If you are reading this because you saw a connection from scanner.auditmypc.com in a firewall log, this page explains what it was.
What it is
AuditMyPC runs a free port scanner. Somebody opens our page, reads the warning, and clicks a button. We then try to open a TCP connection to a short list of ports on their own address to see which ones answer, and we show them the result. The connection you saw is that test.
It only ever goes back to whoever asked
This is the part that matters if you are worried. We only ever scan the address the request came from. Nobody can type in your address, or anyone else’s, and have us scan it for them. The address is read off the connection itself, and the permission slip our page hands the scanner is signed for that one address and expires in about two minutes. There is no field to put a different address in, and no header we will believe instead of the connection.
So if you saw us, one of two things happened: somebody on your network ran the test, or your network recently handed that address to somebody who did.
How to recognise it
- It comes from 64.177.14.241, which is scanner.auditmypc.com in reverse DNS.
- It is a plain TCP handshake and nothing else. We open the connection and close it. Nothing is sent, no banner is read, and nothing about the software behind the port is examined.
- At most 1,024 ports in one run, and one address can ask about at most 4,096 ports in any ten minutes before we start refusing.
- It stops on its own. There is no follow-up, no repeat schedule, and nothing about your network is remembered for next time.
What we keep
One line per scan: the address, how many ports were asked about, a count of how the results came back, and the time. We do not record which individual ports answered, and we never look at what is behind them. That record exists so we can answer the question that brought you here, which is usually some version of “did you connect to us at half past two, and why”.
Have your network left alone
If you would rather we never scanned an address in your range, send the range in CIDR form to monetizers@gmail.com and we will add it to the exclusion list. You do not need to explain why, and we will not argue about it.
Excluded ranges are refused before any connection is opened, so somebody on an excluded network is told plainly that we cannot test them rather than being left with a test that quietly does nothing.
Something worse than a log entry
If you think this service is being misused, or you have found a security problem with it, the contact in our security.txt reaches us and we would rather hear about it than not.
