fbpx
Wikipedia

Shodan (website)

Shodan is a search engine that lets users search for various types of servers (webcams, routers, servers, etc.) connected to the internet using a variety of filters.[1] Some have also described it as a search engine of service banners, which are metadata that the server sends back to the client.[2] This can be information about the server software, what options the service supports, a welcome message or anything else that the client can find out before interacting with the server.

Shodan
Type of site
search engine
Available inEnglish
Created byJohn Matherly
URLwww.shodan.io
RegistrationOptional
Launched2009 (2009)
Current statusActive

Shodan collects data mostly on web servers (HTTP/HTTPS – ports 80, 8080, 443, 8443), as well as FTP (port 21), SSH (port 22), Telnet (port 23), SNMP (port 161), IMAP (ports 143, or (encrypted) 993), SMTP (port 25), SIP (port 5060),[3] and Real Time Streaming Protocol (RTSP, port 554). The latter can be used to access webcams and their video streams.[4]

It was launched in 2009 by computer programmer John Matherly, who, in 2003,[5] conceived the idea of searching devices linked to the Internet.[6] The name Shodan is a reference to SHODAN, a character from the System Shock video game series.[5] Using Shodan with respect to a device the user does not own is a felony crime under the laws of some states in the United States even if no damage is done to the device or system. [7][8][9]

Background edit

The website began as Matherly's pet project, based on the fact that large numbers of devices and computer systems are connected to the Internet. Shodan has since been used to find systems including control systems for water plants, power grids and a cyclotron.[6][10]

Media coverage edit

In May 2013, CNN Money released an article detailing how Shodan can be used to find vulnerable systems on the Internet, including traffic light controls. They show screenshots of those systems, which provided the warning banner "DEATH MAY OCCUR !!!" upon connecting.[11]

In September 2013, Shodan was referenced in a Forbes article claiming it was used in order to find the security flaws in TRENDnet security cameras.[12] The next day, Forbes followed up with a second article talking about the types of things that can be found using Shodan. This included Caterpillar trucks whose onboard monitoring systems were accessible, heating and security control systems for banks, universities, and corporate giants, surveillance cameras, and fetal heart monitors.[13]

In December 2015, various news outlets, including Ars Technica, reported that a security researcher used Shodan to identify accessible MongoDB databases on thousands of systems, including one hosted by Kromtech, the developer of the macOS security tool MacKeeper.[14]

In November 2021, PCMagazine described how Shodan was used by AT&T to detect Internet of Things devices infected with malware.[15]

Usage edit

The website scans the Internet for publicly accessible devices.[16] Shodan currently returns 10 results to users without an account and 50 to those with one. If users want to remove the restriction, they are required to provide a reason and pay a fee.[10] The primary users of Shodan are cybersecurity professionals, researchers and law enforcement agencies. While cybercriminals can also use the website, some have access to botnets that could accomplish the same task without detection.[10]

References edit

  1. ^ "What Is Shodan? How to Use It & How to Stay Protected [2023]". SafetyDetectives. 2021-12-07. Retrieved 2023-04-25.
  2. ^ "What is Shodan? - Shodan Help Center". Shodan. Retrieved 11 November 2021.
  3. ^ "What is Shodan? - Shodan Help Center". Shodan. Retrieved 11 November 2021.
  4. ^ Shodan: The IoT search engine for watching sleeping kids and bedroom antics
  5. ^ a b O’Harrow Jr, Robert (June 3, 2012). "Search engine exposes industrial-sized dangers". Sydney Morning Herald. Retrieved April 10, 2013.
  6. ^ a b O’Harrow Jr, Robert (June 3, 2012). "Cyber search engine Shodan exposes industrial control systems to new risks". Washington Post. Retrieved January 9, 2020.
  7. ^ https://usalertsecurity.com/are-security-cameras-legal-oklahoma/#:~:text=Oklahoma%20statute%20%C2%A721%2D1171,a%20reasonable%20expectation%20of%20privacy.
  8. ^ 13 Okla. Stat. Sec. 13-176.3 (2022).https://law.justia.com/codes/oklahoma/2022/title-13/section-13-176-3/
  9. ^ 21 Okla. Stat. Sec. 21-1993 (2022). https://law.justia.com/codes/oklahoma/2022/title-21/section-21-1993/
  10. ^ a b c Goldman, David (April 8, 2013). "Shodan: The scariest search engine on the Internet". CNN Money. Retrieved April 8, 2013.
  11. ^ Goldman, David (May 2, 2013). "Shodan finds the Internet's most dangerous spots". CNN Money. Retrieved June 21, 2013.
  12. ^ Hill, Kashmir. "Camera Company That Let Hackers Spy On Naked Customers Ordered By FTC To Get Its Security Act Together". Forbes. Retrieved 2013-10-17.
  13. ^ Hill, Kashmir. "The Crazy Things A Savvy Shodan Searcher Can Find Exposed On The Internet". Forbes. Retrieved 2013-10-17.
  14. ^ Degeler, Andrii (15 December 2015). "13 million MacKeeper users exposed after MongoDB door was left open".
  15. ^ Mott, Nathaniel. "AT&T Reveals Malware Targeting Millions of Routers, IoT Devices".
  16. ^ Brinkmann, Martin (April 9, 2013). "Shodan, a search engine for vulnerable Internet devices". ghacks.net. Retrieved April 9, 2013.

