Changeme – A Default Credentials Scanner

Changeme is a default credential scanner that picks up where commercial scanners leave off. It focuses on detecting default and backdoor credentials and not necessarily common credentials. It’s default mode is to scan HTTP default credentials, but has support for other credentials.

Changeme - A Default Credentials Scanner
Changeme – A Default Credentials Scanner

changeme is designed to be simple to add new credentials without having to write any code or modules. changeme keeps credential data separate from code. All credentials are stored in yaml files so they can be both easily read by humans and processed by changeme. Credential files can be created by using the ./ --mkcred tool and answering a few questions.

The tool supports the http/https, mssql, mysql, postgres, ssh, ssh w/key, snmp, mongodb and ftp protocols. Use ./ --dump to output all of the currently available credentials.

You can load your targets using a variety of methods, single ip address/host, subnet, list of hosts, nmap xml file and Shodan query. All methods except for Shodan are loaded as a positional argument and the type is inferred.

Below are some common usage examples.

  • Scan a single host: ./
  • Scan a subnet for default creds: ./
  • Scan using an nmap file ./ subnet.xml
  • Scan a subnet for Tomcat default creds and set the timeout to 5 seconds: ./ -n "Apache Tomcat" --timeout 5
  • Use Shodan to populate a targets list and check them for default credentials: ./ --shodan_query "Server: SQ-WEBCAM" --shodan_key keygoeshere -c camera
  • Scan for SSH and known SSH keys: ./ --protocols ssh,ssh_key
  • Scan a host for SNMP creds using the protocol syntax: ./ snmp://

You can read more and download this tool over here:

Notify of
Inline Feedbacks
View all comments