diff --git a/readme.md b/readme.md index 38bf067..933e77c 100644 --- a/readme.md +++ b/readme.md @@ -6,14 +6,16 @@ Over time, I've collected an assortment of interesting, funny, and depressing search queries to plug into [Shodan](https://www.shodan.io/), the ([literal](https://www.vice.com/en_uk/article/9bvxmd/shodan-exposes-the-dark-side-of-the-net)) internet search engine. Some return facepalm-inducing results, while others return serious and/or ancient vulnerabilities in the wild. -![](screenshots/shodan.png) -*[Most search filters require a Shodan account.](https://account.shodan.io/register)* +

+
+ Most search filters require a Shodan account. +

You can assume these queries only return unsecured/open instances when possible. For your own legal benefit, do not attempt to login (even with default passwords) if they aren't! Narrow down results by adding filters like `country:US` or `org:"Harvard University"` or `hostname:"nasa.gov"` to the end. The world and its devices are quickly becoming more connected through the shiny new [Internet of ~~Things~~ Sh*t](https://motherboard.vice.com/en_us/topic/internet-of-shit) — and exponentially [more dangerous](https://blog.malwarebytes.com/101/2017/12/internet-things-iot-security-never/) as a result. To that end, I hope this list spreads awareness (and, quite frankly, pant-wetting fear) rather than harm. -**And as always, [discover and disclose responsibly](https://www.bugcrowd.com/resource/what-is-responsible-disclosure/)! 😊** +**And as always, [discover and disclose responsibly](https://www.bugcrowd.com/resource/what-is-responsible-disclosure/)! 🤓** --- @@ -43,7 +45,7 @@ The world and its devices are quickly becoming more connected through the shiny "Server: Prismview Player" ``` -![Example: Electronic Billboards](screenshots/billboard2.png) +
Example: Electronic Billboards
### Gas Station Pump Controllers [→](https://www.shodan.io/search?query=%22in-tank+inventory%22+port%3A10001) @@ -52,7 +54,7 @@ The world and its devices are quickly becoming more connected through the shiny "in-tank inventory" port:10001 ``` -![Example: Gas Station Pump Inventories](screenshots/7-11.png) +
Example: Gas Station Pump Inventories
### Automatic License Plate Readers [→](https://www.shodan.io/search?query=P372+%22ANPR+enabled%22) @@ -61,7 +63,7 @@ The world and its devices are quickly becoming more connected through the shiny P372 "ANPR enabled" ``` -![Example: Automatic License Plate Reader](screenshots/plate-reader.png) +
Example: Automatic License Plate Reader
### Traffic Light Controllers / Red Light Cameras [→](https://www.shodan.io/search?query=mikrotik+streetlight) @@ -91,7 +93,7 @@ mikrotik streetlight http.title:"Tesla PowerPack System" http.component:"d3" -ga3ca4f2 ``` -![Example: Tesla PowerPack Charging Status](screenshots/tesla.png) +
Example: Tesla PowerPack Charging Status
### Electric Vehicle Chargers [→](https://www.shodan.io/search?query=%22Server%3A+gSOAP%2F2.8%22+%22Content-Length%3A+583%22) @@ -114,7 +116,7 @@ http.title:"Nordex Control" "Windows 2000 5.0 x86" "Jetty/3.1 (JSP 1.1; Servlet "[1m[35mWelcome on console" ``` -![Example: C4 Max Vehicle GPS](screenshots/c4max.png) +
Example: C4 Max Vehicle GPS
