Tryhackme-Shodan.io

Shodan.io

Task1 Introduction

Go to Shodan.io

Task2 Filters

How do we find Eternal Blue exploits on Shodan?

vuln:ms17-010

Task3 Google & Filtering

ping google.com得到谷歌的IP为142.250.200.142,使用谷歌的IP在Autonomous System Lookup (AS / ASN / IP) | HackerTarget.com查找IP对应的ASN,得到ASN为15169

image-20210917111708978

1.What is the top operating system for MYSQL servers in Google’s ASN?

5.6.40-84.0-log

shodan搜索 asn:AS15169 product:MySQL

image-20210917112558763(作者创建房间时的TOP Version是5.6.40-84.0-log)

2.What is the 2nd most popular country for MYSQL servers in Google’s ASN?

Netherlands

image-20210917112837195

3.Under Google’s ASN, which is more popular for nginx, Hypertext Transfer Protocol or Hypertext Transfer Protocol with SSL?

Hypertext Transfer Protocol

比较搜索 asn:AS15169 product:Nginx port:80 得到23662条结果和 asn :AS15169 product:Nginx port:443 得到223321条结果,Nginx更多使用HTTP协议(Hypertext Transfer Protocol)

4.Under Google’s ASN, what is the most popular city?

Mountain View

谷歌是美国企业,搜索 asn:AS15169 contry:us

image-20210917113450363

5.Under Google’s ASN in Los Angeles, what is the top operating system according to Shodan?

PAN-OS

搜索 asn:AS15169 city:“Los Angeles”

image-20210917113556761

6.Using the top Webcam search from the explore page, does Google’s ASN have any webcams? Yay / nay.

nay

搜索webcam asn:AS15169

image-20210917114041557

Task4 Shodan Monitor

What URL takes you to Shodan Monitor?

https://monitor.shodan.io/dashboard

Task5 Shodan Dorking

What dork lets us find PCs infected by Ransomware?

has_screenshot:true encrypted attention

Task6 Shodan Extension

This will be nice for bug bounties!

Task7 Exploring the API & Conclusion

is will be nice for bug bounties!

Task7 Exploring the API & Conclusion

Read the blog post above!

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值