سُور
Soor SiteQ8 · open source

سُور يفحص شبكة بيتك كما يفحصها المختبِر

يكشف الأجهزة المتصلة بشبكتك وما تفتحه من منافذ خطرة، ويحذّرك من الكاميرا التي ما زالت على كلمة مرور المصنع ومنفذها مفتوح إلى الإنترنت، قبل أن تجدها محركات الفحص العامة. يعمل داخل هاتفك، بلا حساب ولا خادم ولا جمع بيانات.

Soor scans your home network the way a tester would

It finds the devices on your network and the risky ports they leave open, and warns you about the camera still on its factory password with its port open to the internet, before public scanning engines find it. It runs inside your phone, with no account, no server, and no data collection.

ماذا يكشف

What it finds

الكاميرات المكشوفةExposed cameras

كاميرا على كلمة مرور المصنع ومنفذها مرّره الراوتر إلى الإنترنت، وهي الحالة التي تظهر في محركات الفحص العامة.

A camera on its factory password with its port forwarded to the internet by the router, the case that shows up on public scanning engines.

المنافذ الخطرةRisky ports

تحكم عن بُعد مكشوف، منفذ تصحيح أخطاء في صناديق أندرويد، مشاركة ملفات مفتوحة، لوحة إدارة بلا تشفير.

Exposed remote control, a debug port on Android boxes, open file shares, an admin panel with no encryption.

إعدادات الراوترRouter settings

خاصية UPnP التي تفتح منافذ إلى الإنترنت دون علمك، ولوحة إدارة بلا تشفير.

The UPnP feature that opens ports to the internet without your knowledge, and an admin panel with no encryption.

الأجهزة الجديدةNew devices

جهاز ظهر على شبكتك لأول مرة، لتتأكد أنك تعرفه.

A device seen on your network for the first time, so you can be sure you recognise it.

جرّبه

صفحة الويب لا تفحص شبكتك، لكنها تشغّل محرك سُور نفسه على نتائج فحص واقعية لتريك ما يعرضه التطبيق تمامًا. اختر مشهدًا.

Try it

A web page cannot scan your network, but it runs the same Soor engine on realistic scan results to show you exactly what the app displays. Pick a scenario.

soor · engine demo

كيف يعمل

How it works

يرسم شبكتك

يجد الأجهزة المتصلة بشبكتك ويقرأ ما تعلنه من منافذ وخدمات، دون أن يجرب كلمة مرور أو يستغل ثغرة. يطرق الأبواب فقط.

Maps your network

It finds the connected devices and reads the ports and services they announce, without trying a password or exploiting a flaw. It only knocks on doors.

يتعرّف ويقيّم

يطابق كل جهاز بقاعدة معرفة محمولة داخله، فيعرف طُرز الكاميرات المعروفة بكلمة مرور المصنع، والمنافذ التي لا ينبغي أن تكون مفتوحة.

Identifies and judges

It matches each device against a knowledge base carried inside it, so it knows the camera models known for factory passwords and the ports that should not be open.

يفحص الراوتر

يقرأ جدول المنافذ الممرَّرة إلى الإنترنت في الراوتر، فيميّز الجهاز المكشوف للخارج من الجهاز الآمن داخل الشبكة.

Checks the router

It reads the router's table of ports forwarded to the internet, telling a device exposed to the outside from a safe device inside the network.

يشرح ويصلح

يحوّل كل اكتشاف إلى جملة يفهمها غير المختص مع خطوة إصلاح واضحة، بالعربية والإنجليزية. أنت وحدك من يرسل التقرير إن أردت مشاركته.

Explains and fixes

It turns each finding into a sentence a non-specialist understands with a clear fix, in Arabic and English. You alone send the report if you choose to share it.

الكاميرات وكلمة مرور المصنع

الكاميرا تظهر في محركات الفحص العامة لسببين مترابطين: أن الراوتر مرّر منفذها إلى الإنترنت، وأنها ما زالت على كلمة مرور المصنع. سُور يعالج السببين معًا من داخل الشبكة قبل أن يجدها الماسح الخارجي.

سُور لا يجرّب كلمة مرور على أي كاميرا، لأن هذا يجعله أداة هجوم. بدلًا من ذلك يكشف الضعف بثلاث طرق دفاعية: يقرأ جدول UPnP في الراوتر ليعرف إن كان منفذ الكاميرا مفتوحًا إلى الإنترنت، ويتعرّف على طراز الكاميرا فيقول لك إن هذا الطراز يُشحن ببيانات دخول معروفة للعامة، ويقرأ صفحة دخولها إن أعلنت أنها بلا كلمة مرور أو قبلت البث دون مصادقة.

القائمة نفسها من بيانات المصنع هي ما تستعمله محركات الفحص، ووجودها في المشروع للتوعية بضرورة تغييرها لا لاستعمالها.

Cameras and the factory password

A camera appears on public scanning engines for two linked reasons: the router forwarded its port to the internet, and it is still on its factory password. Soor addresses both from inside the network before an outside scanner finds it.

Soor never tries a password on any camera, because that would make it an attack tool. Instead it detects the weakness three defensive ways: it reads the router's UPnP table to see whether the camera's port is open to the internet, it identifies the camera model and tells you that model ships with publicly known login details, and it reads the login page when it announces it has no password set or serves the stream without authentication.

The same factory-credential list is what scanning engines use; it is in the project to raise awareness that they must be changed, not to be used.

لا يجمع بياناتك

سُور يعمل داخل هاتفك بالكامل. لا حساب، ولا خادم لنا، ولا يخرج بشيء عنك. معرفته كلها مشحونة داخله. نسخة الأندرويد لا تطلب إذن الإنترنت أصلًا، فلا تستطيع أن ترسل شيئًا حتى لو أرادت، وهذا مفروض ببنية التطبيق لا بوعد في سياسة الخصوصية، ويمكنك التحقق منه بنفسك في الشيفرة المفتوحة.

It collects nothing

Soor runs entirely inside your phone. No account, no server of ours, and it takes nothing about you out. All its knowledge is shipped inside it. The Android version does not even request internet permission, so it cannot send anything even if it wanted to, and this is enforced by the app's structure rather than promised in a privacy policy, and you can verify it yourself in the open source.