daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

shodan.md (20790B)


      1 ---
      2 title: "Shodan"
      3 description: "Shodan search filters, dorks, CLI and API workflows for internet-wide asset and service discovery."
      4 category: enumeration
      5 tags: [enumeration, osint, recon]
      6 tools: [Shodan]
      7 difficulty: intermediate
      8 updated: "2026-08-09"
      9 source: "repo:Enumeration/Shodan_Cheatsheet.md"
     10 ---
     11 
     12 # Shodan
     13 
     14 **Shodan** is the world's first search engine for Internet-connected devices. Unlike traditional search engines that index web content, Shodan indexes device information.
     15 
     16 | Function | Description |
     17 |:---------|:------------|
     18 | Banner Grabbing | Captures service banners and metadata |
     19 | Port Scanning | Indexes open ports and services |
     20 | Vulnerability Detection | Identifies known CVEs |
     21 | SSL/TLS Analysis | Certificate and encryption info |
     22 | Geographic Mapping | Device location tracking |
     23 | Historical Data | Track changes over time |
     24 
     25 ## Getting Started
     26 
     27 ### Account Setup
     28 
     29 1. Create an account at [shodan.io](https://www.shodan.io).
     30 2. Get your API key: Account → API Key.
     31 3. Choose a plan (free tier available with limitations).
     32 
     33 ### Plan Comparison
     34 
     35 | Feature | Free | Membership | Small Business | Corporate |
     36 |:--------|:----:|:----------:|:--------------:|:---------:|
     37 | Search Results | 10 | Unlimited | Unlimited | Unlimited |
     38 | Query Credits | 0 | 100/month | 10,000/month | Unlimited |
     39 | Scan Credits | 0 | 100/month | 5,000/month | Unlimited |
     40 | Network Monitoring | No | Yes | Yes | Yes |
     41 | API Access | Limited | Full | Full | Full |
     42 
     43 ### CLI Installation
     44 
     45 ```bash
     46 # Install via pip
     47 pip install shodan
     48 
     49 # Initialize with API key
     50 shodan init YOUR_API_KEY
     51 
     52 # Verify installation
     53 shodan info
     54 ```
     55 
     56 ## Query Syntax Reference
     57 
     58 ### Core Filters
     59 
     60 | Filter | Example |
     61 |:------|:-------|
     62 | `title:` | `title:"Admin Panel"` |
     63 | `product:` | `product:"Apache"` |
     64 | `port:` | `port:22` |
     65 | `country:` | `country:"US"` |
     66 | `city:` | `city:"New York"` |
     67 | `region:` | `region:"California"` |
     68 | `org:` | `org:"Google"` |
     69 | `asn:` | `asn:AS15169` |
     70 | `net:` | `net:8.8.8.0/24` |
     71 | `geo:` | `geo:"40.7128,-74.0060"` |
     72 | `vuln:` | `vuln:CVE-2021-44228` |
     73 | `has_screenshot:` | `has_screenshot:true` |
     74 | `html:` | `html:"server version"` |
     75 | `header:` | `header:"Server: Nginx"` |
     76 | `ssl:` | `ssl:"Google"` |
     77 | `ssl.cert.subject.cn:` | `ssl.cert.subject.cn:"*.google.com"` |
     78 | `ssl.cert.issuer.cn:` | `ssl.cert.issuer.cn:"Let's Encrypt"` |
     79 | `os:` | `os:"Windows Server 2019"` |
     80 | `before:` | `before:01/01/2024` |
     81 | `after:` | `after:01/01/2024` |
     82 | `hostname:` | `hostname:"example.com"` |
     83 | `isp:` | `isp:"Comcast"` |
     84 | `version:` | `version:"7.4"` |
     85 | `http.title:` | `http.title:"Dashboard"` |
     86 | `http.status:` | `http.status:200` |
     87 | `http.component:` | `http.component:"WordPress"` |
     88 | `http.favicon.hash:` | `http.favicon.hash:116323821` |
     89 
     90 ### Boolean Operators
     91 
     92 - **AND** → implicit (space between filters)
     93 - **OR** → explicit `OR` keyword
     94 - **NOT** → minus sign (`-`) or `NOT` keyword
     95 
     96 ```text
     97 # AND (implicit)
     98 apache port:80 country:US
     99 
    100 # OR
    101 title:"Camera" OR title:"Webcam"
    102 
    103 # NOT
    104 apache -country:CN
    105 apache NOT country:CN
    106 ```
    107 
    108 ## Finding Cameras
    109 
    110 > **Note — Common IP camera ports.** HTTP: 80, 8080 · HTTPS: 443 · RTSP: 554 · custom ports vary by manufacturer (e.g. 81, 8888).
