Most search filters require a Shodan account.
This has tons of titles, info and categorisation a lot of other mass-lists don't have.
Also, every hour, it re-checks every query on here and updates their count. It also removes dorks that have 0 results.
- Cameras
- Industrial Control Systems
- Network Infastructure
- Printers
- Files and Directories
- Compromised devices and websites
- Miscellaneous
General camera search.
camera
- 3,925,711 results
Hikvision IP Cameras.
product:"Hikvision IP Camera"
- 2,913,624 results
Backdoor exploit at https://ipvm.com/reports/hik-exploit
Webcams running on IPCam Client.
title:"IPCam Client"
- 65,783 results
Older webcams running on GeoVision.
server: GeoHttpServer
- 43,416 results
Avigilion-brand camera/monitoring devices.
title:"Avigilon"
- 19,600 results
Vivotek IP cameras.
server: VVTK-HTTP-Server
- 17,079 results
DVR CCTV cameras accessible via http.
200 ok dvr port:"81"
- 10,347 results
Netwave-make IP cameras.
Netwave IP Camera Content-Length: 2574
- 1,366 results
A UK-based IP camera provider.
WWW-Authenticate: "Merit LILIN Ent. Co., Ltd."
- 1,290 results
Yet another WebCAM software.
product:"Yawcam webcam viewer httpd"
- 685 results
UI3 - the HTML5 web interface for Blue Iris.
title:"ui3 -"
- 543 results
Unsecured Linksys webcams.
title:"+tm01+"
- 495 results
Various IP camera/video management system products.
ACTi
- 409 results
Webcams with screenshots.
webcam has_screenshot:true
- 246 results
Webcams running on webcamXP
server: webcamxp
- 177 results
IP Webcams with screenshots.
has_screenshot:true IP Webcam
- 123 results
Webcams running on webcam 7.
server: "webcam 7"
- 88 results
Webcams running on Blue Iris.
title:"blue iris remote view"
- 34 results
Canon-manufactured megapixel security cameras.
title:"Network Camera VB-M600"
- 33 results
i-Catcher IP-based CCTV systems.
server: "i-Catcher Console"
- 30 results
Linksys WVC80N cameras.
WVC80N
- 25 results
EtherNet/IP
port:44818
- 551,485 results
Modbus
port:502
- 521,373 results
S7
port:102
- 519,179 results
BACnet
port:47808
- 47,474 results
Niagara Fox
port:1911,4911 product:Niagara
- 9,676 results
Gas Station Pump Controllers
"in-tank inventory" port:10001
- 6,342 results
Find gas station pump controllers with accessible inventory data.
More VNC Servers
"authentication disabled" port:5900,5901
- 6,027 results
Another search term for VNC servers - most are on port 5900 or 5901 as these are VNC display ports.
VNC Servers
"authentication disabled" "RFB 003.008"
- 5,608 results
While not always 100% guaranteed to be a system, lots of embedded systems can show up here, along with personal systems.
IEC 60870-5-104
port:2404 asdu address
- 3,688 results
Siemens Industrial Automation
"Siemens, SIMATIC" port:161
- 3,195 results
Omron FINS
port:9600 response code
- 1,997 results
DICOM Medical X-Ray Machines
"DICOM Server Response" port:104
- 1,840 results
DNP3
port:20000 source address
- 1,083 results
PCWorx
port:1962 PLC
- 1,079 results
ProConOS
port:20547 PLC
- 544 results
XZERES Wind Turbine
title:"xzeres wind"
- 462 results
MELSEC-Q
port:5006,5007 product:mitsubishi
- 230 results
Door / Lock Access Controllers
"HID VertX" port:4070
- 199 results
C4 Max Commercial Vehicle GPS Trackers
[1m[35mWelcome on console
- 73 results
Electric Vehicle Chargers
"Server: gSOAP/2.8" "Content-Length: 583"
- 41 results
Nordex Wind Turbine Farms
http.title:"Nordex Control" "Windows 2000 5.0 x86" "Jetty/3.1 (JSP 1.1; Servlet 2.2; java 1.6.0_14)"
- 37 results
Open ATM
NCR Port:"161"
- 29 results
GaugeTech Electricity Meters
"Server: EIG Embedded Web Server" "200 Document follows"
- 29 results
Voting Machines in the United States
"voter system serial" country:US
- 22 results
Traffic Light Controllers / Red Light Cameras
mikrotik streetlight
- 19 results
CAREL PlantVisor Refrigeration Units
"Server: CarelDataServer" "200 Document follows"
- 15 results
HART-IP
port:5094 hart-ip
- 13 results
Fuel Pumps connected to internet
"privileged command" GET
- 9 results
Siemens HVAC Controllers
"Server: Microsoft-WinCE" "Content-Length: 12581"
- 5 results
Samsung Electronic Billboards
Server: Prismview Player
- 3 results
Search for electronic billboards managed by Prismview servers.
