home.social

#shodan — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #shodan, aggregated by home.social.

fetched live
  1. OSINT для ленивых. Часть 16: Находим скрытую инфраструктуру компаний через Shodan

    Если сравнить интернет с мегаполисом, то основная видимая часть это — центральные улицы, улицы поменьше и небольшие переулочки (официальные сайты компаний, странички поменьше), ну и есть задние дворы, подвалы и технические входы, где ходят дворники, технический персонал и где шляется всякая гопота. И вот именно по этим задним дворам гуляет Shodan. Именно там мы отлавливаем разные уязвимости, чтобы гопота не пролезла. В отличие от обычных поисковиков вроде Google, которые индексируют страницы, Shodan индексирует устройства: серверы, камеры, базы данных, роутеры, панели администрирования, IoT-устройства. Случается, что админы компаний забывают закрыть такие вещи и мы можем найти тут самое интересное. Разберемся с этим, что называется, "на пальцах"

    habr.com/ru/articles/1068422/

    #осинт #shodan #osint

  2. OSINT для ленивых. Часть 16: Находим скрытую инфраструктуру компаний через Shodan

    Если сравнить интернет с мегаполисом, то основная видимая часть это — центральные улицы, улицы поменьше и небольшие переулочки (официальные сайты компаний, странички поменьше), ну и есть задние дворы, подвалы и технические входы, где ходят дворники, технический персонал и где шляется всякая гопота. И вот именно по этим задним дворам гуляет Shodan. Именно там мы отлавливаем разные уязвимости, чтобы гопота не пролезла. В отличие от обычных поисковиков вроде Google, которые индексируют страницы, Shodan индексирует устройства: серверы, камеры, базы данных, роутеры, панели администрирования, IoT-устройства. Случается, что админы компаний забывают закрыть такие вещи и мы можем найти тут самое интересное. Разберемся с этим, что называется, "на пальцах"

    habr.com/ru/articles/1068422/

    #осинт #shodan #osint

  3. OSINT для ленивых. Часть 16: Находим скрытую инфраструктуру компаний через Shodan

    Если сравнить интернет с мегаполисом, то основная видимая часть это — центральные улицы, улицы поменьше и небольшие переулочки (официальные сайты компаний, странички поменьше), ну и есть задние дворы, подвалы и технические входы, где ходят дворники, технический персонал и где шляется всякая гопота. И вот именно по этим задним дворам гуляет Shodan. Именно там мы отлавливаем разные уязвимости, чтобы гопота не пролезла. В отличие от обычных поисковиков вроде Google, которые индексируют страницы, Shodan индексирует устройства: серверы, камеры, базы данных, роутеры, панели администрирования, IoT-устройства. Случается, что админы компаний забывают закрыть такие вещи и мы можем найти тут самое интересное. Разберемся с этим, что называется, "на пальцах"

    habr.com/ru/articles/1068422/

    #осинт #shodan #osint

  4. 📢 4 400 automates industriels Rockwell exposés en ligne, dont 22 dans des villes ciblées par des cyberattaques

    Cet article s'appuie sur une recherche publiée par Forescout's Vedere Labs suite à un scan Shodan réalisé le lundi précédant la publication. Il fait écho à un avis conjoint FBI/EPA confirmant des attaques contre des infrastructures d'eau et…

    📖 cyberveille : cyberveille.ch/posts/2026-08-0
    🌐 source : cyberscoop.com/exposed-rockwel
    🟡 vérification factuelle moyenne
    #Shodan #EtherNetIP #Cyberveille

  5. #shodan bietet gerade wieder eine Lifetime Membership für 5$ an.Das ist ein No-Brainer für gelegentliche Shodan Nutzer wie mich. Ich habe diesen Deal vor 8 Jahren gemacht. Ihr findet das Angebot noch bis 9.8. hier: account.shodan.io/billing/memb

  6. #shodan bietet gerade wieder eine Lifetime Membership für 5$ an.Das ist ein No-Brainer für gelegentliche Shodan Nutzer wie mich. Ich habe diesen Deal vor 8 Jahren gemacht. Ihr findet das Angebot noch bis 9.8. hier: account.shodan.io/billing/memb

  7. #shodan bietet gerade wieder eine Lifetime Membership für 5$ an.Das ist ein No-Brainer für gelegentliche Shodan Nutzer wie mich. Ich habe diesen Deal vor 8 Jahren gemacht. Ihr findet das Angebot noch bis 9.8. hier: account.shodan.io/billing/memb

