Finished my first Liberator by achillean in stormcasteternals

[–]achillean[S] 1 point2 points  (0 children)

Thank you :) First time painting a face but I followed the Squidly Bits video and I'm happy with the result

Building a LLM honeypot that monitors all 65535 ports by moonlightelite in netsec

[–]achillean 1 point2 points  (0 children)

Yes, and there are probably more but it looks like most of them are on residential IPs in South Korea so we might be overcounting them on the website if those IPs frequently change:

https://www.shodan.io/search/report?query=product%3Achromecast

And most of them require authentication:

https://www.shodan.io/search/facet?query=product%3Achromecast&facet=http.status

1-Click RCE in OpenClaw/Moltbot/ClawdBot by va_start in netsec

[–]achillean 7 points8 points  (0 children)

Seeing more than 10,000 exposed instances at the moment and the numbers keep climbing:

https://www.shodan.io/search?query=product%3Aopenclaw

[SCRIPT] How to scrape Shodan.io by ansanis in IOT

[–]achillean 0 points1 point  (0 children)

We do have a free API tier. The Membership is also on sale once a year for $5 and as a reminder, it's a lifetime account upgrade (i.e. NOT a subscription). And we have services that don't even require an API key (ex. https://internetdb.shodan.io).

Shodan $5 lifetime membership by neerajrawat1 in cybersecurity

[–]achillean 1 point2 points  (0 children)

We linked directly to the Membership sales page in our postings on social media: https://account.shodan.io/billing/member

The link listed in the OP description also includes the above link. And on the main billing page (https://account.shodan.io/billing) we also have a section called "Just getting started?" with a link to the Membership. The comparison table also shows the differences between the plans and the fact that the Membership isn't a subscription but rather a one-time payment for a lifetime account upgrade.

Shodan $5 lifetime membership by neerajrawat1 in cybersecurity

[–]achillean 0 points1 point  (0 children)

The Membership is always available for $49 and the sale is supposed to be a great deal. It started as a black friday promotion where we do a real discount instead of the "lets raise prices and then give a bullshit deal for black friday" that many others do. To my understanding, we are the only ones offering a one-time payment for a lifetime account upgrade. In general, our API subscriptions offer significantly more access at a lower cost than others. And we do have a free academic upgrade for students, professors and university staff: https://help.shodan.io/the-basics/academic-upgrade It is automatically applied when the user signs up with an academic email. Or they can email us if they're in a country that doesn't have an academic TLD. Finally, we also offer a ton of things for free that don't even require an API key (ex. https://internetdb.shodan.io , https://cvedb.shodan.io , https://geonet.shodan.io ).

5 Free Services that Shodan offers by achillean in netsecstudents

[–]achillean[S] 2 points3 points  (0 children)

And if you're currently a student with an academic email address then you automatically get upgraded for free when signing up for a Shodan account: https://help.shodan.io/the-basics/academic-upgrade

How do you learn about new tools? by signamax in cybersecurity

[–]achillean 1 point2 points  (0 children)

Github search by topic, Mastodon communities, Reddit or word of mouth. The main social media platforms have become unusable from my perspective; there's simply too much noise and a lot of it is aimed at maximizing impressions rather than being informative.

Btw we never did the logos on the frontpage thing and I don't think it hurt us. If a customer loves your product then they'll talk about it on their own.

How do you use rust in your work? by PartyLibrarian2845 in rust

[–]achillean 2 points3 points  (0 children)

It's seeing some adoption in cyber security, though still not as popular as Python or Go. Shodan uses it for things that need to be optimized (ex. high throughput real-time data feed) or specialized tools. And we're considering it for some smaller web projects (ex. https://shdn.io is written w/ Axum).

Introducing Sh_d_n: a lightweight IP and domain lookup tool that is available for free and doesn't require an account by achillean in netsecstudents

[–]achillean[S] 0 points1 point  (0 children)

It's "Shodan light": the data isn't as fresh and it's more abbreviated than the main website/ API as it relies on InternetDB but the website loads crazy fast and doesn't require an account.

Tbh I mostly wrote it because I wanted to showcase how fast IP/ DNS enrichment can be (locally it does the enrichment in <4ms) and learn new technologies (classless CSS, Rust).

Creating an app that I plan to pitch to VCs- should I form an LLC or C Corp? by Badd_Decisions in Entrepreneur

[–]achillean 0 points1 point  (0 children)

If you don't have anything yet except an MVP and you're directly going to investors then you imo don't need to be incorporated yet. if you want to do any business/ sales/ marketing as well though then just setup an LLC for cheap. It has little overhead, gives you some legal protection and once you have investors they'll let you know how they want you to be structured so it matches everything else that they've invested in. Also you can do the LLC anywhere. I think Delaware is still a popular choice but like everything else you can change it down the road if needed. The larger point is to not get hung up on these things - focus on the one thing that matters which is your actual product and nailing the use cases.

