Find cloud servers left open to the whole internet
Every night, WebRun signs in to Alibaba Cloud, walks the security groups in each region, finds inbound rules that let any source address reach a port, matches them to the ECS instances they cover, raises a Trello card per finding, and sends the night's count to your on-call WhatsApp group.
- No credit card
- Under $0.01 per run
- Cancel anytime
How do I find cloud servers exposed to the public internet?
WebRun signs in to Alibaba Cloud every night and walks the security groups in each region, looking for inbound rules that let any source address reach a port. It raises a Trello card per finding with the port and the ECS instances exposed, then sends the night's count to your on-call WhatsApp group.
- Wide open ports surface the same night they appear
- Every finding names the instances behind the rule
- Ports you accept as public are recorded as expected, not raised
Built for cloud engineers · DevOps teams · security operations · platform teams
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
account.alibabacloud.com/loginin a real browser with your saved login - no setup, no API keys. -
1
Alibaba Cloud - audit inbound rules
WebRun opens Alibaba Cloud to audit inbound rules. - Sign in to Alibaba Cloud and select each region you run resources in
- List the security groups and read their inbound rules
- Flag any rule whose source is open to all addresses and record the port and protocol
- Match each flagged group to the ECS instances attached to it and note the instance name and region
Done when Every open inbound rule is listed with its port and the instances it exposes.
-
2
Trello - raise a card per finding
WebRun opens Trello to raise a card per finding. - Open your cloud security board in Trello
- Add a card per finding: region, security group, port, protocol, and the instances behind it
- Put management ports and database ports at the top of the list
- Close out cards whose rule has since been tightened so the board reflects tonight's reality
Done when Tonight's findings are on the board and fixed ones are closed.
-
3
WhatsApp - send the nightly count
WebRun opens WhatsApp to send the nightly count. - Send your on-call group a short WhatsApp message with tonight's count
- Name the highest-risk ports found and link the Trello board
- Say plainly when nothing new was found so the group knows the audit ran
Done when The on-call engineer knows what tonight's audit turned up.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Will it change or delete a security group rule?
No. WebRun reads your security groups and reports what it finds. Tightening or removing a rule stays a human action taken deliberately inside the console.
What if a port is open on purpose?
Give WebRun the list of ports and groups you accept as public, such as a web tier on 80 and 443, and those are recorded as expected instead of raised as findings.
Does the WhatsApp message contain sensitive detail?
No. The message carries a count, the port numbers, and a Trello link. Instance identifiers and rule detail stay on the board behind your own login.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.