External links edit

  • Official website  

shodan, website, this, article, about, search, engine, other, uses, shodan, disambiguation, shodan, search, engine, that, lets, users, search, various, types, servers, webcams, routers, servers, connected, internet, using, variety, filters, some, have, also, d. This article is about the search engine For other uses see Shodan disambiguation Shodan is a search engine that lets users search for various types of servers webcams routers servers etc connected to the internet using a variety of filters 1 Some have also described it as a search engine of service banners which are metadata that the server sends back to the client 2 This can be information about the server software what options the service supports a welcome message or anything else that the client can find out before interacting with the server ShodanType of sitesearch engineAvailable inEnglishCreated byJohn MatherlyURLwww wbr shodan wbr ioRegistrationOptionalLaunched2009 2009 Current statusActiveThis article needs to be updated Please help update this article to reflect recent events or newly available information October 2022 Shodan collects data mostly on web servers HTTP HTTPS ports 80 8080 443 8443 as well as FTP port 21 SSH port 22 Telnet port 23 SNMP port 161 IMAP ports 143 or encrypted 993 SMTP port 25 SIP port 5060 3 and Real Time Streaming Protocol RTSP port 554 The latter can be used to access webcams and their video streams 4 It was launched in 2009 by computer programmer John Matherly who in 2003 5 conceived the idea of searching devices linked to the Internet 6 The name Shodan is a reference to SHODAN a character from the System Shock video game series 5 Using Shodan with respect to a device the user does not own is a felony crime under the laws of some states in the United States even if no damage is done to the device or system 7 8 9 Contents 1 Background 2 Media coverage 3 Usage 4 References 5 External linksBackground editThe website began as Matherly s pet project based on the fact that large numbers of devices and computer systems are connected to the Internet Shodan has since been used to find systems including control systems for water plants power grids and a cyclotron 6 10 Media coverage editIn May 2013 CNN Money released an article detailing how Shodan can be used to find vulnerable systems on the Internet including traffic light controls They show screenshots of those systems which provided the warning banner DEATH MAY OCCUR upon connecting 11 In September 2013 Shodan was referenced in a Forbes article claiming it was used in order to find the security flaws in TRENDnet security cameras 12 The next day Forbes followed up with a second article talking about the types of things that can be found using Shodan This included Caterpillar trucks whose onboard monitoring systems were accessible heating and security control systems for banks universities and corporate giants surveillance cameras and fetal heart monitors 13 In December 2015 various news outlets including Ars Technica reported that a security researcher used Shodan to identify accessible MongoDB databases on thousands of systems including one hosted by Kromtech the developer of the macOS security tool MacKeeper 14 In November 2021 PCMagazine described how Shodan was used by AT amp T to detect Internet of Things devices infected with malware 15 Usage editThe website scans the Internet for publicly accessible devices 16 Shodan currently returns 10 results to users without an account and 50 to those with one If users want to remove the restriction they are required to provide a reason and pay a fee 10 The primary users of Shodan are cybersecurity professionals researchers and law enforcement agencies While cybercriminals can also use the website some have access to botnets that could accomplish the same task without detection 10 References edit What Is Shodan How to Use It amp How to Stay Protected 2023 SafetyDetectives 2021 12 07 Retrieved 2023 04 25 What is Shodan Shodan Help Center Shodan Retrieved 11 November 2021 What is Shodan Shodan Help Center Shodan Retrieved 11 November 2021 Shodan The IoT search engine for watching sleeping kids and bedroom antics a b O Harrow Jr Robert June 3 2012 Search engine exposes industrial sized dangers Sydney Morning Herald Retrieved April 10 2013 a b O Harrow Jr Robert June 3 2012 Cyber search engine Shodan exposes industrial control systems to new risks Washington Post Retrieved January 9 2020 https usalertsecurity com are security cameras legal oklahoma text Oklahoma 20statute 20 C2 A721 2D1171 a 20reasonable 20expectation 20of 20privacy 13 Okla Stat Sec 13 176 3 2022 https law justia com codes oklahoma 2022 title 13 section 13 176 3 21 Okla Stat Sec 21 1993 2022 https law justia com codes oklahoma 2022 title 21 section 21 1993 a b c Goldman David April 8 2013 Shodan The scariest search engine on the Internet CNN Money Retrieved April 8 2013 Goldman David May 2 2013 Shodan finds the Internet s most dangerous spots CNN Money Retrieved June 21 2013 Hill Kashmir Camera Company That Let Hackers Spy On Naked Customers Ordered By FTC To Get Its Security Act Together Forbes Retrieved 2013 10 17 Hill Kashmir The Crazy Things A Savvy Shodan Searcher Can Find Exposed On The Internet Forbes Retrieved 2013 10 17 Degeler Andrii 15 December 2015 13 million MacKeeper users exposed after MongoDB door was left open Mott Nathaniel AT amp T Reveals Malware Targeting Millions of Routers IoT Devices Brinkmann Martin April 9 2013 Shodan a search engine for vulnerable Internet devices ghacks net Retrieved April 9 2013 External links editOfficial website nbsp Retrieved from https en wikipedia org w index php title Shodan website amp oldid 1183818017, wikipedia, wiki, book, books, library,

article

, read, download, free, free download, mp3, video, mp4, 3gp, jpg, jpeg, gif, png, picture, music, song, movie, book, game, games.