Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
25% Recurring Discount on NVMe VPS
Try EnsoVPN - Reliable VPN - 1-Day Free Trial
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
CloudLinux
Try EnsoVPN - Fast & Private VPN - 1-Day Free Trial
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Port Scanning VPS and Dedicated servers for firewall checks

I know most, if not all, provider's Acceptable Use Policies (AUP) or Terms of Service (TOS) here usually don't allow port scanning for the obvious reason it correlates highly with misuse and abuse actors.

However, I would like to scan IP addresses and related domains for my own servers (VPS, VDS, and Dedicated). Adding to the difficulty of this is the fact that some servers are spread out over different providers so I can't just get permission from a single host, I would need to get permission from both the origin host for outbound scanning AND the target host for inbound scanning.

Besides something like Shodan.io or other paid commercial services aimed at enterprise, how best to confirm your service's firewall/iptables are setup properly for personal/hobby project servers? I have used grc.com's Shields Up before but that is local browser based to the currently used IP.

Any information or assistance people could provide would be appreciated.

Thanks

Comments

  • olokeoloke Member, Host Rep

    @stupidgenius said: I would need to get permission from both the origin host for outbound scanning AND the target host for inbound scanning.

    In theory yes but in practice, if both the scanning and scanned server are under your control, nobody will report this as unauthorized scanning 🤔

    Thanked by 2stupidgenius tentor
  • conceptconcept Member

    There are providers that don't care if you do any port scanning against any host.
    Some providers don't mind it as long as its your own servers within the same account like DigitalOcean or OVH.

    If you aren't doing aggressive mass scanning, you won't have much problems.

  • Just use any paid VPN provider. Most of them will only block outbound 25.

    Thanked by 1stupidgenius
  • @oloke said: In theory yes but in practice, if both the scanning and scanned server are under your control, nobody will report this as unauthorized scanning 🤔

    That is fair and I figured one off scans probably would not raise any flags on most hosts, but knowing my luck, I would get flagged by overly proactive network admins.

    Thanked by 1oloke
  • conceptconcept Member

    @luckypenguin said:
    Just use any paid VPN provider. Most of them will only block outbound 25.

    yeah that works too. Sometimes, I just use my own Residential internet to scan and no problems

    Thanked by 1stupidgenius
  • conceptconcept Member

    @stupidgenius said:

    @oloke said: In theory yes but in practice, if both the scanning and scanned server are under your control, nobody will report this as unauthorized scanning 🤔

    That is fair and I figured one off scans probably would not raise any flags on most hosts, but knowing my luck, I would get flagged by overly proactive network admins.

    Hetzner is probably the only one I've seen that is pretty aggressive against port scans in or out.

    Thanked by 2oloke stupidgenius
  • @concept said:

    @stupidgenius said:

    @oloke said: In theory yes but in practice, if both the scanning and scanned server are under your control, nobody will report this as unauthorized scanning 🤔

    That is fair and I figured one off scans probably would not raise any flags on most hosts, but knowing my luck, I would get flagged by overly proactive network admins.

    Hetzner is probably the only one I've seen that is pretty aggressive against port scans in or out.

    given that i had to block their range, theyre certainly doing something wrong.

    Thanked by 2concept stupidgenius
  • @luckypenguin said: Just use any paid VPN provider. Most of them will only block outbound 25.

    That is a good idea, I didn't think of that. Probably the best option.

    @concept said: yeah that works too. Sometimes, I just use my own Residential internet to scan and no problems

    True, it probably would be fine, I was just worried that if it was flagged it would block me from directly access the services from that IP.

  • conceptconcept Member

    @stupidgenius said:

    True, it probably would be fine, I was just worried that if it was flagged it would block me from directly access the services from that IP.

    If you own the server, you control who gets blocked.

  • @concept said: There are providers that don't care if you do any port scanning against any host.

    Could you share their names?

    @concept said: If you own the server, you control who gets blocked.

    I only lease the VPS, VDS, or Dedicated hardware. I don't own the IP space or DC network control. Is it probably pretty rare to be flagged as the owner/lessee of both sides of scan, but it is not impossible if DC Network Admins are monitoring for port scanning.

  • Most providers will be fine. Fell free to PM me. Will give you some hints.

Sign In or Register to comment.