A simple Python script to detect common vulnerabilities in a web application or network target — built as a learning project for penetration testing and vulnerability assessment fundamentals.
⚠️ Only scan hosts you own or have explicit written permission to test. Unauthorized scanning of systems can be illegal in many jurisdictions.
- Port scanning — checks a target for open TCP ports (default: a curated list of commonly-exposed services, or supply your own range).
- Weak-configuration flags — flags known-risky exposures out of the box, e.g. Telnet, unauthenticated Redis/MongoDB defaults, RDP/SMB exposed to the network, plaintext FTP.
- Outdated software detection — grabs service banners (SSH, HTTP, HTTPS, etc.) and compares detected version strings against a small reference table of known-old baselines.
- Simple report generation — prints a readable terminal report and can export a structured JSON report for further processing.
- Python 3.8+
- No third-party packages required (uses only the standard library:
socket,ssl,argparse,concurrent.futures,json).
# Scan common ports on a target with banner grabbing
python3 vuln_scanner.py example.com
# Scan a specific port range
python3 vuln_scanner.py 192.168.1.10 -p 1-1024
# Scan specific ports, skip banner grabbing (faster)
python3 vuln_scanner.py example.com -p 22,80,443 --no-banners
# Save a JSON report
python3 vuln_scanner.py example.com -o reports/scan_result.json============================================================
Vulnerability Scan Report — example.com
============================================================
Scanned at : 2026-09-06T12:00:00+00:00
Duration : 2.31s
Open ports : 2
Risk flags : 1
------------------------------------------------------------
[+] Port 22/tcp — SSH
Banner : SSH-2.0-OpenSSH_7.4
Software: openssh 7.4
⚠ openssh 7.4 appears older than the reference safe baseline 8.0 — check for a newer release.
[+] Port 80/tcp — HTTP
Banner : HTTP/1.1 200 OK
No specific risk flags for this port.
============================================================
Disclaimer: heuristic scan for learning purposes only. Always
verify findings manually before drawing conclusions.
============================================================
- Port scan — attempts a TCP connect to each target port using a thread pool for speed; a successful connect means the port is open.
- Banner grab — for open ports, sends a minimal protocol-appropriate
probe (e.g. an HTTP
HEADrequest) and reads the first response bytes, which often reveal the service name and version. - Risk matching — cross-references the port/service against a table of commonly-risky exposures, and the parsed version against a small known-outdated-version table.
- Report — aggregates findings into a text summary (stdout) and, optionally, a JSON file for further analysis or integration into other tooling.
vuln-scanner/
├── vuln_scanner.py # main script
├── reports/ # example/generated JSON reports land here
├── requirements.txt # (empty — stdlib only, kept for convention)
└── README.md
- UDP port scanning
- Integration with a real CVE/EOL feed instead of the static hint table
- Basic HTTP header checks (missing security headers, exposed server info)
- HTML report export
- Async I/O instead of thread pool for larger port ranges
This is an educational mini-project intended to build intuition around reconnaissance and vulnerability-assessment concepts. It is not a substitute for professional, authorized penetration testing tools like Nmap, Nessus, or OpenVAS.
Leesha