Identity infrastructure exposed to the internet
Directory servers, Kerberos, remote desktop and identity providers are meant to sit behind the edge. These are the ones that don't: a daily count of identity systems that internet-wide scanners can reach right now, worldwide and in the UK.
Updated 04 Oct 2026, 23:17 (UK time) · Source: Shodan
LDAP directory servers (port 389)
Directory servers answering the internet invite password spraying, anonymous binds and enumeration of every account and group.
port:389
Kerberos KDCs (port 88)
An exposed KDC lets anyone request tickets: the starting point for AS-REP roasting and offline password cracking.
port:88
Remote Desktop (port 3389)
Remote Desktop on the open internet is still the most common way into a network: credential stuffing, then a live session.
port:3389
SMB file sharing (port 445)
SMB facing the internet exposes NTLM authentication and file shares to relay and brute-force attacks.
port:445
Keycloak identity servers
Identity provider admin and login pages in the open; fine for login, a problem when the admin console answers too.
http.title:"Keycloak"
Outlook / Exchange web sign-in pages
Outlook web sign-in pages are prime targets for password spraying and real-time phishing proxies.
http.title:"Outlook"
Kubernetes API servers (port 6443)
A reachable Kubernetes API is one leaked service-account token away from the whole cluster.
port:6443 product:"Kubernetes"
Jenkins dashboards open to the internet
Build servers hold deployment keys and cloud credentials: non-human identities with real power.
http.title:"Dashboard [Jenkins]"
How these numbers are made
Each figure is a Shodan count query, refreshed once a day: the number of internet-facing hosts Shodan's scanners last saw answering on that port or serving that page. A count is exposure, not compromise: some hosts are honeypots, research systems or deliberately public, and Shodan's view lags reality by days. Nothing on this page comes from scanning anyone; it reads what Shodan has already recorded.
The point is the pattern: identity systems that should only answer inside a network, or behind an identity-aware proxy, answering the whole internet. If one of these is yours, talk to me.