About the qsa.sh scanner

If you reached this page from a probe in your logs, you found a qsa.sh scan. This page explains exactly what runs, where it comes from, and how to stop it reaching you.

What runs

qsa.sh performs an external, outside-in security and port scan of a single public IP: the address a user connected from when they ran curl qsa.sh. The scan looks only at what the internet can already see of that host — open ports, service and version banners, TLS posture, and known-CVE indicators. It never authenticates, never sends application payloads, and never attempts exploitation. Each user can only ever cause a scan of their own connecting IP; there is no field to point it at anyone else, and known CGNAT, mobile-carrier, IPv6, and detected-anonymizer origins are refused outright.

Concretely: naabu 2.6.1 discovers open ports, nmap 7.93 with the vulners script fingerprints each service and maps it to known CVEs, and nuclei 3.3.9 with the public nuclei-templates checks for exposures and misconfigurations — all open-source, no black-box software. Full per-tier detail is on How it works.

Where scans come from

Scans originate from our scanner nodes and are identified as scanner.qsa.sh. We run a transparent-scanner model (like Shadowserver or Censys): probes egress from our real, attributable server IP addresses — we do not anonymize traffic behind a VPN or hide the source. Reverse DNS (PTR) for our scanner addresses points back to scanner.qsa.sh, and that hostname redirects here so anyone investigating a probe can find this page.

Paid Full and Deep scans use the same transparent scanner egress (scanner.qsa.sh over our real server IPs) and obey the same opt-out list and refusal rules — opting out covers every tier.

Operators: scanner.qsa.sh serves a small 301 redirect to /about. The DNS records and PTR entries for the scanner IPs are set at the hosting/network provider and are outside this application.

How to opt out

You can permanently exclude an IP address or range you control from ever being scanned by qsa.sh. Opt-outs are honoured at the point a scan is admitted, before any packet is sent.

Use the contact form (choose Opt-out request) with the IP address or CIDR range to exclude.

Include enough detail to show you are responsible for the address (for example, that it is your allocation, or the abuse contact for it).

Once added to the opt-out list, the range is refused with an “excluded from scanning” response and no scan is ever run against it.

Known carrier-grade NAT (CGNAT) and mobile-carrier ranges are already excluded by default, as are IPv6 origins and connections our data flags as a proxy, VPN, or Tor, because no single user can be authorized for a whole shared gateway and an anonymizer hides the true origin. Your own cloud, hosting, or datacenter IP is not excluded.

Contact

The contact form is the only way to reach us — we don’t operate an inbound email server, so email sent to qsa.sh addresses won’t be received. Choose the subject that matches:

Abuse & opt-out

Abuse reports and opt-out requests: use the contact form.

Security

Security disclosures: use the contact form.

Operator

qsa.sh is operated by Tuxxin.