  8. #shodan bietet gerade wieder eine Lifetime Membership für 5$ an.Das ist ein No-Brainer für gelegentliche Shodan Nutzer wie mich. Ich habe diesen Deal vor 8 Jahren gemacht. Ihr findet das Angebot noch bis 9.8. hier: account.shodan.io/billing/memb

  9. #shodan bietet gerade wieder eine Lifetime Membership für 5$ an.Das ist ein No-Brainer für gelegentliche Shodan Nutzer wie mich. Ich habe diesen Deal vor 8 Jahren gemacht. Ihr findet das Angebot noch bis 9.8. hier: account.shodan.io/billing/memb

  10. OSINT для ленивых. Часть 13: ShodanX

    Все, кто так или иначе касался OSINT, слышал о Shodan — один из самых популярных инструментов. Удобный графический интерфейс, поиск портов, интернет вещей и все такое. Но нет предела совершенству и у нас есть и ShodanX. Нет, это не новая версия Shodan, и не супер-пупер хацкерский форк. Это - инструмент, который работает как CLI-инструмент для автоматизации разведки, который использует данные Shodan, и не является самостоятельным ресурсом. К чему все это надобно?

    habr.com/ru/articles/1061784/

    #osint #shodan

  11. OSINT для ленивых. Часть 13: ShodanX

    Все, кто так или иначе касался OSINT, слышал о Shodan — один из самых популярных инструментов. Удобный графический интерфейс, поиск портов, интернет вещей и все такое. Но нет предела совершенству и у нас есть и ShodanX. Нет, это не новая версия Shodan, и не супер-пупер хацкерский форк. Это - инструмент, который работает как CLI-инструмент для автоматизации разведки, который использует данные Shodan, и не является самостоятельным ресурсом. К чему все это надобно?

    habr.com/ru/articles/1061784/

    #osint #shodan

  12. OSINT для ленивых. Часть 13: ShodanX

    Все, кто так или иначе касался OSINT, слышал о Shodan — один из самых популярных инструментов. Удобный графический интерфейс, поиск портов, интернет вещей и все такое. Но нет предела совершенству и у нас есть и ShodanX. Нет, это не новая версия Shodan, и не супер-пупер хацкерский форк. Это - инструмент, который работает как CLI-инструмент для автоматизации разведки, который использует данные Shodan, и не является самостоятельным ресурсом. К чему все это надобно?

    habr.com/ru/articles/1061784/

    #osint #shodan

  13. Monitor your Shodan API rate limits with a simple curl to /api-info. Extract credits, query limits, and scan limits via jq. Works on Linux and macOS. Full snippet: #shodan #snippet #api-rate-limits

    valtersit.com/vault/shodan-api

  14. Monitor your Shodan API rate limits with a simple curl to /api-info. Extract credits, query limits, and scan limits via jq. Works on Linux and macOS. Full snippet: #shodan #snippet #api-rate-limits

    valtersit.com/vault/shodan-api

  15. NadMesh: Neues Botnetz durchsucht das Netz gezielt nach offenen KI-Diensten

    Anders als frühere Würmer, die sich unkontrolliert und breit im Netz verteilen, arbeitet NadMesh nach einem strukturierten und fortlaufend optimierten Muster.

    all-about-security.de/nadmesh-

    #shodan #mcp #mcpserver #botnet #cybersecurity

  16. "Russia hacks doorbell cameras to spy on Nato bases"

    Many #cameras are not even secured. They're open for anyone to access, because people don't know or don't care. You don't even need to scan the net to find them. Just get a paid #shodan account and search by location.

    Here's a fedi account that posts screenshots from random cameras around the world: @shodansafari

    telegraph.co.uk/world-news/202

    #webcam #security #privacy #surveillance

  17. "Russia hacks doorbell cameras to spy on Nato bases"

    Many #cameras are not even secured. They're open for anyone to access, because people don't know or don't care. You don't even need to scan the net to find them. Just get a paid #shodan account and search by location.

    Here's a fedi account that posts screenshots from random cameras around the world: @shodansafari

    telegraph.co.uk/world-news/202

    #webcam #security #privacy #surveillance

  18. "Russia hacks doorbell cameras to spy on Nato bases"

    Many #cameras are not even secured. They're open for anyone to access, because people don't know or don't care. You don't even need to scan the net to find them. Just get a paid #shodan account and search by location.

    Here's a fedi account that posts screenshots from random cameras around the world: @shodansafari

    telegraph.co.uk/world-news/202

    #webcam #security #privacy #surveillance

  19. "Russia hacks doorbell cameras to spy on Nato bases"

    Many #cameras are not even secured. They're open for anyone to access, because people don't know or don't care. You don't even need to scan the net to find them. Just get a paid #shodan account and search by location.

