Skip to content

henrykpfeifer/awesome-shodan-queries

Β 
Β 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

5 Commits
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

Awesome Shodan Search Queries Awesome

Based on a blog post at https://jarv.is/notes/shodan-search-queries/.

Over time, I've collected an assortment of interesting, funny, and depressing search queries to plug into Shodan, the (literal) internet search engine. Some return facepalm-inducing results, while others return serious and/or ancient vulnerabilities in the wild.

Most search filters require a Shodan account.

You can assume these queries only return unsecured/open instances when possible. For your own legal benefit, do not attempt to login (even with default passwords) if they aren't! Narrow down results by adding filters like country:US or org:"Harvard University" or hostname:"nasa.gov" to the end.

The world and its devices are quickly becoming more connected through the shiny new Internet of Things Sh*t β€” and exponentially more dangerous as a result. To that end, I hope this list spreads awareness (and, quite frankly, pant-wetting fear) rather than harm.

And as always, discover and disclose responsibly! 😊


Table of Contents


Industrial Control Systems

Samsung Electronic Billboards β†’

"Server: Prismview Player"

Example: Electronic Billboards

Gas Station Pump Controllers β†’

"in-tank inventory" port:10001

Example: Gas Station Pump Inventories

Automatic License Plate Readers β†’

P372 "ANPR enabled"

Traffic Light Controllers / Red Light Cameras β†’

mikrotik streetlight

Voting Machines in the United States β†’

"voter system serial" country:US

Prison Pay Phones β†’

"[2J[H Encartele Confidential"

Tesla PowerPack Charging Status β†’

http.title:"Tesla PowerPack System" http.component:"d3" -ga3ca4f2

Example: Tesla PowerPack Charging Status

Electric Vehicle Chargers β†’

"Server: gSOAP/2.8" "Content-Length: 583"
http.title:"Nordex Control" "Windows 2000 5.0 x86" "Jetty/3.1 (JSP 1.1; Servlet 2.2; java 1.6.0_14)"

C4 Max Commercial Vehicle GPS Trackers β†’

"[1m[35mWelcome on console"

Example: C4 Max Vehicle GPS

DICOM Medical X-Ray Machines β†’

Secured by default, thankfully, but these 1,700+ machines still have no business being on the internet.

"DICOM Server Response" port:104

GaugeTech Electricity Meters β†’

"Server: EIG Embedded Web Server" "200 Document follows"

Example: GaugeTech Electricity Meters

Siemens Industrial Automation β†’

"Siemens, SIMATIC" port:161

Siemens HVAC Controllers β†’

"Server: Microsoft-WinCE" "Content-Length: 12581"

Door / Lock Access Controllers β†’

"HID VertX" port:4070

Railroad Management β†’

"log off" "select the appropriate"

Remote Desktop

Unprotected VNC β†’

"authentication disabled" "RFB 003.008"

Shodan Images is a great supplementary tool to browse screenshots, by the way! β†’

Example: Unprotected VNC

The first result right now. 😞

Windows RDP β†’

99.99% are secured by a secondary Windows login screen.

"\x03\x00\x00\x0b\x06\xd0\x00\x00\x124\x00"

Network Infrastructure

MongoDB β†’

Older versions were insecure by default. Very scary.

"MongoDB Server Information" port:27017 -authentication

Example: MongoDB

Jenkins CI β†’

"X-Jenkins" "Set-Cookie: JSESSIONID" http.title:"Dashboard"

Example: Jenkins CI

Docker APIs β†’

"Docker Containers:" port:2375

Pi-hole Open DNS Servers β†’

"dnsmasq-pi-hole" "Recursion: enabled"

Already Logged-In as root via Telnet β†’

"root@" port:23 -login -password -name -Session

Android Root Bridges β†’

A tangential result of Google's dumb fractured update approach. πŸ™„ More information here.

"Android Debug Bridge" "Device" port:5555

Lantronix Serial-to-Ethernet Adapter Leaking Telnet Passwords β†’

Lantronix password port:30718 -secured

Citrix Virtual Apps β†’

"Citrix Applications:" port:1604

Example: Citrix Virtual Apps

Cisco Smart Install β†’

Vulnerable (kind of "by design," but especially when exposed).

