All templates
For cloud engineers, DevOps teams & security operations

Find cloud servers left open to the whole internet

Every night, WebRun signs in to Alibaba Cloud, walks the security groups in each region, finds inbound rules that let any source address reach a port, matches them to the ECS instances they cover, raises a Trello card per finding, and sends the night's count to your on-call WhatsApp group.

  • No credit card
  • Under $0.01 per run
  • Cancel anytime
14,115 templates Safe automation No code
Every night at 11:00 PM WebRun
1 Alibaba Cloud audit inbound rules
2 Trello raise a card per finding
3 WhatsApp send the nightly count
Run a sample
In short

How do I find cloud servers exposed to the public internet?

WebRun signs in to Alibaba Cloud every night and walks the security groups in each region, looking for inbound rules that let any source address reach a port. It raises a Trello card per finding with the port and the ECS instances exposed, then sends the night's count to your on-call WhatsApp group.

  • Wide open ports surface the same night they appear
  • Every finding names the instances behind the rule
  • Ports you accept as public are recorded as expected, not raised

Built for cloud engineers · DevOps teams · security operations · platform teams

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens account.alibabacloud.com/login in a real browser with your saved login - no setup, no API keys.

  2. 1
    Alibaba Cloud - audit inbound rules
    alibabacloud.com
    WebRun in Alibaba Cloud: audit inbound rules
    WebRun opens Alibaba Cloud to audit inbound rules.
    • Sign in to Alibaba Cloud and select each region you run resources in
    • List the security groups and read their inbound rules
    • Flag any rule whose source is open to all addresses and record the port and protocol
    • Match each flagged group to the ECS instances attached to it and note the instance name and region

    Done when Every open inbound rule is listed with its port and the instances it exposes.

  3. 2
    Trello - raise a card per finding
    trello.com How to Automate Trello
    WebRun in Trello: raise a card per finding
    WebRun opens Trello to raise a card per finding.
    • Open your cloud security board in Trello
    • Add a card per finding: region, security group, port, protocol, and the instances behind it
    • Put management ports and database ports at the top of the list
    • Close out cards whose rule has since been tightened so the board reflects tonight's reality

    Done when Tonight's findings are on the board and fixed ones are closed.

  4. 3
    WhatsApp - send the nightly count
    whatsapp.com How to Automate WhatsApp
    WebRun in WhatsApp: send the nightly count
    WebRun opens WhatsApp to send the nightly count.
    • Send your on-call group a short WhatsApp message with tonight's count
    • Name the highest-risk ports found and link the Trello board
    • Say plainly when nothing new was found so the group knows the audit ran

    Done when The on-call engineer knows what tonight's audit turned up.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
account.alibabacloud.com/login
ScheduleRuns automatically on this cadence
Every night at 11:00 PM
DeliveryHow each run's result reaches you
Exposure findings · WhatsApp
OutputWhat each run produces - A nightly list of security groups with inbound rules open to any source, the ports exposed, and the instances behind each one.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it change or delete a security group rule?

No. WebRun reads your security groups and reports what it finds. Tightening or removing a rule stays a human action taken deliberately inside the console.

What if a port is open on purpose?

Give WebRun the list of ports and groups you accept as public, such as a web tier on 80 and 443, and those are recorded as expected instead of raised as findings.

Does the WhatsApp message contain sensitive detail?

No. The message carries a count, the port numbers, and a Trello link. Instance identifiers and rule detail stay on the board behind your own login.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.