سُور
Soor SiteQ8 · open source

سُور يفحص شبكة بيتك كما يفحصها مختبِر الاختراق

يجد كل جهاز متصل بشبكتك ويقرأ ما يفتحه من منافذ، ويميّز المكشوف منها إلى الإنترنت من الآمن داخل الشبكة، ثم يرتّب ما وجده بحسب الخطورة مع خطوة إصلاح واضحة لكل اكتشاف، وهو يعمل داخل هاتفك، بلا حساب ولا خادم ولا جمع بيانات.

Soor scans your home network the way a penetration tester would

It finds every device on your network and reads the ports each one leaves open, tells what is exposed to the internet from what is safe inside, then ranks what it found by severity with a clear fix for each. It runs inside your phone, with no account, no server, and no data collection.

ماذا يكشف

What it finds

الكاميرات المكشوفةExposed cameras

كاميرا على كلمة مرور المصنع ومنفذها مرّره الراوتر إلى الإنترنت، وهي الحالة التي تظهر في محركات الفحص العامة.

A camera on its factory password with its port forwarded to the internet by the router, the case that shows up on public scanning engines.

المنافذ الخطرةRisky ports

تحكم عن بُعد مكشوف، منفذ تصحيح أخطاء في صناديق أندرويد، مشاركة ملفات مفتوحة، لوحة إدارة بلا تشفير.

Exposed remote control, a debug port on Android boxes, open file shares, an admin panel with no encryption.

إعدادات الراوترRouter settings

خاصية UPnP التي تفتح منافذ إلى الإنترنت دون علمك، ولوحة إدارة بلا تشفير.

The UPnP feature that opens ports to the internet without your knowledge, and an admin panel with no encryption.

الأجهزة الجديدةNew devices

جهاز ظهر على شبكتك لأول مرة، لتتأكد أنك تعرفه.

A device seen on your network for the first time, so you can be sure you recognise it.

افحص بيتًا، ثم أصلحه

اختر بيتًا وشاهد سُور يكتشف أجهزته ويفحص منافذها ويقرأ جدول الراوتر، ثم اضغط أي جهاز لترى منافذه ومدى خطورتها، وطبّق الحل فيعيد المحرك حكمه وترى السور يُرمَّم أمامك، علمًا أن البيت هنا افتراضي لأن صفحة الويب لا تفحص شبكتك، لكنّ كل حكم تراه يُصدره محرك سُور الحقيقي نفسه.

Scan a home, then fix it

Pick a home and watch Soor find its devices, check their ports and read the router's table. Then tap any device to see its ports and how serious they are, apply the fix, and watch the engine judge again as the wall is repaired in front of you. The home is hypothetical, because a web page cannot scan your network, but every verdict you see is computed by the real Soor engine.

شودان وأمثاله

شودان محرك بحث أطلقه جون ماذرلي عام 2009، لكنه لا يفهرس صفحات المواقع كما يفعل جوجل، بل يفهرس الأجهزة المتصلة بالإنترنت نفسها، كالراوترات والكاميرات والخوادم وأجهزة التخزين وأنظمة التحكم الصناعية، فيسجّل ما يعلنه كل جهاز عن نفسه ويتيحه لكل من يبحث.

كيف يعمل

  1. يختار عنوانًا ومنفذًاتعمل ماسحاته على مدار الساعة من مواقع كثيرة حول العالم، فيختار كل منها عنوانًا عشوائيًا على الإنترنت ومنفذًا عشوائيًا.
  2. يتصل بالجهازيحاول الاتصال بذلك المنفذ، فإن أجاب جهاز عرف أن فيه خدمة مفتوحة للإنترنت.
  3. يسجّل ما يعلنهيحفظ الرسالة التي تعرّف بها الخدمة نفسها، وفيها غالبًا اسم الجهاز وطرازه ونسخة برنامجه.
  4. يتيحه للبحثيضيف ما سجّله إلى فهرس يبحث فيه أي أحد بحسب الدولة أو نوع الجهاز أو المنفذ، ثم يعيد الكرّة حتى يمرّ على الإنترنت كله مرة في الأسبوع على الأقل.

