SHODAN
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Interactive tool: Google Dork Builder
Search engine for internet-connected devices. Indexes banners, services, ports, and metadata across the entire IPv4 space.
ACCOUNT & API#
# API key (required for most features) # Free account: limited searches, 1 query credit/month # Membership ($49 one-time): unlimited searches, 100 credits/month # API key location: https://account.shodan.io # API info curl "https://api.shodan.io/api-info?key=YOUR_API_KEY"
CLI INSTALLATION#
pip install shodan shodan init YOUR_API_KEY
CLI COMMANDS#
shodan search "apache" # Basic search shodan search "apache" --fields ip_str,port,org # Specific fields shodan count "apache country:US" # Count results shodan host 1.2.3.4 # Host info shodan stats --facets country "apache" # Faceted stats shodan download results "apache country:DE" # Download results shodan parse results.json.gz # Parse downloaded data shodan scan submit 1.2.3.4 # On-demand scan (credits) shodan scan submit --filename targets.txt # Scan from file shodan myip # Your public IP shodan domain example.com # Domain info shodan info # Account info/credits shodan honeyscore 1.2.3.4 # Honeypot probability shodan alert create "My Network" 1.2.3.0/24 # Create monitor alert shodan alert list # List alerts shodan alert triggers # Available triggers shodan alert enable ALERT_ID trigger_name # Enable trigger shodan stream # Real-time stream (firehose) shodan radar # Real-time map in terminal
BASIC SEARCH FILTERS#
# By service/product product:"Apache httpd" product:"nginx" product:"Microsoft IIS" product:"OpenSSH" product:"MySQL" # By port port:22 # SSH port:80 # HTTP port:443 # HTTPS port:3389 # RDP port:21 # FTP port:3306 # MySQL port:5432 # PostgreSQL port:27017 # MongoDB port:6379 # Redis port:9200 # Elasticsearch port:5900 # VNC port:1883 # MQTT port:502 # Modbus (ICS) port:47808 # BACnet (ICS) port:2404 # IEC 60870-5-104 (ICS) port:20000 # DNP3 (ICS) # By country/city/region country:"US" country:"DE" city:"Berlin" state:"California" geo:"48.8566,2.3522,100" # Lat,Lon,Radius(km) # By organization/ISP/ASN org:"Google" org:"Amazon" isp:"Comcast" asn:"AS15169" # By hostname/domain hostname:"example.com" hostname:".gov" hostname:".edu" # By operating system os:"Windows Server 2019" os:"Linux" os:"Ubuntu" # By version version:"7.4" # By network net:"192.168.0.0/16" net:"10.0.0.0/8" # By SSL/TLS ssl:"example.com" # SSL cert matches ssl.cert.subject.cn:"example.com" # Common name ssl.cert.issuer.o:"Let's Encrypt" # Issuer org ssl.cert.expired:true # Expired certs ssl.cert.serial:1234567890 # Serial number ssl.version:"sslv3" # Insecure version ssl.version:"tlsv1" # TLS 1.0 has_ssl:true # Has SSL/TLS # By HTTP http.title:"Dashboard" http.title:"login" http.status:200 http.status:401 http.component:"WordPress" http.component:"jQuery" http.html:"password" http.favicon.hash:116323821 # Favicon hash # By vulnerability vuln:"CVE-2021-44228" # Log4Shell vuln:"CVE-2019-0708" # BlueKeep vuln:"CVE-2017-0144" # EternalBlue has_vuln:true # Any known vuln # By screenshot has_screenshot:true screenshot.label:"login" # Before/after date before:"01/01/2024" after:"01/06/2024"
COMBINING FILTERS#
# AND (space-separated, implicit) apache country:"US" port:80 # Negative filter (exclude) apache -country:"US" port:22 -product:"OpenSSH" # OR is NOT supported in Shodan syntax # Use multiple queries or the API instead
COMMON SEARCH QUERIES#
