Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
shodan — Shodan Dork查询 | Kitploit
工具/GitHubGitHub/lothos612/shodan
OSINT (开源情报)侦察物联网安全网络映射漏洞分析SCADA/ICS安全信息收集Web安全精选资源数据库安全
GitHublothos612/shodan

shodan

Shodan Dork查询

5861063年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
查看仓库

Shodan 搜索技巧 by twitter.com/lothos612

欢迎提出建议

Shodan 搜索技巧

基础 Shodan 过滤器

city:

查找特定城市的设备。 city:"Bangalore"

country:

查找特定国家的设备。 country:"IN"

geo:

通过指定地理坐标查找设备。 geo:"56.913055,118.250862"

位置

country:us country:ru country:de city:chicago

hostname:

查找匹配主机名的设备。 server: "gws" hostname:"google" hostname:example.com -hostname:subdomain.example.com hostname:example.com,example.org

net:

基于 IP 地址或 /x CIDR 查找设备。 net:210.214.0.0/16

组织

org:microsoft org:"United States Department"

自治系统号 (ASN)

asn:ASxxxx

os:

基于操作系统查找设备。 os:"windows 7"

port:

基于开放端口查找设备。 proftpd port:21

before/after:

查找指定时间之前或之后的设备。 apache after:22/02/2009 before:14/3/2010

SSL/TLS 证书

自签名证书 ssl.cert.issuer.cn:example.com ssl.cert.subject.cn:example.com

过期证书 ssl.cert.expired:true

ssl.cert.subject.cn:example.com

设备类型

device:firewall device:router device:wap device:webcam device:media device:"broadband router" device:pbx device:printer device:switch device:storage device:specialized device:phone device:"voip" device:"voip phone" device:"voip adaptor"

操作系统

os:"windows 7" os:"windows server 2012" os:"linux 3.x"

产品

product:apache product:nginx product:android product:chromecast

客户驻地设备 (CPE)

cpe:apple cpe:microsoft cpe:nginx cpe:cisco

服务器

server: nginx server: apache server: microsoft server: cisco-ios

SSH 指纹

dc:14:de:8e:d7:c1:15:43:23:82:25:81:d2:59:e8:c0

Web

Pulse Secure

http.html:/dana-na

PEM 证书

http.title:"Index of /" http.html:".pem"

Tor / 暗网站点

onion-location

数据库

MySQL

"product:MySQL" mysql port:"3306"

MongoDB

"product:MongoDB" mongodb port:27017

完全开放的 MongoDB

"MongoDB Server Information { "metrics":" "Set-Cookie: mongo-express=" "200 OK" "MongoDB Server Information" port:27017 -authentication

无身份验证的 Kibana 仪表盘

kibana content-legth:217

Elastic

port:9200 json port:"9200" all:elastic port:"9200" all:"elastic indices"

Memcached

"product:Memcached"

CouchDB

"product:CouchDB" port:"5984"+Server: "CouchDB/2.1.0"

PostgreSQL

"port:5432 PostgreSQL"

Riak

"port:8087 Riak"

Redis

"product:Redis"

Cassandra

"product:Cassandra"

工业控制系统

三星电子广告牌

"Server: Prismview Player"

加油站油泵控制器

"in-tank inventory" port:10001

联网的燃油泵:

无需身份验证即可访问 CLI 终端。 "privileged command" GET

自动车牌识别器

P372 "ANPR enabled"

交通灯控制器 / 闯红灯摄像头

mikrotik streetlight

美国投票机

"voter system serial" country:US

开放的 ATM:

可能允许 ATM 访问权限 NCR Port:"161"

运行 Cisco 合法拦截窃听的电信运营商

"Cisco IOS" "ADVIPSERVICESK9_LI-M"

监狱付费电话

"[2J[H Encartele Confidential"

Tesla PowerPack 充电状态

http.title:"Tesla PowerPack System" http.component:"d3" -ga3ca4f2

电动汽车充电器

"Server: gSOAP/2.8" "Content-Length: 583"

海事卫星

Shodan 还制作了一个很棒的船舶追踪器,可以实时显示船舶位置!

