مجموعة من استعلامات بحث Censys الرائعة والغريبة.
هل وجدت استفسارًا رائعًا؟ أرسله هنا
هل أنت مهتم بالمساهمة بطريقة أخرى؟ راجع المبادئ التوجيهية المساهمة
services.service_name: {BACNET, CODESYS, EIP, FINS, FOX, IEC60870_5_104, S7, MODBUS}
services.tls.certificates.leaf_data.subject.common_name: "Prismview" or services.http.response.headers.server: "Prismview Player"
(same_service(port: 10001 and banner: "IN-TANK INVENTORY" ) or services.service_name: ATG) and services.truncated: false
نصيحة احترافية : قم بإضافة
services.truncated: false
إلى استعلامك لاستبعاد مصائد مخترقي الشبكات (المضيفون الذين لديهم أكثر من 100 خدمة).
same_service(http.response.headers.server: "gSOAP/2.8" and http.response.headers.content_length: 583)
services.http.response.html_title: "CAREL Pl@ntVisor"
services.banner: "[1m[35mWelcome on console"
services.http.response.headers.server: "EIG Embedded Web Server"
services.http.response.html_title: "XZERES Wind"
ملاحظة : يعمل هذا الاستعلام بشكل أفضل مع المضيفين الظاهريين المضمنين.
services.http.response.html_title: "Nordex Control" or services.tls.certificates.leaf_data.issuer.domain_component: "NORDEX-AG"
services.software: (vendor: "Saferoads" and product: "VMS" )
services.tls.certificates.leaf_data.issuer.common_name: "Roomba CA"
services.http.response.headers.Www_Authenticate: `Basic realm= "Mein Automower (Robonect Hx+)" `
services.banner: "WinAQMS Data Server" and services.truncated: false
services.http.response.html_title: "Emerson Site Supervisor"
services.http.response.html_title: "'BrightSign®"
same_service(services.http.response.headers.Server= "CAL1.0" and services.http.response.status_code: 200)
services.http.response.headers.set_cookie: "NethixSession"
services.service_name: MIKROTIK_BW and services.pptp.hostname: "HACKED"
services.certificate: {
"64257fc0fac31c01a5ccd816c73ea86e639260da1604d04db869bb603c2886e6" ,
"87f2085c32b6a2cc709b365f55873e207a9caa10bffecf2fd16d3cf9d94d390c"
}
or services.tls.certificates.leaf_data.issuer.common_name: "Major Cobalt Strike"
or services.tls.certificates.leaf_data.subject.common_name: "Major Cobalt Strike"
services.http.response.html_title: "Metasploit" and (
services.tls.certificates.leaf_data.subject.organization: "Rapid7"
or services.tls.certificates.leaf_data.subject.common_name: "MetasploitSelfSignedCA"
)
or services.jarm.fingerprint: {
"07d14d16d21d21d00042d43d000000aa99ce74e2c6d013c745aa52b5cc042d" ,
"07d14d16d21d21d07c42d43d000000f50d155305214cf247147c43c0f1a823"
}
services.http.response.headers.server: "NessusWWW"
or services.tls.certificates.leaf_data.subject.organizational_unit: "Nessus Server"
services.http.response.html_title: "Welcome to ntopng"
or same_service(
services.http.response.html_title: "Global Traffic Statistics"
and services.http.response.headers.server: "ntop/*"
)
services.jarm.fingerprint: "29d21b20d29d29d21c41d21b21b41d494e0df9532e75299f15ba73156cee38"
same_service(port: 7443 and tls.certificates.leaf_data.subject.organization: "Mythic" )
ملحوظة : عند استخدام عامل الخدمة
same_service
، فإنservices.
