Shodan Dork

Advanced IoT & Infrastructure Search

by Faizee Asad

🗄️ Database Exposures

🔍 MySQL Database 🔍 MongoDB (No Auth) 🔍 CouchDB 🔍 phpMyAdmin 🔍 Mongo Express GUI

🔐 Authentication Issues

🔍 Default Passwords 🔍 Guest Login OK 🔍 Auth Disabled 🔍 Default WiFi Password 🔍 VNC No Auth (RFB) 🔍 Unauthorized Access

🎛️ Control Panels & Dashboards

🔍 Dashboard 🔍 Control Panel 🔍 Jenkins Dashboard 🔍 All Jenkins Servers 🔍 Jenkins CI 🔍 Grafana Dashboards 🔍 Kibana 🔍 Argo CD CVE

🚨 Critical CVE Exploits

🔍 Microsoft Exchange RCE CVE-2021-26855 🔍 WSO2 RCE CVE-2022-29464 🔍 WSO2 RCE (Alt) CVE-2022-29464 🔍 Cisco ASA CVE-2020-3452 🔍 VMware Workspace ONE CVE-2022-22954 🔍 Zabbix Auth Bypass CVE-2022-24255 🔍 Argo CD Path Traversal CVE-2022-24348 🔍 Pulse Secure VPN CVE-2019-11510 🔍 F5 BIG-IP CVE-2020-5902 🔍 Intel AMT CVE-2017-5689

🌐 Web Applications

🔍 WordPress Config 🔍 Horde Webmail 🔍 Tomcat (Log4j) 🔍 Exposed API Keys 🔍 Apache Directory Listings

💻 Network Services

🔍 Root Telnet Session 🔍 Windows SMB 🔍 Telnet (No Password) 🔍 Windows RDP 🔍 ProFTPD 🔍 HP Printers