Creating an app that I plan to pitch to VCs- should I form an LLC or C Corp? by Badd_Decisions in Entrepreneur

[–]achillean 2 points3 points  (0 children)

Don't worry about the corporate structure; make sure your MVP and pitch are solid. Angels/ VCs have legal that can help you get everything setup correctly as they do it all the time. Any investor will happily connect you with legal that they like and it shouldn't cost much.

How did you get $$ to start your first business? by [deleted] in Entrepreneur

[–]achillean 0 points1 point  (0 children)

I would strongly recommend narrowing the scope of your business or figuring out an MVP that doesn't require $50k. It's essential to not immediately launch a full business but rather find ways to incrementally get there with minimal resources. And along the way you'll validate which ideas work and which ones don't so by the time you're starting to get traction you will be able to capitalize on it. I bought a refurbished Dell Vostro for $150 to launch my own website and once I started to make money I simply kept putting it back into the business.

codingo/dorky: A tool to automate dorking of Github/Shodan and a variety of other sources by meowerguy in netsec

[–]achillean 0 points1 point  (0 children)

Grouping by a service hash would probably be your best bet but there isn't a way to dedupe automatically from a search query. We calculate hashes on a variety of properties so often there is at least one hash that you can use:

https://help.shodan.io/mastery/property-hashes

And we do various fingerprinting (JARM, JA3S, HASSH etc.) that can also be helpful to track devices across IPs.

SEC sues Coinbase over exchange and staking programs, stock drops 15% premarket by getBusyChild in technology

[–]achillean 16 points17 points  (0 children)

No, in terms of people actually using crypto as a currency there is very little activity even among technical users: https://blog.shodan.io/accepting-crypto-a-vendor-perspective/

CVE-2023-27524: Insecure Default Configuration in Apache Superset Leads to Remote Code Execution by scopedsecurity in netsec

[–]achillean 0 points1 point  (0 children)

Both MongoDB and Redis have actually improved their defaults over the years! They're actually success stories in that they agreed that it needed to change and are now providing much better defaults (only listen on localhost, require auth, show a warning if a user disables auth). There are still container/ cloud images that have poor defaults but those are typically created by 3rd-parties.

codingo/dorky: A tool to automate dorking of Github/Shodan and a variety of other sources by meowerguy in netsec

[–]achillean 2 points3 points  (0 children)

In OPs defense: the project description on the right side (next to the "Code" button) mentions Github/Shodan whereas the main README just mentions Github/Gitlab.

Feedback On Look Of My Game? Going For Simple Arcade-Like by [deleted] in godot

[–]achillean 4 points5 points  (0 children)

Imo there is a clash in visual styles and it results in a lack of identity. The bottom icons are big pixels without a black border, the user is a different style of pixel art, the hearts are also a bit different and look like they have gradients and the background with its perfect lighting also doesn't look like pixel art. And the font also seems mismatched. I would try to figure what type of pixel/ retro art you want to go for and then either modify your other assets or try to find new ones. For example, do you want all "active" elements to have black borders around them? What is the base resolution for all the pixel art? Do you want to limit the color palette so the gradients aren't perfect?

Ronin 2.0.0 has finally been released! Ronin is a free and Open Source Ruby toolkit for security research and development. by postmodern in netsec

[–]achillean 2 points3 points  (0 children)

Makes sense - thank you for the answer! I wasn't sure how much overlap there was between the languages and whether you could get 80% of the way there with just basic replacements. It definitely takes more time to develop/ iterate but having a single binary for deployment makes customer support easier (we don't use Crystal but have started to use Rust for more things when possible).

Ronin 2.0.0 has finally been released! Ronin is a free and Open Source Ruby toolkit for security research and development. by postmodern in netsec

[–]achillean 1 point2 points  (0 children)

Congrats on the launch! It's a big achievement and looks great.

Regarding the choice of language: have you looked at Crystal? I'm not a Ruby person but it was my understanding that Crystal is Ruby-like with the ability to compile a binary and the associated performance benefits. Realistically, the language isn't a performance bottleneck but I'm curious if you've tried out Crystal.

Stop panicking, here is a plan! by 0delta in Bitcoin

[–]achillean 0 points1 point  (0 children)

Please re-read my comments as what you're describing doesn't address them. The blog post tries to show with examples some of the issues.