This Blog has Moved!

This blog is moving to


Thank you for visiting! Content will remain here for archival purposes.
Showing posts with label Shodan. Show all posts
Showing posts with label Shodan. Show all posts

New Shodan Search: Open Windows Servers

A New Shodan Search is now saved on SHODAN - Recently Saved Searches



Title: Open Windows Servers

Description:

??? Openly give out MAC addresses and names Probably Windows Probably an old version No idea what it really is Go wild

URL:

http://ift.tt/WQupms

New Shodan Search: Trilithic

A New Shodan Search is now saved on SHODAN - Recently Saved Searches



Title: Trilithic

Description:

Trilithic creates cable and satellite equipment for diagnostics and maintenance, including Emergency Alert System equipment.

URL:

http://www.shodanhq.com/?q=Trilithic

Blog Updated to Include Shodan Searches and Free Security Resources

I've setup a couple experimental IFTT recipies to automatically post new Shodan searches to my blog, as well as post new Cyber Security resources as they become available.

If you notice it malfunctioning, please let me know via Twitter. This is a brand new feature, and I hope it works well.

Unauthenticated Windows CE Telnet Service Vulnerable Configuration

Since this is a Windows CE configuration issue, and not a software vulnerability, I am releasing this information publicly so that software developers can be aware of the issue.

Tonight I stumbled on a quite scary Shodan search which I'd like to share with everyone.

Windows CE Telnet Service

What is the Windows CE Telnet Service?

Apparently Windows CE has a built in telnet service for debugging of applications, as outlined in this MSDN blog post.

Now the truly scary part about all this is that the telnet server has the ability to disable authentication requirements.

[HKEY_LOCAL_MACHINE\COMM\TELNETD]
    "UseAuthentication"=dword:0
    "IsEnabled"=dword:1

 When you do disable the authentication requirements (for debugging purposes only of course), you're greeted with an administrator level command prompt as soon as you connect with telnet.

From there you can perform all sorts of fun things, like restart the device or access any locally stored file - pretty much any command which is typically available at a Windows command line.

Despite the fact that this was only intended for debugging purposes, Shodan found 892 public facing systems with this vulnerability.  Who knows how many thousands more reside behind corporate firewalls, with organizations completely unaware that their devices with embedded Windows are vulnerable to attack.

Vulnerable Windows CE Telnet Services
Clearly, some embedded Windows developers have accidentally left this setting enabled prior to shipping their devices.  One thing which really stands out is that some of the vulnerable systems are KVMs, meaning that should the KVM be compromised, the attacker will have control of all connected systems, and be able to install a keylogger to capture all usernames/passwords.  Since KVMs do not typically have Antivirus installed, this activity may never be noticed.

As I dive deeper into Shodan, I hope to bring more interesting vulnerabilities like this one to light.  Stay tuned!

Using Shodan to Measure The Security of the Internet

Shodan is a search engine for potentially vulnerable computer systems, based upon header information.

It allows you to perform a lot of neat tricks, such as see what your organization's public footprint looks like, as well as your competitors.  You can use it to find interesting devices such as routers, webcams, printers, etc.

I performed the following searches to see just how many glaringly obvious vulnerable systems are exposed to the internet.

First search: "IIS/5.0".  This search will produce systems which are running Windows 2000 with an IIS web server.  Of course Windows 2000 and IIS 5.0 are no longer supported by Microsoft, and multiple vulnerabilities are publicly known.

So needless to say, I was quite disturbed when I found half a million exposed IIS/5.0 webservers.

IIS 5.0 on Windows 2000
Surely no one would be running a version of Windows older than Win 2000, and connect it to the Internet, right?