HabrAugust 9, 2026🇷🇺Translated from Russian

OSINT for the Lazy Part 16: Discovering Hidden Corporate Infrastructure Through Shodan

If the internet is compared to a large city, the visible part consists of main streets and side alleys that host official company websites, while the backyards, basements, and service entrances are where maintenance staff and potential intruders move. Shodan specializes in exploring exactly these hidden areas by indexing devices instead of web pages.

Unlike conventional search engines such as Google that crawl HTML content, Shodan catalogs internet-connected hardware including servers, IP cameras, databases, routers, administration panels, and IoT equipment. When administrators leave such systems exposed, analysts can discover valuable information about a company’s infrastructure.

1. Search by company domain

The simplest method uses the filter hostname:company.com. Results often reveal forgotten development, VPN, test, and API endpoints such as dev.company.com, vpn.company.com, test.company.com, and api.company.com.

2. Search by SSL certificates

The query ssl:"company.com" locates certificates that mention the target domain and frequently surfaces additional subdomains including jenkins.company.com, internal-api.company.com, and staging.company.com.

3. Search by ASN

Companies that own IP address blocks usually possess an ASN (Autonomous System Number). The filter asn:ASXXXX returns every device registered to that network, exposing servers, routers, and sometimes cameras.

4. Search by IP range

When the exact network block is known, the filter net:192.168.10.0/24 lists all devices inside the range, potentially revealing VPN services, SSH ports, Docker, Kubernetes, GitLab instances, and even internal databases.

5. Search for development infrastructure

Developers commonly use keywords such as dev, stage, staging, test, qa, beta, and internal. Queries like hostname:dev or hostname:staging can uncover unprotected development and staging environments.

6. Search for administration panels

Filters such as title:"Jenkins", title:"Grafana", and title:"Kibana" locate continuous-integration systems, monitoring dashboards, and other operational tools that sometimes remain accessible with default credentials.

7. Search for databases

Port-based queries including port:27017, port:6379, and port:9200 identify MongoDB, Redis, and Elasticsearch instances. Adding an organization filter can tie these services to the target company.

8–10. Cloud, organization, and IoT searches

Additional techniques cover cloud-hosted Docker and Kubernetes APIs, organization-name searches with org:"Company Name", and queries that surface corporate webcams, industrial controllers, and building-automation systems.

A practical five-step workflow combines hostname, SSL, organization, development-keyword, and service-title searches. In one documented case the search sequence led directly to an unprotected jenkins.dev.company.com instance containing CI pipelines, source repositories, and deployment keys.

Shodan does not exploit or attack any system; it merely displays services that are already reachable from the public internet. The most frequent reasons for exposure remain human error: forgotten test servers, temporary development environments, incorrectly configured firewalls, and rushed deployments that leave ports open.

Related articles

AntiMalwareOther

Rostelecom Outage Triggers 29-Minute Mass Disruptions Across Russian Internet Services

A 29-minute failure in Rostelecom's data transmission network on August 6 caused widespread access problems to Russian online services. The operator quickly rerouted traffic to backup equipment, restoring normal operations without revealing the root cause. Users reported issues connecting to marketplaces, banks, social platforms, IT company services and other telecom providers. The majority of complaints originated from Rostelecom's own subscribers who experienced connection and service access failures. Although the incident remained brief and did not escalate into prolonged digital disruption, it highlighted the heavy reliance on a single major provider. The event demonstrated how even a short technical problem at a large operator can simultaneously affect access to stores, financial services and everyday online platforms.

HabrOther

Read-Only Utility Automates Detailed Audits of UserGate NGFW Firewall Policies

A cybersecurity specialist at Gazprom CPS developed a read-only utility to analyze large-scale UserGate NGFW firewall policies without making any configuration changes. The tool connects via the UserGate XML-RPC API to collect rules, statistics, zones, network lists, services, users, and groups, then normalizes the data into a unified model for analysis. It performs eleven independent checks grouped into lifecycle, overly permissive access, observability, and documentation categories, flagging rules that have not fired recently, allow management ports broadly, lack logging, or have empty descriptions. Results are exported to a navigable Excel report featuring a rules-by-checks matrix, human-readable object names, and editable manual verdicts such as OK, requires attention, or false positive. The first full run on a production policy with over 1000 rules and 4500 related objects took 24 minutes and highlighted 39 percent of rules for review, with more than half showing multiple red flags. The approach preserves the original snapshot in JSON for repeatable offline analysis and comparison over time.

AntiMalwareOther

Internet Outages Disrupt Access to Russian Websites and Applications Across Multiple Regions

Users in several Russian regions reported widespread connectivity problems where internet access appeared available but failed to load most domestic websites and online services. Affected areas include Saint Petersburg along with Nizhny Novgorod, Rostov, and Tyumen regions according to reports compiled by the Telegram channel Baza. Connections remained technically active yet produced repeated errors when attempting to reach Russian sites, mobile applications, and web-based platforms. The precise scale of the disruption remains undetermined and it is unclear whether the incidents stem from a single technical fault or simultaneous failures among multiple network operators. No official statements have been issued regarding the root causes or expected restoration timelines. Individuals affected continue to refresh pages and restart applications while waiting for services to recover.

HabrOther

Step-Up Authentication vs 2FA: Implementing Additional Verification for Sensitive Operations in Corporate Systems

Traditional two-factor authentication secures only the initial login, leaving active sessions vulnerable to misuse during sensitive tasks such as accessing payroll data. Step-Up Authentication addresses this by requiring extra verification at the moment of critical actions rather than at login. The article details how one project moved beyond standard Identity Provider features in WSO2 by building a dedicated PIN-code service and gateway-2fa microservice. This approach uses signed cookies with TTL controls and JWT cross-checks to enforce elevated trust levels without disrupting normal user flows. The solution aligns with Zero Trust principles and was monitored via Matomo and ELK for usage and performance metrics. Key implementation considerations include balancing TTL duration, encrypting stored PINs, and conducting load testing before deployment.