📱

Get Our Mobile App

Take your business learning on the go!

Download on the App StoreGet it on Google Play

7 websites that feel illegal...

Neurix13:10

Transcription

The internet has back rooms, public, legal, completely indexed by Google. And yet, the moment you visit them, you feel like you're somewhere you shouldn't be. Today, we're walking through seven of them. Bookmark the ones that don't make you nervous.

At number seven, we have Waggle. Waggle, short for Wireless Geographic Logging Engine, is a global map of Wi-Fi networks. Every router, every SSID, every encryption type. Built over 20 years by volunteers who drive around with phones running an app called War Driving Software. Open the map, scroll to literally any street on Earth, and watch the SSIDs appear. Every yellow pixel you see is a Wi-Fi network that someone somewhere drove past with the app running. The yellow zones are the saturated ones. North America, Europe, Japan. Coverage there is so dense that individual networks blur into a single glowing mass. The purple fringes are the suburbs and rural areas where networks are sparsser and the blue dots scattered across the oceans. Those are mostly fairies and cruise ships logged on their crossings.

Now look at the panel on the right. You can search by SSID. That's the network name your router broadcasts. You can search by BSSID. That's the hardware MAC address of a specific router, unique on Earth. You can filter by date range. You can ask Wiggle to show you only networks that look like free public access points or only commercial ones. Type in the SSID of your home router, and there's a real chance it's on the map. Someone walked past your house with the app running, and now your network name and approximate coordinates are in a public database that's been growing since 2001. Wiggle currently indexes over 1.5 billion networks. The site is legal and the data is public.

At number six, we have Virus Total. Virus Total lets you upload any file or paste any URL and instantly scans it against more than 70 antivirus engines and dozens of sandbox analyzers. It's owned by Google. It's free and it tells you within seconds whether the file your uncle just emailed you is malware. Let's say Sally gets a file from Kim called updater.x. Looks innocent. Updators update things, right? She drags it onto the virus total homepage and waits about 10 seconds. The file is analyzed by dozens of anti virus engines one by one. And there it is. 57 out of 71 security vendors have flagged this file as malicious. The big red ring on the left is the community score. The hash at the top is the file's unique fingerprint. And those little tags underneath are Virus Total's quick read on what the file is and what it does. Spreader is the one you don't want to see. That means this thing is designed to propagate.

In the table below, you can see the result of each analyzer. Every row is one anti virus engine giving its verdict. Acronis says suspicious. Falcon says malicious confidence 100%. They're not hedging. Microsoft labels it Trojan wind 64 meter printer. So it's a clear metas-ploit reverse shell. A handful of vendors at the bottom return green check marks. PaloAlto, Panda, Alibaba. This means they didn't catch it. This is normal. No single antivirus catches everything, which is exactly why virus total scans against 70 of them at once. The aggregate is the answer.

Number five, the Wayback Machine. You maybe know this one, but you probably don't know what it actually contains. The Wayback Machine has archived over 1 trillion web pages, including pages people thought they had deleted. Tweets, press releases that contradicted the next day's press release or politicians old blogs from 2004. Take MySpace.com for example. Remember it? The social network that ruled the internet before Facebook came along. Look at this. The Wayback Machine has saved myspace.com 1,52,843 times between December 1996 and today. That's over a million separate snapshots of one website. The black bar graph at the top is a histogram of those captures by year. See how it ramps up hard around 2005, peaks in 2008, and then plateaus? That's MySpace's entire life cycle drawn as a chart of how often the internet thought it was worth archiving.

Let's go to 2010 for example, the year MySpace was already losing to Facebook but hadn't admitted it yet. Every blue dot is a day with at least one snapshot. The bigger the dot, the more captures that day. If we click January 2nd, the pop-up shows five separate snapshots taken that day timestamped down to the second. If we take the first one, we get the actual MySpace homepage as it existed at 7:23 a.m. on January 2nd, 2010. Top eight friends, glittery profile songs, the whole thing.

Number four, Have I Been Pawned? Have I Been Pawned is a site by Australian security researcher Troy Hunt. You type in your email address and it tells you instantly every single data breach your account has appeared in. Have I Been Pond indexes records from nearly 17 billion accounts with new breaches added within hours of leaks appearing online. The site processes over 18 billion password lookups per month. Let's see what happens when Sally checks her own address. She types sally@yahoo.com, hits check. The page turns red. 161 data breaches. 161 separate times, Sally's email address has appeared in a leaked database somewhere on the internet. That's not unusual. That's actually pretty normal for an account that's been around for a decade.

Scroll down past the headline number and you get the timeline. Every breach Sally was in listed chronologically with a logo, a date, and a write up. Most recent first, April 2026 Carnival. The notorious hacking collective shiny hunters obtained 8.7 million records from the cruise operator's loyalty program, then published them after a failed extortion attempt. Names, dates of birth, geographic locations, loyalty program details. Sally's account got swept up in this one because she booked a cruise 4 years ago and never deleted the account.