حقائق بالأرقام

5 دقائق

تكفي لتصل أغلب الماسحات المعروفة إلى أي جهاز جديد يتصل بالإنترنت، بحسب قياس أجرته GreyNoise عام 2024.

المصدر
45 دقيقة

يحتاجها حاسوب واحد ليفحص عناوين الإنترنت كلها على منفذ واحد، وتنزل إلى نحو خمس دقائق باتصال أسرع، كما أثبت باحثو جامعة ميشيغان عام 2013.

المصدر
كل أسبوع

يمرّ شودان على الإنترنت كله مرة على الأقل، بينما تعمل ماسحاته دون توقف.

المصدر
24 ساعة

تكفي لتظهر التغييرات في نتائج شودان وCensys بعد رصدها، بحسب دراسة علمية نُشرت عام 2021.

المصدر
62

زوجًا فقط من أسماء المستخدمين وكلمات المرور الافتراضية كانت كل ما احتاجه ميراي عام 2016 ليسيطر على مئات الآلاف من الكاميرات والراوترات.

المصدر
73,000

كاميرا في 152 دولة بثّها موقع واحد عام 2014 لأن أصحابها لم يغيّروا كلمة مرور المصنع، وبقي أكثر من ألفين منها متاحًا حتى عام 2025.

المصدر

ليس شودان وحده

ويعمل بالطريقة نفسها محركات أخرى كثيرة، منها Censys الذي أسسه عام 2015 باحثو جامعة ميشيغان أنفسهم الذين صنعوا أداة ZMap، وBinaryEdge من أوروبا، وZoomEye وFOFA من الصين، إضافة إلى عشرات الجهات التي تمسح الإنترنت يوميًا لأغراض البحث والأمن.

ShodanCensysZoomEyeFOFABinaryEdgeONYPHENetlas

هذه المحركات لا تخترق شيئًا، بل تُظهر ما هو مكشوف أصلًا، فإذا اجتمع في جهاز منفذ ممرَّر إلى الإنترنت وكلمة مرور مصنع صار في متناول كل من يبحث، وهذا ما يكشفه سُور من داخل بيتك قبل أن تجده هذه المحركات من خارجه.

ماذا تفعل

  • لا تمرّر منافذ أجهزتك إلى الإنترنت، وعطّل UPnP في الراوتر إن لم تحتجه
  • غيّر كلمة مرور المصنع في كل جهاز فور تركيبه
  • حدّث برامج الراوتر والكاميرات وأجهزة البث باستمرار
  • افحص شبكتك من الداخل بسُور، وابحث في شودان عن عنوان بيتك أنت فقط لترى ما سجّله عنه

لا يتصل سُور بهذه المحركات ولا يرسل إليها شيئًا، بل يرى من داخل شبكتك ما قد تراه هي من خارجها.

مصادر هذا القسم

Shodan and the others

Shodan is a search engine John Matherly launched in 2009, but it does not index web pages the way Google does. It indexes the devices connected to the internet themselves, such as routers, cameras, servers, storage and industrial control systems, and records what each one announces about itself so anyone can search it.

How it works

  1. Picks an address and a portIts scanners run around the clock from many places in the world, each picking a random internet address and a random port.
  2. Connects to the deviceIt tries that port, and if a device answers, it knows there is a service open to the internet.
  3. Records what it announcesIt keeps the message the service introduces itself with, which usually names the device, its model and its software version.
  4. Makes it searchableIt adds the record to an index anyone can search by country, device type or port, then starts again, covering the whole internet at least once a week.

The facts in numbers

5 minutes

is enough for most known scanners to reach a new device that comes online, according to a 2024 measurement by GreyNoise.

Source
45 minutes

is all one computer needs to scan every internet address on one port, and a faster link brings it to about five, as University of Michigan researchers showed in 2013.

