
Memcrashed-DDoS-Exploit
DDoS attack tool for sending forged UDP packets to vulnerable Memcached servers obtained using Shodan API

DDoS attack tool for sending forged UDP packets to vulnerable Memcached servers obtained using Shodan API

Selenium powered Python script to automate searching for vulnerable web apps.

A typical search engine dork scanner scrapes search engines with dorks that you provide in order to find vulnerable URLs.

FireShodanMap is a Realtime map that integrates Firebase, Google Maps and Shodan. A search is carried out using Shodan searching vulnerable devices…

Automated Google dork scanner that fetches exploit-db dork lists and scans targets or the entire internet for vulnerable applications, secret files,…

Exploit for CVE-2018-20555: automated discovery and takeover of Twitter accounts via leaked API keys in vulnerable Social Network Tabs WordPress…

HASSH fingerprints for identifying OpenSSH servers potentially vulnerable to CVE-2024-6387 (regreSSHion).

Identify vulnerable (RCE) vBulletin 5.0.0 - 5.5.4 instances using Shodan (CVE-2019-16759)

Search vulnerable FortiOS devices via Shodan (CVE-2023-27997)

This is a python script that can be used with Shodan CLI to mass hunting Confluence Servers vulnerable to CVE-2022-26134

L1 SOC Analysis: OSINT detection and risk validation of publicly exposed MikroTik RouterOS vulnerable to RCE | Tools: Shodan, NIST NVD

Proof-of-concept exploit for CVE-2024-4577 with Shodan integration for automated discovery of vulnerable targets on the internet.

Gather a list of Citrix appliances in a country / state pair, and check if they're vulnerable to CVE-2019-19781

Exploit for CVE-2017-5487 to enumerate WordPress user accounts via the REST API, extracting sensitive information from vulnerable 4.7 installations.

Python script that uses Shodan to discover Apache HTTP Server 2.4.49 instances vulnerable to CVE-2021-41773 path traversal and file disclosure.

Web scanner that detects CMS versions, plugins, vulnerable JavaScript libraries, email addresses, and phone numbers on target websites, scoring…

pagodo (Passive Google Dork) - Automate Google Hacking Database scraping and searching

Enumerate valid users on Office 365 and Exchange via time-based and error-based techniques across multiple exposed services, including OWA,…