#shodan — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #shodan, aggregated by home.social.
-
OSINT для ленивых. Часть 16: Находим скрытую инфраструктуру компаний через Shodan
Если сравнить интернет с мегаполисом, то основная видимая часть это — центральные улицы, улицы поменьше и небольшие переулочки (официальные сайты компаний, странички поменьше), ну и есть задние дворы, подвалы и технические входы, где ходят дворники, технический персонал и где шляется всякая гопота. И вот именно по этим задним дворам гуляет Shodan. Именно там мы отлавливаем разные уязвимости, чтобы гопота не пролезла. В отличие от обычных поисковиков вроде Google, которые индексируют страницы, Shodan индексирует устройства: серверы, камеры, базы данных, роутеры, панели администрирования, IoT-устройства. Случается, что админы компаний забывают закрыть такие вещи и мы можем найти тут самое интересное. Разберемся с этим, что называется, "на пальцах"
-
OSINT для ленивых. Часть 16: Находим скрытую инфраструктуру компаний через Shodan
Если сравнить интернет с мегаполисом, то основная видимая часть это — центральные улицы, улицы поменьше и небольшие переулочки (официальные сайты компаний, странички поменьше), ну и есть задние дворы, подвалы и технические входы, где ходят дворники, технический персонал и где шляется всякая гопота. И вот именно по этим задним дворам гуляет Shodan. Именно там мы отлавливаем разные уязвимости, чтобы гопота не пролезла. В отличие от обычных поисковиков вроде Google, которые индексируют страницы, Shodan индексирует устройства: серверы, камеры, базы данных, роутеры, панели администрирования, IoT-устройства. Случается, что админы компаний забывают закрыть такие вещи и мы можем найти тут самое интересное. Разберемся с этим, что называется, "на пальцах"
-
OSINT для ленивых. Часть 16: Находим скрытую инфраструктуру компаний через Shodan
Если сравнить интернет с мегаполисом, то основная видимая часть это — центральные улицы, улицы поменьше и небольшие переулочки (официальные сайты компаний, странички поменьше), ну и есть задние дворы, подвалы и технические входы, где ходят дворники, технический персонал и где шляется всякая гопота. И вот именно по этим задним дворам гуляет Shodan. Именно там мы отлавливаем разные уязвимости, чтобы гопота не пролезла. В отличие от обычных поисковиков вроде Google, которые индексируют страницы, Shodan индексирует устройства: серверы, камеры, базы данных, роутеры, панели администрирования, IoT-устройства. Случается, что админы компаний забывают закрыть такие вещи и мы можем найти тут самое интересное. Разберемся с этим, что называется, "на пальцах"
-
📢 4 400 automates industriels Rockwell exposés en ligne, dont 22 dans des villes ciblées par des cyberattaques
Cet article s'appuie sur une recherche publiée par Forescout's Vedere Labs suite à un scan Shodan réalisé le lundi précédant la publication. Il fait écho à un avis conjoint FBI/EPA confirmant des attaques contre des infrastructures d'eau et…
📖 cyberveille : https://cyberveille.ch/posts/2026-08-08-4-400-automates-industriels-rockwell-exposes-en-ligne-dont-22-dans-des-villes-ciblees-par-des-cyberattaques/
🌐 source : https://cyberscoop.com/exposed-rockwell-controllers-water-system-attacks/?ref=metacurity.com
🟡 vérification factuelle moyenne
#Shodan #EtherNetIP #Cyberveille -
#shodan bietet gerade wieder eine Lifetime Membership für 5$ an.Das ist ein No-Brainer für gelegentliche Shodan Nutzer wie mich. Ich habe diesen Deal vor 8 Jahren gemacht. Ihr findet das Angebot noch bis 9.8. hier: https://account.shodan.io/billing/member
-
#shodan bietet gerade wieder eine Lifetime Membership für 5$ an.Das ist ein No-Brainer für gelegentliche Shodan Nutzer wie mich. Ich habe diesen Deal vor 8 Jahren gemacht. Ihr findet das Angebot noch bis 9.8. hier: https://account.shodan.io/billing/member
-
#shodan bietet gerade wieder eine Lifetime Membership für 5$ an.Das ist ein No-Brainer für gelegentliche Shodan Nutzer wie mich. Ich habe diesen Deal vor 8 Jahren gemacht. Ihr findet das Angebot noch bis 9.8. hier: https://account.shodan.io/billing/member
-
#shodan bietet gerade wieder eine Lifetime Membership für 5$ an.Das ist ein No-Brainer für gelegentliche Shodan Nutzer wie mich. Ich habe diesen Deal vor 8 Jahren gemacht. Ihr findet das Angebot noch bis 9.8. hier: https://account.shodan.io/billing/member
-
#shodan bietet gerade wieder eine Lifetime Membership für 5$ an.Das ist ein No-Brainer für gelegentliche Shodan Nutzer wie mich. Ich habe diesen Deal vor 8 Jahren gemacht. Ihr findet das Angebot noch bis 9.8. hier: https://account.shodan.io/billing/member
-
Shodan lifelong membership is currently only $5!
