Find and analyze any reachable server and device on the internet
censys.io
censys.io
None of the programs had any contact information for the programmer or the company that owned the infrastructure.
It is hard to believe people are still putting their plants straight on the internet. Anyone can control any of the outputs which then control real equipment like 200 kV circuit breakers and disconnects, turbines, valves, conveyors, mixers, pumps, etc. If interlocks are implemented in the software as opposed to electrically or mechanically then they can be bypassed which could easily result in equipment damage, injury to personnel, or death.
If there'd been any contact information in the programs I definitely would have gotten in touch
Whether they would actually bother is another matter, of course.
I've consulted for things like hotel groups. Without fail, there are vendors selling this sort of thing, with instructions like "forward telnet port from the internet to our device".
You can try to push back, and sometimes you will be successful, but you can't blame a hotel manager for saying "well this is what they do for a living.. they would know best".
ics-cert@hq.dhs.gov
DHS can use the Censys search engine and find all the PLCs will open modbus ports just as easily as anyone else in the world!
I really encourage you to get involved and participate in this project by submitting feedback, especially if you are a researcher or work in this field. We're at the early stages of choosing technologies, but we'll need more voices to refine the ideas and help with the implementation. The more who contribute, the better. More info: https://caddy.community/t/the-caddy-telemetry-project/3224?u...
I have a Caddy server which showed up on Censys after searching by subnet.
"Censys was created in 2015 at the University of Michigan, by the security researchers who developed ZMap, the most widely used tool for Internet-wide scanning. Over the past five years, the team has performed thousands of Internet-wide scans, consisting of trillions of probes, and has played a central role in the discovery or analysis of some of the most significant Internet-scale vulnerabilities: FREAK, Logjam, DROWN, Heartbleed, and the Mirai botnet."
How does this compare with shodan.io?
Also that "discovery or analysis" qualifier is quite the qualifier. Shodan certainly qualifies for all of those vulns as well, with that qualifier.
It's just a frontend for their public datasets: https://censys.io/data
Shodan is more generalized and scans many different ports.
If you would like your host to be excluded from the Censys results, you can block traffic from the following subnets: 141.212.121.0/24 and 141.212.122.0/24. However, we would encourage you to consider whether this actually accomplishes what you are intending. Internet-wide scanning is pervasive and others will still find your host even if it's not listed in Censys. We will not censor specific hosts or certificates from the Censys results or historical datasets."
If I notify them that they are unauthorized to scan my networks, and they continue to scan them, have they violated the CFAA?
[1]: https://arstechnica.com/tech-policy/2017/08/court-rejects-li...
To do this on wan you need to run zmap which is considered mean.
On the other hand, if you have a small subnet, say, less than a /24, you might as well just nmap it yourself, and then you're also guaranteed to have the latest possible scan.
The details depend on how much the of advertised scan data enrichment they do, but you might for example ask how many vulnerable cable modems of a certain model there are in the network you are responsible for, and what ISP networks they are on.
2^32 / 10 mpps = 7 minutes.
2^120 / 10 mpps = 4e19 centuries.