### [DICOM](https://www.dicomstandard.org/about/) Medical X-Ray Machines [→](https://www.shodan.io/search?query=%22DICOM+Server+Response%22+port%3A104) @@ -132,7 +134,7 @@ Secured by default, thankfully, but these 1,700+ machines still [have no busines "Server: EIG Embedded Web Server" "200 Document follows" ``` -![Example: GaugeTech Electricity Meters](screenshots/power-gaugetech.png) +
Example: GaugeTech Electricity Meters
### Siemens Industrial Automation [→](https://www.shodan.io/search?query=%22Siemens%2C+SIMATIC%22+port%3A161) @@ -179,9 +181,10 @@ Secured by default, thankfully, but these 1,700+ machines still [have no busines [Shodan Images](https://images.shodan.io/) is a great supplementary tool to browse screenshots, by the way! [→](https://images.shodan.io/?query=%22authentication+disabled%22+%21screenshot.label%3Ablank) -![Example: Unprotected VNC](screenshots/vnc.png) - -*The first result right now. 😞* +

+ Example: Unprotected VNC
+ The first result right now. 😞 +

### Windows RDP [→](https://www.shodan.io/search?query=%22%5Cx03%5Cx00%5Cx00%5Cx0b%5Cx06%5Cxd0%5Cx00%5Cx00%5Cx124%5Cx00%22) @@ -207,7 +210,7 @@ Older versions were insecure by default. [Very scary.](https://krebsonsecurity.c "MongoDB Server Information" port:27017 -authentication ``` -![Example: MongoDB](screenshots/mongo.png) +
Example: MongoDB
### Jenkins CI [→](https://www.shodan.io/search?query=%22X-Jenkins%22+%22Set-Cookie%3A+JSESSIONID%22+http.title%3A%22Dashboard%22) @@ -216,7 +219,7 @@ Older versions were insecure by default. [Very scary.](https://krebsonsecurity.c "X-Jenkins" "Set-Cookie: JSESSIONID" http.title:"Dashboard" ``` -![Example: Jenkins CI](screenshots/jenkins.png) +
Example: Jenkins CI
### Docker APIs [→](https://www.shodan.io/search?query=%22Docker+Containers%3A%22+port%3A2375) @@ -262,7 +265,7 @@ Lantronix password port:30718 -secured "Citrix Applications:" port:1604 ``` -![Example: Citrix Virtual Apps](screenshots/citrix.png) +
Example: Citrix Virtual Apps
### Cisco Smart Install [→](https://www.shodan.io/search?query=%22smart+install+client+active%22) @@ -294,7 +297,7 @@ Telnet Configuration: [→](https://www.shodan.io/search?query=%22Polycom+C "Polycom Command Shell" -failed port:23 ``` -![Example: Polycom Video Conferencing](screenshots/polycom.png) +
Example: Polycom Video Conferencing
### [Bomgar Help Desk](https://www.beyondtrust.com/remote-support/integrations) Portal [→](https://www.shodan.io/search?query=%22Server%3A+Bomgar%22+%22200+OK%22) @@ -326,7 +329,7 @@ HP-ILO-4 !"HP-ILO-4/2.53" !"HP-ILO-4/2.54" !"HP-ILO-4/2.55" !"HP-ILO-4/2.60" !"H "x-owa-version" "IE=EmulateIE7" "Server: Microsoft-IIS/7.0" ``` -![Example: OWA for Exchange 2007](screenshots/owa2007.png) +
Example: OWA for Exchange 2007
#### Exchange 2010 [→](https://www.shodan.io/search?query=%22x-owa-version%22+%22IE%3DEmulateIE7%22+http.favicon.hash%3A442749392) @@ -334,7 +337,7 @@ HP-ILO-4 !"HP-ILO-4/2.53" !"HP-ILO-4/2.54" !"HP-ILO-4/2.55" !"HP-ILO-4/2.60" !"H "x-owa-version" "IE=EmulateIE7" http.favicon.hash:442749392 ``` -![Example: OWA for Exchange 2010](screenshots/owa2010.png) +
Example: OWA for Exchange 2010
#### Exchange 2013 / 2016 [→](https://www.shodan.io/search?query=%22X-AspNet-Version%22+http.title%3A%22Outlook%22+-%22x-owa-version%22) @@ -342,7 +345,7 @@ HP-ILO-4 !"HP-ILO-4/2.53" !"HP-ILO-4/2.54" !"HP-ILO-4/2.55" !"HP-ILO-4/2.60" !"H "X-AspNet-Version" http.title:"Outlook" -"x-owa-version" ``` -![Example: OWA for Exchange 2013/2016](screenshots/owa2013.png) +
Example: OWA for Exchange 2013/2016
