AFN Teknoloji
Müşteri

AFN RiskScan Sunum Raporu

AFN Teknoloji — Bilişim Destek ve Danışmanlık Hizmetleri

Bu rapor dis yuzeyde 3 host ve 11 bulgu ile ic agda 14 cihaz ve 123 bulgu icin hazirlanmis birlesik yonetici sunumudur.

Tarih: 23.05.2026 03:01 Ic Ag: 10.10.10.0/24, 10.255.1.0/24, 192.169.1.0/24, 85.105.152.31 Dis Yuzey: afnteknoloji.com Rapor Tipi: Birlesik Sunum
Genel Skor
51
Dikkat Gerektirir
Ic Ag
20
14 cihaz
Dis Yuzey
82
3 host
Kritik
12
Birlesik bulgu sayisi
Yuksek
33
Birlesik bulgu sayisi
GÜVENLİK DURUMU
51/100
🚨 KRİTİK RİSK — SİSTEM HAZIR HEDEF
12
🔴 KRİTİK
33
🟠 YÜKSEK
52
🟡 ORTA
17
📡 SİSTEM
Bu sistem şu an bilinen saldırı yöntemleriyle ele geçirilebilir durumda. 12 kritik bulgu bulunmaktadır ve bunlar güvenlik ekipleri için uzun süredir bilinen, otomatik bot saldırılarına açık zafiyetlerdir. Müdahale, gün/saat değil DAKİKALAR içinde başlamalıdır. Veri kaybı, fidye yazılımı veya KVKK ihlali ihtimali çok yüksek.

Yonetici Ozeti

Rapor, internetten gorunen yuzey ile ic ag hareket alanini tek belgede birlestirir. Dis yuzey bolumu ilk giris riskini; DNS, web ve public servisler uzerinden anlatir. Ic ag bolumu ise bir ihlal sonrasi nasil yayilim olacagini, hangi IP'nin hangi riskleri tasidigini ayni blok altinda gosterir. Bu yapi sayesinde karar verici once resmi gorur, teknik ekip ise IP bazli aksiyona iner.

Ilk Oncelikli Aksiyonlar

  • Ic agda Telnet ve FTP gibi legacy protokolleri kapatip yerine sifreli alternatifler getirin.
  • Domain Controller ve yonetim portlarini sadece yonetim segmentlerinden erisilebilir hale getirin.
  • NAS ve paylasim altyapisinda anonim/public erisim kontrolu yapin, hassas klasorleri yeniden yetkilendirin.
  • Bu HTML rapor tarayicida acildiktan sonra PDF olarak yazdirilabilir ve musteri sunum dosyasi olarak kullanilabilir.

Attack Timeline

0-30 dk
Acik servisler, DNS izleri ve yonetim yuzeyleri tespit edilir.
30-60 dk
Dis yuzeyde public web, VPN, mail veya yonetim paneli uzerinden ilk giris arayisi yapilir.
1-4 saat
Ic agda SMB, RDP, paylasim ve kimlikli audit bulgulari kullanilarak yanal hareket ihtimali degerlendirilir.
4-12 saat
Domain Controller veya kritik yonetim sistemine ulasilirsa etki tum kuruma yayilir.
24+ saat
Onlem alinmazsa veri sizintisi, kesinti ve fidye etkisi yonetim seviyesine tasinabilir.

⏰ İki Senaryo: Müdahale Var vs Yok

Aşağıdaki iki sütun aynı sistemin iki olası geleceğini gösterir. Karar bugün verilmeli.

