🎮 Game/Call Tester
Fetching...
0 ranges
--:--
👻 Ghost
Anonymity20%
Ghost OFF
📋 IP Range Manager
Add network ranges for scanning — CIDR, IP range, single IP, or bulk paste.
CIDR
Range
Single IP
Bulk
CIDR
Label
Enter CIDR to see host count
Quick Add
192.168.88.0/24 103.58.72.0/22 203.76.220.0/22 192.168.1.0/24 10.10.0.0/16 192.168.88.1 10.10.10.0/24
Added Ranges
No ranges added.
👻 Scan Engine
ℹ Simulation Mode — Browser cannot make raw TCP connections. This runs realistic vulnerability analysis. Use RouterOS commands below for real scan on your router.
No ranges loaded.
Add ranges then click Scan
0
Ranges
Hosts
Vulns
Hidden
Live Terminal
RouterOS Real Scan Commands
# Add ranges to generate commands
⚠ MikroTik Default Access — Security Audit
All RouterOS devices ship with known default credentials and open management ports. This panel shows default settings and how to secure them. Audit your own devices only.
🔑 Default Credentials
Default Username
admin
Factory default — must be changed
Default Password
(empty)
No password set at factory
Default WinBox Port
8291 / TCP
Always open, no IP restriction
Default SSH Port
22 / TCP
Enabled by default on all versions
Default IP Address
192.168.88.1
ether1 LAN interface
Default Subnet
192.168.88.0/24
DHCP pool: .2 – .254
Critical: Any device reachable on port 8291 with username "admin" and no password can be fully compromised in seconds. Change password immediately after setup: /password
🔌 Default Open Ports & Services
PortProtocolServiceDefaultRiskFix Command
🛡 Default Firewall State
Input Chain
No rules
All traffic accepted by default
NAT / Masquerade
Not configured
Must be manually set for WAN
WAN Management
All ports open
WinBox/SSH/API accessible from WAN
Neighbor Discovery
All interfaces
Broadcasts topology on WAN
DNS Cache
Remote requests: YES
Open resolver — DDoS amplification risk
Bandwidth Test
Port 2000 open
Amplification attack vector
Quick Hardening — Run These First
🔍 Check Default Access on a Device
MikroTik RouterOS Security Audit
Run a scan first.
Security Findings
Run a scan to see findings.
Discovered Hosts
Normal   Vuln   Hidden
Run a scan first.
👻 Hidden Devices
Devices detected via ARP probing, TTL anomaly, passive sniffing, or protocol broadcasts — not responding to ICMP ping.
Run a scan first.
🌐 Free Proxy List
Public proxy servers for routing HTTP API calls. Click "Use" to activate for IP lookups and geo checks.
⚠ Note: Browser security prevents direct TCP proxy routing. Proxies here work for HTTP API calls (IP lookup, geo). For full scan routing, use /ip proxy on your MikroTik.
Custom Proxy
Active: None
🔒 VPN Config Generator
WireGuard, OpenVPN, and IPSec/L2TP configs for MikroTik RouterOS.
Your Public IP Information
Public IP Address
Fetching...
ISP
Country
City
ASN
Timezone
Network
🗺 IP Geolocation Map
📊 Live Port Monitor
🛡 Firewall Rule Generator
RouterOS /ip firewall filter rules — paste into WinBox Terminal or SSH.
🕵 DNS Leak Check
Checks if DNS queries leak outside your VPN/tunnel.
📄 Full Security Report
Run a scan to generate report.
🌐 Ping Tool
Ready — enter one or more targets (one per line) and click Run Ping
⚡ Quick Ping Targets
🛤 Traceroute — Real Network Path Insight
Browsers can't send raw ICMP/UDP/TCP probes, so a router-style hop list can't be generated here truthfully. Instead this runs a real HTTP round-trip check to the target using your device's own internet connection, plus the real BGP AS-path for that destination from RIPE NCC's live route collectors.
Ready — enter a target and click Run Real Path Insight
⬡ BGP Route Lookup
Enter a prefix or ASN to query BGP routes
📋 BGP Peer Summary
Peer IPASNStatePrefixesUptime
103.16.1.1AS58931Estab48214d 06h
45.64.8.1AS7473Estab921,44032d 11h
202.4.96.2AS17494ActiveReconnecting
103.26.1.1AS38035Estab1347d 22h
192.168.100.1AS137IdleDown 2h 14m
☁ Cloudflare Radar Tools
AS13335 links are examples — swap the ASN in the URL for any network you're investigating.
🔗 Other Looking Glass Quick Links
🛡 RPKI ROA Validation
Checks whether an origin AS is authorized to announce a prefix, validated live against Routinator via RIPEstat. Use this to spot route hijacks or missing/misconfigured ROAs.