"Cobham SATCOM" OR ("Sailor" "VSAT")

潜艇任务控制仪表盘

title:"Slocum Fleet Mission Control"

CAREL PlantVisor 制冷机组

"Server: CarelDataServer" "200 Document follows"

Nordex 风力发电场

http.title:"Nordex Control" "Windows 2000 5.0 x86" "Jetty/3.1 (JSP 1.1; Servlet 2.2; java 1.6.0_14)"

C4 Max 商用车辆 GPS 追踪器

"[1m[35mWelcome on console"

DICOM 医用 X 光机

默认有安全保护,但仍有 1700+ 台设备不该暴露在互联网上。

"DICOM Server Response" port:104

GaugeTech 电表

"Server: EIG Embedded Web Server" "200 Document follows"

西门子工业自动化

"Siemens, SIMATIC" port:161

西门子 HVAC 控制器

"Server: Microsoft-WinCE" "Content-Length: 12581"

门禁控制器

"HID VertX" port:4070

铁路管理系统

"log off" "select the appropriate"

Tesla Powerpack 充电状态:

帮助查找 Tesla Powerpack 的充电状态。 http.title:"Tesla PowerPack System" http.component:"d3" -ga3ca4f2

XZERES 风力涡轮机

title:"xzeres wind"

PIPS 自动车牌识别器

"html:"PIPS Technology ALPR Processors""

Modbus

"port:502"

Niagara Fox

"port:1911,4911 product:Niagara"

GE-SRTP

"port:18245,18246 product:"general electric""

MELSEC-Q

"port:5006,5007 product:mitsubishi"

CODESYS

"port:2455 operating system"

S7

"port:102"

BACnet

"port:47808"

HART-IP

"port:5094 hart-ip"

Omron FINS

"port:9600 response code"

IEC 60870-5-104

"port:2404 asdu address"

DNP3

"port:20000 source address"

EtherNet/IP

"port:44818"

PCWorx

"port:1962 PLC"

Crimson v3.0

"port:789 product:"Red Lion Controls"

ProConOS

"port:20547 PLC"

远程桌面

未受保护的 VNC

"authentication disabled" port:5900,5901 "authentication disabled" "RFB 003.008"

Windows RDP

99.99% 由 Windows 二级登录屏幕保护。

"\x03\x00\x00\x0b\x06\xd0\x00\x00\x124\x00"

C2 基础设施

CobaltStrike 服务器

product:"cobalt strike team server" product:"Cobalt Strike Beacon" ssl.cert.serial:146473198 - 默认证书序列号 ssl.jarm:07d14d16d21d21d07c42d41d00041d24a458a375eef0c576d23a7bab9a9fb1 ssl:foren.zik

Brute Ratel

http.html_hash:-1957161625 product:"Brute Ratel C4"

Covenant

ssl:”Covenant” http.component:”Blazor”

Metasploit

ssl:"MetasploitSelfSignedCA"

网络基础设施

被黑的路由器:

已遭入侵的路由器 hacked-router-help-sos

Redis 开放实例

product:"Redis key-value store"

Citrix:

查找 Citrix Gateway。 title:"citrix gateway"

Weave Scope 仪表盘

可访问 Kubernetes Pod 和 Docker 容器内的命令行,并实时可视化/监控整个基础设施。

title:"Weave Scope" http.favicon.hash:567176827

Jenkins CI

"X-Jenkins" "Set-Cookie: JSESSIONID" http.title:"Dashboard"

Jenkins:

Jenkins 无限制仪表盘 x-jenkins 200

Docker API

"Docker Containers:" port:2375

Docker 私有仓库

"Docker-Distribution-Api-Version: registry" "200 OK" -gitlab

Pi-hole 开放 DNS 服务器

"dnsmasq-pi-hole" "Recursion: enabled"

启用递归的 DNS 服务器

"port: 53" Recursion: Enabled

已通过 Telnet 以 root 登录

"root@" port:23 -login -password -name -Session

Telnet 访问:

无需密码即可进行 Telnet 访问。 port:23 console gateway

Polycom 视频会议系统免验证 Shell

"polycom command shell"

NPort 串口转以太网 / MoCA 设备(无密码)

nport -keyin port:23

Android Root 桥

这是 Google 碎片化更新方式的附带结果。🙄 更多信息请点击这里。

"Android Debug Bridge" "Device" port:5555

Lantronix 串口转以太网适配器泄露 Telnet 密码

Lantronix password port:30718 -secured

Citrix 虚拟应用

"Citrix Applications:" port:1604

Cisco Smart Install

存在漏洞(设计上就如此,暴露后尤其危险)。

"smart install client active"

PBX IP 电话网关

PBX "gateway console" -password port:23

Polycom 视频会议

http.title:"- Polycom" "Server: lighttpd" "Polycom Command Shell" -failed port:23

Telnet 配置:

"Polycom Command Shell" -failed port:23

示例:Polycom 视频会议

Bomgar 帮助台门户

"Server: Bomgar" "200 OK"

Intel 主动管理技术 CVE-2017-5689

"Intel(R) Active Management Technology" port:623,664,16992,16993,16994,16995 ”Active Management Technology”