    111 
    112 ### Camera Brands and Queries
    113 
    114 | Brand | Common Ports | Search Query |
    115 |:------|:-------------|:-------------|
    116 | Axis | 80, 443 | `title:"AXIS"` / `product:"Axis"` |
    117 | D-Link | 80, 8080 | `title:"DCS-930L"` / `product:"D-Link"` |
    118 | Foscam | 80, 88, 443 | `title:"Foscam"` / `product:"Foscam"` |
    119 | Hikvision | 80, 443, 554, 8000, 8080 | `title:"Hikvision"` / `product:"Hikvision"` |
    120 | Dahua | 80, 443, 554, 8000, 8080, 8081, 8888 | `title:"Dahua"` / `html:"Dahua"` |
    121 | Ubiquiti UniFi | 80, 443, 8080, 8443, 7080, 7443 | `title:"UniFi"` / `"UniFi Video"` |
    122 | Reolink | 80, 443, 8080 | `title:"Reolink"` / `product:"Reolink"` |
    123 | Linksys | 80, 1024 | `title:"Linksys WVC80N"` |
    124 | Panasonic | 80, 443 | `title:"Panasonic Network Camera"` |
    125 | Sony | 80, 443 | `title:"Sony Network Camera"` |
    126 | Trendnet | 80, 443 | `title:"TV-IP"` |
    127 | TP-Link | 80, 8080 | `title:"TP-Link"` |
    128 | Vivotek | 80, 443 | `title:"Vivotek"` |
    129 | AvTech | 80, 8888 | `title:"AVTech"` |
    130 | Wansview | 80, 8080 | `title:"Wansview"` |
    131 | Wyze | 80, 443, 8080 | `title:"Wyze"` |
    132 | Uniview | 80, 443, 554, 8080 | `title:"Uniview"` |
    133 | Amcrest | 80, 8080, 8000 | `title:"Amcrest"` |
    134 | Lorex | 80, 443 | `title:"Lorex"` |
    135 | Mobotix | 80, 443, 8080 | `title:"Mobotix"` |
    136 | Avigilon | 80, 443, 554, 8080 | `title:"Avigilon"` |
    137 | FLIR | 80, 443, 554 | `title:"FLIR"` |
    138 
    139 ### Example Camera Queries
    140 
    141 ```text
    142 title:"AXIS" country:"US"                                # Axis cameras in the US
    143 title:"Foscam" has_screenshot:true                       # Foscam with screenshots
    144 title:"Hikvision" city:"New York"                        # Hikvision in New York
    145 title:"TP-Link" port:8080                                # TP-Link on port 8080
    146 title:"DCS-930L" port:8080                               # D-Link on custom port
    147 title:"Reolink" country:"DE" OR country:"GB" OR country:"FR"  # Reolink in Europe
    148 "UniFi Video" has_screenshot:true                        # UniFi with screenshots
    149 html:"Dahua" port:80                                     # Dahua HTML interface
    150 ```
    151 
    152 ## Tips and Tricks for Advanced Searching
    153 
    154 **Boolean operators:**
    155 ```text
    156 title:"Axis" OR title:"Hikvision" OR title:"Dahua"     # multiple brands
    157 title:"Camera" AND port:8080 AND country:"US"          # combine filters
    158 title:"Camera" NOT "authentication required"           # exclude results
    159 ```
    160 
    161 **Advanced query techniques:**
    162 ```text
    163 header:"Server: Boa"                                    # by HTTP header
    164 http.status:200 "admin"                                 # by HTTP status code
    165 "200 OK" http.title:"Index of"                          # open web interfaces
    166 title:"Camera" (port:80 OR port:8080 OR port:8888)      # across multiple ports
    167 product:"Apache" "2.2.15"                               # product + vulnerable version
    168 http.favicon.hash:116323821                             # by favicon hash
    169 ssl.cert.subject.cn:"*.target.com"                      # by SSL certificate
    170 ```
    171 
