Skip to content
Noroxi

Open port · service · CVE

What does your server expose? Port, service, version and its flaws in one report.

We find the ports open to the internet on a domain’s server, read the version the service itself announces and pull the records affecting that version from our CVE database. It is an active scan: a free account lets you scan any public domain, and the unauthenticated-access checks on data services only run on domains you have verified.

A scan needs a free account

A port scan is an active operation; we require an account to limit abuse. The account is free and includes five full scans a day; you can scan any public domain.

Sample report · fictional domain

anadolu-lojistik.example · 203.0.113.10

2 risky ports open, 1 service with an actively exploited flaw

Grade 33/100 · Serious gaps

Open ports
4
Risky
2
Version-matched records
99
Actively exploited
3

Do these first

  1. Close port 6379 (Redis) to the internet

    The service answers without asking for a password

  2. Update Apache HTTP Server 2.4.49

    Records affecting this version include actively exploited ones

  3. Close port 3306 (MySQL) to the internet

    The database port is reachable from the internet

Open ports

  • 22

    SSH

    OpenSSH 8.9p1 · Ubuntu package

    Possible

  • 443

    HTTPS

    Apache/2.4.49

    Version match

  • 3306

    MySQL

    no version read

    High

  • 6379

    Redis

    answers without a password

    Critical

How it works

  1. 01

    Verify your domain

    Add the domain to your account and prove it is yours with a DNS record or a small file. Done once, takes two minutes. Your subdomains are covered too.

  2. 02

    Start the scan

    We try to connect to 106 common TCP ports on the server’s IPv4 address. On an open port we read the service greeting or the response headers. It takes under half a minute.

  3. 03

    Read the report

    Which ports are open, which should not face the internet, where a version can be read and which records affect it: in order of urgency, with how to close each.

What we check

The list is picked from the services that cause the most trouble when left open to the internet.

Web and applicationports
80/443 and alternative HTTP ports, application servers, management consoles.
Remote accessports
SSH, RDP, VNC, WinRM, Telnet and the old r-services.
Databases and data servicesports
MySQL, PostgreSQL, MSSQL, MongoDB, Redis, Memcached, Elasticsearch, message queues.
File sharingports
FTP, SMB, NFS, rsync.
Emailports
SMTP submission, POP3 and IMAP; encrypted and plaintext ports.
Infrastructureports
Docker and Kubernetes interfaces, etcd, LDAP, proxies, VPN.
Admin panelsports
cPanel, WHM, Webmin, Proxmox, Kibana, RabbitMQ management.

What we do

  • Attempt a full TCP connection to every port in the list: open, closed or no answer.
  • On an open port, read what the service itself says: greeting line, HTTP response headers, the same over TLS.
  • On TLS ports read the certificate, protocol and cipher; on SSH the weak algorithms; on VNC a password-less (auth=None) desktop — all by passively reading the handshake.
  • On your verified domains, flag Redis, Memcached, Elasticsearch, Docker and etcd separately when they answer without asking for a password.
  • Match the version read against the CVE database; on distribution packages the match is marked “possible”.

What we do not do

  • No password attempts, no exploitation, no directory or path guessing.
  • No UDP scan and not all 65k ports; only the common TCP ports in the list.
  • On an unverified domain we send no command to a service; a port only shows as open or closed. Government domains are never scanned.
  • A domain behind a CDN, WAF or shared hosting platform (such as Vercel or Netlify) is not scanned: the visible address is the provider’s, and so are its ports.

Free and paid

The report is complete on every plan; no locked rows. What you pay for is how many scans a day you can run and how many domains you can verify.

Free and paidFree accountPro $29/moTeam $99/mo
Full port scans5 per day10 per day50 per day
Verifiable domains115100
Reportcompletecompletecomplete
Banner to CVE (no scan)unlimitedunlimitedunlimited

Asking for the same domain again within 10 minutes returns the saved result and does not use a scan.

All plans

Frequently asked

Can I scan any domain?
Yes, a free account lets you see the open ports and service versions of any public domain. The one difference: the checks for whether services like Redis or Docker answer without a password only run on domains you have verified in your account. Those checks send a command to the service, and we do not send one to someone else’s server without permission. Government domains are never scanned.
Can the scan harm the server?
No. One connection is opened per port, the service is read if it announces itself, and the connection closes. No passwords are tried and no exploit is run. 106 ports in total, at most 24 connections at a time. A firewall may log these connections.
What does a port with “no answer” mean?
The connection attempt got no reply: the port is dropped at a firewall, or the server blocks our address. A closed port refuses the connection explicitly; a port with no answer says nothing. From another network the result may differ.
My site is behind Cloudflare. What happens?
No scan runs and no scan is used: the domain resolves to Cloudflare’s address and the ports we would see are Cloudflare’s. To scan the real server, enter a subdomain that goes straight to it (not through the CDN); subdomains of a verified domain are covered.
How certain is a version match?
When the service states its version and the affected range of a record covers it, we call it a “version match”. On distribution packages (Ubuntu, Debian, RHEL…) fixes are backported without changing the version number, so we mark the match “possible” and keep it out of the score. With no version, nothing is matched.
Who can see the report?
Only you. We do not create shareable links for port scan results; you can copy the report as Markdown or JSON.
Is there scheduled rescanning?
Not yet. Port scans are started by hand for now. Continuous monitoring of subdomain inventory and technologies is a separate product.

See what the outside sees

The account is free. Your first full scan comes out of today’s allowance, and you can scan any public domain.