🚨 EĞER MÜDAHALE EDİLMEZSE
0-24 saat
Otomatik saldırı botları açık servisleri keşfeder, varsayılan parolaları dener.
1-7 gün
Brute-force ve credential stuffing saldırıları artar; başarılı login denemesi olabilir.
7-30 gün
Ele geçirilen ilk hesap üzerinden ağ içinde lateral movement, daha kritik sistemlere geçiş.
1-3 ay
Domain Controller ele geçirilir, ransomware deploy edilir, veri sızdırılır.
3+ ay
Fidye talebi, KVKK ihlal bildirimi, 1-3 milyon TL idari para cezası, marka kaybı, müşteri kaçışı.
⚠ Bu Sistemde Hızlandırıcı Faktörler
• SMBv1 aktif — EternalBlue ve modern ransomware grupları için ilk hedef.
• Telnet açık — kimlik bilgileri ağda açık metin geçer, Wireshark ile yakalanabilir.
• Firewall'da ANY-ANY:Accept kuralı — segmentasyon yok, tek bir ele geçirme tüm ağı açar.
• MFA olmayan admin hesabı — phishing veya credential stuffing ile direkt kontrol kaybı.
• Destek dışı işletim sistemi — yeni CVE'ler asla yamalanmaz, saldırgan için sonsuz açık hedef.
🟢 ÖNERİLER UYGULANIRSA
Saldırı yüzeyi %70-90 azalır
Bilinen CVE ve yanlış konfigürasyonlar kapatılır.
KVKK ve sektörel uyumluluk sağlanır
İhlal bildirim yükümlülüğü ve idari para cezası riski azalır.
Cyber Insurance primleri düşer
Sigorta şirketleri MFA, EDR ve patch durumuna göre prim hesaplar.
İş sürekliliği güçlenir
Ransomware durumunda immutable backup ve segmentasyon ile geri dönüş hızlanır.
Olay sonrası kurtarma maliyeti 100 kat azalır
Önleme TL bin'ler, kurtarma TL milyonlarla ölçülür.
Müşteri ve marka güveni korunur
Bir veri ihlali medyaya yansıdığında sözleşme kayıpları başlar.
⏱ ŞİMDİ NE YAPMALI?
Bu rapordaki 12 kritik ve 33 yüksek bulguya odaklanın. Önceliklendirilmiş aksiyon listesi her bulgu kartının altında 📋 Uygulama Rehberi olarak verilmiştir.

💰 Finansal Etki Tahmini

Türkiye SMB sektörü ortalamalarına ve mevcut bulgulara göre olası bir başarılı saldırının maliyet aralığı. Tahminler IBM Cost of Data Breach 2024 ve KVKK 2024 verilerine dayanır.

📉 Olası Finansal Kayıp

1,555,000 – 16,700,000 TL
Saldırı sonrası kurtarma + iş kaybı + dava maliyetleri

⏱ Beklenen Downtime

81-486 saat
Tüm sistemlerin durma süresi

⚠ İhlal Olasılığı

~%75
Sonraki 12 ay içinde başarılı saldırı

⚖ KVKK / Yasal Risk

100K – 3M TL
İdari para cezası + bildirim yükümlülüğü

Maliyet Kalemleri

🛠 Incident Response & DFIR (forensik)
100.000 – 1.000.000 TL
💾 Sistem kurtarma + yeniden kurulum
50.000 – 500.000 TL
📞 Operasyon kesintisi (saatlik)
5.000 – 50.000 TL/saat
⚖ KVKK idari para cezası
100.000 – 3.000.000 TL
📰 Marka rehabilitasyonu + PR
100.000 – 2.000.000 TL
👤 Müşteri kaybı (ilk 1 yıl)
5-15% revenue kaybı
🏥 Cyber Insurance prim artışı
%50-200 prim artışı
⚖ Olası dava + tazminat
100.000+ TL/dava
💡 ÖNLEME vs TEDAVİ
Bu rapordaki bulguların düzeltme maliyeti, olası bir saldırının maliyetinin 1/100'üdür. Önleyici güvenlik yatırımı her ölçekte en yüksek ROI'ye sahip IT yatırımıdır.

🚀 Önceliklendirilmiş Aksiyon Planı

Tarama bulgularından otomatik üretilen, zaman bazlı eylem listesi. Her madde gerçek bir tespit edilmiş bulguya karşılık gelir.