    172 **Filtering by response content:**
    173 ```text
    174 "username" "password" filetype:html
    175 "It works!" "Apache"                                    # default pages
    176 title:"Admin" OR title:"Administration" OR title:"Dashboard"
    177 http.title:"Login" OR http.title:"Sign In"
    178 ```
    179 
    180 **Organizational & network searches:**
    181 ```text
    182 org:"Company Name"
    183 asn:AS12345
    184 net:192.168.1.0/24
    185 isp:"Amazon Technologies"
    186 ```
    187 
    188 **Performance tips:** use specific queries; combine `port:` with `product`/`title`; use `has_screenshot` sparingly (slows queries); narrow geographic scope; prefer title/product filters (indexed, faster than HTML content).
    189 
    190 ## Finding Vulnerable Servers
    191 
    192 > **Important —** These queries help identify common vulnerabilities. Always use findings responsibly and with proper authorization.
    193 
    194 ### Known Vulnerability Queries
    195 
    196 ```text
    197 vuln:CVE-2014-0160      # Heartbleed
    198 vuln:CVE-2014-0224      # OpenSSL CCS Injection
    199 vuln:CVE-2014-6271      # Shellshock
    200 vuln:ms17-010           # EternalBlue
    201 vuln:CVE-2021-44228     # Log4Shell
    202 vuln:CVE-2021-26855     # ProxyLogon
    203 vuln:CVE-2019-0708      # BlueKeep
    204 vuln:CVE-2017-5638      # Apache Struts
    205 vuln:CVE-2020-1472      # Zerologon
    206 vuln:CVE-2021-34527     # PrintNightmare
    207 ```
    208 
    209 ### Default Credentials
    210 
    211 ```text
    212 "220" "Anonymous FTP login allowed"
    213 "220" "telnet" "default password"
    214 "default password" http.title:"admin"
    215 "cisco" "level 15 access"
    216 ```
    217 
    218 ### Outdated Software
    219 
    220 ```text
    221 "Apache/2.2.15"
    222 "Microsoft-IIS/6.0"
    223 "OpenSSH_5"
    224 "nginx/1.4"
    225 "PHP/5.2"
    226 ```
    227 
    228 ### Example Queries by Service
    229 
    230 ```text
    231 "MongoDB Server Information" port:27017          # open MongoDB
    232 "200 OK" "elastic indices" port:9200             # ElasticSearch without auth
    233 port:445 "smb" "NT_STATUS_ACCESS_DENIED"         # open SMB
    234 port:3389 "Remote Desktop Protocol"              # exposed RDP
    235 "X-Jenkins" "200 OK"                             # Jenkins without auth
    236 "kube-apiserver" port:6443                        # exposed Kubernetes API
    237 "couchdb" port:5984 "200 OK"                      # CouchDB no auth
    238 ```
    239 
    240 ### Geographic Vulnerability Filtering
    241 
    242 ```text
    243 vuln:ms17-010 country:"US"                                    # EternalBlue in US
    244 "MongoDB Server Information" port:27017 country:"DE"          # open MongoDB in Germany
    245 vuln:CVE-2014-6271 region:"California"                        # Shellshock in California
    246 vuln:CVE-2014-0160 city:"London"                             # Heartbleed in London
    247 "Apache/2.2.15" country:"FR" has_screenshot:true             # outdated Apache in France
    248 "220" "Anonymous FTP login allowed" country:"JP"             # anon FTP in Japan
    249 ```
    250 
    251 ## Searching by Geographic Filters
    252 
    253 > **Note — Common geographic filters.** `country:"<code>"` · `city:"<name>"` · `region:"<name>"` · `geo:"<lat>,<lon>"`.
