SlideShare a Scribd company logo
4
Most read
6
Most read
8
Most read
ICS/SCADA/PLC Google/Shodanhq Cheat Sheet




  Gleb Gritsai, Alexander Timorin, Yuri Goltsev, Roman Ilin



               http://scadastrangelove.org/
vendor                product                      google dork                 network info

Siemens     S7-200
                                                                    all models: tcp/udp/102 (by vuln info)




            S7-300                                                  snmp: Siemens, SIMATIC, S7




            S7-3** , PCS7          inurl:/Portal0000.htm            http: /S7Web.css



            Simatic S7                                              snmp: Siemens, SIMATIC S7, CPU-1200
                                                                    Siemens, SIMATIC S7, CPU317-2 PN/DP
                                                                    Siemens, SIMATIC S7, CPU315-2 PN/DP
Siemens, SIMATIC S7 ***

                                      inurl:"Portal/Portal.mwsl"   http: /S7Web.css




Automation License Manager                                         tcp/4410 (by vuln info)




Scalance S,X Security Module firewall                              telnet: Simatic, Scalance
                                                                   snmp: Scalance S*, Scalance W*,
                                                                   Scalance X*
                                                                   DCP protocol (by vuln info)
                                                                   tcp/80




                                                                   netbios: WINCC_SRV21 <0x0>
                                                                   SIEMENS <0x0>
Wincc flexible                                                     WINCC_SRV21 <0x20>
Wincc flexible runtime / TIA Portal                                tcp/2308 (by vuln info)
                                                                   tcp/50523 (by vuln info)
Synco OZW (Web server)                                                       http




SIMATIC HMI Miniweb      intitle:"Miniweb Start Page" | "/CSS/Miniweb.css"   http: /CSS/Miniweb.css




Simatic HMI                                                                  snmp: Siemens, SIMATIC HMI, ***




                                                                             telnet:Welcome to the Windows CE
                                                                             Telnet Service on HMI_Panel
vendor                  product                                google dork                                   network info




               DeltaV and DeltaV
               Workstations/DeltaV
Emerson        ProEssentials Scientific Graph                                                      tcp/udp/111 (by vuln info)



               DeltaV Service Information
               System Ver3.3



   vendor                  product                                google dork                                   network info

Allen-Bradley
Rockwell Automation



               ControlLogix                                                                        tcp/udp/44818 , http
               CompactLogix                     intitle:"Rockwell Automation" "Device Name" "Uptime"
PLC5                                                                http, snmp




                                            inurl:dtm.html intitle:1747-L552
                 SLC-5                      inurl:dtm.html intitle:1747-L551         http, snmp

                 Micrologix                 inurl:home.htm intitle:1766              http, snmp




   vendor                     product                         shodanhq dork                       network info
Schneider Electric



                 PM820SD                    Schneider Electric - PM820SD port:161




                 PM870SD                    Schneider Electric - PM870SD port:161
                 ECC21                      Schneider Electric - ECC21 port:161
                 EGX100MG                   Schneider Electric - EGX100MG port:161



                 PowerLogic PM800           PowerLogic PM800 port:80

                 PowerLogic ION8650 A/B/C   ION8650
PowerLogic ION8650 A/B/C)   8650 ION




PowerLogic ION8600          8600 ION



PowerLogic ION7650/7550     ION 7550


PowerLogic ION7650/7550     ION 7650

PowerLogic ION7300          ION 7300

PowerLogic ION6200          ION6200

PowerLogic PM1200           PM1200

PowerLogic DM6200           DM6200

Powerlogic Enercept

Powerlogic Energy Meter

PowerLogic Branch Current
Monitor                     BCM42

PowerLogic EM4800
PowerLogic E5600

                 PowerLogic Ethernet Gateway
                 (EGX)                         EGX100

                 PowerLogic EGX300             EGX300

                 PowerLogic ION7550RTU         ION 7550RTU
                                               schneider electric




   vendor                     product                               google dork          network info
Schneider Electric
                 Modicon                       intitle:"Quantum CPU Web Server"
                 Quantum/Premiun/Micro         intitle:"Premium CPU Web Server"

                                               intitle:"Citect Web" inurl:scada
                 CitectSCADA                   filetype:htm
                 CitectFacilities




                                               shodanhq: ClearSCADA
                                               "ViewXCtrl is not supported in this web
                                               browser."
                 ClearSCADA                    intitle:"ClearSCADA Home"


                 UnitelWay Device Driver
Vijeo Historian Web Server   several products




             Modicon M340                                                                snmp: "Modicon M340"




    vendor                product                             google dork                           network info
General
Electric