#shodanio #shodan #infosec #cybersecurity #vulnerability #vulnerabilityscanning #osint #dfir
-
Shodan lifelong membership is currently only $5!
#shodanio #shodan #infosec #cybersecurity #vulnerability #vulnerabilityscanning #osint #dfir
-
Shodan lifelong membership is currently only $5!
#shodanio #shodan #infosec #cybersecurity #vulnerability #vulnerabilityscanning #osint #dfir
-
Shodan lifelong membership is currently only $5!
#shodanio #shodan #infosec #cybersecurity #vulnerability #vulnerabilityscanning #osint #dfir
-
Shodan lifelong membership is currently only $5!
#shodanio #shodan #infosec #cybersecurity #vulnerability #vulnerabilityscanning #osint #dfir
-
Lifetime membership, $5 (usually $49). Get you some #Shodan.
https://mastodon.shodan.io/@shodan/117051390447214818 -
Lifetime membership, $5 (usually $49). Get you some #Shodan.
https://mastodon.shodan.io/@shodan/117051390447214818 -
Lifetime membership, $5 (usually $49). Get you some #Shodan.
https://mastodon.shodan.io/@shodan/117051390447214818 -
Lifetime membership, $5 (usually $49). Get you some #Shodan.
https://mastodon.shodan.io/@shodan/117051390447214818 -
Lifetime membership, $5 (usually $49). Get you some #Shodan.
https://mastodon.shodan.io/@shodan/117051390447214818 -
OSINT для ленивых. Часть 13: ShodanX
Все, кто так или иначе касался OSINT, слышал о Shodan — один из самых популярных инструментов. Удобный графический интерфейс, поиск портов, интернет вещей и все такое. Но нет предела совершенству и у нас есть и ShodanX. Нет, это не новая версия Shodan, и не супер-пупер хацкерский форк. Это - инструмент, который работает как CLI-инструмент для автоматизации разведки, который использует данные Shodan, и не является самостоятельным ресурсом. К чему все это надобно?
-
OSINT для ленивых. Часть 13: ShodanX
Все, кто так или иначе касался OSINT, слышал о Shodan — один из самых популярных инструментов. Удобный графический интерфейс, поиск портов, интернет вещей и все такое. Но нет предела совершенству и у нас есть и ShodanX. Нет, это не новая версия Shodan, и не супер-пупер хацкерский форк. Это - инструмент, который работает как CLI-инструмент для автоматизации разведки, который использует данные Shodan, и не является самостоятельным ресурсом. К чему все это надобно?
-
OSINT для ленивых. Часть 13: ShodanX
Все, кто так или иначе касался OSINT, слышал о Shodan — один из самых популярных инструментов. Удобный графический интерфейс, поиск портов, интернет вещей и все такое. Но нет предела совершенству и у нас есть и ShodanX. Нет, это не новая версия Shodan, и не супер-пупер хацкерский форк. Это - инструмент, который работает как CLI-инструмент для автоматизации разведки, который использует данные Shodan, и не является самостоятельным ресурсом. К чему все это надобно?
