Every vunerable Jenkins server in the US
"X-Jenkins" "Set-Cookie: JSESSIONID" http.title:"Dashboard" "HTTP/1.1 200" port:"8080" country:"US"
FTP servers that allow anonymous connections
anonymous@ login ok. port:"21"
VNC connections that have authentication disabled, most of these are stuck behind login screens
"authentication disabled" "RFB 003.008"
ANPR Cameras
P372 "ANPR enabled"
Nordex Wind terbine control pannels
http.title:"Nordex Control" "Windows 2000 5.0 x86" "Jetty/3.1 (JSP 1.1; Servlet 2.2; java 1.6.0_14)"
Medical DICOM servers
"DICOM Server Response" port:104
Open windows XP/Vista RDP instances
(most of these are secure via a login screen)
"\x03\x00\x00\x0b\x06\xd0\x00\x00\x124\x00"
Fully exposed MongoDB GUI interfaces
"Set-Cookie: mongo-express=" "200 OK"
Exposed MongoDB instances
"MongoDB Server Information" port:27017 -authentication
yawcams
"Server: yawcam" "Mime-Type: text/html"
webcamXP/webcam7
("webcam 7" OR "webcamXP") http.component:"mootools" -401
Android IP Webcam Server
"Server: IP Webcam Server" "200 OK"
Security DVRs
html:"DVR_H264 ActiveX"
Every single IP in North Korea
net:175.45.176.0/22,210.52.109.0/24,77.94.35.0/24
Random Minecraft servers
"Minecraft Server" "protocol 340" port:25565
Octoprint 3dprinter control pannels
(you can download STL's stored on the device's and sometimes view IP cameras attached to the printers)
title:"OctoPrint" -title:"Login" http.favicon.hash:1307375944
Yamaha Speakers
"Server: AV_Receiver" "HTTP/1.1 406"
Weave Scope Dashboards
title:"Weave Scope" http.favicon.hash:567176827