             Cimplicity                   intitle:"CIMPLICITY WebView" inurl:main.html   http




             Proficy                      inurl:ProficyPortal/default.asp                http

More Related Content

PDF
SAST vs. DAST: What’s the Best Method For Application Security Testing?
PDF
Web application security & Testing
PPTX
PPTX
Introduction to Maven
PPTX
SANS_PentestHackfest_2022-PurpleTeam_Cloud_Identity.pptx
PDF
Sigma and YARA Rules
PDF
Neat tricks to bypass CSRF-protection
PDF
Cisco acs configuration guide
SAST vs. DAST: What’s the Best Method For Application Security Testing?
Web application security & Testing
Introduction to Maven
SANS_PentestHackfest_2022-PurpleTeam_Cloud_Identity.pptx
Sigma and YARA Rules
Neat tricks to bypass CSRF-protection
Cisco acs configuration guide

What's hot (20)

PPSX
Introduction to threat_modeling
PDF
DevSecOps: What Why and How : Blackhat 2019
PPTX
Security testing fundamentals
PPSX
7 Software Development Security
PPTX
Zephyr 2.6: Comprehensive Test Management
PPTX
Logging, monitoring and auditing
PDF
Practical DevSecOps Course - Part 1
PPTX
SIEM - Activating Defense through Response by Ankur Vats
PDF
Fidelis Endpoint® - Live Demonstration
PDF
Cypress testing
PDF
Application Security - Your Success Depends on it
PDF
Fileless Malware Infections
PPTX
Static Analysis Security Testing for Dummies... and You
PDF
Microsoft Intune - Empowering Enterprise Mobility - Presented by Atidan
ODP
OWASP Secure Coding
PPTX
Backstage at CNCF Madison.pptx
PDF
Checkmarx meetup API Security - API Security top 10 - Erez Yalon
PDF
OWASP Top 10 Web Application Vulnerabilities
PDF
OSS Tools: Creating a Reverse Engineering Plug-in for r2frida
PDF
DTS Solution - Building a SOC (Security Operations Center)
Introduction to threat_modeling
DevSecOps: What Why and How : Blackhat 2019
Security testing fundamentals
7 Software Development Security
Zephyr 2.6: Comprehensive Test Management
Logging, monitoring and auditing
Practical DevSecOps Course - Part 1
SIEM - Activating Defense through Response by Ankur Vats
Fidelis Endpoint® - Live Demonstration
Cypress testing
Application Security - Your Success Depends on it
Fileless Malware Infections
Static Analysis Security Testing for Dummies... and You
Microsoft Intune - Empowering Enterprise Mobility - Presented by Atidan
OWASP Secure Coding
Backstage at CNCF Madison.pptx
Checkmarx meetup API Security - API Security top 10 - Erez Yalon
OWASP Top 10 Web Application Vulnerabilities
OSS Tools: Creating a Reverse Engineering Plug-in for r2frida
DTS Solution - Building a SOC (Security Operations Center)
Ad

Similar to ICS/SCADA/PLC Google/Shodanhq Cheat Sheet (20)

PDF
ICS/SCADA/PLC Google/Shodanhq Cheat Sheet v2
PPTX
Technical Overview of Cisco Catalyst 9200 Series Switches
PDF
ScilabTEC 2015 - Xilinx
PDF
Scada deep inside: protocols and security mechanisms
PPTX
SCADA Strangelove: взлом во имя
PPTX
SCADA Strangelove: Hacking in the Name
PDF
BlackHat 2011 - Exploiting Siemens Simatic S7 PLCs (slides)
PDF
Mohamed Zakaria 01-2017
PDF
Introduction to Industrial Control Systems : Pentesting PLCs 101 (BlackHat Eu...
PPT
FE_Technologies_PLC.ppt
PPT
FE_Technologies_PLC.ppt
PPT
CHM_Technologies_PLC.ppt
PDF
SELTA Energy Automation Portfolio 2018
PDF
WebAccess Scada Driver List_V17_20211015.pdf
PDF
practical-guide-to-opcua.pdf
PDF
Edge-Core - экономия без потери качества | Семинар для интеграторов 15.06.17
PDF
26.1.7 lab snort and firewall rules
PPT
S7 bas-16
PDF
Overview of RTaW SysML-Companion
PPTX
PARAMETER SENSING REMOTE OPERATED VIDEO ENHANCED RECEIVER
ICS/SCADA/PLC Google/Shodanhq Cheat Sheet v2
Technical Overview of Cisco Catalyst 9200 Series Switches
ScilabTEC 2015 - Xilinx
Scada deep inside: protocols and security mechanisms
SCADA Strangelove: взлом во имя
SCADA Strangelove: Hacking in the Name
BlackHat 2011 - Exploiting Siemens Simatic S7 PLCs (slides)
Mohamed Zakaria 01-2017
Introduction to Industrial Control Systems : Pentesting PLCs 101 (BlackHat Eu...
FE_Technologies_PLC.ppt
FE_Technologies_PLC.ppt
CHM_Technologies_PLC.ppt
SELTA Energy Automation Portfolio 2018
WebAccess Scada Driver List_V17_20211015.pdf
practical-guide-to-opcua.pdf
Edge-Core - экономия без потери качества | Семинар для интеграторов 15.06.17
26.1.7 lab snort and firewall rules
S7 bas-16
Overview of RTaW SysML-Companion
PARAMETER SENSING REMOTE OPERATED VIDEO ENHANCED RECEIVER
Ad