البادئة اختيارية.
services.jarm.fingerprint: "00000000000000000041d00000041d9535d5979f591ae8e547c5e5743e5b64"
same_service(
http.response.body: { "Blazor" , "covenant.css" }
and tls.certificates.leaf_data.issuer.common_name: "Covenant"
)
same_service(
services.tls.certificates.leaf_data.subject.common_name= "P18055077" and
services.tls.certificates.leaf_data.subject.province= "Minnesota" and
services.tls.certificates.leaf_data.subject.locality= "Minnetonka" and
services.tls.certificates.leaf_data.subject.organization= "Pajfds" and
services.tls.certificates.leaf_data.subject.organizational_unit= "Jethpro"
)
same_service(
services.tls.certificates.leaf_data.pubkey_bit_size: 2048 and
services.tls.certificates.leaf_data.subject.organization: /(ACME|Partners|Tech|Cloud|Synergy|Test| Debug )? ?(co|llc|inc|corp|ltd)?/ and
services.jarm.fingerprint: 3fd21b20d00000021c43d21b21b43d41226dd5dfc615dd4a96265559485910 and
services.tls.certificates.leaf_data.subject.country: US and
services.tls.certificates.leaf_data.subject.postal_code: /<1001-9999>/
)
ملاحظة : يستخدم هذا البحث regex ويتطلب حسابًا مدفوعًا.
نصيحة احترافية : حاول إزالة JARM للعثور على المزيد من مثيلات Sliver.
services.jarm.fingerprint: "20d14d20d21d20d20c20d14d20d20daddf8a68a1444c74b6dbe09910a511e6"
services.http.response.body_hash= "sha1:1a279f5df4103743b823ec2a6a08436fdf63fe30"
same_service(
services.http.response.body_hash: { "sha1:bc517bf173440dad15b99a051389fadc366d5df2" , "sha1:dcb32e6256459d3660fdc90e4c79e95a921841cc" }
and services.http.response.headers.expires: 0
and services.http.response.headers.cache_control: "*"
)
services.banner_hashes: "sha256:7987d0c39c4839572ab88c6d82da01395f74e0c31f12d94c58d0e1bed0b0c75c"
services.http.response.headers.Server: "NimPlant C2 Server" or services.http.response.body_hashes: "sha256:636d68bd1bc19d763de95d0a6406f4f77953f9973389857353ac445e2b6fff87"
services.tls.certificates.leaf_data.subject_dn: "C=CN, L=HangZhou, O=Alibaba (China) Technology Co.\, Ltd., CN=*.aliyun.com"
services.tls.certificates.leaf_data.subject.common_name: "AsyncRAT Server"
services.tls.certificates.leaf_data.subject.common_name: "BitRAT"
services.tls.certificates.leaf_data.subject.common_name: { "Orcus Server" , "OrcusServerCertificate" }
services.tls.certificates.leaf_data.subject.common_name: { "Anony96" , "Quasar Server CA" }
services.tls.certificates.leaf_data.subject.common_name: "unk"
services.tls.certificates.leaf_data.subject.common_name: "DcRat Server"
same_service((services.http.response.html_title= "Deimos C2" or services.tls.certificates.leaf_data.subject.organization= "Acme Co" ) and services.port: 8443)
services.tls.certificates.leaf_data.subject_dn: "C=US, ST=Minnesota, L=Minnetonka, O=Pajfds, OU=Jethpro, CN=P18055077"
services.tls.certificates.leaf_data.subject_dn: "CN=localhost, C=AU, ST=Some-State, O=Internet Widgits Pty Ltd"
services.tls.certificates.leaf_data.issuer_dn: "C=XX, ST=1, L=1, O=1, OU=1, CN=*"
same_service(services.http.response.headers.Etag= "" aa3939fc357723135870d5036b12a67097b03309 "" and services.http.response.headers.Server= "nginx/1.13.8" ) or same_service(services.tls.certificates.leaf_data.issuer.organization:/[a-zA-Z]{10}/ and services.tls.certificates.leaf_data.subject.organization:/[a-zA-Z]{10}/ and services.tls.certificates.leaf_data.subject.organizational_unit= "CONTROL" )
ملاحظة : يستخدم هذا البحث regex ويتطلب حسابًا مدفوعًا.
