Skip to content

Ironfang Security

About the Ironfang Security scanner

If you have seen connections from Ironfang Security, this page says who we are, why the traffic exists, what it looks like and how to reach us.

Who we are

Ironfang Ltd is a UK company, registered in England and Wales under number 12764014. We build and operate developer and security products from the UK, and Ironfang Security is one of them.

The scanner is ours. It is not a research project and it does not sweep the internet: every connection belongs to a check that a customer asked for.

Why you may see this traffic

Ironfang Security runs the External Security Check: automated, low-impact security checks of a domain from the public internet. A customer adds a domain in the Ironfang portal, proves they control it and starts a scan.

If the traffic reached a system of yours, the most likely reason is that someone who controls a domain pointing at it asked for that domain to be checked. That may be you, a colleague, an agency or a hosting provider acting for the domain's owner.

Only verified, authorised domains

Before anything is checked, the customer adds a TXT record under the domain, which only someone who controls its DNS can create, and confirms they are authorised to test it. The record is checked again before every scan; if it is missing, the scan is refused.

Only the verified domain is checked, at the addresses its own DNS points to. Hostnames found in public certificate logs are listed for the customer and never scanned, and the scanner refuses to connect to private, loopback and other non-public addresses, whatever DNS says.

How to recognise it

Scanner traffic comes from the addresses below and every HTTP request carries the User-Agent shown.

Source addresses

  • 87.242.201.101

This is the complete list. If it changes, this page changes first.

Reverse DNS

Dedicated scanner hostnames, with matching reverse DNS, are being set up. Until they are in place, the addresses above may not resolve to a name that says Ironfang Security, so rely on the address and the User-Agent.

User-Agent

Every HTTP and HTTPS request sends this, with a link back to this page:

IronfangSecurity/1.0 (External Security Check; +https://ironfang.com/security/scanning)

What the traffic looks like

Everything a scan does:

  • DNS lookups of the domain's records (addresses, nameservers, MX, TXT, CAA, DNSSEC, SPF, DMARC and DKIM at common selectors). They go through public resolvers, so your nameservers see the resolver rather than us.
  • A handful of ordinary HTTP and HTTPS GET requests per host, such as the home page over HTTP and HTTPS and /.well-known/security.txt. No forms are submitted and nothing is logged in to.
  • TLS handshakes to HTTPS ports to read the certificate and see which protocol versions and cipher suites the server accepts.
  • One TCP connection attempt to each port on a short, fixed list. The connection is opened and closed; nothing is sent, and a greeting is read only from services that speak first, such as SSH.
  • A search of public certificate transparency logs for related names. That touches the logs, not your systems.

The ports it tries

  • 21 FTP
  • 22 SSH
  • 23 Telnet
  • 80 HTTP
  • 443 HTTPS
  • 445 SMB
  • 1433 Microsoft SQL Server
  • 1521 Oracle Database
  • 2375 Docker API
  • 3306 MySQL / MariaDB
  • 3389 Remote Desktop (RDP)
  • 5432 PostgreSQL
  • 5900 VNC
  • 5984 CouchDB
  • 6379 Redis
  • 8080 HTTP (alternate)
  • 8443 HTTPS (alternate)
  • 9042 Cassandra
  • 9200 Elasticsearch
  • 11211 Memcached
  • 27017 MongoDB

It never attempts exploitation, password guessing or any login, fuzzing, SQL injection or cross-site scripting payloads, denial of service, or anything that writes to your systems.

Rate limits

Every scan job keeps to fixed limits, and the free service limits how often a domain can be scanned at all.

  • At most 8 HTTP requests to any one host in a scan.
  • At most 2 connections open to any one address at a time, with at least 150 milliseconds between connection attempts.
  • A 8-second timeout on every connection and request, and a hard stop for each job after 2 minutes.
  • A full scan of a domain at most once every 60 minutes, at most 20 scans a day per customer, and one scan running at a time per customer.
  • A recheck repeats only the checks behind one finding, on one host.

Allowlisting the scanner

If your firewall, WAF or intrusion detection blocks the scanner, the customer's results will show checks that could not complete. To let it through, allow the source addresses above and, where your WAF matches on headers, the User-Agent.

Allow it for ports 80 and 443 at least, and for the other listed ports only if you want their exposure checked. We never switch to another address to get around a block; if the scanner is blocked, the check simply reports that it was.

Reporting a problem

If the scanner caused a problem, or you think a scan was not authorised, email security@ironfang.com or use the contact form. Please include:

  • the source address you saw;
  • the time, with its time zone;
  • the destination address, host name or port that was reached.

From those three facts we can find the scan, the customer and the authorisation behind it, and stop a scan, or every scan by that customer, at once.

Opting a domain out

A domain is only checked while its verification record exists. If you control a domain and find a TXT record at _ironfang-verification under it that you did not create or no longer want, remove it: no further scan of the domain can start without it.

If you own a domain or network and want it excluded from Ironfang Security altogether, or you cannot reach its DNS, write to us at the address above with the domain or addresses, and we will stop checks of it.

Policies

Reporting a vulnerability in Ironfang itself is covered by our Vulnerability Disclosure Policy. Use of Ironfang Security is governed by the Terms of Service and the Acceptable Use Policy, and the documentation describes the scan policy a customer confirms.