Ready — enter an ASN and prefix to validate
🌍 Global IP Announcement by AS & IP
Enter an ASN to see every prefix it announces worldwide plus its upstream/peer ASNs, or an IP/prefix to see every origin AS announcing it globally and the upstream of the top origin AS — live from RIPE NCC RIS route collectors positioned around the world.
Ready — enter an ASN or IP/prefix
👁 Peers Announcing (IP)
Live, peer-level detail from RIPE NCC's route collectors: which peers are announcing this IP/prefix, which AS originated it, and how many RRCs (collector nodes) worldwide see it — formatted as "Peers announcing (prefix) originated by AS(x) and seen by (n) RRCs."
Ready — enter an IP or prefix
🌐 DNS Propagation Checker
Real-time query across Google, Cloudflare, and Quad9 public DNS-over-HTTPS resolvers via your device's own internet connection — see exactly what each one currently returns.
Ready — enter a domain and click Check Propagation
🚫 Blacklist / RBL Checker
Real DNS-based lookup against 5 widely-used public blacklists (Spamhaus ZEN, SpamCop, Barracuda, SORBS, CBL) — useful before troubleshooting "emails not delivering" or "why is our IP blocked" tickets. Enter multiple IPs, one per line (up to 25).
🧹 Blacklist Remover: when an IP is listed, a direct removal/delisting link appears next to each blacklist below — opens that RBL's official self-service delist page.
Ready — enter one or more IPv4 addresses to check
🌐 Full IP Prefix Blacklist Scan
Checks every host address in a /24 (or smaller) block against the same 5 blacklists. Capped at 254 hosts and run in small batches to stay responsive — a full /24 scan can take a couple of minutes.
Ready — enter a /24 or smaller CIDR block
🛡 IP Abuse Check & Reporting
Powered by AbuseIPDB — check IP/prefix/ASN abuse confidence, submit abuse reports, and keep a local add/remove/edit report log with import & export. Requires a free AbuseIPDB API key.
🔑 Get / Manage API Key
🔍 Check IP / Prefix / ASN
Enter a single IPv4/IPv6 address, a CIDR prefix (e.g. 103.10.124.0/24), or an ASN (e.g. AS132203 or 132203).
Ready — enter an IP, CIDR prefix, or ASN and click Check
🚩 Report an IP
At least one category is required. Do not include personally identifiable information (PII) in the comment — reports are visible to the AbuseIPDB community.
Categories (select at least one)
Ready — fill in the IP, at least one category, and submit
📋 Bulk Check
Paste up to 50 IPs, one per line. Each is checked individually against AbuseIPDB (rate-limited to stay within your plan's daily quota).
🔗 Open AbuseIPDB Bulk-Check
Ready — paste IPs above and click Check All
📤 Bulk Report
One report per line — ip,categories,comment (categories = comma/semicolon-separated category IDs, e.g. 14;18 or 14,18 — wrap the whole line's categories in quotes if needed). Comment optional.
🔗 Open AbuseIPDB Bulk-Report (CSV upload)
Ready — paste report lines above and click Submit All Reports
💾 Local Report Log
Every Check & Report action above is logged here automatically. You can also add, edit, or remove entries manually, then import/export the whole log.
No entries yet — check or report an IP above, or add one manually.
ℹ Note: AbuseIPDB's API is designed for server-side use and may not send browser CORS headers, so Check/Report calls made directly from this page can occasionally be blocked by your browser with a network/CORS error. If that happens, use the "Open AbuseIPDB…" links to complete the action on abuseipdb.com directly, or run this tool behind a small server-side proxy on your own domain. Free-tier accounts are limited to 1,000 checks/day and reports are rate-limited — plan bulk actions accordingly.
📋 Bulk IP → ASN Lookup
Paste up to 50 IPs and/or ASNs (one per line). IPs get a real RIPEstat lookup for their announcing ASN(s) and covering prefix; ASNs (e.g. AS13335) expand into every prefix that ASN announces worldwide. Handy for triaging abuse logs or traffic lists.
Ready — paste IPs above and click Lookup All
🚧 IP Block Checker — Domain & Server Address
Checks whether a domain or server IP is reachable from your device's real internet connection — compares public DNS resolution against an actual live connection attempt. If DNS resolves fine but the real connection consistently fails while other sites work, that's a real sign of a network-level block (ISP/firewall/DPI) rather than the site being down.
Ready — enter a domain and/or one or more server IPs
🎛 Scan Engine — IP / Prefix / AS + Ports
Honest limitation upfront: browsers cannot open arbitrary raw TCP sockets, so this can't do a true SYN port scan like nmap. What it can do — for real, over your device's own connection — is attempt a real network round trip to each target:port and time it. A fast reply (even an error/certificate mismatch) means something answered at the network layer; a full timeout usually means filtered/firewalled/unreachable. Certain ports (25, 23, 53, 179, 587, etc.) are blocked outright by the browser itself for security and can't be tested at all — marked "Browser-blocked".
