Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Instant external security scan of your own IP | curl qsa.sh

0
Medium
Published: 07/29/2026 (07/29/2026, 20:20:16 UTC)
Source: Reddit BlueTeam

Description

qsa.sh is a service that performs an external security scan of the public IP address from which the user connects. It uses open-source tools like naabu, nmap + vulners, and nuclei to scan open ports, services, and vulnerabilities, streaming results live to the user's terminal. The scan only targets the user's own IP address, with a 15-second abort window before scanning begins to ensure consent. Known carrier-grade NAT, mobile carriers, VPNs, proxies, Tor, and IPv6 addresses are refused to prevent unauthorized scanning. Results are ephemeral and not stored on disk.

Reddit Discussion

r/blueteamsec·posted by u/tuxxin
00

I built qsa.sh to give you an instant, outside-in security scan of your own public IP straight from your terminal.

You can run it without piping to bash.

curl qsa.sh

What it does: It triggers a real external port and vulnerability scan (using open-source tools like naabu, nmap + vulners, and nuclei) of the public IP you're connecting from, streamed live back to your terminal in about 30 seconds.

How it handles safety & consent:

Only your IP: There is no target input field. You cannot point it at anyone else.

The 15-second abort window: When you run the command, it prints your detected IP and gives you a 15-second grace period (Ctrl-C) to abort before anything is actually scanned.

Refusals: Known CGNAT, mobile-carrier, and detected VPN/Tor/IPv6 origins are refused outright.

Zero retention: The results are entirely ephemeral and streamed live—nothing is written to disk.

Curious to hear what people think.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/29/2026, 20:37:17 UTC

Technical Analysis

qsa.sh provides an instant external security scan of the user's own public IP address by running open-source scanning tools (naabu, nmap + vulners, nuclei) from external scanner nodes. The scan is initiated by a simple curl command and streams live results back to the user's terminal in about 30 seconds. The service enforces consent by showing the detected IP and allowing a 15-second abort window before scanning. It refuses scanning requests from IPs associated with CGNAT, mobile carriers, VPNs, proxies, Tor, and IPv6 to avoid unauthorized scans. Scan results are ephemeral, not stored, and the scanning duration is capped. The service requires that users are authorized to scan the IP address they connect from, emphasizing legal compliance.

Potential Impact

The service itself does not introduce a vulnerability but provides a tool for users to externally assess their own public IP address for open ports and known vulnerabilities. It helps users identify potential exposure visible from the internet. There is no indication of exploitation or malicious activity associated with the service. The impact is informational and aids in security posture assessment rather than posing a direct threat.

Mitigation Recommendations

No mitigation is required as this is a security scanning service designed for authorized use only. Users must ensure they have authorization to scan the IP address they use. The service includes safeguards such as a 15-second abort window and refusal of scans from shared or anonymized IP ranges to prevent unauthorized scanning. Users should follow the service's terms of use and applicable laws regarding scanning.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
blueteamsec+AskNetsec+Information_Security
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Domain
null
Newsworthiness Assessment
{"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":[],"foundNonNewsworthy":[]}
Has External Source
true
Trusted Domain
false

Threat ID: 6a6a64709c2644c7f8032639

Added to database: 07/29/2026, 20:37:04 UTC

Last enriched: 07/29/2026, 20:37:17 UTC

Last updated: 07/30/2026, 02:51:52 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses