Shodan & Censys
Shodan and Censys are powerful OSINT tools designed for network discovery, enabling red teams to identify exposed devices, services, and potential vulnerabilities in target networks. This section demonstrates their practical use in authorized testing scenarios, focusing on querying public-facing infrastructure and extracting actionable intelligence.
Shodan for Network Discovery¶
Shodan is a search engine for internet-connected devices, indexing services like SSH, HTTP, FTP, and more. It allows querying by port, service, IP range, or vulnerability.
Basic Querying¶
Use the Shodan CLI (shodan) or API to search for exposed assets. For example:
shodan search "port:22" # Find SSH servers
shodan search "http.title:Apache" # Find Apache web servers
shodan search "vuln:unauthenticated" # Filter by known vulnerabilities
{
"ip": "192.0.2.1",
"port": 22,
"product": "OpenSSH 8.2",
"banner": "SSH-2.0-OpenSSH_8.2",
"org": "Example Corp"
}
--vuln flag can highlight vulnerabilities:Advanced Filters¶
Combine filters for precision:
shodan search "country:US city:New York" "http.title:WordPress" # Target specific regions
shodan search "ip:192.0.2.0/24" "ssl.version:TLS 1.0" # Check for outdated TLS
Censys for TLS and Service Discovery¶
Censys specializes in TLS/SSL certificate data and network services, making it ideal for analyzing encrypted traffic and identifying misconfigured servers.
Querying TLS Data¶
Use the Censys CLI (censys) to search for TLS configurations:
censys search "tls.cipher:suite:TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256" # Find specific ciphers
censys search "http.title:nginx" # Find Nginx servers
{
"ip": "192.0.2.2",
"tls": {
"server_name": "example.com",
"protocols": ["TLSv1.2", "TLSv1.3"],
"certificates": [
{
"subject": "CN=example.com",
"issuer": "CN=Let's Encrypt"
}
]
}
}
Filtering by IP/Port¶
Target specific ranges or ports:
censys search "ip:192.0.2.0/24" "port:443" # Check HTTPS servers in a range
censys search "service:http" "http.server:Apache" # Find Apache HTTP servers
Combining Shodan and Censys¶
For comprehensive network discovery, pair both tools:
1. Use Shodan to identify devices and services.
2. Use Censys to analyze TLS configurations or deeper service details.
Example Workflow:
# Find a server via Shodan
shodan search "title:MySQL" --output json > mysql_servers.json
# Use Censys to check TLS on those IPs
censys search "ip:192.0.2.1" "tls.version:TLS 1.0" # Check for weak TLS
Key takeaways¶
- Shodan excels at general network discovery, exposing devices and services.
- Censys specializes in TLS/SSL data, making it ideal for analyzing encrypted traffic.
- Combine both tools for a holistic view of target infrastructure.
- Always operate within authorized boundaries and respect legal/ethical guidelines.