-
Monitor your Shodan API rate limits with a simple curl to /api-info. Extract credits, query limits, and scan limits via jq. Works on Linux and macOS. Full snippet: #shodan #snippet #api-rate-limits
https://www.valtersit.com/vault/shodan-api-rate-limit-monitoring-via-account-info-endpoint-7f6b91/
-
Monitor your Shodan API rate limits with a simple curl to /api-info. Extract credits, query limits, and scan limits via jq. Works on Linux and macOS. Full snippet: #shodan #snippet #api-rate-limits
https://www.valtersit.com/vault/shodan-api-rate-limit-monitoring-via-account-info-endpoint-7f6b91/
-
NadMesh: Neues Botnetz durchsucht das Netz gezielt nach offenen KI-Diensten
Anders als frühere Würmer, die sich unkontrolliert und breit im Netz verteilen, arbeitet NadMesh nach einem strukturierten und fortlaufend optimierten Muster.
-
"Russia hacks doorbell cameras to spy on Nato bases"
Many #cameras are not even secured. They're open for anyone to access, because people don't know or don't care. You don't even need to scan the net to find them. Just get a paid #shodan account and search by location.
Here's a fedi account that posts screenshots from random cameras around the world: @shodansafari
-
"Russia hacks doorbell cameras to spy on Nato bases"
Many #cameras are not even secured. They're open for anyone to access, because people don't know or don't care. You don't even need to scan the net to find them. Just get a paid #shodan account and search by location.
Here's a fedi account that posts screenshots from random cameras around the world: @shodansafari
-
"Russia hacks doorbell cameras to spy on Nato bases"
Many #cameras are not even secured. They're open for anyone to access, because people don't know or don't care. You don't even need to scan the net to find them. Just get a paid #shodan account and search by location.
Here's a fedi account that posts screenshots from random cameras around the world: @shodansafari
-
"Russia hacks doorbell cameras to spy on Nato bases"
Many #cameras are not even secured. They're open for anyone to access, because people don't know or don't care. You don't even need to scan the net to find them. Just get a paid #shodan account and search by location.
Here's a fedi account that posts screenshots from random cameras around the world: @shodansafari
-
"Russia hacks doorbell cameras to spy on Nato bases"
Many #cameras are not even secured. They're open for anyone to access, because people don't know or don't care. You don't even need to scan the net to find them. Just get a paid #shodan account and search by location.
Here's a fedi account that posts screenshots from random cameras around the world: @shodansafari
-
Discover how a tiny 16x16 pixel image reveals critical server details. Explore the favicon attack surface to identify software and spot deceptive honeypots.
#Favicon #AttackSurface #Cybersecurity #ThreatIntelligence #Shodan
https://meterpreter.org/favicon-attack-surface/?utm_source=mastodon&utm_medium=jetpack_social
-
Discover how a tiny 16x16 pixel image reveals critical server details. Explore the favicon attack surface to identify software and spot deceptive honeypots.
