Shodan Dorks

Basic

City:

Find devices in a particular city.

city:"Bangalore"

Country:

Find devices in a particular country.

country:"IN"

Geo:

Find devices by giving geographical coordinates.

geo:"56.913055,118.250862"

Location

country:us
country:ru
city:chicago
country:ru country:de city:chicago

Hostname:

Find devices matching the hostname.

Net:

Find devices based on an IP address or /x CIDR.

Organization

Autonomous System Number (ASN)

OS:

Find devices based on operating system.

Port:

Find devices based on open ports.

Before/after:

Find devices before or after between a given time.

SSL/TLS Certificates

  • Self signed certificates

  • Expired certificates

Device Type

Operating System

Product

Customer Premises Equipment (CPE)

Server

ssh fingerprints

Web

Pulse Secure

PEM Certificates

Databases

MySQL

MongoDB

elastic

Memcached

CouchDB

PostgreSQL

Riak

Redis

Cassandra

Industrial Control Systems

Samsung Electronic Billboards

Gas Station Pump Controllers

Fuel Pumps connected to internet:

No auth required to access CLI terminal.

Automatic License Plate Readers

Traffic Light Controllers / Red Light Cameras

Voting Machines in the United States

Open ATM:

Telcos Running Cisco Lawful Intercept Wiretaps

Prison Pay Phones

Tesla PowerPack Charging Status

Electric Vehicle Chargers

Maritime Satellites

Shodan made a pretty sweet Ship Tracker that maps ship locations in real time, too!

Submarine Mission Control Dashboards

CAREL PlantVisor Refrigeration Units

Nordex Wind Turbine Farms

C4 Max Commercial Vehicle GPS Trackers

DICOM Medical X-Ray Machines

Secured by default, thankfully, but these 1,700+ machines still have no business being on the internet.

GaugeTech Electricity Meters

Siemens Industrial Automation

Siemens HVAC Controllers

Door / Lock Access Controllers

Railroad Management

Tesla Powerpack charging Status:

Helps to find the charging status of tesla powerpack.

XZERES Wind Turbine

PIPS Automated License Plate Reader

Modbus

Niagara Fox

GE-SRTP

MELSEC-Q

CODESYS

S7

BACnet

HART-IP

Omron FINS

IEC 60870-5-104

DNP3

EtherNet/IP

PCWorx

Crimson v3.0

ProConOS

Remote Desktop

Unprotected VNC

Windows RDP

99.99% are secured by a secondary Windows login screen.

Network Infrastructure

Hacked routers:

Routers which got compromised

Redis open instances

Citrix:

Find Citrix Gateway.

Weave Scope Dashboards

Command-line access inside Kubernetes pods and Docker containers, and real-time visualization/monitoring of the entire infrastructure.

MongoDB

Older versions were insecure by default. Very scary.

Mongo Express Web GUI

Like the infamous phpMyAdmin but for MongoDB.

Jenkins CI

Jenkins:

Jenkins Unrestricted Dashboard

Docker APIs

Docker Private Registries

Pi-hole Open DNS Servers

Already Logged-In as root via Telnet

Telnet Access:

NO password required for telnet access.

Polycom video-conference system no-auth shell

NPort serial-to-eth / MoCA devices without password

Android Root Bridges

A tangential result of Google's sloppy fractured update approach.

Lantronix Serial-to-Ethernet Adapter Leaking Telnet Passwords

Citrix Virtual Apps

Cisco Smart Install

Vulnerable (kind of "by design," but especially when exposed).

PBX IP Phone Gateways

Polycom Video Conferencing

Telnet Configuration:

Bomgar Help Desk Portal

Intel Active Management CVE-2017-5689

HP iLO 4 CVE-2017-12542

Lantronix ethernet adapter’s admin interface without password

Wifi Passwords:

Helps to find the cleartext wifi passwords in Shodan.

Misconfigured Wordpress Sites:

The wp-config.php if accessed can give out the database credentials.

Outlook Web Access:

Exchange 2007

Exchange 2010

Exchange 2013 / 2016

Lync / Skype for Business

Network Attached Storage (NAS)

SMB (Samba) File Shares

Produces ~500,000 results...narrow down by adding "Documents" or "Videos", etc.

Specifically domain controllers:

Concerning default network shares of QuickBooks files:

FTP Servers with Anonymous Login

Iomega / LenovoEMC NAS Drives

Buffalo TeraStation NAS Drives

Logitech Media Servers

Plex Media Servers

Tautulli / PlexPy Dashboards

Home router attached USB

Webcams

Hipcam

Yawcams

webcamXP/webcam7

Android IP Webcam Server

Security DVRs

Surveillance Cams:

With username:admin and password: :P

Printers & Copiers:

HP Printers

Xerox Copiers/Printers

Epson Printers

Canon Printers

Home Devices

Yamaha Stereos

Apple AirPlay Receivers

Apple TVs, HomePods, etc.

Chromecasts / Smart TVs

Crestron Smart Home Controllers

Random Stuff

OctoPrint 3D Printer Controllers

Etherium Miners

Apache Directory Listings

Substitute .pem with any extension or a filename like phpinfo.php.

Misconfigured WordPress

Exposed wp-config.php files containing database credentials.

Too Many Minecraft Servers

Literally Everything in North Korea

Last updated