Three things are talking. Raqib listens to all of them.
Jetpack watches WordPress sites and bills you monthly. Fing watches
networks and steers you toward a subscription and a dongle. Neither of
them hears the tracker tag in your coat pocket. These are the same
question asked in three places — what is around me, and is any of it a
problem — and nobody answers all three in one app.
WiFi · the network you are on
See who is on your WiFi
Every address on the local /24 gets a TCP connect probe. A refused
connection proves a host exists just as surely as an accepted one —
that distinction is what makes the sweep fast and permission-free. mDNS
and reverse DNS then put names to whatever answered.
Local network8 devices
- 192.168.1.1 · Router80 443 53
- 192.168.1.47 · Camera554 23
- 192.168.1.211 · Unidentified5555
- 192.168.1.102 · NAS445 548 2049
- 192.168.1.37 · This device—
Findings2 exposed
CRITICAL
Telnet is open (port 23)
Telnet sends passwords in plain text and is the single most common way cheap IoT devices get recruited into botnets. Disable it.
CRITICAL
Android Debug Bridge is open (port 5555)
Anyone on this network can install apps and read data on that device without any prompt.
Nine risky services are catalogued in plain language — Telnet, FTP, ADB, SMB, RDP, VNC, Redis, MongoDB, UPnP.
Radio · the air around you
Who is advertising nearby
Phones, earbuds, tags and TVs shout their presence over Bluetooth
constantly, to anything willing to listen. Raqib listens, works out what
each one probably is, and flags the ones that match a finder-network
tag. It does not connect to any of them.
Bluetooth5 advertising
- Earbuds or headphones−52 dBm
- Tracker tag−41 dBm
- Watch or band−67 dBm
- TV or streamer−74 dBm
- Bluetooth gadget−88 dBm
Findings1 worth a look
MEDIUM
Looks like a tracker tag
This advertisement matches a finder-network tag — AirTag, SmartTag, Tile and similar. Harmless if it is yours. Worth checking if you did not bring one in.
Twelve seconds of listening, strongest signal per device wins. No pairing, no GATT, nothing written.
Sites · what you publish
Your own certificates and headers
A check follows the redirect chain by hand, reads the certificate off
the socket, looks for six response headers, scans the first 512 KB
for mixed content, and notices when a server volunteers its own version
number. Every fault carries a penalty, and the penalties make the grade.
Siteschecked 14:22
- seraf.devC 76 · UP · 142 ms
- old.example.comF 17 · DOWN · 500
Findingsseraf.dev · 3
HIGH
Missing Content-Security-Policy
Without it, one injected script tag is enough to take over the page. Costs 15 points.
MEDIUM
Certificate expires in 24 days
Worth confirming auto-renewal is actually working. Costs 10 points.
Grades are arithmetic, not opinion: 100 minus every penalty, floored at zero. A is 90 and up.