Exposed Network Service Dorks
Find exposed network services: SSH, FTP, Telnet, RDP, VNC, SMB, and more.
SSH Servers
lowSSH servers indexed across the internet. Check for weak passwords and outdated versions.
Telnet Open
highTelnet services transmit credentials in plaintext. Often found on legacy devices.
RDP Exposed
highRemote Desktop Protocol. Major target for brute-force and BlueKeep (CVE-2019-0708).
VNC Open
highVNC remote desktop servers. Many run without authentication or with weak passwords.
FTP Anonymous
mediumFTP servers that may allow anonymous login and file listing.
SMB Shares
highSMB file sharing. Check for EternalBlue (MS17-010) and open shares.
SNMP Public
mediumSNMP with default "public" community string. Exposes device info and network topology.
LDAP Open
highLDAP directories accessible externally. May expose Active Directory structure.
NFS Exports
mediumNetwork File System exports. May allow unauthorized file access.