator.py) constructs an exhaustive list of transform strings by computing the Cartesian product of the four static tables. Each iteration yields a comma-separated 4-tuple in the format encryption,hash,auth,group, representing one possible security policy to test against the target.
Executing ike-scan and Parsing Responses
During execution, Patator builds and launches the following command structure:
ike-scan -M --sport <src_port> <host> --dport <port> --trans <transform> [-A --id <groupname>] [--vendor <vid> ...]
The module uses subprocess.Popen to execute this command and captures both stdout and stderr. It then parses the output for the presence of SA= (Security Association), which indicates that the VPN gateway accepted the proposed transform set. If detected, the raw transform string and endpoint information are stored in the response object.
Result Aggregation and Display
The Controller_IKE class manages result collection through its push_final() method (around lines 4249–4250), storing each valid transform in a dictionary keyed by endpoint and mode (Main or Aggressive). Finally, the show_final() method (lines 4187–4222) translates the numeric IDs into human-readable names and displays a formatted matrix showing the accepted encryption, hash, authentication, and group parameters for each discovered SA.
Practical IKE Enumeration Examples
Basic Main Mode Enumeration
To enumerate all possible transform sets against a target VPN gateway in Main Mode:
patator ike_enum host=10.0.0.1 \
transform=MOD0 \
0=TRANS \
-x ignore:fgrep=NO-PROPOSAL
Here, transform=MOD0 instructs Patator to use the generated transform iterator, while 0=TRANS maps this iterator to the module's first positional argument. The -x ignore:fgrep=NO-PROPOSAL filter excludes unsuccessful probes from the output.
Aggressive Mode with Group Identification
To test Aggressive Mode and specify a custom group name for identification:
patator ike_enum host=10.0.0.1 \
transform=MOD0 \
aggressive=1 \
groupname=TestGroup \
0=TRANS \
-x ignore:fgrep=NO-PROPOSAL
Setting aggressive=1 appends the -A flag to the underlying ike-scan command, while groupname populates the --id parameter required for Aggressive Mode handshakes.
Enumerating with Custom Vendor IDs
To include specific vendor IDs in the IKE handshake:
patator ike_enum host=10.0.0.1 \
transform=MOD0 \
vid=0x00a0b1,0x00a0b2 \
0=TRANS \
-x ignore:fgrep=NO-PROPOSAL
The vid parameter accepts comma-separated hexadecimal values, each passed as --vendor <id> to ike-scan to fingerprint specific VPN implementations.
Summary
- Patator's IKE_enum module extracts four specific cryptographic parameters from IKEv1 VPN endpoints: encryption algorithm, hash algorithm, authentication method, and Diffie-Hellman group.
- The module wraps
ike-scanand parses theSA=string in responses to identify accepted transform sets. - Static lookup tables in
src/patator/patator.py(lines 4164–4175) translate numeric IDs to human-readable security policy names. - The
generate_transforms()function creates exhaustive test cases via Cartesian product of all possible 4-tuples. - Results are aggregated by the
Controller_IKEclass and displayed as formatted matrices distinguishing between Main and Aggressive modes.
Frequently Asked Questions
What is the difference between Main Mode and Aggressive Mode in Patator's IKE enumeration?
Main Mode uses six message exchanges to establish the IKE SA and provides identity protection, while Aggressive Mode completes the exchange in three messages but transmits the initiator's identity in the clear. In Patator, enabling aggressive=1 adds the -A flag to the ike-scan command and allows specifying a groupname via the --id parameter, which can reveal different transform sets or group-specific policies than Main Mode probes.
How does Patator generate the list of transform sets to test?
Patator calls generate_transforms() (around line 4180 in src/patator/patator.py) to build the complete list by calculating the Cartesian product of the four static ID tables: IKE_ENC, IKE_HASH, IKE_AUTH, and IKE_GROUP. This generates every possible combination of encryption, hash, authentication, and DH group parameters, creating an exhaustive iterator of comma-separated transform strings for systematic testing.
Can Patator retrieve VPN credentials during IKE enumeration?
No. According to the source code in lanjelot/patator, the IKE_enum module only parses the SA= string from ike-scan output to identify accepted cryptographic parameters. It does not implement aggressive mode credential extraction, XAUTH password cracking, or PSK recovery. The module strictly enumerates VPN transform sets and connection modes, not authentication secrets.
What does the SA= string indicate in the ike-scan output?
The SA= string indicates that the VPN gateway has successfully negotiated a Security Association using the proposed transform set. When Patator's execute() method detects this string in the subprocess output (around lines 7474–7481 of patator.py), it records the endpoint, mode, and specific transform combination as a valid VPN security policy offered by the target.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →