Jump to content

Shodan Safari, where hackers heckle the worst devices put on the internet


NelsonG

Recommended Posts

If you leave something on the internet long enough, someone will hack it.

The reality is that many device manufacturers make it far too easy by using default passwords that are widely documented, allowing anyone to log in as “admin” and snoop around. Often, there’s no password at all.

Enter “Shodan Safari,” a popular part-game, part-expression of catharsis, where hackers tweet and share their worst finds on Shodan, a search engine for exposed devices and databases popular with security researchers. Almost anything that connects to the internet gets scraped and tagged in Shodan’s vast search engine — including what the device does and internet ports are open, which helps Shodan understand what the device is. If a particular port is open, it could be a webcam. If certain header comes back, it’s backend might be viewable in the browser.

Think of Shodan Safari as internet dumpster diving.

From cameras to routers, hospital CT scanners to airport explosive detector units, you’d be amazed — and depressed — at what you can find exposed on the open internet.

Like a toilet, or prized pot plant, or — as we see below — someone’s actual goat.

The reality is that Shodan scares people — and it should. It’s a window into the world of absolute insecurity. It’s not just exposed devices but databases — storing anything from two-factor codes to your voter records, and where you’re going to the gym tonight. But devices take up the bulk of what’s out there. Exposed CCTV cameras, license plate readers, sex toys, and smart home appliances. If it’s out there and exposed, it’s probably on Shodan.

If there’s ever a lesson to device makers, not everything has to be connected to the internet.

Here’s some of the worst things we’ve found so far. (And here’s where to send your best finds.)

ac-unit.jpeg

An office air conditioning controller. (Screenshot: Shodan)

 

airport.jpg

A weather station monitor at an airport in Alabama. (Screenshot: Shodan)

 

bank.jpeg

A web-based financial system at a co-operative credit bank in India. (Screenshot: Shodan)

 

beef.jpeg

For some reason, a beef factory. (Screenshot: Shodan)

 

bells.jpeg

An electric music carillon near St. Louis. used for making church bell melodies. (Screenshot: Shodan)

 

biogas.jpeg

A bio-gas production and refinery plant in Italy. (Screenshot: Shodan)

 

birb.jpg

A bird. Just a bird. (Screenshot: Shodan via @Joshbal4)

 

brewery.jpeg

A brewery in Los Angeles. (Screenshot: Shodan)

 

cinema.jpg

The back end of a cinema’s projector system. Many simply run Windows. (Screenshot: Shodan via @tacticalmaid)

 

engine-room.jpeg

The engine room of a Dutch fishing boat. (Screenshot: Shodan)

 

explosives.jpeg

An explosive residue detector at Heathrow Airport’s Terminal 3. (Screenshot: TechCrunch)

 

fishtank.jpeg

A fish tank water control and temperature monitor. (Screenshot: Shodan)

 

flowers.jpeg

A climate control system for a flower store in Colorado Springs. (Screenshot: Shodan)

 

tesla.jpeg

The web interface for a Tesla PowerPack. (Screenshot: Shodan via @xd4rker)

 

instagram.jpeg

An Instagram auto-follow bot.(Screenshot: Shodan)

 

pharmacy.jpeg

A terminal used by a pharmacist. (Screenshot: Shodan)

 

phils-bbq.jpeg

A controller for video displays and speakers at a Phil’s BBQ restaurant in Texas. (Screenshot: Shodan)

 

printingpress.jpeg

A Kodak Lotem printing press. (Screenshot: Shodan)

 

rickroll.jpeg

Someone’s already hacked lawn sprinkler system. Yes, that’s Rick Astley. (Screenshot: Shodan)

 

sulfur.jpeg

A sulfur dioxide detector. (Screenshot: Shodan)

 

therapy.jpeg

An internet-connected knee recovery machine. (Screenshot: Shodan)

 

windows-xp.jpeg

Somehow, a really old version of Windows XP still in existence. (Screenshot: Shodan)

 

workout.jpeg

Someone’s workout machine. (Screenshot: Shodan)

Techcrunch?d=2mJPEYqXBVI Techcrunch?d=7Q72WNTAKBA Techcrunch?d=yIl2AUoC8zA Techcrunch?i=BLr2jz1Stl4:rVfIwiEEfLM:-BT Techcrunch?i=BLr2jz1Stl4:rVfIwiEEfLM:D7D Techcrunch?d=qj6IDK7rITs
BLr2jz1Stl4

View the full article

Link to comment
Share on other sites

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Our picks

    • Wait, Burning Man is going online-only? What does that even look like?
      You could have been forgiven for missing the announcement that actual physical Burning Man has been canceled for this year, if not next. Firstly, the nonprofit Burning Man organization, known affectionately to insiders as the Borg, posted it after 5 p.m. PT Friday. That, even in the COVID-19 era, is the traditional time to push out news when you don't want much media attention. 
      But secondly, you may have missed its cancellation because the Borg is being careful not to use the C-word. The announcement was neutrally titled "The Burning Man Multiverse in 2020." Even as it offers refunds to early ticket buyers, considers layoffs and other belt-tightening measures, and can't even commit to a physical event in 2021, the Borg is making lemonade by focusing on an online-only version of Black Rock City this coming August.    Read more...
      More about Burning Man, Tech, Web Culture, and Live EventsView the full article
      • 0 replies
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
×
×
  • Create New...