Open Ports & Services Discovery

Every host on the internet exposes a set of TCP ports. Each open port reveals a service — SSH for remote administration, HTTP(S) for web servers, FTP for file transfer, DNS for name resolution, RDP for remote desktop, Modbus for industrial control systems, MQTT for IoT messaging. QROS scans every open port and identifies the service behind it.

QROS · Explore · 203.0.113.4551 ports
Open ports & service banners
22/tcpOpenSSH 9.2p1SSH
443/tcpnginx 1.24 · TLS 1.3HTTPS
80/tcpnginx 1.24HTTP
3306/tcpMySQL 5.7 · internet-exposedDB
502/tcpModbus · industrial controlICS

How QROS discovers open ports

QROS connects to every indexed host and attempts a TCP handshake on each of 51 common ports — from the well-known (22, 80, 443) to the industrial (502 Modbus, 20000 DNP3) and IoT (1883 MQTT, 8883 MQTTS, 9100 printer). For each open port, QROS:

What you see in a QROS host dossier

When you open a host in QROS Explore, you see a complete dossier with every open port, the service behind it, the software version, and any CVEs. Here's an example of what a host dossier looks like:

🇪🇸 45.33.32.156 critical

scanme.nmap.org · United States · Fremont · Linode

2 open ports 16 CVEs Risk score: 98/100
PortServiceSoftwareCVEs
22SSHOpenSSH 6.6.15
80HTTPApache 2.4.711
ssh http
View full dossier →

Why open port discovery matters

You can't secure what you can't see. Most organisations don't know which ports their servers expose to the internet. An open Redis on port 6379 without authentication, an RDP on 3389 exposed to the world, or a Modbus on 502 with no firewall — these are the entry points attackers use. QROS gives you the same visibility attackers already have, so you can close unnecessary ports before they're exploited.

Search open ports by country, service or product

QROS Explore lets you search the entire indexed host database by port, service, product, country or CVE — no login required. Search all hosts with SSH, all HTTPS endpoints, all RDP servers, or all Modbus devices in seconds.

The 51 ports QROS scans

22 SSH21 FTP23 Telnet25 SMTP53 DNS 80 HTTP110 POP3143 IMAP443 HTTPS445 SMB 587 SMTPS993 IMAPS995 POP3S1433 MSSQL3306 MySQL 3389 RDP5432 PgSQL6379 Redis8080 HTTP-alt8443 HTTPS-alt 9200 Elastic27017 Mongo7547 TR-0698291 Winbox5900 VNC 5060 SIP5061 SIP-TLS502 Modbus102 S74840 OPC UA 20000 DNP347808 BACnet44818 EtherIP2404 IEC-1041911 Niagara 1883 MQTT9100 Printer2375 Docker11211 Memcached37777 Dahua 5000 UPnP5601 Kibana15672 RabbitMQ789 Tor8883 MQTTS 2049 NFS111 RPC135 MS-RPC139 NetBIOS465 SMTPS 636 LDAPS

FAQ

How does QROS scan open ports?

QROS connects to every indexed host on 51 common TCP ports and attempts a TCP handshake. For each open port, it grabs the service banner, identifies the software and version, and reads the TLS certificate on encrypted ports.

What ports does QROS scan?

QROS scans 51 common ports including SSH (22), HTTP/HTTPS (80, 443, 8080, 8443), FTP (21), DNS (53), RDP (3389), Modbus (502), MQTT (1883, 8883), Redis (6379), MongoDB (27017), Elasticsearch (9200), and more.

Is port scanning legal?

Yes. QROS only reads what a host exposes to any connecting client — open ports, banners and certificates. It does not bypass security measures, authenticate, exploit, or access personal data. See the legal notice for the full analysis under Spanish and European law.

Try this service with QROS

Explore now →