Awesome Shodan Search Queries

image Jarvs Blogarrow-up-right

Over time, I've collected an assortment of interesting, funny, and depressing search queries to plug into Shodanarrow-up-right, the (literalarrow-up-right) internet search engine. Some return facepalm-inducing results, while others return serious and/or ancient vulnerabilities in the wild.

Most search filters require a Shodan account.arrow-up-right

You can assume these queries only return unsecured/open instances when possible. For your own legal benefit, do not attempt to login (even with default passwords) if they aren't! Narrow down results by adding filters like country:US or org:"Harvard University" or hostname:"nasa.gov" to the end.

The world and its devices are quickly becoming more connected through the shiny new Internet of Things Sh*tarrow-up-right β€” and exponentially more dangerousarrow-up-right as a result. To that end, I hope this list spreads awareness (and, quite frankly, pant-wetting fear) rather than harm.

And as always, discover and disclose responsiblyarrow-up-right! πŸ€“


Table of Contents


Industrial Control Systems

Samsung Electronic Billboards πŸ”Ž β†’arrow-up-right

Example: Electronic Billboards

Gas Station Pump Controllers πŸ”Ž β†’arrow-up-right

Example: Gas Station Pump Inventories

Automatic License Plate Readers πŸ”Ž β†’arrow-up-right

Example: Automatic License Plate Reader

Traffic Light Controllers / Red Light Cameras πŸ”Ž β†’arrow-up-right

Voting Machines in the United States πŸ”Ž β†’arrow-up-right

Wiretapping mechanism outlined by Cisco in RFC 3924arrow-up-right:

Lawful intercept is the lawfully authorized interception and monitoring of communications of an intercept subject. The term "intercept subject" [...] refers to the subscriber of a telecommunications service whose communications and/or intercept related information (IRI) has been lawfully authorized to be intercepted and delivered to some agency.

Example: Tesla PowerPack Charging Status

Electric Vehicle Chargers πŸ”Ž β†’arrow-up-right

Maritime Satellites πŸ”Ž β†’arrow-up-right

Shodan made a pretty sweet Ship Trackerarrow-up-right that maps ship locations in real time, too!

Example: Maritime Satellites

Submarine Mission Control Dashboards πŸ”Ž β†’arrow-up-right

Example: CAREL PlantVisor Refrigeration Units

C4 Maxarrow-up-right Commercial Vehicle GPS Trackers πŸ”Ž β†’arrow-up-right

Example: C4 Max Vehicle GPS

Secured by default, thankfully, but these 1,700+ machines still have no businessarrow-up-right being on the internet.

Example: GaugeTech Electricity Meters

Siemens Industrial Automation πŸ”Ž β†’arrow-up-right

Siemens HVAC Controllers πŸ”Ž β†’arrow-up-right

Door / Lock Access Controllers πŸ”Ž β†’arrow-up-right

Railroad Management πŸ”Ž β†’arrow-up-right


Remote Desktop

Shodan Imagesarrow-up-right is a great supplementary tool to browse screenshots, by the way! πŸ”Ž β†’arrow-up-right

Example: Unprotected VNC The first result right now. 😞

99.99% are secured by a secondary Windows login screen.


Network Infrastructure

Command-line access inside Kubernetes pods and Docker containers, and real-time visualization/monitoring of the entire infrastructure.

Example: Weave Scope Dashboards

Older versions were insecure by default. Very scary.arrow-up-right

Example: MongoDB

Like the infamous phpMyAdminarrow-up-right but for MongoDB.

Example: Mongo Express GUI

Example: Jenkins CI

Docker Private Registries πŸ”Ž β†’arrow-up-right

Already Logged-In as root via Telnet πŸ”Ž β†’arrow-up-right

Android Root Bridges πŸ”Ž β†’arrow-up-right

A tangential result of Google's sloppy fractured update approach. πŸ™„ More information here.arrow-up-right

Citrix Virtual Apps πŸ”Ž β†’arrow-up-right

Example: Citrix Virtual Apps

Cisco Smart Install πŸ”Ž β†’arrow-up-right

Vulnerablearrow-up-right (kind of "by design," but especially when exposed).

PBX IP Phone Gateways πŸ”Ž β†’arrow-up-right

Telnet Configuration: πŸ”Ž β†’arrow-up-right

Example: Polycom Video Conferencing

Outlook Web Access:

Example: OWA for Exchange 2007

Example: OWA for Exchange 2010

Exchange 2013 / 2016 πŸ”Ž β†’arrow-up-right

Example: OWA for Exchange 2013/2016

Lync / Skype for Business πŸ”Ž β†’arrow-up-right


Network Attached Storage (NAS)

SMB (Samba) File Shares πŸ”Ž β†’arrow-up-right

Produces ~500,000 results...narrow down by adding "Documents" or "Videos", etc.

Specifically domain controllers: πŸ”Ž β†’arrow-up-right

Concerning default network shares of QuickBooksarrow-up-right files: πŸ”Ž β†’arrow-up-right

FTP Servers with Anonymous Login πŸ”Ž β†’arrow-up-right

Iomega / LenovoEMC NAS Drives πŸ”Ž β†’arrow-up-right

Example: Iomega / LenovoEMC NAS Drives

Buffalo TeraStation NAS Drives πŸ”Ž β†’arrow-up-right

Example: Buffalo TeraStation NAS Drives

Logitech Media Servers πŸ”Ž β†’arrow-up-right

Example: Logitech Media Servers

Example: PlexPy / Tautulli Dashboards

Webcams

Example images not necessary. 🀦

Android IP Webcam Server πŸ”Ž β†’arrow-up-right


Printers & Copiers:

Example: HP Printers

Xerox Copiers/Printers πŸ”Ž β†’arrow-up-right

Example: Xerox Copiers/Printers

Example: Epson Printers

Example: Canon Printers

Home Devices

Example: Yamaha Stereos

Apple AirPlay Receivers πŸ”Ž β†’arrow-up-right

Apple TVs, HomePods, etc.

Chromecasts / Smart TVs πŸ”Ž β†’arrow-up-right


Random Stuff

OctoPrint 3D Printer Controllers πŸ”Ž β†’arrow-up-right

Example: OctoPrint 3D Printers

Example: Etherium Miners

Apache Directory Listings πŸ”Ž β†’arrow-up-right

Substitute .pem with any extension or a filename like phpinfo.php.

Misconfigured WordPress πŸ”Ž β†’arrow-up-right

Exposed wp-config.phparrow-up-right files containing database credentials.

Too Many Minecraft Servers πŸ”Ž β†’arrow-up-right

Literally Everythingarrow-up-right in North Korea πŸ‡°πŸ‡΅ πŸ”Ž β†’arrow-up-right

TCP Quote of the Day πŸ”Ž β†’arrow-up-right

Port 17 (RFC 865arrow-up-right) has a bizarre historyarrow-up-right...

Find a Job Doing This! πŸ‘©β€πŸ’Ό πŸ”Ž β†’arrow-up-right


If you've found any other juicy Shodan gems, whether it's a search query or a specific example, definitely drop a commentarrow-up-right on the blog or open an issue/PR here on GitHubarrow-up-right.

Bon voyage, fellow penetrators! πŸ˜‰

License

CC0arrow-up-right

To the extent possible under law, Jake Jarvisarrow-up-right has waived all copyright and related or neighboring rights to this work.

Mirrored from a blog post at https://jarv.is/notes/shodan-search-queries/.

Last updated