Sinisterly
Everything you need to know about shodan - part 2 - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Tutorials (https://sinister.li/Forum-Tutorials)
+--- Thread: Everything you need to know about shodan - part 2 (/Thread-Everything-you-need-to-know-about-shodan-part-2)



Everything you need to know about shodan - part 2 - m0nk1337 - 02-22-2021

hello guys, lets continue our shodan posts.

so today we will discuss that what information does shodan gets from SSL. Nowdays every website must have SSL otherwise search engines will give a warning before we cam access the website so SSL is very important source of information for shodan so lets dig in further to know what information ssl contains.

the first thing is version, shodan crawler tries to connect with the server will all the SSL versions like TLSV1, SSLV3, TLSV1, SSLV2 etc and then it tells which version does the ssl service supports. it is made available in the ssl.version field of shodan search and it looks like this :

ssl {
version : [ "TLSV1", " -SSLV2" ]
}

if a version from that list has a - sign this means that the service doesn't supports that version

the next is logjam info, shodan tries to connect to ssl using diffie-hellman cipher and then gets the info like public_key, bits, fingerprint etc

the last and my favourite one is Vulnerability info. The shodan automatically tests the SSL for vulnerabilities and tells if it is vulnerable or not to any SSL vulnerability.

lets take example of heartbleed vulnerability (CVE-2014-0160)

Shodan automatically tests servers for heartbleed vuln which is an ssl based vuln.

if you want to find sites vulnerable to SSL based attacks then you can use the vuln: tag with a cve

for example to find sites with heatbleed vulnerability then search for vuln:CVE-2014-0160

Thats all for today guys we will discuss advanced thing now as the basics are already cleared. Thankyou