Nicholas TongShodan Membership
56 / 56
the search engine that still lists the port I closed
"SSH-2.0-OpenSSH_8.9p1 Ubuntu, port 22, last seen three weeks ago." That result is sitting in Shodan's index right now, attached to bayou-1, the $4 Dallas VPS I wrote about in the Tailscale post. I closed port 22 on that box weeks ago, moved SSH behind the VPN, deleted the forward, and told the internet I'd done so. Shodan kept showing the banner anyway, with a last-seen date well after the closing, which made me stand up from my chair for a second. The week on that date was also the week I finally replaced the UPS battery under bayou-1, which is the only reason I can date my side of it at all.
The banner was stale. I logged into the box and nothing was listening on 22, spent one of the membership's scan credits from outside and got the same silence, and the panic lasted about four minutes. But that result page taught the whole review in one screen: Shodan is an inventory of what the internet saw, on the day it looked. It is not live truth, and it is not a hacking tool. It's a record, and records lag, and the lag is a security lesson all by itself.
the part everyone gets wrong
The framing people bring to this site was set by a CNN Money headline in April 2013: "the scariest search engine on the Internet." Thirteen years later it's still the frame, and it's wrong in both directions. Shodan doesn't break into anything. It rings the doorbell of every reachable device on the planet, writes down what the doorbell sees, the software banners, the open ports, the protocol handshakes that advertise themselves, and lets you search the notebook. Everything in it was collected by asking, politely, over the public internet, the way any scanner does. The scary part was never the search engine. The scary part is what the notebook says: hundreds of thousands of services that answer a stranger's handshake and tell it what they are.
Calling it useless reconnaissance is the opposite error, and the bug bounty crowd knows better. For recon, Shodan is the outside view of an organization: which networks they own, what's listening on their edges, which services were deployed and forgotten. My recon routine starts there, and $49 once is the cheapest ticket in security I know of.
what forty-nine dollars actually buys
The membership is a one-time $49 payment, and per the billing page, archived because the live one blocks automated fetching, it comes with 100 query credits a month, 100 scan credits a month, and the ability to watch 16 IP addresses for changes. The scan credits are the part I use most: you can ask Shodan to look at your own address on demand, today, instead of waiting for its crawler's schedule. For comparison, the subscription API plans run $69, $359, and $1,099 a month, and those are for people doing this professionally at scale. The one-time membership covers me, my lab, my parents' network, and bayou-1, with credits to spare.
Running that check on your own edge takes an afternoon the first time and fifteen minutes a quarter after that. Enumerate what you think is public. Search your IP ranges and your hostnames. Compare the answer to what you believe, and the gap between those two lists is your actual security review. When I ran mine properly, the stale SSH banner was the headline, and the fact that I had to learn about its staleness from a third party was the real finding: I had been telling people for years to run an outside-in check, and I hadn't run my own in over a year. The advice was fine. My compliance with it wasn't.
Where the product shows its age, and I want to be fair here: the blog hasn't been updated since August 2024, the Honeyscore prototype feature threw an HTTP 522 error when I tried it in early October, and the documentation pages disagree with each other about which plan includes the tag:ics filter, which as far as I can tell needs the enterprise tiers, not the $49 membership. This is a small company that built a thing in 2009 and has mostly left it alone. For a search index, that's stability. For the features page, it's gentle rot.
the water plants never look
Shodan's own industrial control systems page catalogs what the notebook says about OT: Modbus, S7, DNP3, BACnet, and it notes that Modbus devices can be found and accessed without requiring any authentication, which matches everything I wrote about the CLICK PLC last week. The protocol has no login. Finding one on the public internet is finding a door with no lock and no frame.
In January 2024, someone using the handle CARR manipulated the screens and setpoints at small municipal water systems in Muleshoe and Abernathy, Texas, towns with water departments smaller than most IT staffs, and claimed tank overflows on video. The Treasury Department sanctioned two CARR members on July 19, 2024. In December 2025, CISA advisory AA25-343A described the mechanism used by groups like these: brute-forcing credentials on HMIs exposed to the internet through remote access protocols like VNC. No zero-days. Default or weak passwords, on systems findable with a public search engine, in towns that share an operator between them.
The people who most need to read Shodan are the people who never have. A water system operator who searches their own utility's address and finds their HMI listed is having the best bad day of their career, because the listing is a discovery that costs a phone call, and not having the listing costs a boil notice. I've kept the framing careful here on purpose: exposure is not compromise. But exposure with a password brute-forceable from anywhere is the first step of compromise, and small systems are exactly the ones without a security team to notice either one. This is the infrastructure nobody budgets for, which is why I keep writing about it.
run it against yourself first
- Spend one of the 100 monthly scan credits on your own IP before you search anything else. The outside view is the only view that doesn't flatter you.
- Search your domains, your IP ranges, your organization name. Shodan indexes banners, ports, and certificates, and each one is a different way to find the thing you forgot.
- When a result surprises you, verify from inside the box before you assume compromise or relief. My SSH banner was stale inventory, and the four minutes of panic were cheaper than the year of not checking.
- Set up monitoring on the 16 watchable IPs you care about, so changes come to you instead of waiting for a quarterly check to catch them.
- If you run anything OT, even a lab: put it behind a VPN, put authentication in front of it, and then search Shodan for it anyway. The notebook is the ground truth other people see.
That stale banner stayed in the index for a while, then quietly disappeared on one of the crawler's later passes, which is how the internet forgives: not with apologies, just with a schedule.
The scariest search engine in the world is the one that knows your network better than you do. For $49, the cheap move is to be that person.