#Favicon #AttackSurface #Cybersecurity #ThreatIntelligence #Shodan
https://meterpreter.org/favicon-attack-surface/?utm_source=mastodon&utm_medium=jetpack_social
-
https://www.europesays.com/hu/136462/ Olyan eszközökkel figyelnek meg minket Magyarországon a mindennapok során, amelyek más nyugati országokban tiltva vannak #Hikvision #HU #Hungarian #Hungary #kamera #kína #Magyar #Magyarország #megfigyelés #Shodan
-
Shodan Dork Cheat Sheet
In this cheat sheet, I cover useful Shodan search queries, filtering techniques, and practical reconnaissance workflows for cybersecurity assessments
https://denizhalil.com/2023/12/19/shodan-dork-cheat-sheet/#CyberSecurity #Shodan #OSINT #Reconnaissance #AttackSurface #ThreatIntelligence #Pentesting #RedTeam #InfoSec #EthicalHacking #SecurityResearch #DenizHalil
-
Shodan Dork Cheat Sheet
In this cheat sheet, I cover useful Shodan search queries, filtering techniques, and practical reconnaissance workflows for cybersecurity assessments
https://denizhalil.com/2023/12/19/shodan-dork-cheat-sheet/#CyberSecurity #Shodan #OSINT #Reconnaissance #AttackSurface #ThreatIntelligence #Pentesting #RedTeam #InfoSec #EthicalHacking #SecurityResearch #DenizHalil
-
Shodan Dork Cheat Sheet
In this cheat sheet, I cover useful Shodan search queries, filtering techniques, and practical reconnaissance workflows for cybersecurity assessments
https://denizhalil.com/2023/12/19/shodan-dork-cheat-sheet/#CyberSecurity #Shodan #OSINT #Reconnaissance #AttackSurface #ThreatIntelligence #Pentesting #RedTeam #InfoSec #EthicalHacking #SecurityResearch #DenizHalil
-
From this week's Linux Update: Every pen test begins with information gathering. Give yourself a head start with the Shodan search engine and its powerful toolkit.
https://www.linux-magazine.com/Issues/2026/303/Shodan?utm_source=mlm
#PenTesting #Shodan #SearchEngine #sysadmin #vulnerability #database #WebServer #security -
From this week's Linux Update: Every pen test begins with information gathering. Give yourself a head start with the Shodan search engine and its powerful toolkit.
https://www.linux-magazine.com/Issues/2026/303/Shodan?utm_source=mlm
#PenTesting #Shodan #SearchEngine #sysadmin #vulnerability #database #WebServer #security -
From this week's Linux Update: Every pen test begins with information gathering. Give yourself a head start with the Shodan search engine and its powerful toolkit.
https://www.linux-magazine.com/Issues/2026/303/Shodan?utm_source=mlm
#PenTesting #Shodan #SearchEngine #sysadmin #vulnerability #database #WebServer #security -
From this week's Linux Update: Every pen test begins with information gathering. Give yourself a head start with the Shodan search engine and its powerful toolkit.
https://www.linux-magazine.com/Issues/2026/303/Shodan?utm_source=mlm
#PenTesting #Shodan #SearchEngine #sysadmin #vulnerability #database #WebServer #security -
From this week's Linux Update: Every pen test begins with information gathering. Give yourself a head start with the Shodan search engine and its powerful toolkit.
https://www.linux-magazine.com/Issues/2026/303/Shodan?utm_source=mlm
#PenTesting #Shodan #SearchEngine #sysadmin #vulnerability #database #WebServer #security -
-
-
-
-
-
-
-
-
-
The hacking i was promised! And what do i get now? "Let #Shodan 'think' up an exploit for you and go to bed." #Mythos #SystemShock #SystemShockRemake #Anthropic
-
The hacking i was promised! And what do i get now? "Let #Shodan 'think' up an exploit for you and go to bed." #Mythos #SystemShock #SystemShockRemake #Anthropic
-
La chute d'YggTorrent : autopsie d'un suicide technique. 🏴☠️
En colère contre la monétisation du site, l'attaquant "Grolum" a profité d'une config désastreuse pour tout détruire :
1️⃣ IP réelle exposée sur Shodan via un favicon.
2️⃣ SphinxQL ouvert sans auth.
3️⃣ Secrets admin en clair dans un XML.Quand on gère des millions d'utilisateurs, la négligence technique se paie cash. 💸
🎙️ Analyse technique à écouter ici :
https://backslash-podcast.fr/episodes/03-integrale-mars-2026/ -
La chute d'YggTorrent : autopsie d'un suicide technique. 🏴☠️
En colère contre la monétisation du site, l'attaquant "Grolum" a profité d'une config désastreuse pour tout détruire :
1️⃣ IP réelle exposée sur Shodan via un favicon.
2️⃣ SphinxQL ouvert sans auth.