🚨 İLK 24 SAAT
12 kritik bulgu — acil müdahale gerekli
1.
Microsoft SQL Server (port 1433) Ağa Açık (2 cihazda): 1) Default kimlik bilgilerini DERHAL değiştirin (kompleks parola). 2) Veritabanını sadece uygulama sunucusundan erişilebilir kılın (firewall ACL). 3) MongoDB/Redi...
2.
Lateral Movement Risk (SMB + RDP): Restrict both services using segment-based access controls.
3.
FortiGate Policy #1 (LAN_TO_SD_WAN) — AnyAny: DELETE this rule, or narrow source/destination/service fields to specific objects. Example: src=LAN_users, dst=Server_subnet, service=445/SMB,3389/RDP
4.
FortiGate Telnet management active: Set admin-telnet to disable; use SSH only for CLI access.
5.
FortiGate Any→Any:Accept rules (1) — firewall bypass: 1) Review each any-any rule INDIVIDUALLY — why was it added, who owns it? 2) DELETE rules with no owner or stale rules IMMEDIATELY. 3) Narrow the necessary ones to...
6.
Hikvision Backdoor Authentication Bypass (CVE-2017-7921): Firmware'i 5.4.5 veya üzerine güncelleyin. Tüm Hikvision kameraları kontrol edin.
7.
Hikvision Command Injection RCE (CVE-2021-36260): Firmware'i 2021 sonrası en güncel sürüme yükseltin.
8.
CVE-2006-5051 — banner match (CVSS 9.3): OpenSSH 9.x sürümüne acilen güncelleyin. Bu sürüm son derece tehlikelidir.
⚠ İLK 7 GÜN
33 yüksek risk bulgu — yapılandırılmış proje
1.
SQL 'sa' Account Enabled: Disable the sa account or restrict it to controlled break-glass scenarios only.
2.
SQL Login Password Policy Exceptions Found: Enable CHECK_POLICY and CHECK_EXPIRATION for SQL logins; disable unnecessary SQL logins.
3.
MSSQL Mixed Mode Enabled: Move to Windows/Entra-only authentication if possible; for any remaining SQL logins, enforce strong passwords and rotation.
4.
SQL 'sa' Account Observed as Sysadmin: Disable the sa account or place it under strong controls; log its usage and prefer alternative management accounts.
5.
MSSQL Connection Established Without Encryption: Install a TLS certificate and enforce encrypted connections on the SQL Server side.
6.
VLAN trust violation: internal → virtual-wan-link: NARROW the internal → virtual-wan-link rule. Permit only required ports (e.g. 445 for file server, 3389 for RDP). Add a schedule (business hours). Make the IPS profil...
7.
FortiGate Policy #2 (SSL_TO_LAN) — InternalSegmentation: Make inter-VLAN rules service-based (only the required ports) and schedule-based (business hours). Attach an IPS profile.
8.
FortiGate Policy #3 (LAN_TO_SSL_VPN) — InternalSegmentation: Make inter-VLAN rules service-based (only the required ports) and schedule-based (business hours). Attach an IPS profile.
📅 30 GÜN İÇİNDE
52 orta seviye iyileştirme
1.
Eksik HTTP Security Headers (5 adet) — port 80 (2 cihazda): Web sunucu/reverse proxy seviyesinde header'ları ekleyin: HSTS ('max-age=31536000; includeSubDomains'), X-Frame-Options 'DENY', CSP 'default-src self', X-Con...
2.
No HTTPS (2 cihazda): Configure an SSL/TLS certificate and redirect traffic to HTTPS.
3.
RDP Management Exposure (2 cihazda): RDP erisimini yalnizca yonetim VLAN'lariyla sinirlandirin.
4.
Database Service Exposure (2 cihazda): Veritabani erisimini yalnizca uygulama sunuculari ve yonetim aglariyla sinirlandirin.
5.
General File Share Surface (3 cihazda): Public/anonymous share dogrulamasi icin kimlikli veya kontrollu null-session audit yapin; gereksiz paylasimlari kapatin.
6.
Credential Attack Surface (10 cihazda): Yonetim erisimlerini ayri VLAN, MFA ve hesap kilitleme politikalariyla koruyun.
7.
Customer Declared SQL Detected: Restrict database access to application servers and management networks only.
8.
Likely File Server / Share Surface (3 cihazda): Verify public/anonymous share status, close unnecessary shares, and tighten ACLs.

📊 Önceki Tarama ile Karşılaştırma

Önceki tarama: 16.05.2026 16:06 (6 gün önce). Mevcut tarama ile karşılaştırma:

✓ Kapatılmış Bulgu

2
Kritik: 0 | Yüksek: 1

⚠ Yeni Bulgu

123
Kritik: 12 | Yüksek: 32

❗ Hâlâ Açık

0
Geçen taramadan beri çözülmemiş

📈 Trend

Risk artıyor
Net değişim: +121

⚠ Yeni Tespit Edilen Bulgular

Geçen taramadan sonra ortaya çıkan bulgular — bunlar yeni saldırı yüzeyi.

