Shodan
Web siteWikipedia
23
MENTIONS
18
EPISODES
18
PODCASTS
Search complete. 23 mentions across 18 episodes found for "Shodan".
Sep 5, 2026
TWiRT Ep. 816 - Deciphering FCC EAS Cybersecurity Rules with Shane Toven
S
28:17Shane TovenGUEST
But, you know, there's still a lot of them out there with, you know, with default passwords just on public IP.
S
28:21Shane TovenGUEST
And you can hit them on Shodan and you can see them right there.
S
28:23Shane TovenGUEST
And if you can see it, so can somebody else, anybody on the Internet.
K
28:28Kirk HarnackHOST
Yes, exactly.
10 MINS LATER
K
38:51Kirk HarnackHOST
Indeed, the remote control interface uh... was was available on the public internet apparently with the default username and password and hackers got in change the arty s which you could generate it internal to the excited several excited slated to do that then that's fine as far as it goes but you gotta lock it down and protect so they get and they change the arty s to some filthy nasty thing and then they go change the password again and into the computer transmitter at all or or disable the existing password And the station is screwed until they get to the transmitter site.
K
39:29Kirk HarnackHOST
No, our
S
39:29Shane TovenGUEST
mutual good friend and colleague Jeff Welton from Nautel was literally just talking about this on one of his presentations the other day where he does a search on Shodan and a bunch of transmitters, whether they be from Gates Air or from Nautel or whatever.
S
39:43Shane TovenGUEST
And one of them, in fact, had already been changed to say, I've been hacked or something to that effect.
Risky Business #851 -- Agents are just ones and zeros, and tigers are just atoms
P
25:31Patrick GrayHOST
when people can't get their favorite brand of frozen pie at the military commissary, and that might, you know, sap their will to fight?
T
25:38The GrugqHOST
My take on this is, okay, it is possible that it's Iran or some other threat actor who's got this 5D chess approach, or hypothetically, it's a 20-year-old who found something on Shodan and clicked the button that said defrost, and then nothing happened, and they went away, and suddenly it's in the news, and they think it's hilarious.
P
26:03Patrick GrayHOST
Yes.
T
26:03The GrugqHOST
Like-
“Vulnerability Management: Beyond Scanners and Reducing Risk” by Carlos Lozano, CEO, Rent A Hacker (AA2565)
L
2:35Lorena RuizNARRATOR
As a result, a malicious user can actively exploit the vulnerability.
L
2:39Lorena RuizNARRATOR
24 hours doesn't seem like a lot of time, but in many cases the exploitation of these vulnerabilities can become something as simple as entering Shodan and doing a search of all vulnerable assets exposed to the internet and attacking them automatically.
L
2:54Lorena RuizNARRATOR
So 24 hours is no small matter at all.
L
2:57Lorena RuizNARRATOR
The next day, they again reviewed the information, and the results were again zero.
First days of PIF dominated by tensions between external partners
N
47:31Nicola KawanaGUEST
Nice.
N
47:32Nicola KawanaGUEST
Shodan,
A
47:33Aggie TupouHOST
where can our viewers or where can those who are here in Melbourne be able to come and see this piece then? Yeah.
S
47:39Shadon MeredithGUEST
Ah, Melbourne, yes.
RDP Security Best Practices Every Admin Ignores Until It's Too Late
M
15:41Mike SaylorGUEST
And then you've got the people that really understand what the value of that exposed service.
M
15:47Mike SaylorGUEST
And they're going to use tools like Shodan, which is a nefarious, it's not, it's a legitimate search engine, but it's a hundred percent used for bad stuff most of the time.
M
16:00Mike SaylorGUEST
So in Shodan, so in Google, you would say, what is RDP? In Shodan, you would say, show me every network that has RDP service exposed to the internet around the entire globe.
M
16:13Mike SaylorGUEST
And it will tell you.
M
16:15Mike SaylorGUEST
So it looks for those types of things.
The Stanislav Petrov Lesson for AI and Offensive Cyber
C
8:55Chase CunninghamHOST
We're not talking about open source information here.
C
8:57Chase CunninghamHOST
We're not talking about Googling and Shodan and stuff like that.
C
9:01Chase CunninghamHOST
We're talking about letting private companies literally get inside of someone else's systems and do recon work, the stuff that we did at TAO at NSA.
C
9:10Chase CunninghamHOST
OK, there are cyber effect operations as well, and this is where we sort of move from that to other things.
South Africa’s Tourism Boom, Iran Sanctions, Safer Communities & the Rise of AI-Powered Cybercrime
C
69:06Craig PetersonGUEST
Automation controllers need to be able to have internet access so that engineers can log on remotely to monitor them, to manage And that can expose us to dramatic vulnerabilities if that equipment is not kept up to date and properly secured and regularly tested.
C
69:23Craig PetersonGUEST
And we have seen plenty of online tools and data engines like Shodan where the Internet of Things is mapped out.
C
69:30Craig PetersonGUEST
And connected devices ranging from CCTV to sophisticated engineering equipment controllers are available and accessible online, and they're poorly secured.
C
69:39Craig PetersonGUEST
So that can create a major vulnerability, especially in emerging markets like South Africa, where the budget doesn't exist at the national level, then extraordinary amounts of money on security.
Hacking All The Devices, with AI? - Rob Allen - PSW #941
P
52:01Paul AsadoorianHOST
But they say the tools are disguised as legitimate OT monitoring software, read and write PLC memory, and they found these exposed devices via Sensus and ZoomEye, which are essentially...
P
52:19Paul AsadoorianHOST
Shodan-like sites.
P
52:22Paul AsadoorianHOST
Targeting blah, blah, blah, targeting everything that runs PLCs.
P
52:27Paul AsadoorianHOST
Notably, the advisory does not name a CVE, a threat actor, define indicators of compromise at all.
Hacking All The Devices, with AI? - Rob Allen - PSW #941
P
52:01Paul AsadoorianHOST
But they say the tools are disguised as legitimate OT monitoring software, read and write PLC memory, and they found these exposed devices via Sensus and ZoomEye, which are essentially...
P
52:19Paul AsadoorianHOST
Shodan-like sites.
P
52:22Paul AsadoorianHOST
Targeting blah, blah, blah, targeting everything that runs PLCs.
P
52:27Paul AsadoorianHOST
Notably, the advisory does not name a CVE, a threat actor, define indicators of compromise at all.
Hacking All The Devices, with AI? - Rob Allen - PSW #941
P
52:01Paul AsadoorianHOST
But they say the tools are disguised as legitimate OT monitoring software, read and write PLC memory, and they found these exposed devices via Sensus and ZoomEye, which are essentially...
P
52:19Paul AsadoorianHOST
Shodan-like sites.
P
52:22Paul AsadoorianHOST
Targeting blah, blah, blah, targeting everything that runs PLCs.
P
52:27Paul AsadoorianHOST
Notably, the advisory does not name a CVE, a threat actor, define indicators of compromise at all.
8 more episodes mention Shodan.
Create an account to see the whole feed, search across every transcript, and follow the entities you care about.