HP iLO 4 CVE-2017-12542

HP-ILO-4 !"HP-ILO-4/2.53" !"HP-ILO-4/2.54" !"HP-ILO-4/2.55" !"HP-ILO-4/2.60" !"HP-ILO-4/2.61" !"HP-ILO-4/2.62" !"HP-iLO-4/2.70" port:1900

Lantronix 以太网适配器管理界面(无密码)

"Press Enter for Setup Mode port:9999"

WiFi 密码:

帮助在 Shodan 中找到明文 WiFi 密码。 html:"def_wirelesspassword"

配置错误的 WordPress 站点:

如果访问 wp-config.php 可能泄露数据库凭据。 http.html:"* The wp-config.php creation script uses this file"

Outlook Web Access:

Exchange 2007

"x-owa-version" "IE=EmulateIE7" "Server: Microsoft-IIS/7.0"

Exchange 2010

"x-owa-version" "IE=EmulateIE7" http.favicon.hash:442749392

Exchange 2013 / 2016

"X-AspNet-Version" http.title:"Outlook" -"x-owa-version"

Lync / Skype for Business

"X-MS-Server-Fqdn"

网络附加存储 (NAS)

SMB (Samba) 文件共享

产生约 500,000 个结果...可通过添加 "Documents" 或 "Videos" 等缩小范围。

"Authentication: disabled" port:445

特指域控制器:

"Authentication: disabled" NETLOGON SYSVOL -unix port:445

QuickBooks 文件的默认网络共享:

"Authentication: disabled" "Shared this folder to access QuickBooks files OverNetwork" -unix port:445

允许匿名登录的 FTP 服务器

"220" "230 Login successful." port:21

Iomega / LenovoEMC NAS 驱动器

"Set-Cookie: iomega=" -"manage/login.html" -http.title:"Log In"

Buffalo TeraStation NAS 驱动器

Redirecting sencha port:9000

Logitech 媒体服务器

"Server: Logitech Media Server" "200 OK"

示例:Logitech 媒体服务器

Plex 媒体服务器

"X-Plex-Protocol" "200 OK" port:32400

Tautulli / PlexPy 仪表盘

"CherryPy/5.1.0" "/home"

家用路由器连接的 USB

"IPC$ all storage devices"

网络摄像头

通用摄像头搜索

title:camera

带截图的网络摄像头

webcam has_screenshot:true

D-Link 网络摄像头

"d-Link Internet Camera, 200 OK"

Hipcam

"Hipcam RealServer/V1.0"

Yawcams

"Server: yawcam" "Mime-Type: text/html"

webcamXP/webcam7

("webcam 7" OR "webcamXP") http.component:"mootools" -401

Android IP 网络摄像头服务器

"Server: IP Webcam Server" "200 OK"

安全 DVR

html:"DVR_H264 ActiveX"

监控摄像头:

使用用户名 admin 和密码 :P NETSurveillance uc-httpd Server: uc-httpd 1.0.0

打印机和复印机:

HP 打印机

"Serial Number:" "Built:" "Server: HP HTTP"

Xerox 复印机/打印机

ssl:"Xerox Generic Root"

Epson 打印机

"SERVER: EPSON_Linux UPnP" "200 OK"

"Server: EPSON-HTTP" "200 OK"

Canon 打印机

"Server: KS_HTTP" "200 OK"

"Server: CANON HTTP Server"

家用设备

Yamaha 立体声音响

"Server: AV_Receiver" "HTTP/1.1 406"

Apple AirPlay 接收器

Apple TV、HomePod 等。

"\x08_airplay" port:5353

Chromecast / 智能电视

"Chromecast:" port:8008

Crestron 智能家居控制器

"Model: PYNG-HUB"

随机内容

Calibre 图书馆

"Server: calibre" http.status:200 http.title:calibre

OctoPrint 3D 打印机控制器

title:"OctoPrint" -title:"Login" http.favicon.hash:1307375944

以太坊矿机

"ETH - Total speed"

Apache 目录列表

将 .pem 替换为任意扩展名或文件名,如 phpinfo.php。

http.title:"Index of /" http.html:".pem"

配置错误的 WordPress

暴露 wp-config.php 文件,包含数据库凭据。

http.html:"* The wp-config.php creation script uses this file"

太多的 Minecraft 服务器

"Minecraft Server" "protocol 340" port:25565

朝鲜的所有设备

net:175.45.176.0/22,210.52.109.0/24,77.94.35.0/24

下载工具
device:"load balancer"
device:"print server"
device:terminal
device:remote
device:telecom
device:power
device:proxy
device:pda
device:bridge