Free Open Ports Scan (Non-Intrusive)
Opens TCP connections to 38 database, admin and service ports (RDP, VNC, MySQL, Postgres, Redis, Mongo, Docker) on your host. No exploitation, results in about a minute.
- TCP connect check
- Database and admin ports
- No exploitation

Security Risks of Open Ports
- Increases potential entry points for attackers
- Exposes services that may have vulnerabilities
- Provides reconnaissance information to attackers
- Enables service-specific attack techniques
- Service identification and version detection
- Outdated software versions with known exploits
- Misconfigured services and unnecessary features
- Unencrypted data transmission and storage
- Violates security best practices and standards
- May breach compliance requirements (PCI DSS, HIPAA)
- Increases audit findings and remediation costs
- Demonstrates poor security posture to stakeholders
How to reduce exposure
- Address Critical and High-risk ports first
- Follow port-specific security recommendations
- Use risk categorization to prioritize fixes
- Implement dynamic scoring to track improvements
- Implement firewall rules to block unnecessary ports
- Use network segmentation and VLAN isolation
- Configure load balancers and reverse proxies
- Implement IP whitelisting and access controls
- Disable unused services and unnecessary features
- Update software to latest secure versions
- Configure strong authentication and access controls
- Implement encryption for data in transit and at rest
What this scan checks
- Remote access and directory (3389 RDP, 5900 VNC, 23 Telnet, 389 LDAP)
- Databases and caches (3306, 5432, 1433, 1521, 6379, 11211, 27017, 27018, 5984, 9042, 7687, 8086)
- Mail and file sharing (110, 143, 21, 445, 2049, 873)
- Containers and orchestration (2375 Docker, 2379/2380 etcd, 6443 Kubernetes, 5985 WinRM, 8500 Consul)
- Search, queues and admin UIs (9200, 9300, 5601, 8983, 5672, 15672, 1883, 7000, 7001, 8888)
- 2-tier risk categorization (critical and high-risk ports)
- Score deduction per open port, weighted by tier
- Port-specific security recommendations
- Attack surface mapping with risk prioritization
- TCP connect check from outside your network, on the target host only
- No banner grabbing or exploitation
- Security recommendations for each exposed service
Across 1,095 recent network scans, 43.6% have at least one externally-reachable port that should be closed.
Implementation examples
Once you've identified the gap, applying the fix is straightforward. Here are the three configurations developers reach for most often to close an unwanted port.
Linux host firewall (ufw)
# Default-deny inbound, allow only what you need
sudo ufw default deny incoming
sudo ufw default allow outgoing
# Public web traffic
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
# SSH only from a trusted admin range
sudo ufw allow from 203.0.113.0/24 to any port 22 proto tcp
# Explicitly close a previously exposed database port
sudo ufw deny 3306/tcp
sudo ufw enableAWS Security Group (Terraform)
resource "aws_security_group" "web" {
name = "web-sg"
description = "Public web only; admin scoped to office IP"
vpc_id = var.vpc_id
ingress {
from_port = 443
to_port = 443
protocol = "tcp"
cidr_blocks = ["0.0.0.0/0"]
}
ingress {
from_port = 22
to_port = 22
protocol = "tcp"
cidr_blocks = ["203.0.113.10/32"]
}
egress {
from_port = 0
to_port = 0
protocol = "-1"
cidr_blocks = ["0.0.0.0/0"]
}
}GCP firewall rule (gcloud)
# Allow only HTTPS from anywhere
gcloud compute firewall-rules create allow-https \
--network=default \
--direction=INGRESS \
--action=ALLOW \
--rules=tcp:443 \
--source-ranges=0.0.0.0/0
# Restrict SSH to a known admin CIDR
gcloud compute firewall-rules create allow-ssh-admin \
--network=default \
--direction=INGRESS \
--action=ALLOW \
--rules=tcp:22 \
--source-ranges=203.0.113.0/24
# Deny direct access to the database tier
gcloud compute firewall-rules create deny-db-public \
--network=default \
--direction=INGRESS \
--action=DENY \
--rules=tcp:3306,tcp:5432,tcp:6379,tcp:27017 \
--source-ranges=0.0.0.0/0Tool-specific questions
Is this port scan intrusive or harmful?
Why do some ports appear open intermittently?
Which ports are most commonly targeted by attackers?
What's the difference between open and filtered ports?
How often should I scan for open ports?
What should I do if I find unexpected open ports?
Can I use this scan for compliance auditing?
What's the best way to secure database ports?
How does the risk categorization system work?
Built for the engineers who already have enough to fix.
Fast results
Comprehensive checks
Step-by-step fixes
More free checks, for the rest of your surface.
Complete Security Scan
Pre-Pentest Security Scan
Security Compliance Checker
WAF Checker
Security Headers Test
TLS/SSL Security Checker
Frequently asked.
What is Barrion?
How safe is Barrion to use for security testing?
What types of security issues does Barrion identify?
What specific security checks does Barrion perform?
Will my auditor or enterprise customers accept the pentest report?
How often does Barrion test my app?
Is Barrion suitable for security testing of all business sizes?
How does Barrion handle data security and privacy during security testing?
What if I'm not satisfied with Barrion's security testing service?
How does Barrion help with SOC 2, ISO 27001, NIS2, and other compliance frameworks?
Anything else? Email contact@barrion.io.
Fix it once, then watch it stay fixed.
A pentest shows what is exploitable today. A scheduled passive scan re-checks this tool's results and alerts you when a deploy undoes the fix.
What you get for free
18 core security checks via this tool, passive scans, step-by-step remediation, security score on every result.
What Essential adds from €199/mo
Pentest credits every month, +17 advanced checks, weekly passive scans, email alerts and audit-ready PDFs for SOC 2 / ISO 27001 / PCI.