    254 
    255 ```text
    256 http country:"US"                                # web servers in the US
    257 ftp country:"DE"                                 # FTP in Germany
    258 telnet city:"London"                             # Telnet in London
    259 rdp region:"California"                           # RDP in California
    260 mysql city:"Paris"                               # MySQL in Paris
    261 "elastic indices" port:9200 city:"Berlin"        # Elasticsearch in Berlin
    262 http geo:"40.7128,-74.0060"                       # near New York City
    263 ```
    264 
    265 SSH by country: `ssh country:"US"` · `ssh country:"JP"` · `ssh country:"GB"` · `ssh country:"DE"` · `ssh country:"AU"`.
    266 
    267 ## Finding Plex Media Servers
    268 
    269 Common port: HTTP 32400.
    270 
    271 ```text
    272 "X-Plex-Protocol" port:32400                                       # worldwide
    273 "X-Plex-Protocol" port:32400 country:"US"                          # in the US
    274 "X-Plex-Protocol" port:32400 country:"DE" has_screenshot:true      # with screenshots
    275 "X-Plex-Version" port:32400                                        # by version
    276 ```
    277 
    278 ## Finding Raspberry Pi Devices
    279 
    280 Common ports: SSH 22, HTTP 80.
    281 
    282 ```text
    283 "Raspbian" port:22                               # via SSH
    284 "Raspberry Pi" port:80                            # via HTTP
    285 "Raspbian" port:22 country:"US"                   # in the US
    286 title:"Pi-hole" http.component:"Pi-hole"          # Pi-hole instances
    287 "RFB" "Raspbian" port:5900                         # with VNC
    288 ```
    289 
    290 ## Finding Proxmox Servers
    291 
    292 Common port: HTTPS 8006.
    293 
    294 ```text
    295 "Proxmox" port:8006
    296 "Proxmox" port:8006 country:"US"
    297 "Proxmox" port:8006 has_screenshot:true
    298 title:"Proxmox Virtual Environment"
    299 ```
    300 
    301 ## Finding Web Cameras & Video Streaming
    302 
    303 > **Note — Common streaming ports.** MJPEG: 8081, 8082, 8888 · RTSP: 554, 322 · HTTP: 80, 8080.
    304 
    305 ```text
    306 "MJPEG Server" port:8081                          # MJPEG streams
    307 "Motion JPEG" port:8888                            # motion JPEG
    308 port:554 "rtsp"                                    # RTSP streams
    309 "200 OK" "webcam" NOT "password"                   # webcams with no auth
    310 "IP Webcam Server" http.component:"IP Webcam"      # IP Webcam Android app
    311 title:"Blue Iris" http.favicon.hash:-1616143106    # Blue Iris DVR
    312 ```
    313 
    314 ## Finding IoT Devices
    315 
    316 > **Note — Common IoT protocols/ports.** MQTT: 1883, 8883 (TLS) · CoAP: 5683 · ZigBee: 6100 · smart-home hubs: 8080-8090.
    317 
    318 ```text
    319 port:1883                                          # IoT via MQTT
    320 title:"Home" OR title:"Smart" port:8080             # smart-home hubs
    321 "MQTT" port:1883                                    # open MQTT brokers
    322 product:"Arduino" OR product:"Raspberry Pi" OR product:"ESP"
    323 title:"Home Assistant" port:8123                    # Home Assistant
    324 "SmartThings" port:39500                            # SmartThings hubs
    325 "Philips hue" port:80                               # Philips Hue bridges
    326 "Nest" port:443                                     # Nest devices
    327 "Ring" product:"Ring"                               # Ring doorbells
    328 ```
    329 
    330 ## Finding Industrial Control Systems
    331 
    332 > **Important — Common ICS/SCADA protocols.** Modbus: 502 · Siemens S7: 102 · Profinet: 34962-34964 · OPC UA: 4840 · DNP3: 20000 · BACnet: 47808 · EtherNet/IP: 44818.
