*cybersnippets
Dorks for shodan.io website. Taken from publicly available sources.
Shodan is a search engine that lets the user find specific types of computers (webcams, routers, servers, etc.) connected to the internet using a variety of filters.
Find devices in a particular city.
city:"Bangalore"
Find devices in a particular country.
country:"IN"
Find devices by giving geographical coordinates.
geo:"56.913055,118.250862"
Find devices matching the hostname.
server: "gws" hostname:"google"
Find devices based on an IP address or /x CIDR.
net:210.214.0.0/16
Find devices based on operating system.
os:"windows 7"
Find devices based on open ports.
proftpd port:21
Find devices before or after between a given time.
apache after:22/02/2009 before:14/3/2010
Find Citrix Gateway.
title:"citrix gateway"
Helps to find the cleartext wifi passwords in Shodan.
html:"def_wirelesspassword"
With username:admin and password: :P
NETSurveillance uc-httpd
No auth required to access CLI terminal.
"privileged command" GET
But may contain secondary windows auth
"\x03\x00\x00\x0b\x06\xd0\x00\x00\x124\x00"
It may give info about mongo db servers and dashboard
"MongoDB Server Information" port:27017 -authentication
Complete Anon access
"220" "230 Login successful." port:21
Jenkins Unrestricted Dashboard
x-jenkins 200
Routers which got compromised
hacked-router-help-sos
May allow for ATM Access availability
NCR Port:"161"
NO password required for telnet access.
port:23 console gateway
The wp-config.php if accessed can give out the database credentials.
http.html:"* The wp-config.php creation script uses this file"
Find sites hiring.
"X-Recruiting:"
Find android root bridges with port 5555.
"Android Debug Bridge" "Device" port:5555
Shows the miners running ETH.
"ETH - Total speed"
Helps to find the charging status of tesla powerpack.
http.title:"Tesla PowerPack System" http.component:"d3" -ga3ca4f2
"default password"
os:windows port:3389 has_screenshot:yes
country:gb city:london product:MySQL
org:google ssl.cert.expired:true
"authentication disabled" "RFB 003.008"
anonymous@ login ok. port:"21"
port:"445" Authentication: "disabled"
"Authentication: disabled" NETLOGON SYSVOL -unix port:445
"This feature requires the one-time use of the username "cisco" with the password "cisco""
"Serial Number:" "Built:" "Server: HP HTTP"
"SERVER: EPSON_Linux UPnP" "200 OK" "Server: EPSON-HTTP" "200 OK
Please create a pull request if you want to contribute.
device:firewall device:router device:wap device:webcam device:media device:"broadband router" device:pbx device:printer device:switch device:storage device:specialized device:phone device:"voip" device:"voip phone" device:"voip adaptor" device:"load balancer" device:"print server" device:terminal device:remote device:telecom device:power device:proxy device:pda device:bridge