Critical Microsoft SQL Server (port 1433) Ağa Açık @ 192.169.1.17
Critical Lateral Movement Risk (SMB + RDP) @ 192.169.1.17
Critical FortiGate Policy #1 (LAN_TO_SD_WAN) — AnyAny @ 192.169.1.99
Critical FortiGate Telnet management active @ 192.169.1.99
Critical FortiGate Any→Any:Accept rules (1) — firewall bypass @ 192.169.1.99
Critical Hikvision Backdoor Authentication Bypass (CVE-2017-7921) @ 192.169.1.111
Critical Hikvision Command Injection RCE (CVE-2021-36260) @ 192.169.1.111
Critical CVE-2006-5051 — banner match (CVSS 9.3) @ 192.169.1.113
Critical SMBv1 protocol active — MS17-010 risk @ 192.169.1.117
Critical Microsoft SQL Server (port 1433) Ağa Açık @ 192.169.1.117
Critical Likely Domain Controller @ 192.169.1.117
Critical End-of-Life / Near-EOL Windows Version @ 192.169.1.117
High SQL 'sa' Account Enabled @ 192.169.1.17
High SQL Login Password Policy Exceptions Found @ 192.169.1.17
High MSSQL Mixed Mode Enabled @ 192.169.1.17

✓ Kapatılmış Bulgular

Geçen taramada vardı, bu taramada artık yok — başarılı remediation.

High Credential Attack Surface @ 172.67.68.118
Medium Web Service Exposure @ 172.67.68.118

🛡 FortiGate Ağ Topolojisi & VLAN Trust Haritası

FortiGate REST API üzerinden alınan VLAN/interface yapısı ve aralarındaki firewall policy ilişkilerinin görsel haritası.

Tespit Edilen VLAN / Interface'ler

🟢 dmz

Subnet: 10.10.10.0/24
Rol: dmz
Tip: physical

🟢 fortilink

Subnet: 10.255.1.0/24
Rol: undefined
Tip: aggregate

🟢 internal

Subnet: 192.169.1.0/24
Rol: lan
Tip: hard-switch

🟢 internal1

Rol: undefined
Tip: physical

🟢 internal2

Rol: undefined
Tip: physical

🟢 internal3

Rol: undefined
Tip: physical

🟢 internal4

Rol: undefined
Tip: physical

🟢 internal5

Rol: undefined
Tip: physical

🟢 internal6

Rol: undefined
Tip: physical

🟢 internal7

Rol: undefined
Tip: physical

🟢 l2t.root

Rol: undefined
Tip: tunnel

⚫ modem

Rol: undefined
Tip: physical

🟢 naf.root

Rol: undefined
Tip: tunnel

🟢 ssl.root

Rol: undefined
Tip: tunnel

🟢 wan1

Subnet: 85.105.152.31/32
Rol: wan
Tip: physical

🟢 wan2

Subnet: 192.168.1.0/24
Rol: wan
Tip: physical

VLAN-Arası Trust İlişkileri

Aşağıdaki tabloda hangi bölgenin hangi bölgeye nasıl erişebildiği gösterilmiştir. Renk kodu: 🔴 Kritik, 🟠 Yüksek, 🟡 Orta, ⚪ Bilgi.

Kaynak Hedef Erişim UTM Risk
internal virtual-wan-link ANY-ANY (ALL) ✗ Yok 🟠 Yüksek
↳ 'internal' → 'virtual-wan-link' is unrestricted (service=ALL) — segmentation violation.
ssl.root internal Sınırlı (ALL) ✗ Yok ⚪ Bilgi
internal ssl.root Sınırlı (ALL) ✗ Yok ⚪ Bilgi

FortiGate Policy Risk Özeti

Kritik

1

Yüksek

2

Orta

0

Toplam Politika

4

🛡 Antivirüs / EDR Envanteri

Domain'deki Windows cihazların antivirüs/EDR durumu. WMI SecurityCenter2 + Win32_Service ile tespit edildi.

✓ AV/EDR Var

0

✗ AV YOK

0

EDR Yüklü

0

Sadece Defender

0

Kontrol Edilemedi

2

Cihaz Bazlı AV/EDR Durumu

Hostname IP OS AV Ürünü EDR Durum
ANFNERSUR 192.169.1.17 - - ❓ Erişilemedi
dc 192.169.1.117 Microsoft Windows Server 2012 R2 Standard - - ❓ Erişilemedi

📡 DHCP Lease Envanteri & Ghost Device Tespiti

FortiGate veya Windows DHCP sunucusundan alınan IP/MAC/Hostname eşleştirmesi. AD'de olmayan cihazlar (ghost device) belirgin uyarı olarak işaretlendi.