"smart install client active"

PBX IP Phone Gateways β†’

PBX "gateway console" -password port:23

Polycom Video Conferencing β†’

http.title:"- Polycom" "Server: lighttpd"

Telnet Configuration: β†’

"Polycom Command Shell" -failed port:23

Example: Polycom Video Conferencing

"Server: Bomgar" "200 OK"

Intel Active Management CVE-2017-5689 β†’

"Intel(R) Active Management Technology" port:623,664,16992,16993,16994,16995
HP-ILO-4 !"HP-ILO-4/2.53" !"HP-ILO-4/2.54" !"HP-ILO-4/2.55" !"HP-ILO-4/2.60" !"HP-ILO-4/2.61" !"HP-ILO-4/2.62" port:1900

Outlook Web Access:

Exchange 2007 β†’

"x-owa-version" "IE=EmulateIE7" "Server: Microsoft-IIS/7.0"

Example: OWA for Exchange 2007

Exchange 2010 β†’

"x-owa-version" "IE=EmulateIE7" http.favicon.hash:442749392

Example: OWA for Exchange 2010

Exchange 2013 / 2016 β†’

"X-AspNet-Version" http.title:"Outlook" -"x-owa-version"

Example: OWA for Exchange 2013/2016

Lync / Skype for Business β†’

"X-MS-Server-Fqdn"

Network Attached Storage (NAS)

SMB (Samba) File Shares β†’

Produces ~500,000 results...narrow down by adding "Documents" or "Videos", etc.

"Authentication: disabled" port:445

Specifically domain controllers: β†’

"Authentication: disabled" NETLOGON SYSVOL -unix port:445

Iomega / LenovoEMC NAS Drives β†’

"Set-Cookie: iomega=" -"manage/login.html" -http.title:"Log In"

Example: Iomega / LenovoEMC NAS Drives

Buffalo TeraStation NAS Drives β†’

Redirecting sencha port:9000

Example: Buffalo TeraStation NAS Drives

Logitech Media Servers β†’

"Server: Logitech Media Server" "200 OK"

Example: Logitech Media Servers

Plex Media Servers β†’

"X-Plex-Protocol" "200 OK" port:32400
"CherryPy/5.1.0" "/home"

Example: PlexPy / Tautulli Dashboards


Webcams

Example images not necessary. 🀦

Yawcams β†’

"Server: yawcam" "Mime-Type: text/html"

webcamXP/webcam7 β†’

("webcam 7" OR "webcamXP") http.component:"mootools" -401

Android IP Webcam Server β†’

"Server: IP Webcam Server" "200 OK"

Security DVRs β†’

html:"DVR_H264 ActiveX"

Printers & Copiers:

HP Printers β†’

"Serial Number:" "Built:" "Server: HP HTTP"

Example: HP Printers

Xerox Copiers/Printers β†’

ssl:"Xerox Generic Root"

Example: Xerox Copiers/Printers

Epson Printers β†’

"SERVER: EPSON_Linux UPnP" "200 OK"
"Server: EPSON-HTTP" "200 OK"

Example: Epson Printers

Canon Printers β†’

"Server: KS_HTTP" "200 OK"
"Server: CANON HTTP Server"

Example: Canon Printers


Home Devices

Yamaha Stereos β†’

"Server: AV_Receiver" "HTTP/1.1 406"

Example: Yamaha Stereos

Chromecasts / Smart TVs β†’

"Chromecast:" port:8008
"Model: PYNG-HUB"

Random Stuff

OctoPrint 3D Printer Controllers β†’

title:"OctoPrint" -title:"Login" http.favicon.hash:1307375944

Example: OctoPrint 3D Printers

Etherium Miners β†’

"ETH - Total speed"

Example: Etherium Miners

Apache Directory Listings β†’

Substitute .pem with any extension or a filename like phpinfo.php.

http.title:"Index of /" http.html:".pem"

Too Many Minecraft Servers β†’

"Minecraft Server" "protocol 340" port:25565

Literally Everything in North Korea πŸ‡°πŸ‡΅ β†’

net:175.45.176.0/22,210.52.109.0/24,77.94.35.0/24

TCP Quote of the Day β†’

Port 17 (RFC 865) has a bizarre history...

port:17 product:"Windows qotd"

Find a Job Doing This! πŸ‘©β€πŸ’Ό β†’

"X-Recruiting:"

If you've found any other juicy Shodan gems, whether it's a search query or a specific example, definitely drop a comment on the blog or open an issue/PR here on GitHub.

Bon voyage, fellow penetrators! πŸ˜‰

License

CC0

To the extent possible under law, Jake Jarvis has waived all copyright and related or neighboring rights to this work.

About

πŸ” A collection of interesting, funny, and depressing search queries to plug into https://shodan.io/

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published