More from qqlan (20)

PDF
D1 t1 t. yunusov k. nesterov - bootkit via sms
PDF
Kaspersky SAS SCADA in the Cloud
PPTX
Миссиоцентрический подход к кибербезопасности АСУ ТП
PDF
ABUSE THEIR CLOUDS. ОБЛАЧНЫЕ ВЫЧИСЛЕНИЯ ГЛАЗАМИ ПЕНТЕСТЕРА, ЮРИЙ ГОЛЬЦЕВ, СЕ...
PDF
Best of Positive Research 2013
PDF
Web-style Wireless IDS attacks, Sergey Gordeychik
PDF
G. Gritsai, A. Timorin, Y. Goltsev, R. Ilin, S. Gordeychik, and A. Karpin, “S...
PPTX
SCADA StrangeLove: Too Smart Grid in da Cloud [31c3]
PDF
Pt infosec - 2014 - импортозамещение
PPTX
SCADA StrangeLove Kaspersky SAS 2014 - LHC
PDF
Firebird Interbase Database engine hacks or rtfm
PDF
SCADA StrangeLove 2: We already know
PDF
Internet connected ICS/SCADA/PLC
PDF
SCADA deep inside:protocols and software architecture
PDF
Techniques of attacking ICS systems
PDF
Positive Technologies Application Inspector
PPTX
Database honeypot by design
PDF
Positive Technologies Application Inspector
PPTX
Black Hat: XML Out-Of-Band Data Retrieval
PDF
Positive Technologies - S4 - Scada under x-rays
D1 t1 t. yunusov k. nesterov - bootkit via sms
Kaspersky SAS SCADA in the Cloud
Миссиоцентрический подход к кибербезопасности АСУ ТП
ABUSE THEIR CLOUDS. ОБЛАЧНЫЕ ВЫЧИСЛЕНИЯ ГЛАЗАМИ ПЕНТЕСТЕРА, ЮРИЙ ГОЛЬЦЕВ, СЕ...
Best of Positive Research 2013
Web-style Wireless IDS attacks, Sergey Gordeychik
G. Gritsai, A. Timorin, Y. Goltsev, R. Ilin, S. Gordeychik, and A. Karpin, “S...
SCADA StrangeLove: Too Smart Grid in da Cloud [31c3]
Pt infosec - 2014 - импортозамещение
SCADA StrangeLove Kaspersky SAS 2014 - LHC
Firebird Interbase Database engine hacks or rtfm
SCADA StrangeLove 2: We already know
Internet connected ICS/SCADA/PLC
SCADA deep inside:protocols and software architecture
Techniques of attacking ICS systems
Positive Technologies Application Inspector
Database honeypot by design
Positive Technologies Application Inspector
Black Hat: XML Out-Of-Band Data Retrieval
Positive Technologies - S4 - Scada under x-rays

Recently uploaded (20)

PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PPTX
MYSQL Presentation for SQL database connectivity
PPTX
A Presentation on Artificial Intelligence
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Approach and Philosophy of On baking technology
PDF
KodekX | Application Modernization Development
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Electronic commerce courselecture one. Pdf
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
NewMind AI Monthly Chronicles - July 2025
PDF
Spectral efficient network and resource selection model in 5G networks
Digital-Transformation-Roadmap-for-Companies.pptx
MYSQL Presentation for SQL database connectivity
A Presentation on Artificial Intelligence
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
20250228 LYD VKU AI Blended-Learning.pptx
Approach and Philosophy of On baking technology
KodekX | Application Modernization Development
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
NewMind AI Weekly Chronicles - August'25 Week I
“AI and Expert System Decision Support & Business Intelligence Systems”
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Electronic commerce courselecture one. Pdf
Encapsulation_ Review paper, used for researhc scholars
Dropbox Q2 2025 Financial Results & Investor Presentation
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
NewMind AI Monthly Chronicles - July 2025
Spectral efficient network and resource selection model in 5G networks