    Here's a fedi account that posts screenshots from random cameras around the world: @shodansafari

    telegraph.co.uk/world-news/202

    #webcam #security #privacy #surveillance

  20. "Russia hacks doorbell cameras to spy on Nato bases"

    Many #cameras are not even secured. They're open for anyone to access, because people don't know or don't care. You don't even need to scan the net to find them. Just get a paid #shodan account and search by location.

    Here's a fedi account that posts screenshots from random cameras around the world: @shodansafari

    telegraph.co.uk/world-news/202

    #webcam #security #privacy #surveillance

  21. About this time of year (July or August) there's often a membership sale for #Shodan - anyone have any details? #infosec

  22. About this time of year (July or August) there's often a membership sale for #Shodan - anyone have any details? #infosec

  23. About this time of year (July or August) there's often a membership sale for #Shodan - anyone have any details? #infosec

  24. About this time of year (July or August) there's often a membership sale for #Shodan - anyone have any details? #infosec

  25. From this week's Linux Update: Every pen test begins with information gathering. Give yourself a head start with the Shodan search engine and its powerful toolkit.
    linux-magazine.com/Issues/2026
    #PenTesting #Shodan #SearchEngine #sysadmin #vulnerability #database #WebServer #security

  26. From this week's Linux Update: Every pen test begins with information gathering. Give yourself a head start with the Shodan search engine and its powerful toolkit.
    linux-magazine.com/Issues/2026

  27. From this week's Linux Update: Every pen test begins with information gathering. Give yourself a head start with the Shodan search engine and its powerful toolkit.
    linux-magazine.com/Issues/2026
    #PenTesting #Shodan #SearchEngine #sysadmin #vulnerability #database #WebServer #security

  28. From this week's Linux Update: Every pen test begins with information gathering. Give yourself a head start with the Shodan search engine and its powerful toolkit.
    linux-magazine.com/Issues/2026
    #PenTesting #Shodan #SearchEngine #sysadmin #vulnerability #database #WebServer #security

  29. From this week's Linux Update: Every pen test begins with information gathering. Give yourself a head start with the Shodan search engine and its powerful toolkit.
    linux-magazine.com/Issues/2026
    #PenTesting #Shodan #SearchEngine #sysadmin #vulnerability #database #WebServer #security

  30. Wann wieder #shodan membership flash sale? Juli, August rum?

  31. Wann wieder #shodan membership flash sale? Juli, August rum?

  32. Wann wieder #shodan membership flash sale? Juli, August rum?

  33. Wann wieder #shodan membership flash sale? Juli, August rum?

  34. Wann wieder #shodan membership flash sale? Juli, August rum?

  35. @smgt not a homelab service but I would argue #shodan comes closest to what you're describing 🤪🤣

  36. @smgt not a homelab service but I would argue #shodan comes closest to what you're describing 🤪🤣

  37. @smgt not a homelab service but I would argue #shodan comes closest to what you're describing 🤪🤣

  38. @smgt not a homelab service but I would argue #shodan comes closest to what you're describing 🤪🤣

  39. The hacking i was promised! And what do i get now? "Let #Shodan 'think' up an exploit for you and go to bed." #Mythos #SystemShock #SystemShockRemake #Anthropic

  40. The hacking i was promised! And what do i get now? "Let #Shodan 'think' up an exploit for you and go to bed." #Mythos #SystemShock #SystemShockRemake #Anthropic

  41. La chute d'YggTorrent : autopsie d'un suicide technique. 🏴‍☠️

    En colère contre la monétisation du site, l'attaquant "Grolum" a profité d'une config désastreuse pour tout détruire :
    1️⃣ IP réelle exposée sur Shodan via un favicon.
    2️⃣ SphinxQL ouvert sans auth.
    3️⃣ Secrets admin en clair dans un XML.

    Quand on gère des millions d'utilisateurs, la négligence technique se paie cash. 💸

    🎙️ Analyse technique à écouter ici :
    backslash-podcast.fr/episodes/

    #YggTorrent #OpSec #Shodan #CyberSécurité

  42. La chute d'YggTorrent : autopsie d'un suicide technique. 🏴‍☠️

    En colère contre la monétisation du site, l'attaquant "Grolum" a profité d'une config désastreuse pour tout détruire :
    1️⃣ IP réelle exposée sur Shodan via un favicon.
    2️⃣ SphinxQL ouvert sans auth.
    3️⃣ Secrets admin en clair dans un XML.

