SecWeb

Port Scanner

Scan any domain or IP for open TCP ports across 30 common services — web, mail, databases, remote access, and more. Fast, safe, and passive.

Try:

What Is a Port Scanner?

A port scanner probes a target host to determine which TCP or UDP ports are open and accepting connections. Every service running on a server — a web server, an SSH daemon, a database — listens on a specific port. By scanning the ports, you build a picture of what's running on the server and how exposed it is to the internet.

Port scanning is a fundamental step in any security assessment. Attackers use it to map out attack surfaces. Defenders use it to verify their firewall rules are working and to identify services that shouldn't be publicly reachable.

How This Scanner Works

This tool performs a TCP connect scan. For each port in our scan list, we attempt to open a TCP connection using non-blocking sockets. If the connection succeeds within the timeout, the port is open. If it's refused, the port is closed. If there's no response, the port is filtered (usually by a firewall).

Unlike aggressive port scanners (like nmap with SYN scanning), our approach:

  • Requires no root privileges on the scanning server
  • Is indistinguishable from a legitimate visitor connecting to your services
  • Does not attempt service fingerprinting or banner grabbing beyond basic protocol detection
  • Uses parallel non-blocking sockets — 30 ports scanned in ~2 seconds

Ports We Scan and Why

Web Ports (80, 443, 8000, 8080, 8443, 8888)

Standard HTTP and HTTPS. Non-standard ports (8000, 8080, 8443, 8888) often host development servers, admin panels, or API endpoints that should not be publicly exposed.

Mail Ports (25, 110, 143, 465, 587, 993, 995)

SMTP for sending, POP3 and IMAP for receiving. Normal if you run a mail server. Should use TLS versions (465/587 for SMTP, 993/995 for IMAP/POP3) and never expose plaintext versions to untrusted networks.

Remote Access (22, 23, 3389, 5900)

SSH, Telnet, RDP, and VNC. SSH on port 22 is common and reasonable. Telnet (23) sends credentials in plaintext and should never be used. RDP and VNC should be behind a VPN, never exposed to the public internet.

Databases (1433, 3306, 5432, 6379, 11211, 27017, 9200)

MSSQL, MySQL, PostgreSQL, Redis, Memcached, MongoDB, Elasticsearch. None of these should ever be publicly accessible. They have no business being reachable from outside your private network. Exposure of any of these is a critical finding.

File Transfer (21, 139, 445)

FTP, NetBIOS, and SMB. FTP transmits credentials in plaintext. SMB and NetBIOS on the public internet are a major risk — they've been used in ransomware attacks (WannaCry, NotPetya) and should always be firewalled.

Other (53, 2375, 15672)

DNS on TCP, Docker API, and RabbitMQ Management. Docker API exposed publicly allows full container takeover. RabbitMQ Mgmt exposed publicly allows message queue manipulation. Both are critical.

Why Exposed Database Ports Are Critical

Every few months there's a story about a company leaking millions of records because a MongoDB, Elasticsearch, or Redis instance was left open to the internet. This happens constantly — automated bots scan for these ports continuously and exploit them within minutes of exposure.

Modern databases like Redis, Memcached, and MongoDB often ship with authentication disabled by default. If you spin one up on a cloud server and don't have a firewall in front, it's public within minutes and compromised within hours.

If this scanner reports any database port as open, treat it as an emergency. Restrict it immediately.

Understanding Your Scan Results

Each open port gets a risk classification:

  • Critical — Redis, Memcached, MongoDB, Elasticsearch, Docker API, RabbitMQ Mgmt. Authentication often disabled by default.
  • High — Traditional databases (MySQL, PostgreSQL, MSSQL), RDP, VNC, Telnet, SMB. Requires auth but should never be public.
  • Medium — FTP, POP3, IMAP, alternative web ports. Legacy protocols or admin interfaces.
  • Info — Standard web ports, mail with TLS, SSH. Normal for a public server.

Ethical & Legal Considerations

Port scanning is a gray area legally. In most jurisdictions it's not explicitly illegal, but unauthorized scanning of systems you don't own can:

  • Violate computer misuse laws in some countries (US CFAA, UK CMA, India IT Act)
  • Trigger intrusion detection systems and get your IP banned
  • Be interpreted as a precursor to attack

Only scan hosts you own or have explicit written permission to scan. If you're evaluating a potential client or vendor, ask first. The consent checkbox exists for a reason.

Frequently Asked Questions

In most jurisdictions port scanning is legal when done on systems you own or have written permission to test. It becomes legally problematic when done against systems you don't own with malicious intent, or in jurisdictions with strict computer misuse laws. Always scan your own infrastructure, or get explicit written consent first.
"Filtered" means our scan didn't receive any response — neither a connection success nor a connection refused. This typically means a firewall is silently dropping packets (DROP rule rather than REJECT). This is the ideal security posture for ports that shouldn't be public.
If no ports return as open, your firewall is correctly dropping the scanned traffic. Note that our scanner only checks 30 ports — an open port outside our list won't be detected. For comprehensive firewall verification, use a proper security assessment tool that scans the full range.
When your site is behind a CDN or reverse proxy like Cloudflare, our scan reaches Cloudflare's edge server, not your origin. The results show Cloudflare's exposed ports — usually 80 and 443 — not your actual server. To scan the origin, temporarily disable the CDN or scan the origin IP directly.
In order of priority: (1) Redis/Memcached/MongoDB (27017, 6379, 11211) — usually have zero authentication, compromised within minutes; (2) Docker API (2375) — allows full container takeover; (3) Traditional databases (3306, 5432, 1433) — brute-forceable; (4) RDP (3389) — the #1 ransomware entry point; (5) SMB (445) — the vector for WannaCry and similar worms. Any of these being publicly open is a serious issue.
Both. Enter a domain name and we'll resolve it to an IP before scanning, or paste an IP address directly. Private and internal IPs (10.x.x.x, 192.168.x.x, 127.0.0.1) are blocked for security reasons — they would give the impression of scanning internal networks that our server has access to.
Yes — completely free. Guests can run 3 scans per hour; registered users get 15. Each scan makes 30 network connections and consumes server resources, which is why there's a limit.
SecWeb Icon

Add SecWeb to your Home Screen

Get quick access to your security scans directly from your device.

Tap the Share icon below, then select "Add to Home Screen".