    333 
    334 ```text
    335 port:502 "Modbus"
    336 port:102 "Siemens"
    337 "Siemens" OR "Modbus" OR "PLC"
    338 port:44818 "Allen-Bradley"
    339 port:47808 "BACnet"
    340 port:20000 "DNP3"
    341 port:4840 "OPC"
    342 "Schneider Electric" port:502
    343 "GE" "PLC" OR "PACSystems"
    344 ```
    345 
    346 ## Finding Network Attached Storage (NAS)
    347 
    348 > **Note — Common NAS ports.** QNAP: 8080, 8443 · Synology: 5000, 5001 · WD MyCloud: 80 · Netgear ReadyNAS: 80, 443.
    349 
    350 ```text
    351 title:"QNAP" port:8080
    352 "Synology" port:5000
    353 "WD MyCloud" port:80
    354 "NAS" "sharing" has_screenshot:true
    355 title:"FreeNAS" OR title:"TrueNAS"
    356 title:"ReadyNAS"
    357 title:"Buffalo" "NAS"
    358 title:"Drobo"
    359 ```
    360 
    361 ## Finding Database Servers
    362 
    363 > **Note — Common DB ports.** MySQL 3306 · PostgreSQL 5432 · MongoDB 27017 · Redis 6379 · Cassandra 9042 · Elasticsearch 9200 · CouchDB 5984 · InfluxDB 8086 · Neo4j 7474.
    364 
    365 ```text
    366 "MongoDB Server Information" port:27017 -"authentication"   # unprotected MongoDB
    367 "redis_version" port:6379
    368 port:5432 "PostgreSQL"
    369 "elasticsearch" port:9200
    370 "MySQL" port:3306 -"Access denied"
    371 "couchdb" port:5984 "Welcome"
    372 port:9042 "cassandra"
    373 port:8086 "InfluxDB"
    374 port:7474 "neo4j"
    375 port:3306 "MariaDB"
    376 port:1521 "Oracle"
    377 port:1433 "SQL Server"
    378 ```
    379 
    380 ## Finding VPN & Remote Access Services
    381 
    382 > **Note — Common remote access ports.** OpenVPN 1194 · WireGuard 51820 · IPSec 500/4500 · RDP 3389 · VNC 5900-5999 · SSH 22 · TeamViewer 5938.
    383 
    384 ```text
    385 "OpenVPN" port:1194
    386 port:3389 has_screenshot:true
    387 port:5900 "RFB"                                    # VNC
    388 "Citrix" port:1494
    389 "Fortinet" ssl:"Fortinet"
    390 "GlobalProtect" ssl:"Palo Alto"
    391 "Pulse Secure" port:443
    392 "SonicWall" port:443
    393 port:7070 "AnyDesk"
    394 port:5938 "TeamViewer"
    395 port:51820                                          # WireGuard
    396 ```
    397 
    398 ## Finding Printers & Multifunction Devices
    399 
    400 > **Note — Common printer ports.** HP/Canon/Xerox: 80, 443, 9100 (JetDirect) · Ricoh: 80, 443, 8080 · IPP: 631.
    401 
    402 ```text
    403 "HP" port:9100
    404 title:"Canon" port:80
    405 "Xerox" OR "WorkCentre"
    406 "printer" port:80 has_screenshot:true
    407 title:"Brother" "printer"
    408 title:"EPSON" port:80
    409 title:"Ricoh" port:80
    410 title:"Kyocera"
    411 port:631 "IPP"
    412 ```
    413 
    414 ## Finding Game Servers
    415 
    416 > **Note — Common game server ports.** Minecraft 25565 · Counter-Strike/ARK 27015 · Rust 28015 · TeamSpeak 9987.
    417 
    418 ```text
    419 "Minecraft Server" port:25565
    420 product:"Counter-Strike" port:27015
    421 "ARK" port:27015
    422 product:"Rust" port:28015
    423 product:"TeamSpeak" port:9987
    424 "Valheim" port:2456
    425 product:"Garry's Mod"
    426 "7 Days to Die" port:26900
    427 ```
    428 
    429 ## Finding Cloud Services & APIs
    430 
    431 > **Note — Common cloud/API ports.** HTTP/HTTPS 80/443 · API gateways 8080/8443 · Docker 2375/2376.
