Instant external security scan of your own IP | curl qsa.sh
qsa.sh is a service that performs an external security scan of the public IP address from which the user connects. It uses open-source tools like naabu, nmap + vulners, and nuclei to scan open ports, services, and vulnerabilities, streaming results live to the user's terminal. The scan only targets the user's own IP address, with a 15-second abort window before scanning begins to ensure consent. Known carrier-grade NAT, mobile carriers, VPNs, proxies, Tor, and IPv6 addresses are refused to prevent unauthorized scanning. Results are ephemeral and not stored on disk.
AI Analysis
Technical Summary
qsa.sh provides an instant external security scan of the user's own public IP address by running open-source scanning tools (naabu, nmap + vulners, nuclei) from external scanner nodes. The scan is initiated by a simple curl command and streams live results back to the user's terminal in about 30 seconds. The service enforces consent by showing the detected IP and allowing a 15-second abort window before scanning. It refuses scanning requests from IPs associated with CGNAT, mobile carriers, VPNs, proxies, Tor, and IPv6 to avoid unauthorized scans. Scan results are ephemeral, not stored, and the scanning duration is capped. The service requires that users are authorized to scan the IP address they connect from, emphasizing legal compliance.
Potential Impact
The service itself does not introduce a vulnerability but provides a tool for users to externally assess their own public IP address for open ports and known vulnerabilities. It helps users identify potential exposure visible from the internet. There is no indication of exploitation or malicious activity associated with the service. The impact is informational and aids in security posture assessment rather than posing a direct threat.
Mitigation Recommendations
No mitigation is required as this is a security scanning service designed for authorized use only. Users must ensure they have authorization to scan the IP address they use. The service includes safeguards such as a 15-second abort window and refusal of scans from shared or anonymized IP ranges to prevent unauthorized scanning. Users should follow the service's terms of use and applicable laws regarding scanning.
Instant external security scan of your own IP | curl qsa.sh
Description
qsa.sh is a service that performs an external security scan of the public IP address from which the user connects. It uses open-source tools like naabu, nmap + vulners, and nuclei to scan open ports, services, and vulnerabilities, streaming results live to the user's terminal. The scan only targets the user's own IP address, with a 15-second abort window before scanning begins to ensure consent. Known carrier-grade NAT, mobile carriers, VPNs, proxies, Tor, and IPv6 addresses are refused to prevent unauthorized scanning. Results are ephemeral and not stored on disk.
Reddit Discussion
I built qsa.sh to give you an instant, outside-in security scan of your own public IP straight from your terminal.
You can run it without piping to bash.
curl qsa.sh
What it does: It triggers a real external port and vulnerability scan (using open-source tools like naabu, nmap + vulners, and nuclei) of the public IP you're connecting from, streamed live back to your terminal in about 30 seconds.
How it handles safety & consent:
Only your IP: There is no target input field. You cannot point it at anyone else.
The 15-second abort window: When you run the command, it prints your detected IP and gives you a 15-second grace period (Ctrl-C) to abort before anything is actually scanned.
Refusals: Known CGNAT, mobile-carrier, and detected VPN/Tor/IPv6 origins are refused outright.
Zero retention: The results are entirely ephemeral and streamed live—nothing is written to disk.
Curious to hear what people think.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
qsa.sh provides an instant external security scan of the user's own public IP address by running open-source scanning tools (naabu, nmap + vulners, nuclei) from external scanner nodes. The scan is initiated by a simple curl command and streams live results back to the user's terminal in about 30 seconds. The service enforces consent by showing the detected IP and allowing a 15-second abort window before scanning. It refuses scanning requests from IPs associated with CGNAT, mobile carriers, VPNs, proxies, Tor, and IPv6 to avoid unauthorized scans. Scan results are ephemeral, not stored, and the scanning duration is capped. The service requires that users are authorized to scan the IP address they connect from, emphasizing legal compliance.
Potential Impact
The service itself does not introduce a vulnerability but provides a tool for users to externally assess their own public IP address for open ports and known vulnerabilities. It helps users identify potential exposure visible from the internet. There is no indication of exploitation or malicious activity associated with the service. The impact is informational and aids in security posture assessment rather than posing a direct threat.
Mitigation Recommendations
No mitigation is required as this is a security scanning service designed for authorized use only. Users must ensure they have authorization to scan the IP address they use. The service includes safeguards such as a 15-second abort window and refusal of scans from shared or anonymized IP ranges to prevent unauthorized scanning. Users should follow the service's terms of use and applicable laws regarding scanning.
Technical Details
- Source Type
- Subreddit
- blueteamsec+AskNetsec+Information_Security
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Domain
- null
- Newsworthiness Assessment
- {"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":[],"foundNonNewsworthy":[]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6a6a64709c2644c7f8032639
Added to database: 07/29/2026, 20:37:04 UTC
Last enriched: 07/29/2026, 20:37:17 UTC
Last updated: 07/30/2026, 02:51:52 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.