The personal blog of Alden.


Shodan Stories Day 49: Solving Crimes and Protecting the Innocent in Paris


Another boring day on the shared searches. I decided to search for IPs with “dev environment” in the title, hoping to find something good. Ace Attorney Online on 163.172.128.52 Many of the results were pretty interesting and I think it’s a fruitful search overall, but one result in France stood out to me. It’s the “developer environment” for a webpage running on port 8080 dedicated to fan-made versions of the popular Ace Attorney games.…
Read more ⟶

Shodan Stories Day 48: Processing Wood Products in Piet Retief, Dahua Botnets, MikroTik Botnets, and Particle Board


Kind of a weird one today. I didn’t like any of the searches I’d seen so I decided to search for anything that had “production plant” in the title. A Woodchem Production Plant on 154.126.209.18 I wasn’t entirely sure what I was looking for, but got several dozen results. I decided to pick one in South Africa. On port 80 it was running a login for a Dahua Technology device. Dahua mostly makes surveillance products like cameras and patrol drones(!…
Read more ⟶

Shodan Stories Day 47: Looking at Feet in Tokyo


I’m busy preparing for a trip today and running errands so a quick one today. I found another Steven Wu webcam entirely by accident, just browsing Shodan’s webserver snapshots (see day 38 if Steven Wu doesn’t ring a bell). I like the Steven Wu cameras. The very simple interface, the snapshot approach. Feels right. IP Camera on 110.5.43.249 The camera’s webserver is running on port 81. Specifically what interested me about this webcam was its area of focus.…
Read more ⟶

Shodan Stories Day 46: Getting Connected in Vietnam, GPON ONT, VNPT, and the Mysteries of DNS Addressing


Someone was really looking for GPONs today, as I saw at least three searches for GPON related devices. What’s a GPON you wonder? Let’s find out together. VNPT GPON ONT on 14.161.15.80 GPON stands for Gigabit Passive Optical Network. Though the real details of how they work escape me, it seems that they are a commonly used device by ISPs to separate out cable traffic between customers, frequently referred to as the “last mile” between the ISP and the end customer.…
Read more ⟶

Shodan Stories Day 45: Filferro in Empuriabrava, .NET Games, eMule, Pokémon Armageddon, and the Joy Only Known to Those Who Keep Their Campsites Cow Free


Another day another search. Today I found a shared search for “emule”. “What’s an emule?” I asked myself, and dove in. An eMule on 87.216.176.220 eMule is an “electronic mule”, duh. It’s a kind of peer to peer software, different from bittorent, but I’m not sure exactly how. Every explanation I’ve found on how it works is a bit over my head, or at least over my attention span. It seemed like eMule was mostly popular in Europe, and I picked a result in Spain with eMule running on port 8000.…
Read more ⟶

Shodan Stories Day 44: Dealing with the Devil in Quebec, Repetitive Jetpack Death, Dr. Cheetos' Pain Chamber, Ludum Dare 43, Unity Web GL, and What Happened to Dave?


Saw a great search today, this for Unity Engine Web Players. Unity is a hugely popular 3D game engine, primarily used for making video games but has a wide range of applications, including workflow simulation, architectural prototyping, and filmmaking. Typically Unity outputs run as stand alone applications, but it also has the ability to output applications for the web via Web GL. Unity Web GL on 52.15.155.102 There were about 600 results for this search and I picked the first result I found.…
Read more ⟶

Shodan Stories Day 43: Jamming Out in Centerville, Bundesliga Fans, and the Discreet Charm of the Presentation Page


I decided to double dip on AV receivers since someone was going so deep on them the past few days. Today I decided to look at Pioneer. Pioneer AV Receiver on 167.142.82.87 I mostly know pioneer as a manufacturer of CDJs, and had no idea that they had a diverse product line beyond DJ equipment. They make bike equipment and accessories, a wide variety of audio equipment, and some kinds of computer electronics.…
Read more ⟶

Shodan Stories Day 42: Party Mode in Kleppestø, Yamaha Receivers, and Incredible Web Design


I saw that someone was searching for quite a few different types of AV receivers today. I decided to look into one of their searches, this one for Yamaha receiver. Yamaha AV Recievers on 90.149.252.214 I’m not sure what the typical use-case for remote control of an AV receiver is. Maybe if you run a cafe and you want to make sure your untrustworthy employees don’t make the music too loud while you’re out?…
Read more ⟶

Shodan Stories Day 41: Mining for Innovation in Abu Dhabi, Trapped in the Multiverse of Project Validation, Haunted by the Lightbulb of Ideas, Tasked with an Eternity of Teamwork Communication Adjustment


I saw someone searching for “snapchat” today. “YOLO”, I said to myself, and dived in. Fujairah Innovation Mine on 83.111.19.71 The search was in fact pulling up some of Snapchat’s production servers. Those were fairly boring however, though I did find something a little more interesting. This is a website for an organization called Fujairah Innovation Mine, which seems to be a typical tech startup incubator. The website was was running on port 7548 of the IP, so it clearly couldn’t be the official version.…
Read more ⟶

Shodan Stories Day 40: Blue_7 in Beijing, GGGG, Evading Government Censures, Server Login Lists, Abandoned Blogs, Shadow Socks, Telegram Chat Rooms, and the Mystery of Using URLs as Passwords


I spent so long trying to figure out what I found today that I’ve forgotten how I found it. I think it was from someone’s search for “USB”, but I’m now unable to recreate the search. A Mystery on 118.24.95.11 However I discovered this IP, I first arrived at what looked like a normal blog on port 8083. There is a very ~hacker~ image of a guy in ad hoody as the author’s picture.…
Read more ⟶