← All videos

iPhone Port Scanner: Find Open Ports on Your Home Network

Playing loads the YouTube player (Google). Or watch it on YouTube.

Scan the open ports of every device on the network from an iPhone: what a port scan does, the three scan depths, which open ports matter, and how to close one.

Chapters

Read the matching guide

Transcript

Every device on your network keeps a few doors open for other devices. Those doors are called ports. A printer listens on one for print jobs, a camera on another for its video. Most are harmless, a few are not. In this video we scan the ports of every device from an iPhone, and work out which open ports deserve your attention.

We use DeviceShelf for iPhone with its demo network, a made-up home with a dozen devices. None of these addresses are real. On your own phone, the same steps show your own network.

The scan that fills the device list already checks ports. The number in the summary at the top counts all open ports it found, here thirty one across the network.

In each row, the small numbers under the name are that device's open ports. The router has fifty three for name lookups, and eighty and four forty three for its settings page. The DiskStation adds four forty five for file sharing and five thousand for its admin pages. The printer has six thirty one and ninety one hundred for printing.

Open a device to see its ports with the services behind them. This Raspberry Pi answers on twenty two, which is SSH for remote access, eighty for a web page, and twenty three. Twenty three is Telnet, and we'll come back to it.

A port shows up as open when the device answers a connection on it. That's all a port scan does: it knocks on each door and notes which ones answer. It doesn't log in and doesn't change anything.

How many doors the app knocks on is up to you. In the settings, under Scan depth, there are three levels.

Quick checks seventeen well-known ports: file transfer, SSH, Telnet, web, Windows file sharing, cameras, printers, remote desktop, and the port iPhones use to sync. It's fast and finds the usual suspects.

Standard is the default. It adds the ports of smart-home hubs like Home Assistant and Homebridge, media servers like Plex, MQTT, Docker, Chromecast and Windows remote management. That's the right choice for a regular check.

Deep checks every port from one to one thousand and twenty four, the whole range where classic services live. It takes noticeably longer, so use it when you want to know everything about a network, not for every scan.

Below that, Scan intensity sets how hard the app knocks. Gentle spaces the requests out, which protects weak Wi-Fi, powerline adapters and fragile cheap devices. Aggressive is faster on a healthy network. Normal sits in between and suits most homes.

Now the important part: which of these open ports are a problem? The Security tab answers that. It goes through every open port the scan found, and lists the ones worth your attention, with a risk score for the whole network on top.

The demo network scores forty six out of a hundred, with one high, two medium and one info finding. It's a risk score, so lower is better. Let's go through them.

High: Telnet open on the Raspberry Pi, port twenty three. Telnet is remote access without encryption. Everything, including the password, crosses the network as plain text. There's no good reason to leave it on today. Switch it off on the device and use SSH, which the Pi already has on port twenty two.

Medium: SMB open on the DiskStation and on the MacBook, port four forty five. That's Windows file sharing. On a NAS it's the reason the NAS exists, so medium here means: make sure it has a strong password and that the router never forwards this port to the internet.

Info: a camera detected. That's not a fault, just a reminder. Cameras are popular targets, so check that this one belongs to you, has a password that isn't the factory one, and gets firmware updates.

How do you close a port? Not in the scanner. A port is open because a program on the device listens on it. You close it on the device itself: switch off the service in its settings, or uninstall it. For the Pi that's one command to disable Telnet. For most gadgets it's a switch in their app or on their web page.

Then scan again. Pull down the list or tap Scan, and the port disappears from the device and from the Security tab, and the score goes down. Doing that once after every new gadget is a good habit.

To sum up: the device list shows every open port. Scan depth decides how many ports get checked, from seventeen to over a thousand. The Security tab tells you which open ports matter and why. And you close a port on the device, then scan again to confirm. DeviceShelf for iPhone is in the App Store, and the link is in the description.

More videos