The personal blog of Alden.


Shodan Stories Day 29: Crypto World in Santa Monica, Trello Boards, Tokenization, and the Vectorialists


I saw someone searching for “ICO”. At first I thought maybe it had something to do with the groundbreaking 2001 indie game, but after browsing some links I realized that no, it meant “Initial Coin Offering”, and yes this is another crypto thing. CoinCircle’s ICOStats Tracker on 165.227.6.170 Most of the results on Shodan are websites and webservers, but I found one running on Digital Ocean that’s just a web app running on port 3000.…
Read more ⟶

Shodan Stories Day 28: Joining the Electric World in Darmstadt


Today I saw someone searching for “turbines”. An intriguing search, certainly, and at first I thought that they were looking for wind turbines. No however it seems that whoever it was just randomly searched turbines. I decided to roll with it and see what came up. B-I-A Vertriebs GmbH on 82.165.151.127 I ended up deciding on the web server run by a German wholesaler for electricity parts named B-I-A Vertriebs. There seemed to be some other interesting results but this company had one very compelling trump card that cleanly explains whatever success they have in the area of industrial electric parts and devices.…
Read more ⟶

Shodan Stories Day 27: A Connoisseur of Sorts in Shenzhen, Western Digital 2 Go, and Rest In Peace TwonkyMedia


Saw somebody doing a search for “twonky”. What a name! I had to find out about it. A Twonky Media Server on 14.155.113.144 Twonky is one of many personal media servers I’ve now run into, meant to run either on a network attached storage device or on a computer. The purpose I assume is to be able to stream your media from any devices on your network without having to worry about storying them locally (so if you’ve stolen a lot of blueray movie rips from bittorent and want to watch them on your phone or something).…
Read more ⟶

Shodan Stories Day 26: Multicasting in Siberia, UDP Packet Pixies, and Free Civ


The other day I saw someone on Shodan searching for “udpxy”, and I couldn’t determine what was going on with that because all of the results would give me 401 no auth errors. Today I realized that I could, of course, add “200 OK” to the search and only return successful connections. So I did. A Udpxy Server on 5.136.117.163 There were only two results, both in Russia, so I picked the one that seemed a little more interesting, from Tomsk, Siberia.…
Read more ⟶

Shodan Stories Day 25: Helping Strangers in Singapore


Today I saw someone searching for “SingTel”, and had given a description of the search saying “what? no auth? W o a h”. Pretty compelling stuff, so I gave it a search myself. The actual query was a little more complicated, “Server: Arcadyan httpd 1.0 200 OK org:“Singtel Fibre Broadband” “. An Unsecured Router on 219.74.62.124 Every result for the search was in Singapore, which I realized is because Singtel is one of the largest ISPs and mobile network providers in Singapore.…
Read more ⟶

Shodan Stories Day 24: Watching the News in Cheongju, IPTime Routers, Synology Yet Again, and TVheadend


Today I saw a search just for “TVheadend” and I thought it looked like a weird name so I decided to investigate. TVheadened Server on 125.181.166.200 TVheadend is an open source streaming server and recorder for streaming television on Linux, FreeBSD, or Android machines. I believe it works by intercepting television input and putting it into streamable format, which means that the machine running this server would need some kind of cable or radio tv receiver (maybe even a Dreambox 😄).…
Read more ⟶

Shodan Stories Day 23: Super Mediocrity in Albuquerque, Wifi Garage Doors, WebIOPi, and the Great Xylophone Saga of 2015


Today’s was a true delight, a real moment of striking gold, of finding something so beautifully weird that I can barely contain my excitement in writing this. Truly the spice of life, this. I started off wanting to find a wifi connected garage door, and I read that garage door openers are a common application of WebIOPi, which is a toolkit for Raspberry Pis to turn them into common IoT products via their GPIO pins.…
Read more ⟶

Shodan Stories Day 22: Raising Cow Fighting Squid in Yilan


I saw someone’s search for “Synology DiskStation” and even given our little foray into Synology back on day 20 I was ready to dive back into the world of the globe’s premier network attached storage maker. A Prototype of a Taiwanese Farm’s Website on 114.34.78.222 The DiskStation promises “personal cloud storage” which to me sounds just like a personal server you connect to the internet, but maybe I’m just old fashioned.…
Read more ⟶

Shodan Stories Day 21: POWERful Plates in Fargo, Digital Signage, Unsecured Pis, and the Cold Cold Midwest Winter


Today I saw someone searching for “Screenly OSE” and actually gave a description for their search saying “screenly ose for the pi, think of a billboard system”. So I gave it a go. A Raspberry Pi Digital Sign on 140.186.23.181 Screenly is a software for doing digital signage off of a Raspberry Pi. They have a “Pro” version for quite a bit of money ($20/month minumum but up to $800/month) and also an open source edition, which is what OSE stands for.…
Read more ⟶

Shodan Stories Day 20: υηκηοωη ιδεηեτγ in France, Private Telephone Exchanges, Network Attached Storage, and Getting Lost in the Matrix


Oh what a tangled web we weave. I’m not really sure what’s going on with this one or how I got here, I wanted to explore a search I had seen on Shodan called “3cx servers bcn” but now I’m trapped in a digital hall of mirrors. 3CX is a private telephone exchange that sometimes runs over VoIP, and has servers that typically tend to run on 5001. υηκηοωη ιδεηեτγ on 62.…
Read more ⟶