Playbook · beginner · 1–2 hours
Close accidental WAN exposure
Discover what the internet can see on your public IP, shut down risky forwards, and replace remote access with VPN.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
Scenario
After a home audit you suspect RDP, NAS, or camera ports might be reachable from WAN — or UPnP opened something you forgot. Confirm externally, fix router rules, re-test.
Goals
Identify public IP and external open services
Map each open port to an internal owner
Remove or replace with VPN
Verify clean external posture
Requirements
Router admin
Ability to check external ports (phone LTE or online tester)
Safety
Do not scan other people’s IPs
Coordinate with household before cutting remote access they rely on
Steps
External view
Intent: See yourself as an attacker on the internet would.
Actions
- curl ipify for public IP
- Shodan/Censys host lookup; ShieldsUP common ports
- Optional: scan your public IP only for specific ports you manage
Internal correlation
Intent: Match WAN ports to UPnP and manual forwards.
Actions
- upnpc -l and router port-forward UI
- Identify destination LAN IPs and services
Replace remote access
Intent: Remove permanent holes.
Actions
- Delete unnecessary forwards and UPnP maps
- Install WireGuard or Tailscale for admin access
- Disable WAN admin on router
Verify
Intent: Prove the fix.
Actions
- Re-check ShieldsUP/Shodan after TTL/cache time
- From LTE, confirm ports closed; from VPN, confirm access works
Remediation outcomes
No consumer RDP/SMB/NAS to 0.0.0.0/0
UPnP off or tightly monitored
VPN standard for remote admin
Quarterly external re-check on calendar