Skip to main content

Network scanning

Register an IP address or range you own, scan it for open ports and exposed services, and ask Vulnara's security experts about a finding.

Besides code, Vulnara scans networks. You register an IP address or range that you own, start a scan, and Vulnara reports every open port it finds with the service, product and version behind it.

What it is for

An open port running an old service is one of the easiest ways into a network. A network scan shows you what the outside world can see on your hosts, so you can close what should not be open and update what is out of date.

How it works

  • Vulnara scans the hosts in the range one at a time, so progress is reported host by host and one unreachable host does not stop the scan.
  • On each host it checks the 100 most common TCP ports and identifies the service running on each open one.
  • Every open port becomes a finding carrying the host, hostname, protocol, port, service name, state, product, version, extra information, the reason it was reported, a confidence value and the CPE identifier where one is known. Ports that give no response or no useful service information are not reported.
  • The network's security score is worked out from its findings. Open ports weigh more than filtered ones, and closed ports add nothing. Services that are commonly attacked, such as HTTP, FTP, Telnet and SSH, add more risk, as does a service on its standard port and any disclosed product, version or CPE. Low-confidence findings count for less.
The Networks screen listing registered networks with their type and security score

What you can set

  • Name: a label for the network.
  • Network: an IPv4 or IPv6 address, or a CIDR range such as 192.168.1.0/24 or 2001:db8::/112. A range can cover at most 65,536 addresses.
  • Network Type: Public, Private, VPN, Internal, External, DMZ or Unknown. Vulnara suggests a type from the range; choose Unknown if you are not sure.
  • Ownership confirmation: you must confirm that you own the network or have permission from its owner to scan it.

Do it

  1. Add the network

    Open Networks in the web app and choose Add Network. Enter a name, the address or range, and the network type, tick the ownership confirmation and save.

  2. Start the scan

    Select the network and choose Scan Network, then confirm. You can also choose New Scan in the sidebar and pick Network. The scan appears in the tasks bar with the hosts scanned out of the total.

  3. Read the results

    Open Network Scans to see each scan and its findings. On a finding, choose Request Consultation to ask Vulnara's security experts to help you understand and resolve it.

A network scan result listing open ports with their service, product and version

The same operations exist in the API:

sh
vulnara start_network_scan --networkId <network-id>

Good to know

  • A range larger than 65,536 addresses, such as an IPv6 /64, is refused and the scan is marked failed.
  • Your plan sets how many networks you can hold and limits network scans. At the network limit you cannot add another network, and the web app offers an upgrade. If a plan change leaves you holding more networks than the plan allows, scans are refused until you are back within it.
  • You can cancel a running network scan from the tasks bar. It stops before the next host.
  • Vulnara notifies you when a network scan finishes or fails. See Notifications.
  • Deleting a network cancels any scan still pending for it. You can also transfer a network to another account.

Manage Your Cookie Preferences

We use cookies to enhance your experience. You can accept all cookies, decline non-essential cookies, or manage preferences below. Privacy Policy