    432 
    433 ```text
    434 port:2375 product:"Docker"                          # exposed Docker APIs
    435 title:"Kubernetes Dashboard"
    436 "X-Jenkins" http.title:"Dashboard"
    437 http.title:"GitLab"
    438 title:"Grafana"
    439 title:"Kibana"
    440 title:"Prometheus" port:9090
    441 title:"Portainer"
    442 title:"Swagger UI"
    443 "169.254.169.254"                                   # AWS metadata leaks
    444 http.title:"Index of /.git"                         # exposed .git directories
    445 http.title:"Index of" ".env"                        # exposed .env files
    446 ```
    447 
    448 ## Finding Network Infrastructure
    449 
    450 > **Note — Common network device ports.** SNMP 161 · SSH 22 · Telnet 23 · BGP 179.
    451 
    452 ```text
    453 "cisco" product:"Cisco IOS"
    454 "Juniper" product:"Juniper"
    455 product:"MikroTik"
    456 "EdgeOS" OR "Ubiquiti"
    457 title:"pfSense"
    458 title:"OPNsense"
    459 "FortiGate" ssl:"Fortinet"
    460 "SonicWall" port:443
    461 "BIG-IP" product:"BIG-IP"
    462 "NETGEAR" product:"NETGEAR"
    463 "TP-LINK" product:"TP-LINK"
    464 port:161 "public"                                   # SNMP enabled
    465 ```
    466 
    467 ## Advanced Filtering Techniques
    468 
    469 ```text
    470 ssl:"OpenSSL/1.0" "weak"                            # weak SSL/TLS configs
    471 "Basic realm" port:80                               # exposed info
    472 vuln:CVE-2021-21315
    473 "X-Powered-By: PHP" port:80                          # by response header
    474 header:"X-Custom-Header"                             # custom applications
    475 geo:"40.7128,-74.0060"                              # geographic proximity
    476 ssl.cert.issuer.cn:ssl.cert.subject.cn              # self-signed certs
    477 ssl.cert.expired:true                                # expired certs
    478 http.component:"WordPress" http.component_category:"cms"
    479 ```
    480 
    481 ## Using Shodan CLI for Advanced Queries
    482 
    483 ```bash
    484 # Install and initialize
    485 pip install shodan
    486 shodan init YOUR_API_KEY
    487 
    488 # Basic search
    489 shodan search "apache"
    490 
    491 # Export results with specific fields
    492 shodan search "title:Camera" --fields ip_str,port,org,country,html
    493 
    494 # Download bulk data
    495 shodan download camera-results "title:Camera"
    496 
    497 # Host information lookup
    498 shodan host 8.8.8.8
    499 shodan host --history 8.8.8.8
    500 
    501 # Stream real-time Shodan data
    502 shodan stream
    503 
    504 # Count results for a query
    505 shodan count "apache"
    506 
    507 # Parse downloaded data
    508 shodan parse camera-results.json.gz --fields ip_str,port
    509 
    510 # Domain / DNS
    511 shodan domain example.com
    512 shodan dns resolve example.com
    513 shodan dns reverse 8.8.8.8
    514 
    515 # Stats with facets
    516 shodan stats --facets country apache
    517 
    518 # Convert data format
    519 shodan convert results.json.gz csv
    520 ```
    521 
    522 ## Shodan API Usage (Python)
    523 
    524 **Basic search:**
    525 ```python
    526 import shodan
    527 
    528 api = shodan.Shodan('YOUR_API_KEY')
    529 results = api.search('apache')
    530 
    531 for result in results['matches']:
    532     print(f"IP: {result['ip_str']}")
    533     print(f"Port: {result['port']}")
    534     print(f"Org: {result.get('org', 'N/A')}")
    535     print("---")
    536 ```
    537 
    538 **Host lookup:**
    539 ```python
    540 import shodan
    541 
    542 api = shodan.Shodan('YOUR_API_KEY')
    543 host = api.host('8.8.8.8')
    544 
    545 print(f"IP: {host['ip_str']}")
    546 print(f"Organization: {host.get('org', 'N/A')}")
    547 print(f"OS: {host.get('os', 'N/A')}")
    548 
    549 for item in host['data']:
    550     print(f"Port: {item['port']}")
    551     print(f"Banner: {item['data'][:100]}...")