Toplam Lease

35

Aktif Lease

0

👻 Ghost Device

0

DHCP Kaynak

FortiGate (192.169.1.99)

DHCP Lease Detayları

IP MAC Hostname Vendor Interface/Scope Durum
192.169.1.110 00:08:9b:cd:3a:ee NAS ICP Electronics Inc. internal leased
192.169.1.111 b4:a3:82:b2:42:17 Hangzhou Hikvision Digital Technology Co.,Ltd. internal leased
192.169.1.112 cc:4d:75:8e:35:f9 zhimi-airp-rmb1_mibt35F9 Beijing Xiaomi Mobile Software Co., Ltd internal leased
192.169.1.113 d8:ec:e5:7d:e2:a9 GS1920 Zyxel Communications Corporation internal leased
192.169.1.114 b8:ec:a3:f5:b8:cb NWA1123-ACv2 Zyxel Communications Corporation internal leased
192.169.1.115 24:18:c6:16:b2:1c dreame_vacuum_p2150a HUNAN FN-LINK TECHNOLOGY LIMITED internal leased
192.169.1.117 1c:98:ec:52:1a:5c dc Hewlett Packard Enterprise internal leased
192.169.1.118 e8:6f:38:8b:f9:c9 EYUPTURAN internal leased
192.169.1.119 ce:22:a8:5d:ea:07 iPhone Yerel / Rastgele MAC internal leased
192.169.1.120 d4:1a:d1:59:f0:5d NWA1123ACv3 Zyxel Communications Corporation internal leased
192.169.1.122 2c:d2:6b:dc:1c:c8 internal leased
192.169.1.123 1c:98:ec:52:1a:5f ILOCZ162000MA Hewlett Packard Enterprise internal leased
192.169.1.125 16:c7:f0:4e:09:1b iPhone Yerel / Rastgele MAC internal leased
192.169.1.126 40:ec:99:8d:a5:ae SATINALMAAKIF internal leased
192.169.1.127 62:5b:65:ce:aa:e2 REDMI-Note-15-Pro Yerel / Rastgele MAC internal leased
192.169.1.128 5c:e2:8c:6c:4f:38 NWA1123-AC-PRO Zyxel Communications Corporation internal leased
192.169.1.129 fe:4a:ed:8b:8e:df iPhone Yerel / Rastgele MAC internal leased
192.169.1.132 fa:21:77:6c:e9:c9 OPPO-A5 Yerel / Rastgele MAC internal leased
192.169.1.133 ee:cb:06:d2:7a:a5 iPhone Yerel / Rastgele MAC internal leased
192.169.1.134 74:3a:f4:68:fc:90 DESKTOP-FCUHE6R internal leased
192.169.1.135 4c:d7:17:97:26:35 DESKTOP-M797DTC internal leased
192.169.1.136 60:e3:27:1a:ea:8c DESKTOP-8HEC84Q internal leased
192.169.1.137 ec:3a:56:7d:2b:c6 DESKTOP-8HEC84Q internal leased
192.169.1.138 f2:49:ee:b5:4e:86 Yerel / Rastgele MAC internal leased
192.169.1.139 9e:95:41:14:90:02 iPhone Yerel / Rastgele MAC internal leased
192.169.1.140 ce:1d:c1:f4:fb:08 MacBookPro Yerel / Rastgele MAC internal leased
192.169.1.141 8a:8e:12:79:d6:8c iPhone Yerel / Rastgele MAC internal leased
192.169.1.142 6c:f2:d8:2a:0d:fb Canon2a0dfb internal leased
192.169.1.143 20:0b:74:b7:e1:59 Canon2a0dfb internal leased
192.169.1.144 72:7f:ab:85:e9:a9 iPhone Yerel / Rastgele MAC internal leased
192.169.1.145 00:45:e2:4a:59:81 DESKTOP-PVONHGQ internal leased
192.169.1.146 b8:ec:a3:1d:6a:84 NWA5121-NI Zyxel Communications Corporation internal leased
192.169.1.147 c2:4e:9e:21:1e:66 iPhone Yerel / Rastgele MAC internal leased
192.169.1.148 1c:74:0d:f9:bd:07 WAC6103D-I Zyxel Communications Corporation internal leased
192.169.1.17 bc:f1:05:68:6b:3b ANFNERSUR Intel Corporate internal leased

📋 Compliance Çerçevesi Eşleştirmesi (KVKK / ISO 27001 / CIS / NIST CSF)

Tespit edilen bulgular uluslararası ve yerel güvenlik çerçevelerinde belirli kontrolleri ihlal eder. Aşağıdaki tablo, ihlal edilen kontrolleri framework bazında özetler.