### Lync / Skype for Business [→](https://www.shodan.io/search?query=%22X-MS-Server-Fqdn%22) @@ -379,7 +382,7 @@ Specifically domain controllers: [→](https://www.shodan.io/search?query=% "Set-Cookie: iomega=" -"manage/login.html" -http.title:"Log In" ``` -![Example: Iomega / LenovoEMC NAS Drives](screenshots/iomega.png) +
Example: Iomega / LenovoEMC NAS Drives
### Buffalo TeraStation NAS Drives [→](https://www.shodan.io/search?query=Redirecting+sencha+port%3A9000) @@ -388,7 +391,7 @@ Specifically domain controllers: [→](https://www.shodan.io/search?query=% Redirecting sencha port:9000 ``` -![Example: Buffalo TeraStation NAS Drives](screenshots/buffalo.png) +
Example: Buffalo TeraStation NAS Drives
### Logitech Media Servers [→](https://www.shodan.io/search?query=%22Server%3A+Logitech+Media+Server%22+%22200+OK%22) @@ -397,7 +400,7 @@ Redirecting sencha port:9000 "Server: Logitech Media Server" "200 OK" ``` -![Example: Logitech Media Servers](screenshots/logitech.png) +
Example: Logitech Media Servers
### [Plex](https://www.plex.tv/) Media Servers [→](https://www.shodan.io/search?query=%22X-Plex-Protocol%22+%22200+OK%22+port%3A32400) @@ -413,7 +416,7 @@ Redirecting sencha port:9000 "CherryPy/5.1.0" "/home" ``` -![Example: PlexPy / Tautulli Dashboards](screenshots/plexpy.png) +
Example: PlexPy / Tautulli Dashboards
--- @@ -463,7 +466,7 @@ html:"DVR_H264 ActiveX" "Serial Number:" "Built:" "Server: HP HTTP" ``` -![Example: HP Printers](screenshots/hp.png) +
Example: HP Printers
### Xerox Copiers/Printers [→](https://www.shodan.io/search?query=ssl%3A%22Xerox+Generic+Root%22) @@ -472,7 +475,7 @@ html:"DVR_H264 ActiveX" ssl:"Xerox Generic Root" ``` -![Example: Xerox Copiers/Printers](screenshots/xerox.png) +
Example: Xerox Copiers/Printers
### Epson Printers [→](https://www.shodan.io/search?query=%22SERVER%3A+EPSON_Linux+UPnP%22+%22200+OK%22) @@ -485,7 +488,7 @@ ssl:"Xerox Generic Root" "Server: EPSON-HTTP" "200 OK" ``` -![Example: Epson Printers](screenshots/epson.png) +
Example: Epson Printers
### Canon Printers [→](https://www.shodan.io/search?query=%22Server%3A+KS_HTTP%22+%22200+OK%22) @@ -498,7 +501,7 @@ ssl:"Xerox Generic Root" "Server: CANON HTTP Server" ``` -![Example: Canon Printers](screenshots/canon.png) +
Example: Canon Printers
--- @@ -513,7 +516,7 @@ ssl:"Xerox Generic Root" "Server: AV_Receiver" "HTTP/1.1 406" ``` -![Example: Yamaha Stereos](screenshots/yamaha.png) +
Example: Yamaha Stereos
### Apple AirPlay Receivers [→](https://www.shodan.io/search?query=%22%5Cx08_airplay%22+port%3A5353) @@ -550,7 +553,7 @@ Apple TVs, HomePods, etc. title:"OctoPrint" -title:"Login" http.favicon.hash:1307375944 ``` -![Example: OctoPrint 3D Printers](screenshots/octoprint.png) +
Example: OctoPrint 3D Printers
### Etherium Miners [→](https://www.shodan.io/search?query=%22ETH+-+Total+speed%22) @@ -559,7 +562,7 @@ title:"OctoPrint" -title:"Login" http.favicon.hash:1307375944 "ETH - Total speed" ``` -![Example: Etherium Miners](screenshots/eth.png) +
Example: Etherium Miners
### Apache Directory Listings [→](https://www.shodan.io/search?query=http.title%3A%22Index+of+%2F%22+http.html%3A%22.pem%22)