This week we audited our own infrastructure with Shodan — the search engine that indexes what any internet-connected device is already exposing publicly: open ports, active services, software versions.
Before turning that outside view on a client, we turned it on ourselves first. That's how we work: evidence before opinion, our own infrastructure included.
What we found
Our production server exposes only what it should — no surprises, no forgotten ports from some earlier configuration.
Shodan flagged two vulnerabilities based on the software version exposed in the banner. We investigated each one thoroughly before reacting. Both turned out to be false positives: the tool detects by the version number the software reports, not by the security patches already applied underneath that version. An automated alert is a starting point, not a conclusion — it has to be verified against the real source before acting on it.
A configuration that looked like a weakness at first glance turned out to be a conscious decision, necessary to keep certain functionality working. Not everything a scanner flags is a mistake — sometimes it's a trade-off already made with eyes open, not an oversight.
Why this matters beyond the specific finding
External reconnaissance tools don't replace your own vigilance — they complement it. They give you something no internal audit can give on its own: the same view anyone searching from outside would have.
And the most valuable exercise isn't always found in a client's infrastructure. Sometimes it's in confirming — or questioning — your own first, before offering anyone else a look you haven't given yourself.
We look first. Then we decide.
At Directsales PTY, we don't recommend tools before understanding what's actually exposed. We audit first — our own infrastructure included — and decide after, with evidence, not assumptions.
Want to know what your own infrastructure is really showing right now? Schedule a technical conversation with Directsales PTY.