Skip to content

feat(prober): scan all 65535 ports (nmap -p-) - #85

Merged
ralyodio merged 1 commit into
masterfrom
full-port-scan
Jul 6, 2026
Merged

ralyodio merged 1 commit into
masterfrom
full-port-scan

Conversation

@ralyodio

@ralyodio ralyodio commented Jul 6, 2026

Copy link
Copy Markdown
Contributor

Switches the exposed-services prober from top-100 to a full 65535-port TCP-connect scan (nmap -sT -Pn -p- -T4 --host-timeout 1500s) — catching anything exposed is the whole point of drift detection. Safe because targets are owner-verified and the scan runs on the dedicated off-Railway droplet.

Timeouts stretched to match a multi-minute scan: reconcile window 15m→40m, nmap ceiling 30m, SSE stream 5m→45m with a 15s heartbeat so long running scans don't drop the connection. PRD §12 updated.

🤖 Generated with Claude Code

Full TCP port scan instead of top-100 — the point of exposed-services drift is
to catch anything open. Safe because targets are owner-verified and scanning
runs on the dedicated off-Railway droplet.

- prober: nmap -sT -Pn -p- -T4 --host-timeout 1500s; execFile ceiling 30m.
- prober-queue: RUNNING_TIMEOUT_MS 15m -> 40m for long scans.
- SSE route: MAX_MS -> 45m + 15s heartbeat so idle proxies don't drop the
  connection while a long scan sits in 'running'.
- PRD §12: document full-range scan + ownership/off-Railway justification.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@ralyodio
ralyodio merged commit 1d607fb into master Jul 6, 2026
@ralyodio
ralyodio deleted the full-port-scan branch July 6, 2026 23:45
@github-actions

github-actions Bot commented Jul 6, 2026

Copy link
Copy Markdown

vu1nz Security Review

0 finding(s) in PR #?

No security issues found.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant