Network Security
What Barrion checks when it evaluates your site's network-level security including open ports and DNS configuration.
Barrion checks your site's network infrastructure for risks that exist independently of your application code: exposed services, insecure DNS configuration, and abandoned subdomains that attackers could claim.
What Barrion Checks
Open Ports
Barrion scans your domain for services that are publicly accessible on the internet but should not be. Common examples include database ports, file transfer services, and administrative interfaces.
Services like databases and internal management tools are meant for private access only. When they are exposed to the internet, they become targets for brute-force attacks and unauthorized access attempts.
Severity: High
Subdomain Takeover
Barrion checks whether any subdomains of your domain point to external services that are no longer provisioned under your account. For example, if you previously used a cloud hosting service and deleted the account, but left the DNS record pointing to it, an attacker could claim that service and serve malicious content on your subdomain.
Severity: High
DNS Security (CAA)
Barrion checks for Certificate Authority Authorization (CAA) records, which restrict which certificate authorities are permitted to issue TLS certificates for your domain.
Severity: Low
What to Do
Network-level findings typically require action from whoever manages your infrastructure or hosting. Share High severity findings with your IT or DevOps team as a priority. Open database ports and subdomain takeover risks are among the most critical issues Barrion can detect. DNS configuration changes are made through your domain registrar or DNS provider.