services.banner= "HTTP/1.1 401 UnauthorizedrnServer: Microsoft-IIS/7.5rnDate: <REDACTED>rnContent-Type: text/htmlrnWWW-Authenticate: NTLMrnContent-Length: 0rn"
services.http.response.body: "Titan Stealer"
same_service(
(services.http.response.html_title: "Index of /" or services.http.response.html_title: "Directory Listing for /" )
and services.http.response.body: /.*?(cve|metasploit|cobaltstrike|sliver|covenant|brc4|brute-ratel|commander-runme|bruteratel|ps2exe|(badger|shellcode|sc|beacon|artifact|payload|teamviewer|anydesk|mimikatz|cs|rclone).(exe|ps1|vbs|bin|nupkg)).*/
)
ملاحظة : يستخدم هذا البحث regex ويتطلب حسابًا مدفوعًا.
services.software.product: "Splunk"
services.http.response.body: ' "couchdb" : "Welcome" '
same_service(services.http.response.html_title=`cAdvisor - /` and services.http.response.status_code=200 and services.http.request.uri= "*/containers/" )
same_service(services.http.response.html_title=`Consul by HashiCorp` and services.http.request.uri: "*/ui/" )
same_service(services.http.response.headers.Server= "Netdata Embedded HTTP*" and services.http.response.html_title= "netdata dashboard" )
same_service(services.http.response.headers.unknown.name: "X-Rancher-Version" and services.http.response.html_title: "Loading…" )
same_service(services.http.request.uri: "*/dashboard/" and services.http.response.html_title: "Traefik" )
same_service(services.http.response.html_title: "Weave Scope" and services.http.response.body= "*WEAVEWORKS_CSRF*" )
same_service(banner: "Counter-Strike" and service_name: VALVE)
services: (port: 30120 and http.response.headers: (key: "Location" and value.headers: "https://cfx.re/join/*" ))
services.software.vendor: "Plex"
services.software.vendor: "Jellyfin"
services.http.request.uri: "mythweb"
services.banner: "$GPRMC"
services.http.response.html_title: "Index of /"
services.http.response.html_title: "Swagger UI - "
services.http.response.html_title: "Home - Mongo Express"
services.http.response.html_title: "shell2http"
same_service(services.banner: "Enter 'help' for a list of built-in commands" and services.service_name: TELNET) and services.truncated: false
services.redis.ping_response: "PONG"
services.kubernetes.pod_names: *
services.http.response.body: "The wp-config.php creation script uses this file"
same_service(services.http.response.html_title: "Setup AdGuard Home" and services.http.request.uri= "*/install.html" )
same_service(services.http.response.html_title: "node exporter" and services.http.response.body: "/metrics" )
services.http.response.body: "<h2>vmagent</h2>"
same_service(http.response.html_title: "SonarQube" and http.response.status_code: 200 and http.response.protocol: "HTTP/1.1" )
ip: "2001::/3"
services.truncated: true
location.country: "North Korea"
dns.names: *.gov or dns.names: *.mil or name: *.gov or name: *.mil
same_service(services.port: 53 and not services.service_name: DNS) and services.truncated: false
بناء الجملة البديل دون
services.
البادئة داخل وظيفةsame_service
:same_service(port: 53 and not service_name: DNS) and services.truncated: false
same_service(services.port: {21, 22, 80} and not services.service_name: {HTTP, SSH, FTP, UNKNOWN}) and services.truncated: false
same_service(services.port: 22 and not services.service_name: {SSH} and not services.banner: { "Connection refused" , "SSH-" , "Exceeded MaxStartups" , "Too many users" , "Connection closed by server" }) and services.truncated: false
not same_service(services.port: 443 and services.name: UNKNOWN and services.tls.certificates.leaf_data.subject_dn: *) and same_service(services.port: {80, 443} and not services.service_name: {KUBERNETES, ANYCONNECT, OPENVPN, HTTP} and not services.banner: “HTTP/”) and services.truncated: false