    Quand on gère des millions d'utilisateurs, la négligence technique se paie cash. 💸

    🎙️ Analyse technique à écouter ici :
    backslash-podcast.fr/episodes/

    #YggTorrent #OpSec #Shodan #CyberSécurité

  43. ----------------

    🔹 🛠️ Tool: ThreatSentry AI

    ThreatSentry AI is presented as an enterprise-focused threat-hunting platform that automates external asset discovery, enriches findings from multiple sources, and applies ensemble machine learning to prioritize risk. The project lists PyQt5 for UI, scikit-learn for ML, and SQLAlchemy for persistence, and names EclipseManic as project lead.

    🔹 Core pipeline and integrations

    The platform performs continuous external visibility via Shodan queries (preset and custom), extracts service banners across common products (examples in the project include Apache, Nginx, MySQL, IIS), and correlates banner data with NVD CVE information. CVSS-based severity classification is applied where CVE matches are found; the README notes that CVE metrics are updated only when vulnerabilities are identified to avoid data loss.

    🔹 Machine learning and scoring

    The risk engine is described as an ensemble combining Random Forest, Gradient Boosting, and Neural Network components. Models evaluate 40+ attributes spanning temporal context (exposure duration, patch lag), network position (service criticality, segmentation), behavioral signals (authentication failures, traffic anomalies), and compliance impact (data sensitivity, regulatory exposure). Each risk prediction includes a confidence score in the 0–1 range. The system is described as having configurable automatic retraining with analyst feedback integration for continuous learning.

    🔹 Platform capabilities and outputs

    ThreatSentry AI emphasizes proactive alerting and executive-ready dashboards that surface high-risk assets ahead of incidents. Preset Shodan queries are provided for common service classes (SSL, RDP, ICS/Modbus), with support for organization-specific custom queries. The architecture is described as extensible for integrating internal systems (SIEM, CMDB, patch sources) although specifics are implementation-dependent.

    🔹 Project context

    The README highlights single-developer authorship with assistance from AI development tools for code generation and documentation. The repo frames the project as addressing alert fatigue, fragmented data, and reactive security postures by converting multi-source telemetry into prioritized, confidence-scored intelligence.

    🔹 Hashtags

    🔹 ThreatSentryAI #Shodan #NVD #CVE #CVSS

    🔗 Source: github.com/EclipseManic/Threat

  44. ----------------

    🔹 🛠️ Tool: ThreatSentry AI

    ThreatSentry AI is presented as an enterprise-focused threat-hunting platform that automates external asset discovery, enriches findings from multiple sources, and applies ensemble machine learning to prioritize risk. The project lists PyQt5 for UI, scikit-learn for ML, and SQLAlchemy for persistence, and names EclipseManic as project lead.

    🔹 Core pipeline and integrations

    The platform performs continuous external visibility via Shodan queries (preset and custom), extracts service banners across common products (examples in the project include Apache, Nginx, MySQL, IIS), and correlates banner data with NVD CVE information. CVSS-based severity classification is applied where CVE matches are found; the README notes that CVE metrics are updated only when vulnerabilities are identified to avoid data loss.

    🔹 Machine learning and scoring

    The risk engine is described as an ensemble combining Random Forest, Gradient Boosting, and Neural Network components. Models evaluate 40+ attributes spanning temporal context (exposure duration, patch lag), network position (service criticality, segmentation), behavioral signals (authentication failures, traffic anomalies), and compliance impact (data sensitivity, regulatory exposure). Each risk prediction includes a confidence score in the 0–1 range. The system is described as having configurable automatic retraining with analyst feedback integration for continuous learning.

    🔹 Platform capabilities and outputs

    ThreatSentry AI emphasizes proactive alerting and executive-ready dashboards that surface high-risk assets ahead of incidents. Preset Shodan queries are provided for common service classes (SSL, RDP, ICS/Modbus), with support for organization-specific custom queries. The architecture is described as extensible for integrating internal systems (SIEM, CMDB, patch sources) although specifics are implementation-dependent.

    🔹 Project context

    The README highlights single-developer authorship with assistance from AI development tools for code generation and documentation. The repo frames the project as addressing alert fatigue, fragmented data, and reactive security postures by converting multi-source telemetry into prioritized, confidence-scored intelligence.

    🔹 Hashtags

    🔹 ThreatSentryAI #Shodan #NVD #CVE #CVSS

    🔗 Source: github.com/EclipseManic/Threat