ICS/SCADA/PLC Google/Shodanhq Cheat Sheet

  • 1. ICS/SCADA/PLC Google/Shodanhq Cheat Sheet Gleb Gritsai, Alexander Timorin, Yuri Goltsev, Roman Ilin http://scadastrangelove.org/
  • 2. vendor product google dork network info Siemens S7-200 all models: tcp/udp/102 (by vuln info) S7-300 snmp: Siemens, SIMATIC, S7 S7-3** , PCS7 inurl:/Portal0000.htm http: /S7Web.css Simatic S7 snmp: Siemens, SIMATIC S7, CPU-1200 Siemens, SIMATIC S7, CPU317-2 PN/DP Siemens, SIMATIC S7, CPU315-2 PN/DP
  • 3. Siemens, SIMATIC S7 *** inurl:"Portal/Portal.mwsl" http: /S7Web.css Automation License Manager tcp/4410 (by vuln info) Scalance S,X Security Module firewall telnet: Simatic, Scalance snmp: Scalance S*, Scalance W*, Scalance X* DCP protocol (by vuln info) tcp/80 netbios: WINCC_SRV21 <0x0> SIEMENS <0x0> Wincc flexible WINCC_SRV21 <0x20> Wincc flexible runtime / TIA Portal tcp/2308 (by vuln info) tcp/50523 (by vuln info)
  • 4. Synco OZW (Web server) http SIMATIC HMI Miniweb intitle:"Miniweb Start Page" | "/CSS/Miniweb.css" http: /CSS/Miniweb.css Simatic HMI snmp: Siemens, SIMATIC HMI, *** telnet:Welcome to the Windows CE Telnet Service on HMI_Panel
  • 5. vendor product google dork network info DeltaV and DeltaV Workstations/DeltaV Emerson ProEssentials Scientific Graph tcp/udp/111 (by vuln info) DeltaV Service Information System Ver3.3 vendor product google dork network info Allen-Bradley Rockwell Automation ControlLogix tcp/udp/44818 , http CompactLogix intitle:"Rockwell Automation" "Device Name" "Uptime"
  • 6. PLC5 http, snmp inurl:dtm.html intitle:1747-L552 SLC-5 inurl:dtm.html intitle:1747-L551 http, snmp Micrologix inurl:home.htm intitle:1766 http, snmp vendor product shodanhq dork network info Schneider Electric PM820SD Schneider Electric - PM820SD port:161 PM870SD Schneider Electric - PM870SD port:161 ECC21 Schneider Electric - ECC21 port:161 EGX100MG Schneider Electric - EGX100MG port:161 PowerLogic PM800 PowerLogic PM800 port:80 PowerLogic ION8650 A/B/C ION8650
  • 7. PowerLogic ION8650 A/B/C) 8650 ION PowerLogic ION8600 8600 ION PowerLogic ION7650/7550 ION 7550 PowerLogic ION7650/7550 ION 7650 PowerLogic ION7300 ION 7300 PowerLogic ION6200 ION6200 PowerLogic PM1200 PM1200 PowerLogic DM6200 DM6200 Powerlogic Enercept Powerlogic Energy Meter PowerLogic Branch Current Monitor BCM42 PowerLogic EM4800
  • 8. PowerLogic E5600 PowerLogic Ethernet Gateway (EGX) EGX100 PowerLogic EGX300 EGX300 PowerLogic ION7550RTU ION 7550RTU schneider electric vendor product google dork network info Schneider Electric Modicon intitle:"Quantum CPU Web Server" Quantum/Premiun/Micro intitle:"Premium CPU Web Server" intitle:"Citect Web" inurl:scada CitectSCADA filetype:htm CitectFacilities shodanhq: ClearSCADA "ViewXCtrl is not supported in this web browser." ClearSCADA intitle:"ClearSCADA Home" UnitelWay Device Driver
  • 9. Vijeo Historian Web Server several products Modicon M340 snmp: "Modicon M340" vendor product google dork network info General Electric Cimplicity intitle:"CIMPLICITY WebView" inurl:main.html http Proficy inurl:ProficyPortal/default.asp http