Source
Every week

Shodan covers the whole internet at least once, while its scanners never stop.

Source
24 hours

is enough for changes to show up in Shodan and Censys results once seen, according to a 2021 academic study.

Source
62

default username and password pairs were all Mirai needed in 2016 to take over hundreds of thousands of cameras and routers.

Source
73,000

cameras in 152 countries were streamed by a single website in 2014 because their owners never changed the factory password, and over two thousand were still accessible in 2025.

Source

Not only Shodan

Many other engines work the same way, among them Censys, founded in 2015 by the same University of Michigan researchers who built ZMap, BinaryEdge from Europe, and ZoomEye and FOFA from China, alongside dozens of organisations that scan the internet every day for research and security.

ShodanCensysZoomEyeFOFABinaryEdgeONYPHENetlas

These engines break into nothing. They show what is already exposed. When a device has a port forwarded to the internet and a factory password, it is within reach of anyone who searches, and that is what Soor finds from inside your home before these engines find it from outside.

What to do

  • Do not forward your devices' ports to the internet, and turn off UPnP on the router if you do not need it
  • Change the factory password on every device as soon as you set it up
  • Keep the router, cameras and streaming boxes updated
  • Check your network from inside with Soor, and look up your own home address on Shodan, only yours, to see what it has recorded

Soor never contacts these engines or sends them anything. It sees from inside your network what they might see from outside.

Sources for this section

كيف يعمل

How it works

يرسم خريطة شبكتك

يجد الأجهزة المتصلة بشبكتك ويقرأ ما تعلنه من منافذ وخدمات، دون أن يجرب كلمة مرور أو يستغل ثغرة، فهو يطرق الأبواب فقط.

Maps your network

It finds the connected devices and reads the ports and services they announce, without trying a password or exploiting a flaw. It only knocks on doors.

يتعرّف ويقيّم

يطابق كل جهاز بقاعدة معرفة محمولة داخله، فيعرف طُرز الكاميرات المعروفة بكلمة مرور المصنع، والمنافذ التي لا ينبغي أن تكون مفتوحة.

Identifies and judges

It matches each device against a knowledge base carried inside it, so it knows the camera models known for factory passwords and the ports that should not be open.

يفحص الراوتر

يقرأ جدول المنافذ الممرَّرة إلى الإنترنت في الراوتر، فيميّز الجهاز المكشوف للخارج من الجهاز الآمن داخل الشبكة.

Checks the router

It reads the router's table of ports forwarded to the internet, telling a device exposed to the outside from a safe device inside the network.

يشرح ويرشدك إلى الحل

يحوّل كل اكتشاف إلى جملة يفهمها غير المختص مع خطوة إصلاح واضحة، بالعربية والإنجليزية، وأنت وحدك من يرسل التقرير إن أردت مشاركته.

Explains and guides the fix

It turns each finding into a sentence a non-specialist understands with a clear fix, in Arabic and English. You alone send the report if you choose to share it.

الكاميرات وكلمة مرور المصنع

الكاميرا تظهر في محركات الفحص العامة لسببين مترابطين: أن الراوتر مرّر منفذها إلى الإنترنت، وأنها ما زالت على كلمة مرور المصنع، وسُور يعالج السببين معًا من داخل الشبكة قبل أن يجدها الماسح الخارجي.

سُور لا يجرّب كلمة مرور على أي كاميرا، لأن هذا يجعله أداة هجوم، بل يكشف الضعف بثلاث طرق دفاعية: يقرأ جدول UPnP في الراوتر ليعرف إن كان منفذ الكاميرا مفتوحًا إلى الإنترنت، ويتعرّف على طراز الكاميرا فيقول لك إن هذا الطراز يُشحن ببيانات دخول معروفة للعامة، ويقرأ صفحة دخولها إن أعلنت أنها بلا كلمة مرور أو قبلت البث دون مصادقة.

