About the data
What this site publishes
OSN is a search over information that any computer on the internet can already see.
What is published
- Services reachable on the public internet. Which ports answer on an address, and what the service says about itself to anyone who connects.
- Software versions. The product and version seen in those responses.
- Known vulnerabilities. Published vulnerabilities (CVEs) matched from those versions.
- Domain names. Registration status, public DNS records and host names known under a domain.
- Addresses and networks. The route an address is announced in and the network that announces it, its registry network and abuse contact, its reverse DNS name, its country (and, where the network's operator publishes it, its city), and whether it is a Tor relay, a VPN or privacy relay address, a cloud or hosting address, or on a current public blocklist.
How matches are made
A vulnerability is listed for a host when the version a service announced falls in the range that vulnerability affects.
A match is an indication, not proof. Nothing is tested for exploitability, and fixes are often backported: vendors and distributions patch a flaw without changing the version number. Treat a match as a reason to check, not as a finding.
Addresses, locations and blocklists
Routes and their validity, network relationships and registry data are public routing and registry information. A location is shown at city level only where the operator of the network publishes it for its own addresses; otherwise only the country is shown. A location is approximate and says nothing about a person.
A blocklist entry means a public list currently names the address or a range that contains it: it is shown with what the list is about and since when. Private, reserved and unallocated address space is never called blocklisted. Lists change by the hour; an entry is not proof of wrongdoing.
What is not published
Only publicly reachable information is shown: nothing that needs a login, a password or a way around an access control.
The site shows technical data about internet-facing services and domains: no names of people, personal e-mail addresses, message content or tracking of people. Network abuse contacts shown are the role mailboxes networks publish for that purpose.
IP addresses of internet-facing devices and the host names that point to them are shown as observed; operators can ask for removal or opt out at [email protected].
Removal and abuse
To have an address or an address range removed from this site, or to report abuse, write to [email protected]. Name the addresses or the range and say how you are responsible for them. Requests are answered within a few working days.
To report a security problem with this site itself, see security.txt.
Visitors
What the site records about its own visitors is described in Privacy.