Scans are capped at 5 target IPs × 40 ports per run (larger ranges are sampled/truncated) to stay responsive in a browser — this is a safety limit, not a bug.
Ready — choose a target type, enter a target and ports, then click Run Scan
⊞ IPv4 Subnet Calculator
Enter an IP/CIDR to calculate
⊞ IPv6 CIDR Helper
Enter an IPv6 prefix

⊞ Subnet Splitter
Incident Tracker
Shift Handover Log
Current Shift Info
Add Log Entry
Shift Log Entries0 entries
No entries yet — start your shift and add events
NOC Contact Directory
ISP / IIG Network Overview
Live
Upstream / Peering Link StatusLive
InterfaceProviderUtilStatus
Live Event LogAuto
Traffic Overview — Last 15 Minutes Simulated — replace with SNMP/NetFlow feed
Inbound
0 Gbps
Outbound
0 Gbps
Packet Loss
0%
BGP Peers
0/0
15m ago10m ago5m agoNow
Service Catalog — IIG / GGC / FNA / CDN / BDIX
Services0
IDNameTypeBWProviderVLAN/PortCost/moStatusActions
Client Registry — Downstream ISPs & Direct Clients
Clients0
IDNameContactPhoneServicesIP/ASBWStatusActions
🔌 Port Manager
Add, edit & remove ports. Changes auto-save to browser storage.
Add / Edit Port
Port #
Service Name
Protocol
Risk Level
Description
Quick Add
8291 WinBox 22 SSH 23 Telnet 80 HTTP 443 HTTPS 21 FTP 161 SNMP 8728 API 8729 API-SSL 1723 PPTP 2000 BW Test 53 DNS 3306 MySQL 179 BGP 1194 OpenVPN 13231 WireGuard
📦 Bulk Add / Import
One port per line: port,name,proto,risk,description — only port is required (risk: crit/high/med/low/info). e.g. 8291,WinBox,TCP,crit,MikroTik mgmt
Saved Ports
Port Service Protocol Risk Description Actions
💾 Auto-Save: All changes are automatically saved to your browser's local storage and will persist across sessions.
🌍 CDN Node Finder
Scan & discover Google, Facebook/WhatsApp, and major CDN delivery nodes using live DNS resolution.
🔎 Custom Domain Node Scan
🛰 Search by ASN / IP Prefix
Find which CDN/network owns an ASN or IP prefix, and list its announced prefixes — powered by RIPEstat.
💾 Saved Custom Nodes
Bulk add — one per line: domain,label,tag (label/tag optional)
No saved custom nodes yet.
ℹ Note: Uses Google DNS-over-HTTPS API for real DNS resolution and RIPEstat for ASN/prefix data. Results show actual CDN node IPs. Geo lookup available per-node.
🎮 Quick Game Test — Presets & Server Scanner
Pick a game, and this runs a real network-quality check against that publisher's public infrastructure (login/CDN/API edge) — resolving IPs, geolocating them, and measuring latency, jitter, and loss over several samples.
ℹ Browsers can't open raw game-server sockets, so this measures HTTPS round-trip quality to each publisher's public edge as a proxy for ISP routing/peering health toward that game's network — not literal live matchmaking-server ping.
📶 Regional Priority Order (reference)
🛰 Game Server Scanner
Enter/pick a game and scan — resolves each known server, looks up its live ASN & announced prefix via RIPEstat, geolocates it, and measures latency + packet loss in one table.
📁 My Custom Preset Games
No custom games added yet.
📁 My Saved Game Servers — Manual Tracker
Track game server endpoints (name, ASN, IP prefix, IP), run real latency / packet-loss quality checks over this device's own connection, and export/import the list.
+ Add Game Server
Bulk add — one per line: name,asn,prefix,ip,region (asn/prefix/region optional)
🔁 IP ⇄ Domain Lookup
Resolve domains to their IP(s), or reverse-lookup IPs to hostnames — then save any result straight into the Game Servers list below.
📋 Game Servers
No game servers yet — add one above.
ℹ Note: Latency & packet loss are measured via real HTTP round-trips from this device (browsers can't send raw ICMP). Each test fires several probes per server — packet loss % is the share that didn't get a response in time.
💾 Full System Backup & Restore
Everything saved on this device — Link Inventory, Service Catalog, Client Registry, Contacts, Port Manager, Custom CDN Nodes, theme, and sidebar layout — lives only in this browser's local storage. Back it up before clearing browser data, switching devices, or updating the tool, and restore it any time.
⬇ Create Backup
Downloads a single .json file containing all NetGuard data currently stored on this device.
⬆ Restore From Backup
Select a previously downloaded backup .json file. This will overwrite all current data on this device with the contents of the file.
⚠ Reset All Data
Permanently erases every saved item on this device (links, services, clients, contacts, ports, custom nodes, theme, layout). This cannot be undone — download a backup first.