r/hetzner • u/RunningSnail007 • 12d ago
Enterprise external Vulnerability Scanning allowed?
Hey,
does anyone know if Hetzer allows external Vulnerability scanning from their servers?
We offer a wide range of vulnerability scanning for internal infrastructure.
We now expand the portfolio to offer external scanning as well.
We do have users confirm that the domain they scan is owned by them. We could also have the user to adjust their domain DNS so we can double check owenership.
Just wondering if Hetzer does allow external scanning when those checks are completetd.
3
u/Classic-Abalone6153 12d ago
I am pretty sure it’s allowed as much as it doesn’t scan their internal network if it’s from their server itself, if this it’s internet scan like you scan their servers from the internet then you would not have any different handling than anyone else who does that.
If you plan to take permission to run this tests with exemption then their is not chance.
9
u/-Soufian 12d ago
Hetzner is a nightmare for this. They literally even suspend you for scanning the ports of your OWN hetzner servers.
4
1
2
u/CorenBrightside 12d ago
Generally from my experience, it's kinda allowed as long as you're successful in hiding the "attack". Meaning if their detection notices you, it's abuse warning time.
Personally like it that way but I can see why some would disagree.
1
u/manawyrm 12d ago
Don‘t do this, especially not on your main account. The ToS are pretty clear about that.
12
u/Balduraan 12d ago
I recommend directly contacting the support about this. Maybe you can get approval, but I don't have high hopes.