TCP Port Scanning Β· Service Identification Β· Fingerprinting Β· Web Security Assessment
A lightweight Python-based security scanner built to understand how network reconnaissance and basic security assessment work internally.
The project combines TCP port scanning, service identification, banner grabbing, service fingerprinting, HTTP enumeration, default-page detection, basic security findings, error handling, multiple-target scanning, and structured reporting.
π― Project Goal: Scan β Identify β Fingerprint β Analyze β Assess β Report
flowchart LR
A["π― Target"] --> B["π Scan"]
B --> C["π Detect Ports"]
C --> D["π§© Identify Service"]
D --> E["π΅οΈ Fingerprint"]
E --> F["π HTTP Analysis"]
F --> G["β οΈ Risk Analysis"]
G --> H["π Generate Report"]
H --> A
- TCP port scanning
- IP address and hostname scanning
- Multiple-target scanning
- Custom port-range scanning
- Target validation and hostname resolution
- Timeout and unreachable-host handling
- Open-port detection
- Common service identification
- Banner grabbing
- Basic application fingerprinting
- Unknown-service handling
- HTTP
GET /enumeration - HTTP response analysis
- Default web-page detection
- Server-header information disclosure checks
- Basic HTTP security observations
- Risk-level classification
- Structured scan results
- Scan summary
- Security findings and recommendations
- Result logging
- Basic unusual-port/behavior observations
TARGET
β
VALIDATE TARGET
β
TCP PORT SCAN
β
IDENTIFY OPEN PORTS
β
SERVICE IDENTIFICATION
β
BANNER GRABBING
β
SERVICE FINGERPRINTING
β
HTTP DETECTED?
β
HTTP GET /
β
CONTENT + HEADER ANALYSIS
β
SECURITY FINDINGS
β
STRUCTURED REPORT
The scanner uses information returned by a service to perform basic fingerprinting.
For example, an HTTP response may disclose an Apache server and version. The scanner uses recognizable patterns to identify the apparent application.
Fingerprinting answers:
"What service or application appears to be running?"
It does not automatically answer whether that application is vulnerable.
| Fingerprinting | Vulnerability Scanning |
|---|---|
| Identifies an apparent service/application | Determines whether a known weakness may exist |
| Uses banners and response patterns | Usually correlates product/version/configuration with vulnerability intelligence |
| Example: Apache Web Server detected | Example: matching a product/version to a CVE |
| Implemented | Not currently implemented |
The scanner currently does not query Qualys, Tenable, Nessus, NVD, or OpenVAS databases.
When an HTTP service is detected, the scanner requests the root page and analyzes the returned response.
Current checks include:
| Check | Purpose | Example Risk |
|---|---|---|
| Default Page | Detects common default web-server pages | LOWβMEDIUM |
| Information Disclosure | Identifies exposed server/version information | LOW |
| HTTP Service | Highlights unencrypted HTTP for review | MEDIUM |
A detected default page is treated as a configuration/security observation, not automatically as a vulnerability.
The project uses basic, project-defined categories:
INFO Β· LOW Β· LOW-MEDIUM Β· MEDIUM Β· HIGH
These categories are intended for educational assessment and prioritization.
β οΈ They are not official CVSS, Qualys, Tenable, or Nessus ratings.
The scanner is designed to continue scanning when individual network problems occur.
It handles situations such as:
- Invalid or unresolvable targets
- Connection timeouts
- Unreachable hosts
- Closed ports
- Missing banners
- Unknown services
- Individual socket errors
A result such as βNo banner receivedβ is not necessarily a security issue; many services do not expose banners.
Multiple authorized targets can be scanned in one execution.
The scanner processes targets independently and produces results for each target.
Scanning large port ranges across multiple targets can take significantly longer depending on network latency, timeout settings, firewalls, and target response behavior.
The scanner reports information such as:
- Target and resolved IP
- Port range
- Open ports
- Associated services
- Detected applications
- Service/banner responses
- Web security findings
- Risk levels
- Recommendations
- Scan duration
Results are also saved to scan_results.txt.
The project can highlight basic observations from the current scan, such as:
- High-numbered open ports
- Unexpected services
- Multiple web services
- Other rule-based unusual findings
A single scan cannot determine historical peak hours, system load, CPU/memory utilization, or traffic trends. Those require repeated monitoring and comparison over time.
- Python 3.x
- Standard Python libraries
- Linux / Kali Linux recommended
- Network access to the authorized target
No external Python package is required for the basic scanner.
Run the scanner with Python 3 and provide the target, starting port, and ending port when prompted.
Example test environment:
Target: 127.0.0.1
Port Range: 1β65535
For safe testing, use your own machine, virtual machines, CTF environments, or systems for which you have explicit authorization.
A typical web-server assessment may identify:
DEFAULT PAGE
A known default web-server page was detected.
INFORMATION DISCLOSURE
The server response exposes software/version information.
HTTP
The web service is accessible through unencrypted HTTP and should be reviewed where sensitive information is involved.
Each finding is accompanied by a basic risk classification and recommendation.
This is a learning-focused security scanner, not a replacement for professional vulnerability-management or penetration-testing platforms.
The current project focuses on:
TCP Scanning + Service Identification + Banner Grabbing + Fingerprinting + HTTP Enumeration + Basic Configuration Checks + Security Reporting
It does not guarantee detection of all vulnerabilities.
A service may hide its banner, use a non-standard port, require authentication, or restrict connections.
Unknown Service β No Risk
Known Application β Vulnerable
- π Faster multithreaded/asynchronous scanning
- π¬ Improved service and version fingerprinting
- π HTTPS/TLS and certificate analysis
- π‘οΈ HTTP security-header checks
- ποΈ CVE/NVD integration
- π CVSS-based vulnerability scoring
- π JSON / HTML reporting
- π Historical scan comparison
- ποΈ Scan-history database
- π Web dashboard
- π Security alerts
This project demonstrates practical concepts in:
Networking: TCP/IP, sockets, ports, hostname resolution, connection handling, timeouts
Reconnaissance: Port scanning, service enumeration, banner grabbing, fingerprinting
Web Security: HTTP requests/responses, server headers, default pages, basic configuration assessment
Python: Socket programming, exception handling, functions, loops, dictionaries, lists, string matching, file handling, and IP validation
Use this project only on systems you own or have explicit authorization to test.
- π§ͺ Personal cybersecurity labs
- π₯οΈ Virtual machines
- π― CTF environments
- π Authorized penetration tests
- π’ Approved internal security assessments
Do not scan third-party systems or networks without permission.
This project is provided for educational and authorized security-testing purposes only.
The author is not responsible for damage, service disruption, unauthorized access, or misuse resulting from this software.
Always obtain appropriate authorization before performing security testing.