Shodan providing service to find vulnerable servers in Internet




 "This content only for educational purpose not for illegal activities"
Shodan is a search engine that lets the user find specific types of computers (webcams, routers, servers, etc.) connected to the internet using a variety of filters. Some have also described it as a search engine of service banners, which are meta-data the server sends back to the client. This can be information about the server software, what options the service supports, a welcome message or anything else that the client can find out before interacting with the server.

The website began as Matherly's pet project. It was launched in 2009 by computer programmer John Matherly, who, in 2003, conceived the idea of searching devices linked to the Internet.The name Shodan is a reference to SHODAN, a character from the System Shock video game series. Shodan users are able to find systems including traffic lights, security cameras, home heating systems as well as control systems for water parks, gas stations, water plants, power grids, nuclear power plants and particle-accelerating cyclotrons;[citation needed] most have little security.Many devices use "admin" as their username and "1234" as their password, and the only software required to connect to them is a web browser.

Shodan collects data mostly on web servers (HTTP/HTTPS - port 80, 8080, 443, 8443), as well as FTP (port 21), SSH (port 22), Telnet (port 23), SNMP (port 161), SIP (port 5060),and Real Time Streaming Protocol (RTSP, port 554). The latter can be used to access webcams and their video stream.

How to Use???

1) Goto https://www.shodan.io/
2)Register your account (Deep search you need shodan account)
3)If you want to search for servers with RDP which are available on the Internet.

RDP's TCP service port number is 3389.

So, in search bar  type port:3389

Once you click search, you will get the result like below image.
Shodan provides the detailed result of your search.


Which result contains server IP,ISP,SSL certificate,Protocol,application version detail.

As per the image globally 1,696,053 (approx.) servers available with RDP service on the internet.Shodan also providing the result categories (countries, Organizations, OS).

Here you can search for servers, vulnerabilities, IP cameras, any IOT devices.

If you want to find the specific vulnerable server follow the below syntax.
Syntax: vuln:(CVE No.)

(CVE Identifiers (also called "CVE names," "CVE numbers," "CVE-IDs," and "CVEs") are unique, common identifiers for publicly known information security vulnerabilities.)

Example :
 CVE              - CVE-2014-0160
Vulnerability - OpenSSL 'Heartbleed' vulnerability 

In Shodan search like vuln:cve-2014-0160

by, interestingly shodan helps to find hacked serves on the internet.Here we have to use the keyword title:"hacked by". Based on this information there are roughly 2,000+ websites hackers have been compromised recently and advertise it using the string "Hacked by". Unsurprisingly, the majority of the compromised websites are running on port 80 (HTTP).

To  search IP-Camera's Click Here

To know more about Shodan vulnerability search engine Click Here





Post a Comment

0Comments
Post a Comment (0)