Show HN: Personal IoT scanner and search engine
github.com
github.com
What's the legality of actually running something like this?
So it's great for finding web interfaces for DVR systems, printers, routers, obscure websites, etc. And it's good for collecting a random sample of host=>header data for research.
But it's not going to search for exposed database ports or other protocols unless someone wants to modify it for that purpose.
As far as the legality goes, it's probably on-par with something like nmap and will differ by region. However, it's only collecting the headers responded by a server voluntarily rather than probing all possible ports for exploits. In essence it's like typing random IP addresses into your browser until you get responses.
I've mainly been using it for sampling and exploration purposes. Like a bite-sized version of Shodan.