3️⃣ Secrets admin en clair dans un XML.Quand on gère des millions d'utilisateurs, la négligence technique se paie cash. 💸
🎙️ Analyse technique à écouter ici :
https://backslash-podcast.fr/episodes/03-integrale-mars-2026/ -
----------------
🔹 🛠️ Tool: ThreatSentry AI
ThreatSentry AI is presented as an enterprise-focused threat-hunting platform that automates external asset discovery, enriches findings from multiple sources, and applies ensemble machine learning to prioritize risk. The project lists PyQt5 for UI, scikit-learn for ML, and SQLAlchemy for persistence, and names EclipseManic as project lead.
🔹 Core pipeline and integrations
The platform performs continuous external visibility via Shodan queries (preset and custom), extracts service banners across common products (examples in the project include Apache, Nginx, MySQL, IIS), and correlates banner data with NVD CVE information. CVSS-based severity classification is applied where CVE matches are found; the README notes that CVE metrics are updated only when vulnerabilities are identified to avoid data loss.
🔹 Machine learning and scoring
The risk engine is described as an ensemble combining Random Forest, Gradient Boosting, and Neural Network components. Models evaluate 40+ attributes spanning temporal context (exposure duration, patch lag), network position (service criticality, segmentation), behavioral signals (authentication failures, traffic anomalies), and compliance impact (data sensitivity, regulatory exposure). Each risk prediction includes a confidence score in the 0–1 range. The system is described as having configurable automatic retraining with analyst feedback integration for continuous learning.
🔹 Platform capabilities and outputs
ThreatSentry AI emphasizes proactive alerting and executive-ready dashboards that surface high-risk assets ahead of incidents. Preset Shodan queries are provided for common service classes (SSL, RDP, ICS/Modbus), with support for organization-specific custom queries. The architecture is described as extensible for integrating internal systems (SIEM, CMDB, patch sources) although specifics are implementation-dependent.
🔹 Project context
The README highlights single-developer authorship with assistance from AI development tools for code generation and documentation. The repo frames the project as addressing alert fatigue, fragmented data, and reactive security postures by converting multi-source telemetry into prioritized, confidence-scored intelligence.
🔹 Hashtags
-
----------------
🔹 🛠️ Tool: ThreatSentry AI
ThreatSentry AI is presented as an enterprise-focused threat-hunting platform that automates external asset discovery, enriches findings from multiple sources, and applies ensemble machine learning to prioritize risk. The project lists PyQt5 for UI, scikit-learn for ML, and SQLAlchemy for persistence, and names EclipseManic as project lead.
🔹 Core pipeline and integrations
The platform performs continuous external visibility via Shodan queries (preset and custom), extracts service banners across common products (examples in the project include Apache, Nginx, MySQL, IIS), and correlates banner data with NVD CVE information. CVSS-based severity classification is applied where CVE matches are found; the README notes that CVE metrics are updated only when vulnerabilities are identified to avoid data loss.
🔹 Machine learning and scoring
The risk engine is described as an ensemble combining Random Forest, Gradient Boosting, and Neural Network components. Models evaluate 40+ attributes spanning temporal context (exposure duration, patch lag), network position (service criticality, segmentation), behavioral signals (authentication failures, traffic anomalies), and compliance impact (data sensitivity, regulatory exposure). Each risk prediction includes a confidence score in the 0–1 range. The system is described as having configurable automatic retraining with analyst feedback integration for continuous learning.
🔹 Platform capabilities and outputs
ThreatSentry AI emphasizes proactive alerting and executive-ready dashboards that surface high-risk assets ahead of incidents. Preset Shodan queries are provided for common service classes (SSL, RDP, ICS/Modbus), with support for organization-specific custom queries. The architecture is described as extensible for integrating internal systems (SIEM, CMDB, patch sources) although specifics are implementation-dependent.
🔹 Project context
The README highlights single-developer authorship with assistance from AI development tools for code generation and documentation. The repo frames the project as addressing alert fatigue, fragmented data, and reactive security postures by converting multi-source telemetry into prioritized, confidence-scored intelligence.
🔹 Hashtags