شودان وأمثاله
شودان محرك بحث أطلقه جون ماذرلي عام 2009، لكنه لا يفهرس صفحات المواقع كما يفعل جوجل، بل يفهرس الأجهزة المتصلة بالإنترنت نفسها، كالراوترات والكاميرات والخوادم وأجهزة التخزين وأنظمة التحكم الصناعية، فيسجّل ما يعلنه كل جهاز عن نفسه ويتيحه لكل من يبحث.
كيف يعمل
- يختار عنوانًا ومنفذًاتعمل ماسحاته على مدار الساعة من مواقع كثيرة حول العالم، فيختار كل منها عنوانًا عشوائيًا على الإنترنت ومنفذًا عشوائيًا.
- يتصل بالجهازيحاول الاتصال بذلك المنفذ، فإن أجاب جهاز عرف أن فيه خدمة مفتوحة للإنترنت.
- يسجّل ما يعلنهيحفظ الرسالة التي تعرّف بها الخدمة نفسها، وفيها غالبًا اسم الجهاز وطرازه ونسخة برنامجه.
- يتيحه للبحثيضيف ما سجّله إلى فهرس يبحث فيه أي أحد بحسب الدولة أو نوع الجهاز أو المنفذ، ثم يعيد الكرّة حتى يمرّ على الإنترنت كله مرة في الأسبوع على الأقل.
حقائق بالأرقام
5 دقائقتكفي لتصل أغلب الماسحات المعروفة إلى أي جهاز جديد يتصل بالإنترنت، بحسب قياس أجرته GreyNoise عام 2024.
المصدر
45 دقيقةيحتاجها حاسوب واحد ليفحص عناوين الإنترنت كلها على منفذ واحد، وتنزل إلى نحو خمس دقائق باتصال أسرع، كما أثبت باحثو جامعة ميشيغان عام 2013.
المصدر
كل أسبوعيمرّ شودان على الإنترنت كله مرة على الأقل، بينما تعمل ماسحاته دون توقف.
المصدر
24 ساعةتكفي لتظهر التغييرات في نتائج شودان وCensys بعد رصدها، بحسب دراسة علمية نُشرت عام 2021.
المصدر
62زوجًا فقط من أسماء المستخدمين وكلمات المرور الافتراضية كانت كل ما احتاجه ميراي عام 2016 ليسيطر على مئات الآلاف من الكاميرات والراوترات.
المصدر
73,000كاميرا في 152 دولة بثّها موقع واحد عام 2014 لأن أصحابها لم يغيّروا كلمة مرور المصنع، وبقي أكثر من ألفين منها متاحًا حتى عام 2025.
المصدر
ليس شودان وحده
ويعمل بالطريقة نفسها محركات أخرى كثيرة، منها Censys الذي أسسه عام 2015 باحثو جامعة ميشيغان أنفسهم الذين صنعوا أداة ZMap، وBinaryEdge من أوروبا، وZoomEye وFOFA من الصين، إضافة إلى عشرات الجهات التي تمسح الإنترنت يوميًا لأغراض البحث والأمن.
ShodanCensysZoomEyeFOFABinaryEdgeONYPHENetlas
هذه المحركات لا تخترق شيئًا، بل تُظهر ما هو مكشوف أصلًا، فإذا اجتمع في جهاز منفذ ممرَّر إلى الإنترنت وكلمة مرور مصنع صار في متناول كل من يبحث، وهذا ما يكشفه سُور من داخل بيتك قبل أن تجده هذه المحركات من خارجه.
ماذا تفعل
- لا تمرّر منافذ أجهزتك إلى الإنترنت، وعطّل UPnP في الراوتر إن لم تحتجه
- غيّر كلمة مرور المصنع في كل جهاز فور تركيبه
- حدّث برامج الراوتر والكاميرات وأجهزة البث باستمرار
- افحص شبكتك من الداخل بسُور، وابحث في شودان عن عنوان بيتك أنت فقط لترى ما سجّله عنه
لا يتصل سُور بهذه المحركات ولا يرسل إليها شيئًا، بل يرى من داخل شبكتك ما قد تراه هي من خارجها.
مصادر هذا القسم
Shodan and the others
Shodan is a search engine John Matherly launched in 2009, but it does not index web pages the way Google does. It indexes the devices connected to the internet themselves, such as routers, cameras, servers, storage and industrial control systems, and records what each one announces about itself so anyone can search it.
How it works
- Picks an address and a portIts scanners run around the clock from many places in the world, each picking a random internet address and a random port.
- Connects to the deviceIt tries that port, and if a device answers, it knows there is a service open to the internet.
- Records what it announcesIt keeps the message the service introduces itself with, which usually names the device, its model and its software version.
- Makes it searchableIt adds the record to an index anyone can search by country, device type or port, then starts again, covering the whole internet at least once a week.
The facts in numbers
5 minutesis enough for most known scanners to reach a new device that comes online, according to a 2024 measurement by GreyNoise.
Source
45 minutesis all one computer needs to scan every internet address on one port, and a faster link brings it to about five, as University of Michigan researchers showed in 2013.
Source
Every weekShodan covers the whole internet at least once, while its scanners never stop.
Source
24 hoursis enough for changes to show up in Shodan and Censys results once seen, according to a 2021 academic study.
Source
62default username and password pairs were all Mirai needed in 2016 to take over hundreds of thousands of cameras and routers.
Source
73,000cameras in 152 countries were streamed by a single website in 2014 because their owners never changed the factory password, and over two thousand were still accessible in 2025.
Source
Not only Shodan
Many other engines work the same way, among them Censys, founded in 2015 by the same University of Michigan researchers who built ZMap, BinaryEdge from Europe, and ZoomEye and FOFA from China, alongside dozens of organisations that scan the internet every day for research and security.
ShodanCensysZoomEyeFOFABinaryEdgeONYPHENetlas
These engines break into nothing. They show what is already exposed. When a device has a port forwarded to the internet and a factory password, it is within reach of anyone who searches, and that is what Soor finds from inside your home before these engines find it from outside.
What to do
- Do not forward your devices' ports to the internet, and turn off UPnP on the router if you do not need it
- Change the factory password on every device as soon as you set it up
- Keep the router, cameras and streaming boxes updated
- Check your network from inside with Soor, and look up your own home address on Shodan, only yours, to see what it has recorded
Soor never contacts these engines or sends them anything. It sees from inside your network what they might see from outside.
Sources for this section