The personal blog of Alden.


Shodan Stories Day 19: Never Trust Me With The WiFi


Today I’m staying with a friend whose partner has a pretty serious media server set up (with 64TB! of content), and I thought I’d take a look to see if I could find it on Shodan. And sure enough I could! My Friend’s Media Server on 104.172.240.189 So I had previously seen a Plex service running on an IP back on day 9, but I didn’t investigate it too much because at the time I was focused on the irrigation system.…
Read more ⟶

Shodan Stories Day 18: Defaced Server in Walnut, Hacking in a Nutshell, These Jokes Don't Write Themselves!


In what I hope will become an infrequently regular feature I decided today to look for an already hacked server that had been defaced. I had found one in the process of defacement on my very first day, but the fully defaced ones are interesting largely because of the tags left by the hackers themselves. I’m a little nervous about drawing attention to myself by publishing hacker tags in plaintext (easily found via Google alerts) so I’ll mostly be doing that via images.…
Read more ⟶

Shodan Stories Day 17: An ATM in Perm, Russia and Just How Much Market Capture Does Windows 2000 Have Anyway?


Today I thought it might be fun to find an ATM, largely because I wanted to answer the question “why connect an ATM to the internet with a static IP?” I checked for past Shodan searches for ATMs to see if I could find anyone else looking for some so I would know what to look for, and I was able to find someone else looking for ATMs from a brand named NCR, which work over port 169.…
Read more ⟶

Shodan Stories Day 16: A Serbian Highway


I’m pretty busy today with Processing Day so I’ll keep today’s short. Shodan may be best known for finding strangers' webcams, but I hadn’t gone for one yet because early on in this project I decided that on days when I don’t have a lot of time I’d just find an unsecured webcam and grab a still image. Today is one of those days. Someone’s Webcam in Belgrade on 109.206.96.249 Running on port 8080, using Webcam 7.…
Read more ⟶

LocalNet Adventure LA!! Reference Page


You can download the slides here Hey All! This page exists to supplement my LocalNet Adventure!! workshop with a lot of technical background that I don’t directly address in the workshop. Hopefully even if you’re a command line pro you’ll find something new here. References and Resources American Artist’s Black Gooey Universe Dhruv Mehrota’s Othernet NYCMesh Dan Phiffer’s Occupy.here Wifi art of Third Space Collective France Telecom’s Minitel Alternate Reality Games (e.…
Read more ⟶

Shodan Stories Day 15: Deftly Avoiding Turning On A Stranger's Lights in Bologna, the Commercial Level ESP8266, Getting Too Close with WiGLE, and What's the Deal with Home Automation Anyway?


Another IoT home device today. At this point I’m picturing the people with these things basically having a Wallace and Gromit style lifestyle (note: I do have a wifi plug and yes this is my lifestyle). This one was inspired by another search I didn’t recognize, for “Sonoff”. A Sonoff wifi enabled plug on 87.20.184.148 Sonoff is a company that makes IoT plugs and switches, as well as a couple of models of IoT fans and light bulbs.…
Read more ⟶

Shodan Stories Day 14: Startling Strangers in Vreden, DIY Home Automation, and the German Word for Waking Up in the Middle of the Night with the Realization That You Left Your Server Unsecured


This is another find inspired by recent searches on Shodan. I saw searches “FHEM Home Automation” and I needed to know more. Fhem Home Automation Server on 85.190.248.171 Every single result for FHEM was from Germany. So I picked the first one and got going. Looking up FHEM first on Google I found that it is an open source server software for doing home automation, built in perl and meant to be run on any kind of full time 24 /7 computer, like a Raspberry Pi.…
Read more ⟶

Shodan Stories Day 13: Space X Email Server in Tokyo, No Not That Space X


In honor of my spending about six hours on an airplane today I decided to search Shodan for “satellite” and, giving myself over to fate, pick the first result without looking at it. The Email Server of a Long Defunct Conference at 163.44.163.77 Since I was inspired by the fact that my airplane is being serviced by satellite internet I was of course hoping that I would find the IP for a real actual space satellite, though I suspected I was more likely to find someone’s satellite internet router or satellite dish.…
Read more ⟶

Shodan Stories Day 12: Influencer to Brand Marketplace and Authentic Content Platform in St Louis, Damaging My Klout Score via Unauthorized API Calls, GraphQL IDEs, and the Center of the Internet


Today I saw a top search for something called “GraphQL”. Taking the bait on the unknown, I started looking. A Startup Named Zipline’s API Staging Space on 184.169.231.191 The first thing I noticed about GraphQL’s distribution on Shodan was that it was all in the US. The second was that it was, by a huge margin, all in Ashburn, Virginia. After doing a quick google search I figured out that this is certainly because Amazon has so many datacenters there (leading it to be cheekily referred to as the “center of the internet”), and every GraphQL service seemed to be running on an Amazon EC2 instance.…
Read more ⟶

Shodan Stories Day 11: Machine Learning in Beijing and the Mysteries of 126 and 163


Today I went looking for MongoDB databases. I used MongoDB back in Shawn Van Every’s servers class, I remember feeling pretty cool using a NoSQL database. Shodan indicated that MongoDB tends to work off of port 27017 so that’s where I started looking. The Shell of Someone’s Machine Learning Blog on 35.185.145.24 I picked one of the first results I found on Shodan. According to Shodan it’s located in Singapore and hosted on Google Cloud services.…
Read more ⟶