Habr•August 9, 2026•🇷🇺Translated from Russian

OSINT for the Lazy Part 16: Discovering Hidden Corporate Infrastructure Through Shodan

If the internet is compared to a large city, the visible part consists of main streets and side alleys that host official company websites, while the backyards, basements, and service entrances are where maintenance staff and potential intruders move. Shodan specializes in exploring exactly these hidden areas by indexing devices instead of web pages.

Unlike conventional search engines such as Google that crawl HTML content, Shodan catalogs internet-connected hardware including servers, IP cameras, databases, routers, administration panels, and IoT equipment. When administrators leave such systems exposed, analysts can discover valuable information about a company’s infrastructure.

1. Search by company domain

The simplest method uses the filter hostname:company.com. Results often reveal forgotten development, VPN, test, and API endpoints such as dev.company.com, vpn.company.com, test.company.com, and api.company.com.

2. Search by SSL certificates

The query ssl:"company.com" locates certificates that mention the target domain and frequently surfaces additional subdomains including jenkins.company.com, internal-api.company.com, and staging.company.com.

3. Search by ASN

Companies that own IP address blocks usually possess an ASN (Autonomous System Number). The filter asn:ASXXXX returns every device registered to that network, exposing servers, routers, and sometimes cameras.

4. Search by IP range

When the exact network block is known, the filter net:192.168.10.0/24 lists all devices inside the range, potentially revealing VPN services, SSH ports, Docker, Kubernetes, GitLab instances, and even internal databases.

5. Search for development infrastructure

Developers commonly use keywords such as dev, stage, staging, test, qa, beta, and internal. Queries like hostname:dev or hostname:staging can uncover unprotected development and staging environments.

6. Search for administration panels

Filters such as title:"Jenkins", title:"Grafana", and title:"Kibana" locate continuous-integration systems, monitoring dashboards, and other operational tools that sometimes remain accessible with default credentials.

7. Search for databases

Port-based queries including port:27017, port:6379, and port:9200 identify MongoDB, Redis, and Elasticsearch instances. Adding an organization filter can tie these services to the target company.

8–10. Cloud, organization, and IoT searches

Additional techniques cover cloud-hosted Docker and Kubernetes APIs, organization-name searches with org:"Company Name", and queries that surface corporate webcams, industrial controllers, and building-automation systems.

A practical five-step workflow combines hostname, SSL, organization, development-keyword, and service-title searches. In one documented case the search sequence led directly to an unprotected jenkins.dev.company.com instance containing CI pipelines, source repositories, and deployment keys.

Shodan does not exploit or attack any system; it merely displays services that are already reachable from the public internet. The most frequent reasons for exposure remain human error: forgotten test servers, temporary development environments, incorrectly configured firewalls, and rushed deployments that leave ports open.

Related articles

Habr•Other

macOS User Investigates Claude Regional Block via Logs and Restores Work Site Access with Targeted WireGuard Routes

A detailed case study describes how a macOS user analyzed Claude application logs after experiencing regional unavailability errors while using WireGuard VPN. The investigation covered ~/Library/Logs/Claude/ files containing markers like app-unavailable-in-region and region_unavailable, cross-referenced with tunnel activity dates from August to October 2026. No direct evidence linked the VPN to the account block, as tunnel logs were overwritten and system journals returned Operation not permitted errors. The user then addressed a secondary issue where WireGuard blocked access to work services including amoCRM, TGBooster, and Geekjob. Custom host routes were added via route add commands to direct specific IPv4 addresses through the local gateway while keeping Claude traffic in the tunnel. A launchd-based PF kill switch was tested for tunnel failure protection but caused a full internet outage on October 5 due to anchor and hook conflicts, leading to its rollback. By October 8, work sites functioned under VPN with verified routes, though persistent kill switch protection remained unresolved.

Habr•Other

Publishing Internal APIs from DMZ Without Direct LAN Connections: Five Tested Architectures

When an API gateway resides in the DMZ but security policies forbid outbound connections into the LAN, organizations must adopt alternative patterns to expose internal services synchronously. The article examines five production-ready approaches built on the NEOMSA APIM platform, ranging from custom request-reply logic over Kafka to zero-code solutions using ActiveMQ Artemis and experimental reverse HTTP in HAProxy. Each pattern is evaluated against criteria such as the need for DMZ-to-LAN firewall rules, volume of custom code, support for streaming responses, and measured performance. Load tests on the Artemis-based bridge reached 50 requests per second with a 95th percentile latency of approximately 100 ms, while the Kafka implementation required roughly 2,500 lines of Java to emulate missing reply semantics. The analysis highlights trade-offs in operational complexity, vendor support implications, and security posture, particularly the benefit of preventing any outbound initiation from the DMZ.

AntiMalware•Other

FSB in Chelyabinsk Region Proposes QR-Code Passports for Tracking Construction Materials to Combat Theft

The regional branch of Russia's Federal Security Service in Chelyabinsk has suggested introducing an electronic tracking system for construction materials using unique QR codes assigned to each batch. The initiative aims to reduce theft and fraud during the construction of social facilities by creating a verifiable digital record of material movement from supplier to site. According to official representative Tatyana Sosnina, the system would allow real-time comparison between ordered quantities, project documentation, and actual usage on site. This approach is expected to help customers and oversight bodies quickly identify discrepancies between procurement records and physical consumption. The proposal does not yet include any announced timelines or estimated implementation costs. Experts note that the effectiveness of such QR-based tracking will ultimately depend on the accuracy of data entry at every stage of the supply chain rather than on the codes themselves.

AntiMalware•Other

Russian Internet Services Hit by Outages After Drone Attack on Yandex Data Center in Sasovo

On October 8, multiple Russian websites and internal corporate systems experienced significant disruptions. Users reported issues accessing media outlets, transport services, and marketplaces, with many problems affecting internal company tools and professional platforms. Cian linked its website and app outage to an infrastructure partner incident, while developers A101, Granel, and Brusnika also faced temporary unavailability. T-Bank reported problems with its corporate messenger and email distributions, and similar internal system issues appeared at Ozon, Wildberries, and HSE. Astral warned of possible delays in electronic reporting and document management services. Yandex confirmed a fire at its Sasovo data center in Ryazan region following a drone attack, with no casualties but full shutdown of the facility. Experts note that not all complaints can be attributed to a single event due to varying scales of impact across companies.