Awesome Shodan Search Queries

image Jarvs Blog

Over time, I've collected an assortment of interesting, funny, and depressing search queries to plug into Shodan, the (literal) internet search engine. Some return facepalm-inducing results, while others return serious and/or ancient vulnerabilities in the wild.

Most search filters require a Shodan account.

You can assume these queries only return unsecured/open instances when possible. For your own legal benefit, do not attempt to login (even with default passwords) if they aren't! Narrow down results by adding filters like country:US or org:"Harvard University" or hostname:"nasa.gov" to the end.

The world and its devices are quickly becoming more connected through the shiny new Internet of Things Sh*t β€” and exponentially more dangerous as a result. To that end, I hope this list spreads awareness (and, quite frankly, pant-wetting fear) rather than harm.

And as always, discover and disclose responsibly! πŸ€“


Table of Contents


Industrial Control Systems

Samsung Electronic Billboards πŸ”Ž β†’

Example: Electronic Billboards

Gas Station Pump Controllers πŸ”Ž β†’

Example: Gas Station Pump Inventories

Automatic License Plate Readers πŸ”Ž β†’

Example: Automatic License Plate Reader

Traffic Light Controllers / Red Light Cameras πŸ”Ž β†’

Voting Machines in the United States πŸ”Ž β†’

Telcos Running Cisco Lawful Intercept Wiretaps πŸ”Ž β†’

Wiretapping mechanism outlined by Cisco in RFC 3924:

Lawful intercept is the lawfully authorized interception and monitoring of communications of an intercept subject. The term "intercept subject" [...] refers to the subscriber of a telecommunications service whose communications and/or intercept related information (IRI) has been lawfully authorized to be intercepted and delivered to some agency.

Prison Pay Phones πŸ”Ž β†’

Example: Tesla PowerPack Charging Status

Electric Vehicle Chargers πŸ”Ž β†’

Maritime Satellites πŸ”Ž β†’

Shodan made a pretty sweet Ship Tracker that maps ship locations in real time, too!

Example: Maritime Satellites

Submarine Mission Control Dashboards πŸ”Ž β†’

CAREL PlantVisor Refrigeration Units πŸ”Ž β†’

Example: CAREL PlantVisor Refrigeration Units

C4 Max Commercial Vehicle GPS Trackers πŸ”Ž β†’

Example: C4 Max Vehicle GPS

DICOM Medical X-Ray Machines πŸ”Ž β†’

Secured by default, thankfully, but these 1,700+ machines still have no business being on the internet.

GaugeTech Electricity Meters πŸ”Ž β†’

Example: GaugeTech Electricity Meters

Siemens Industrial Automation πŸ”Ž β†’

Siemens HVAC Controllers πŸ”Ž β†’

Door / Lock Access Controllers πŸ”Ž β†’

Railroad Management πŸ”Ž β†’


Remote Desktop

Unprotected VNC πŸ”Ž β†’

Shodan Images is a great supplementary tool to browse screenshots, by the way! πŸ”Ž β†’

Example: Unprotected VNC The first result right now. 😞

Windows RDP πŸ”Ž β†’

99.99% are secured by a secondary Windows login screen.


Network Infrastructure

Command-line access inside Kubernetes pods and Docker containers, and real-time visualization/monitoring of the entire infrastructure.

Example: Weave Scope Dashboards

Older versions were insecure by default. Very scary.

Example: MongoDB

Like the infamous phpMyAdmin but for MongoDB.

Example: Mongo Express GUI

Jenkins CI πŸ”Ž β†’

Example: Jenkins CI

Docker APIs πŸ”Ž β†’

Docker Private Registries πŸ”Ž β†’

Pi-hole Open DNS Servers πŸ”Ž β†’

Already Logged-In as root via Telnet πŸ”Ž β†’

Android Root Bridges πŸ”Ž β†’

A tangential result of Google's sloppy fractured update approach. πŸ™„ More information here.

Lantronix Serial-to-Ethernet Adapter Leaking Telnet Passwords πŸ”Ž β†’

Citrix Virtual Apps πŸ”Ž β†’

Example: Citrix Virtual Apps

Cisco Smart Install πŸ”Ž β†’

Vulnerable (kind of "by design," but especially when exposed).

PBX IP Phone Gateways πŸ”Ž β†’

Polycom Video Conferencing πŸ”Ž β†’

Telnet Configuration: πŸ”Ž β†’

Example: Polycom Video Conferencing

Intel Active Management CVE-2017-5689 πŸ”Ž β†’

Outlook Web Access:

Exchange 2007 πŸ”Ž β†’

Example: OWA for Exchange 2007

Exchange 2010 πŸ”Ž β†’

Example: OWA for Exchange 2010

Exchange 2013 / 2016 πŸ”Ž β†’

Example: OWA for Exchange 2013/2016

Lync / Skype for Business πŸ”Ž β†’


Network Attached Storage (NAS)

SMB (Samba) File Shares πŸ”Ž β†’

Produces ~500,000 results...narrow down by adding "Documents" or "Videos", etc.

Specifically domain controllers: πŸ”Ž β†’

Concerning default network shares of QuickBooks files: πŸ”Ž β†’

FTP Servers with Anonymous Login πŸ”Ž β†’

Iomega / LenovoEMC NAS Drives πŸ”Ž β†’

Example: Iomega / LenovoEMC NAS Drives

Buffalo TeraStation NAS Drives πŸ”Ž β†’

Example: Buffalo TeraStation NAS Drives

Logitech Media Servers πŸ”Ž β†’

Example: Logitech Media Servers

Plex Media Servers πŸ”Ž β†’

Example: PlexPy / Tautulli Dashboards

Webcams

Example images not necessary. 🀦

webcamXP/webcam7 πŸ”Ž β†’

Android IP Webcam Server πŸ”Ž β†’

Security DVRs πŸ”Ž β†’


Printers & Copiers:

HP Printers πŸ”Ž β†’

Example: HP Printers

Xerox Copiers/Printers πŸ”Ž β†’

Example: Xerox Copiers/Printers

Epson Printers πŸ”Ž β†’

Example: Epson Printers

Canon Printers πŸ”Ž β†’

Example: Canon Printers

Home Devices

Yamaha Stereos πŸ”Ž β†’

Example: Yamaha Stereos

Apple AirPlay Receivers πŸ”Ž β†’

Apple TVs, HomePods, etc.

Chromecasts / Smart TVs πŸ”Ž β†’


Random Stuff

OctoPrint 3D Printer Controllers πŸ”Ž β†’

Example: OctoPrint 3D Printers

Etherium Miners πŸ”Ž β†’

Example: Etherium Miners

Apache Directory Listings πŸ”Ž β†’

Substitute .pem with any extension or a filename like phpinfo.php.

Misconfigured WordPress πŸ”Ž β†’

Exposed wp-config.php files containing database credentials.

Too Many Minecraft Servers πŸ”Ž β†’

Literally Everything in North Korea πŸ‡°πŸ‡΅ πŸ”Ž β†’

TCP Quote of the Day πŸ”Ž β†’

Port 17 (RFC 865) has a bizarre history...

Find a Job Doing This! πŸ‘©β€πŸ’Ό πŸ”Ž β†’


If you've found any other juicy Shodan gems, whether it's a search query or a specific example, definitely drop a comment on the blog or open an issue/PR here on GitHub.

Bon voyage, fellow penetrators! πŸ˜‰

License

CC0

To the extent possible under law, Jake Jarvis has waived all copyright and related or neighboring rights to this work.

Mirrored from a blog post at https://jarv.is/notes/shodan-search-queries/.

Last updated