Number three, Osent Industries. This one is genuinely surreal. Type in an email address, a phone number, or just a username, and Osent Industries shows you every online account that email address, phone number, or username is registered to. Not just the obvious ones like Instagram, Facebook, or LinkedIn, but also the ones people forget about, like Strava, Cash App, Airbnb, Adobe, Spotify, the old dating profiles, or that account on a fitness app from 2017. OSEN Industries is used by over 5,000 law enforcement agencies worldwide, journalists, fraud investigators, and corporate security teams. The one caveat is that there's no free tier to test it with. OSENT Industries is built for professional investigators and access is subscription only.

Number two, Instacam. Now, we're getting into the uncomfortable zone. Insecam aggregate publicly accessible IP cameras whose owners never set a password. Parking lots, construction sites, the inside of someone's restaurant kitchen at 3:00 a.m. or sometimes worse. As you can see, the front page shows a grid of thumbnails from around the world refreshing every few seconds. Here we have a quiet street in Suyama, Japan at night. Someone's office in Buonosiris with a keyboard and a mouse on the desk. Somebody is going to sit down at that computer in a few hours. and a stranger on the internet already knows what their setup looks like. We also see a road in Tokyo. Note that the timestamps on the feeds are real. These aren't recordings. This is happening right now.

The site organizes everything you'd expect a search engine to organize. You can filter by manufacturer. For example, let's take Bosch. The results show Bosch cameras across the word. One brand and one default password somebody never changed and you get a spread across six countries on a single page. A backyard in southern Italy. The interior of what looks like a sports club in Vienna. A traffic speed camera in the Czech Republic. And then two separate angles inside a slot machine arcade in Chicago. You can literally see a person sitting at one of the machines. They have no idea this video is being broadcast to the internet, indexed, and served to anyone who clicks Bosch.

You can also filter by country. Let's look at Germany. We can see three different cameras in the same city. Bon, all from homeowners or small businesses who set up a camera and forgot to put a password on it. A church somewhere else in Germany. And a backyard with a garden. These feeds are technically public. The cameras are broadcasting them to the open internet without authentication, which is why INCAM can legally list them, but the existence of the website itself feels deeply wrong, and it's a permanent reminder to set a password on every device you connect to your network.

Number one, Showdan. Showdan is a search engine for internet connected devices. It can find routers, servers, webcams, smart fridges, traffic lights, or power plant control systems. The way it works is genuinely simple. Showdan crawls the entire IPv4 address space port by port and records the banner. This is the greeting message that each device sends back when you knock. Then it makes those banners searchable. Let's run a few searches. We start with port 22. Port 22 is SSH, the protocol system administrators use to remotely log into servers. So this query is asking showdan show me every machine on the internet listening for remote login. And there is the result. Look at the left panel. United States 5.8 million devices. China 2.2 million. Germany 2.1 million. We can see that there are 17 million machines publicly accessible for SSH login worldwide.

The right side shows individual results. Each one is a real machine with a real IP, a real location, and a real banner identifying its software version. That exceeded Mac startup's message at the top of the first two results is interesting. That means those servers are being scanned so aggressively right now that they're hitting their connection limit and rejecting new sessions. Showdan caught them mid-overload. Let's narrow our results down. We can add the country parameter to filter the search for SSH servers to the United States. And there is the result. We can see there is 5.87 million SSH servers in the US. The banners on the right show real open SSH versions, real fingerprints, and real cryptographic keys. Anyone running a vulnerability scan against this list could check in seconds which of these servers are running an outdated SSH version with a known vulnerabilities.

SSH isn't the only protocol Showdown has in its arsenal. You can search for other protocols too. Telnet, FTP, RTSP for video streams, Modbus and other industrial control protocols, MongoDB databases, and dozens more. And you can combine filters in endless ways by city, by organization, or by operating system. The full reference is at shodden.io/arch/filters. And curated example queries are at shden.io/explore.

So that's it for today. We've explored seven websites that might seem totally illegal, but none of them actually are. They don't ask you to do anything that you couldn't already do with a little patience and a script. What they do is make the existing exposure of the internet visible. And once you've seen it, you can't really unsee it.

Here are a few rules. If you go exploring, don't log into anything you find. Even with default credentials, accessing a system that isn't yours is unauthorized access under computer fraud laws in nearly every country. Don't access systems that aren't yours. Looking at a public banner is legal, but interacting with the device behind it isn't. So, don't be the person who makes the news. Just look, learn, and then go patch your own stuff.

If you enjoyed this video, hit subscribe so you don't miss any future deep dives into the weird corners of cyber security. See you in the next one.