    552 ```
    553 
    554 **Streaming API:**
    555 ```python
    556 import shodan
    557 
    558 api = shodan.Shodan('YOUR_API_KEY')
    559 for banner in api.stream.banners():
    560     print(banner)
    561 ```
    562 
    563 **Network alerts:**
    564 ```python
    565 import shodan
    566 
    567 api = shodan.Shodan('YOUR_API_KEY')
    568 alert = api.create_alert('My Network', '192.168.1.0/24')
    569 print(f"Alert ID: {alert['id']}")
    570 ```
    571 
    572 ## Practical Search Strategies
    573 
    574 ```text
    575 product:"Cisco" "privilege" "escalation"                   # 1. vulnerability chain
    576 "default username is" OR "default password is"             # 2. default installs
    577 "200 OK" after:2024-01-01                                  # 3. recently indexed
    578 "Apache/2.4.49" OR "Apache/2.4.50"                         # 4. known CVEs
    579 "SCADA" OR "HMI" OR "historian"                            # 5. critical infrastructure
    580 org:"Your Company Name"                                    # 6. your org's exposure
    581 ssl.cert.subject.cn:"yourcompany.com" -org:"Your Company"  # 7. shadow IT
    582 title:"Index of /backup"                                   # 8. misconfigured storage
    583 http.title:"phpMyAdmin" OR http.title:"Adminer"            # 9. exposed dev envs
    584 http.title:"admin" http.status:200 -http.title:"login"     # 10. exposed admin panels
    585 ```
    586 
    587 ## Ethical Considerations
    588 
    589 > **Important —**
    590 > - **Permission:** always have explicit authorization before attempting any access or testing.
    591 > - **Responsibility:** use findings to improve security and report vulnerabilities responsibly.
    592 > - **Legal compliance:** comply with all relevant regulations (CFAA, GDPR, etc.).
    593 > - **No malicious intent:** never use Shodan for unauthorized access or data theft.
    594 
    595 **Pre-search checklist:** authorization confirmed · legitimate security purpose · legal implications reviewed · prepared to disclose responsibly · Shodan ToS understood · findings reported to the right parties.
    596 
    597 **Common mistakes to avoid:** over-broad searches (false positives), assuming every result is vulnerable, unauthorized testing, premature public disclosure, assuming ownership of exposed services, ignoring honeypots.
    598 
    599 ## Responsible Vulnerability Disclosure
    600 
    601 1. **Identify** — confirm the vulnerability, document with evidence, note affected systems/versions.
    602 2. **Find contact** — check `/.well-known/security.txt`, the org's site, published VDPs, or whois/reverse DNS.
    603 3. **Report** — send a detailed technical report, allow a reasonable timeline (typically 90 days), do not disclose before a patch, offer to verify the fix.
    604 4. **Document** — keep records of all communications, dates, responses, and patch releases.
    605 
    606 | Timeline | Action |
    607 |:--------:|:-------|
    608 | Day 1 | Discover and confirm vulnerability |
    609 | Day 1 | Contact vendor with details |
    610 | Day 30 | Follow up if no response |
    611 | Day 60 | Consider escalation |
    612 | Day 90 | Coordinate public disclosure after patch |
    613 
    614 ## Resources and References
    615 
    616 - [Shodan Official Website](https://www.shodan.io)
    617 - [Shodan CLI Documentation](https://cli.shodan.io)
    618 - [Shodan API Documentation](https://developer.shodan.io)
    619 - [Shodan Query Cheat Sheet](https://cheatsheet.shodan.io)
    620 
    621 **Related tools:** Censys, ZoomEye, GreyNoise, BinaryEdge, Shodan Maps.