Awesome Shodan Search Queries
Over time, I've collected an assortment of interesting, funny, and depressing search queries to plug into Shodan, the (literal) internet search engine. Some return facepalm-inducing results, while others return serious and/or ancient vulnerabilities in the wild.
Most search filters require a Shodan account.
You can assume these queries only return unsecured/open instances when possible. For your own legal benefit, do not attempt to login (even with default passwords) if they aren't! Narrow down results by adding filters like country:US or org:"Harvard University" or hostname:"nasa.gov" to the end.
The world and its devices are quickly becoming more connected through the shiny new Internet of Things Sh*t β and exponentially more dangerous as a result. To that end, I hope this list spreads awareness (and, quite frankly, pant-wetting fear) rather than harm.
And as always, discover and disclose responsibly! π€
Table of Contents
Industrial Control Systems
Samsung Electronic Billboards π β

Gas Station Pump Controllers π β

Automatic License Plate Readers π β

Traffic Light Controllers / Red Light Cameras π β
Voting Machines in the United States π β
Telcos Running Cisco Lawful Intercept Wiretaps π β
Wiretapping mechanism outlined by Cisco in RFC 3924:
Lawful intercept is the lawfully authorized interception and monitoring of communications of an intercept subject. The term "intercept subject" [...] refers to the subscriber of a telecommunications service whose communications and/or intercept related information (IRI) has been lawfully authorized to be intercepted and delivered to some agency.
Prison Pay Phones π β
Tesla PowerPack Charging Status π β

Electric Vehicle Chargers π β
Maritime Satellites π β
Shodan made a pretty sweet Ship Tracker that maps ship locations in real time, too!

Submarine Mission Control Dashboards π β
CAREL PlantVisor Refrigeration Units π β

Nordex Wind Turbine Farms π β

Secured by default, thankfully, but these 1,700+ machines still have no business being on the internet.

Siemens Industrial Automation π β
Siemens HVAC Controllers π β
Door / Lock Access Controllers π β
Railroad Management π β
Remote Desktop
Unprotected VNC π β
Shodan Images is a great supplementary tool to browse screenshots, by the way! π β
The first result right now. π
Windows RDP π β
99.99% are secured by a secondary Windows login screen.
Network Infrastructure
Weave Scope Dashboards π β
Command-line access inside Kubernetes pods and Docker containers, and real-time visualization/monitoring of the entire infrastructure.

MongoDB π β
Older versions were insecure by default. Very scary.

Mongo Express Web GUI π β
Like the infamous phpMyAdmin but for MongoDB.

Jenkins CI π β

Docker APIs π β
Docker Private Registries π β
Already Logged-In as root via Telnet π β
root via Telnet π βAndroid Root Bridges π β
A tangential result of Google's sloppy fractured update approach. π More information here.
Lantronix Serial-to-Ethernet Adapter Leaking Telnet Passwords π β
Citrix Virtual Apps π β

Cisco Smart Install π β
Vulnerable (kind of "by design," but especially when exposed).
PBX IP Phone Gateways π β
Telnet Configuration: π β

Bomgar Help Desk Portal π β
Intel Active Management CVE-2017-5689 π β
HP iLO 4 CVE-2017-12542 π β
Outlook Web Access:
Exchange 2007 π β

Exchange 2010 π β

Exchange 2013 / 2016 π β

Lync / Skype for Business π β
Network Attached Storage (NAS)
SMB (Samba) File Shares π β
Produces ~500,000 results...narrow down by adding "Documents" or "Videos", etc.
Specifically domain controllers: π β
Concerning default network shares of QuickBooks files: π β
FTP Servers with Anonymous Login π β
Iomega / LenovoEMC NAS Drives π β

Buffalo TeraStation NAS Drives π β

Logitech Media Servers π β

Tautulli / PlexPy Dashboards π β

Webcams
Example images not necessary. π€¦
Yawcams π β
webcamXP/webcam7 π β
Android IP Webcam Server π β
Security DVRs π β
Printers & Copiers:
HP Printers π β

Xerox Copiers/Printers π β

Epson Printers π β

Canon Printers π β

Home Devices
Yamaha Stereos π β

Apple AirPlay Receivers π β
Apple TVs, HomePods, etc.
Chromecasts / Smart TVs π β
Crestron Smart Home Controllers π β
Random Stuff
OctoPrint 3D Printer Controllers π β

Etherium Miners π β

Apache Directory Listings π β
Substitute .pem with any extension or a filename like phpinfo.php.
Misconfigured WordPress π β
Exposed wp-config.php files containing database credentials.
Too Many Minecraft Servers π β
Literally Everything in North Korea π°π΅ π β
TCP Quote of the Day π β
Port 17 (RFC 865) has a bizarre history...
Find a Job Doing This! π©βπΌ π β
If you've found any other juicy Shodan gems, whether it's a search query or a specific example, definitely drop a comment on the blog or open an issue/PR here on GitHub.
Bon voyage, fellow penetrators! π
License
To the extent possible under law, Jake Jarvis has waived all copyright and related or neighboring rights to this work.
Mirrored from a blog post at https://jarv.is/notes/shodan-search-queries/.
Last updated