Live data from Hacker News

Shodan: The scariest search engine on the Internet

money.cnn.com

121–130 of 152 posts

Re: Shodan: The scariest search engine on the Internet

#121
post #84

They also missed ERIPP, which does something similar. This is all old news though, these things are constantly mentioned in other security reports. Even the government knows these things exist, which means that CNN is not scouping anyone :)

ERIPP is cool (I spoke to the author years ago), but to my knowledge it hasn't been updated in a while. And I cover 20+ services at the moment, so it's not just HTTP.

Re: Shodan: The scariest search engine on the Internet

#122
post #101
post #85

Earlier quoted context omitted.

Shoot me an email.

Would be interesting to offer this script as "ptaas" penetration testing as a service. That way instead of having the script and having the potential to abuse the script (or temptation) someone would be forced to allow tracking of the IP (presumably their own or their companies) that they are doing the testing on (and you could compile statistics for use elsewhere as a condition if they got the script for free). I kn…

[deleted]

Re: Shodan: The scariest search engine on the Internet

#123

Earlier quoted context omitted.

My Netgear Router N600 does exactly that. There's a nice laminated sticker on the bottom with the admin password.

Most of those types are some sort of hash of the MAC which are quickly reversed. A quick search will contain many fruitful examples. How else do you think the default password ends up the same on a system reset?

Yeah, but at least it's not trivial to learn the MAC of a system across the world (right? I admit I don't know a whole lot about this.) Anyone sitting on the LAN so that they know the MAC likely has other attack avenues anyway.

Re: Shodan: The scariest search engine on the Internet

#124

Earlier quoted context omitted.

Assuming they didn't, you know, disconnect you while you were doing it. There are actual people up there; presumably they have manual overrides.

Right. I was assuming/implying a lot by saying, "if you had the controls." In the hypothetical where you have complete control of the ISS (despite manual overrides, et al), you'd still have a very hard time hitting a specific target on Earth. You could crash the thing fairly easily though. That's all I meant to say; I understand that this isn't a practical reality.

Yup, I understood. I was just adding a thought about how it was even more impractical than your comment suggested. Wasn't arguing against your point itself.

Re: Shodan: The scariest search engine on the Internet

#125
I've been playing with the data from the Carna botnet output[1]. Basically someone scanned a massive portion of the Internet using broken routers as bots. There's some interesting finds in the data but analysing it is quite awkward given the size. Shodan is interesting but unless you take up a subscription is pretty limited.

[1] - http://internetcensus2012.bitbucket.org/paper.html

Re: Shodan: The scariest search engine on the Internet

#126
post #55
post #8

Eagerly awaiting the moment someone at CNN finds out about Metasploit. I'd like to think of it as a kind of "Dark Firefox".

Love this: http://www.metasploit.com/about/penetration-testing-basics/ "You can become a penetration tester at home by testing your own server and later make a career out of it." Sounds like the old style correspondence school ads - a bit hokey. http://www.thefreedictionary.com/correspondence+school I would have rewritten that as: "Many people have actually made a career out of being a penetration tester by first tes…

http://gogd.tjs-labs.com/show-picture?id=1160663127&size...

"By and large, Management agrees that there is but one adequate solution to the problem ... a solution that can be applied only by Management itself."

Re: Shodan: The scariest search engine on the Internet

#127
post #125

I've been playing with the data from the Carna botnet output[1]. Basically someone scanned a massive portion of the Internet using broken routers as bots. There's some interesting finds in the data but analysing it is quite awkward given the size. Shodan is interesting but unless you take up a subscription is pretty limited. [1] - http://internetcensus2012.bitbucket.org/paper.html

Actually, more than 90% of the website's services are completely free! There are only 2 services that I charge for: HTTPS and Telnet. All of the new stuff for the past year I've added and made available for free. And with the Developer API you can easily access the data from within your own scripts.

Oh, and I've seen this in a few locations now but: NO SUBSCRIPTION REQUIRED. All of the stuff that's sold on the website is a one-time charge. There are no subscriptions on the website :)

Re: Shodan: The scariest search engine on the Internet

#129
post #58
post #55

Earlier quoted context omitted.

Love this: http://www.metasploit.com/about/penetration-testing-basics/ "You can become a penetration tester at home by testing your own server and later make a career out of it." Sounds like the old style correspondence school ads - a bit hokey. http://www.thefreedictionary.com/correspondence+school I would have rewritten that as: "Many people have actually made a career out of being a penetration tester by first tes…

You can absolutely learn to do penetration testing on your own time with your own servers. We have a script we give people to do the same thing. If you feel like you have a knack for systems programming, being a good systems programmer is 1/2 the hard part of appsec; the other 1/2 is literally "taking pleasure in finding creative ways to break things", and you can find out if you have that personality streak in just…

When you say "a script" what do you mean? A script that configures a server incorrectly to let you see the kind of things you can do?

Re: Shodan: The scariest search engine on the Internet

#130
post #22

Earlier quoted context omitted.

Crazy idea, if you don't know what you're talking about, shut the hell up.

I used to be able to tell people like you to go back to Reddit. Unfortunately the quality of HN has declined far enough that your content-free insulting of a decent question is not immediately recognizable as something with no place here. I consider that fact a sad commentary on how far HN has fallen.

What would happen if HN were split into sub-communities like reddit?

Also saying reddit doesn't have quality discussion is a bit unfair to the minority of subreddits that do.

Post reply on HN