# Exposed databases product:"MongoDB" -authentication product:"Redis" -authentication product:"Elasticsearch" port:9200 product:"CouchDB" port:5984 port:5432 "PostgreSQL" "no password" # Default credentials / admin panels http.title:"Dashboard" http.status:200 http.title:"admin" http.status:200 http.title:"phpMyAdmin" http.title:"Kibana" http.title:"Grafana" http.title:"Jenkins" "default password" port:80 # Webcams / IoT has_screenshot:true port:554 # RTSP cameras http.title:"webcamXP" http.title:"IP Camera" product:"Hikvision" "Server: yawcam" "Server: webcam" # Industrial Control Systems (ICS/SCADA) tag:"ics" port:502 "Modbus" port:47808 "BACnet" port:20000 "DNP3" port:44818 "EtherNet/IP" "Siemens" port:102 "Schneider Electric" "Rockwell Automation" # Network infrastructure product:"Cisco IOS" product:"MikroTik" "Server: Netgear" http.title:"RouterOS" "Fortinet" port:443 "SonicWall" port:443 "pfSense" "Ubiquiti" port:443 # VPN / Remote access product:"OpenVPN" "Citrix" http.title:"NetScaler" http.title:"Pulse Secure" http.title:"GlobalProtect" product:"Fortinet SSL VPN" # Email servers product:"Microsoft Exchange" "X-OWA-Version" product:"Postfix" product:"Dovecot" # Vulnerable services vuln:"CVE-2021-44228" product:"Apache" # Log4Shell vuln:"CVE-2021-34473" # ProxyShell vuln:"CVE-2023-34362" # MOVEit ssl.version:"sslv3" # POODLE vulnerable ssl.version:"tlsv1" # TLS 1.0 (deprecated) "X-Powered-By: PHP/5" # Old PHP # Cloud / misconfig org:"Amazon" port:9200 # AWS Elasticsearch org:"Microsoft Azure" port:3389 # Azure RDP org:"Google Cloud" port:22 # GCP SSH http.title:"Index of /" # Directory listing
PYTHON API#
import shodan
api = shodan.Shodan('YOUR_API_KEY')
# Search
results = api.search('apache country:US')
for result in results['matches']:
print(f"{result['ip_str']}:{result['port']}")
print(result['data'])
# Host info
host = api.host('1.2.3.4')
print(host['os'])
print(host['ports'])
for item in host['data']:
print(f"Port: {item['port']}, Banner: {item['data'][:100]}")
# Count
count = api.count('apache')
print(f"Total: {count['total']}")
# Search with facets
results = api.search('apache', facets=[('country', 10)])
for facet in results['facets']['country']:
print(f"{facet['value']}: {facet['count']}")
# Network alerts
alert = api.create_alert('My Alert', '1.2.3.0/24')
triggers = api.alert_triggers()
# Scan
scan = api.scan(['1.2.3.4'])
# DNS lookup
dns = api.dns.resolve(['google.com', 'example.com'])
reverse = api.dns.reverse(['8.8.8.8'])
# Exploits API
exploits = api.exploits.search('apache')
FAVICON HASH SEARCH#
# Calculate favicon hash for finding specific web apps
import mmh3, requests, codecs
response = requests.get('https://target.com/favicon.ico')
favicon = codecs.encode(response.content, 'base64')
hash = mmh3.hash(favicon)
print(f"http.favicon.hash:{hash}")
# Common favicon hashes
http.favicon.hash:116323821 # Cobalt Strike (default)
http.favicon.hash:-1137190734 # Spring Boot
http.favicon.hash:81586312 # Jenkins
http.favicon.hash:1485257654 # Laravel
SHODAN MONITOR#
# Real-time monitoring of your assets shodan alert create "Corp Network" 10.0.0.0/8 shodan alert enable ALERT_ID new_service shodan alert enable ALERT_ID open_database shodan alert enable ALERT_ID vulnerable shodan alert enable ALERT_ID ssl_expired shodan alert enable ALERT_ID internet_scanner # Notification integrations: email, Slack, webhook, PagerDuty
SHODAN MAPS & IMAGES#
# Shodan Maps: https://maps.shodan.io # Visual search with geographic display # Shodan Images: https://images.shodan.io # Browse screenshots of services (RDP, VNC, webcams)
TIPS#
- Use quotes for exact multi-word matches - Combine filters for precision (product + country + port) - Favicon hash is powerful for finding specific applications - has_screenshot:true reveals visual services (RDP, VNC, web) - Monitor your own org with alerts for exposure detection - Free tier is limited; membership unlocks full search - vuln: filter requires membership or higher - Use download + parse for bulk analysis - SSL cert searches find related infrastructure - Check ssl.cert.expired:true for low-hanging fruit