Automatic License Plate Readers
P372 "ANPR enabled"
- 2 results
Submarine Mission Control Dashboards
title:"Slocum Fleet Mission Control"
- 1 result
Railroad Management
"log off" "select the appropriate"
- 1 result
Tesla Powerpack charging Status
http.title:"Tesla PowerPack System" http.component:"d3" -ga3ca4f2
- 1 result
General MySQL Database Search
product:MySQL
- 3,412,635 results
Remote PostgreSQL Connections
port:5432 PostgreSQL
- 794,362 results
MongoDB Server Information on Default Port
"MongoDB Server Information" port:27017
- 109,362 results
Default MongoDB Instances
mongodb port:27017
- 109,360 results
Open Elasticsearch Databases
port:"9200" all:elastic
- 32,262 results
Jenkins CI
"X-Jenkins" "Set-Cookie: JSESSIONID" http.title:"Dashboard"
- 17,486 results
Cisco Smart Install
smart install client active
- 7,732 results
Android Root Bridges
"Android Debug Bridge" "Device" port:5555
- 4,961 results
Listed Apache CouchDB
product:"CouchDB"
- 4,942 results
Polycom Video Conferencing
http.title:"- Polycom" "Server: lighttpd"
- 3,735 results
Pi-hole Open DNS Servers
"dnsmasq-pi-hole" "Recursion: enabled"
- 3,128 results
Lantronix Serial-to-Ethernet Adapter Leaking Telnet Passwords
Lantronix password port:30718 -secured
- 653 results
Accessible Kibana Dashboards
kibana content-length:217
- 572 results
Already Logged-In as root via Telnet
"root@" port:23 -login -password -name -Session
- 560 results
Exposed MongoDB Express Web Interfaces
"Set-Cookie: mongo-express=" "200 OK"
- 441 results
Citrix Virtual Apps
"Citrix Applications:" port:1604
- 298 results
PBX IP Phone Gateways
PBX "gateway console" -password port:23
- 217 results
Docker Private Registries
"Docker-Distribution-Api-Version: registry" "200 OK" -gitlab
- 142 results
Telnet Configuration
"Polycom Command Shell" -failed port:23
- 29 results
Weave Scope Dashboards
title:"Weave Scope" http.favicon.hash:567176827
- 14 results
Vulnerable CouchDB Instances
port:"5984"+Server: "CouchDB/2.1.0"
- 4 results
General Printer Search
printer
- 92,655 results
HP Printers Remote Restart
port:161 hp
- 12,790 results
Canon Printer HTTP Servers
Server: CANON HTTP Server
- 10,655 results
HTTP Accessible Epson Printers
http 200 server epson -upnp
- 3,106 results
Samsung Printers with SyncThru Web Service
title:"syncthru web service"
- 1,036 results
Unsecured Telnet Access to Printers
port:23 "Password is not set"
- 427 results
Remote Access to Xerox Printers
ssl:"Xerox Generic Root"
- 394 results
Epson Printers via HTTP Server
"Server: EPSON-HTTP" "200 OK"
- 346 results
HP LaserJet Printers via HTTP
"HP-ChaiSOE" port:"80"
- 160 results
Lexmark Printer Control Panels
Printer Type: Lexmark
- 151 results
Brother Printers Admin Interface
"Location: /main/main.html" debut
- 65 results
Printers with FTP Access
Laser Printer FTP Server
- 8 results
Open Lists of Files and Directories
http.title:"Index of /"
- 386,508 results
Samba Shares with Authentication Disabled
"Authentication: disabled" port:445 product:"Samba"
- 284,669 results
Filezilla FTP
filezilla port:"21"
- 261,255 results
Open Lists on Port 80
port:80 title:"Index of /"
- 155,303 results
FTP Access Without Credentials
"220" "230 Login successful." port:21
- 64,062 results
Anonymous Access Allowed FTP
"Anonymous access allowed" port:"21"
- 33,706 results
NDMP on FTP Port 10000
ftp port:"10000"
- 12,043 results
Vulnerable vsftpd Service
vsftpd 2.3.4
- 3,323 results
QuickBooks Files Shared Over Network
"QuickBooks files OverNetwork" -unix port:445
- 46 results
General Hacked Label Search
hacked
- 1,910 results
Compromised Legacy Systems on Port 4444
port:4444 system32
- 1,282 results
Compromised Routers Labeled HACKED-ROUTER
HACKED-ROUTER
- 854 results
Compromised Routers
hacked-router-help-sos
- 841 results
Hacked By in HTTP Title
http.title:"Hacked by"
- 539 results
Variation of Hacked By Label Search
hacked by
- 300 results
Compromised Hosts Advertising Default Password
HACKED-ROUTER-HELP-SOS-HAD-DEFAULT-PASSWORD
- 114 results
Compromised FTP Servers
HACKED FTP server
- 72 results
Ransomware Infected RDP Services
"attention" "encrypted" port:3389
- 14 results
Owned By Label in HTTP Title
http.title:"0wn3d by"
- 5 results
General Dashboard Interfaces
http.title:"dashboard"
- 318,311 results
Control Panel Access Points
http.title:"control panel"
- 67,191 results
Minecraft Servers
"Minecraft Server" "protocol 340" port:25565
- 11,353 results
Tesla-related Interfaces
http.title:"Tesla"
- 684 results
Everything in North Korea
net:175.45.176.0/22,210.52.109.0/24,77.94.35.0/24
- 63 results
EIG Electricity Meters
"Server: EIG Embedded Web Server" "200 Document follows"
- 29 results
Misconfigured WordPress Installations
http.html:"* The wp-config.php creation script uses this file"
- 10 results
Ethereum Miners
ETH - Total speed
- 1 result
i'm not responsible for any misuse of this list :) explore responsibly!