All Apps and Add-ons

Does the Hurricane Labs App for Shodan support CIDR notation when populating the CSV file it references?

hazaklioglu
New Member
0 Karma

rdaul
New Member

I also faced the same problem. Hurricane labs app is querying Shodan and providing the results. I figured out in my case, the API is broken. Shodan REST API documentation (link below) specifies that net filter to be used for the CIDR notation. However, I know the API key works as I tested with the 4.2.2.2, but it wont work for CIDR, for ex: query=net:4.2.2.0/30 (which ideally should return the results)
https://developer.shodan.io/api

You can try this on your browser with your API key and query as per the document.
https://api.shodan.io/shodan/host/search?key={YOUR_API_KEY}&query={query}

I presume if this gets fixed then the app will work for CIDR.

0 Karma

gaylorddusautoi
New Member

I'm facing issue with CIDR.
I made some tests with 8.8.8.8, it's working properly but not with 8.8.8.0/24 notation.
Did I miss something ?

0 Karma

mcmaster
Communicator

The only CSV I can think of for the app is the one you set up under "Configure" in the app (shodan_lookup.csv), which absolutely supports CIDR notation.

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...