ومثل هذه القوائم من بيانات المصنع هو ما تستعمله برمجيات خبيثة كميراي لاقتحام الأجهزة، أما محركات الفحص فلا تجرّب كلمات المرور بل تسجّل ما تعلنه الأجهزة فقط، ووجود القائمة في المشروع للتوعية بضرورة تغييرها لا لاستعمالها.

Cameras and the factory password

A camera appears on public scanning engines for two linked reasons: the router forwarded its port to the internet, and it is still on its factory password. Soor addresses both from inside the network before an outside scanner finds it.

Soor never tries a password on any camera, because that would make it an attack tool. Instead it detects the weakness three defensive ways: it reads the router's UPnP table to see whether the camera's port is open to the internet, it identifies the camera model and tells you that model ships with publicly known login details, and it reads the login page when it announces it has no password set or serves the stream without authentication.

Lists of factory credentials like this one are what malware such as Mirai uses to break into devices. Scanning engines do not try passwords; they only record what devices announce. The list is in the project to raise awareness that these passwords must be changed, not to be used.

احصل على سُور

سُور منشور على App Store، وعلى Google Play ما زال في الاختبار المغلق قبل نشره للجميع، والانضمام إليه مفتوح لمن يرغب، وكل مختبِر يقرّب يوم النشر.

سُور لشبكة بيتك أو لشبكة أنت مسؤول عنها، وفحص شبكة لا تملكها، كشبكة مقهى أو مطار أو مكان عمل، قد يخالف القانون وهو خلاف الغرض من التطبيق.

Get Soor

Soor is on the App Store. On Google Play it is still in closed testing before its public release; joining is open to anyone, and every tester brings the release day closer.

Soor is for your home network, or a network you are responsible for. Scanning a network you do not own, such as a café, airport or workplace, may be against the law and is not what the app is for.

أندرويدAndroid

أرسل بريد حسابك في Google إلى site@hotmail.com لنضيفك إلى المختبرين، ثم افتح رابط الاشتراك واضغط «أصبح مختبِرًا»، ويصلك التطبيق وتحديثاته من Google Play مباشرة.

Send the email of your Google account to site@hotmail.com to be added as a tester, then open the opt-in link and tap Become a tester. The app and its updates then come straight from Google Play.

آيفونiPhone

سُور منشور على App Store، فثبّته من صفحته في المتجر وتصلك تحديثاته منه.

Soor is on the App Store. Install it from its store page and updates come from there.

مفتوح المصدرOpen source

الشيفرة كلها على GitHub، ومن يحب البناء بنفسه يجد فيها تطبيقي الأندرويد والآيفون والموقع والمحرك المشترك بينها.

Everything is on GitHub: the Android and iPhone apps, this site, and the engine they share, for anyone who prefers to build it themselves.

لا يجمع بياناتك

سُور يعمل داخل هاتفك بالكامل، فلا حساب ولا خادم لنا ولا يخرج بشيء عنك، ومعرفته كلها مشحونة داخله، ولا يتصل إلا بعناوين داخل شبكة بيتك، إذ في شيفرته قاعدة ترفض أي عنوان خارجها قبل أن يتصل به، وتُختبر هذه القاعدة آليًا مع كل بناء، ويمكنك أن تتحقق منها بنفسك في الشيفرة المفتوحة.

وتطلب نسخة الأندرويد إذن الإنترنت لأن أندرويد يشترطه لأي اتصال بالشبكة حتى داخل البيت، أما ما يُبقي سُور في بيتك فهو تلك القاعدة لا غياب الإذن.

سياسة الخصوصية كاملة

It collects nothing

Soor runs entirely inside your phone. No account, no server of ours, and it takes nothing about you out. All its knowledge is shipped inside it, and it only ever connects to addresses inside your home network: a rule in its code refuses any other address before connecting, the rule is tested automatically on every build, and you can verify it yourself in the open source.

The Android version asks for the internet permission because Android requires it for any network connection, even inside the home. What keeps Soor in your home is that rule, not the absence of a permission.

The full privacy policy