ISO 27001

5 ihlal edilen kontrol
36 toplam eşleşme

CIS Controls v8

7 ihlal edilen kontrol
36 toplam eşleşme

KVKK

2 ihlal edilen kontrol
16 toplam eşleşme

NIST CSF

2 ihlal edilen kontrol
16 toplam eşleşme

Detay: Framework × Kontrol × Bulgu

Framework Kontrol Açıklama İhlal Sayısı
CIS Controls v8 12.1 Maintain inventory of network boundaries 2
CIS Controls v8 12.2 Segregate networks 2
CIS Controls v8 12.4 Establish and maintain architecture diagrams 12
CIS Controls v8 2.2 Ensure software is supported 2
CIS Controls v8 3.10 Encrypt sensitive data in transit 12
CIS Controls v8 6.3 Require MFA for externally-exposed apps 2
CIS Controls v8 8.2 Collect audit logs 4
ISO 27001 A.12.4.1 Event logging 4
ISO 27001 A.12.6.1 Vulnerability management 2
ISO 27001 A.13.1.1 Network controls 26
ISO 27001 A.13.1.3 Segregation in networks 2
ISO 27001 A.9.4.2 Secure log-on procedures 2
KVKK Md.12 Yetersiz kimlik doğrulama 14
KVKK Md.12 — Veri güvenliği Şifrelenmemiş iletişim 2
NIST CSF PR.AC-5 Network integrity protected 14
NIST CSF PR.AC-7 Authentication of users/devices 2

🛡 Risk Skorları

Müşterinin ransomware'e karşı hazırlık ve patch yönetimi performansı — sektör benchmark karşılaştırması ile.

🛡 Ransomware Hazırlık

60/100
C — Orta (Önemli Eksikler)
AV/EDR Kapsama: 0% (0/15p)
Immutable Backup: ✗ Yok (5/20p)
Off-site Backup: ✗ Yok (5/15p)
Admin MFA: ✓ Var (15/15p)
AD Hardening: 100% (20/20p)
Segmentation: 15/15p

📅 Patch Compliance

0/100
Kontrol edilen: 0 Windows asset
Ortalama patch yaşı: 0 gün
≤ 30 gün: 0 cihaz
30-90 gün: 0 cihaz
> 90 gün: 0 cihaz

🎭 Tehdit Aktör Eşleştirmesi & 📊 Sektör Karşılaştırması

Bu Ortam Hangi Tehdit Grubunun Saldırı Kalıbına Uyuyor?

Tespit edilen bulgular bilinen ransomware/APT grupların MITRE ATT&CK tekniklerine göre eşleştirildi. Yüksek eşleşme = bu grup için ideal hedefsiniz.

⚠ FIN7 / Carbanak

%50 EŞLEŞME
MITRE: G0046

Finansal odaklı APT. POS, ATM, banka hedefler. JavaScript backdoor + PowerShell.

Eşleşen TTPs: PowerShell, Macro, Office, RDP

⚠ LockBit 3.0

%36 EŞLEŞME
MITRE: G1015

Dünyada en yaygın ransomware. RaaS modeli — affiliates her sektörü hedefler.

Eşleşen TTPs: FortiGate, SSL VPN, RDP, Domain Admin

📊 Sektör Ortalaması ile Karşılaştırma — KOBİ

🏆 SEKTÖR ÜSTÜ — Tebrikler, sektör ortalamasının çok üzerinde güvenlisiniz.
Metrik Sizin Ortamınız Sektör Ortalaması Fark
🔴 Kritik Bulgu 12 28 -57%
🟠 Yüksek Bulgu 32 60 -47%
📋 Toplam Bulgu 246 100

📈 Trend Grafiği — Son Taramalar Karşılaştırması

afn için son 6 tarama bulgu sayılarının zaman içindeki değişimi. Trend yukarı doğruysa müdahale yeterli değil, aşağı doğruysa iyileştirme gözleniyor.

0 8 16 24 32 30 Apr 30 Apr 16 May 16 May 16 May 23 May 13 13 12 0 0 12 27 27 32 0 1 32 0 0 0 0 0 0 0 0 0 0 0 0 Kritik Yüksek Orta Düşük
İlk tarama → Son tarama: 📈 Bulgu artışı (Kritik -1, Yüksek +5)

🔵 Microsoft 365 / Cloud Denetim Sonuçları

Tenant: Afn Teknoloji Bilişim Des ve Dan Hiz Tic Ltd Şti | Tenant ID: 4dc8682a-591e-4905-b51a-5a6c98c26c51 | Domain: afnteknoloji.com

👥 Kullanıcılar

19
Lisanslı: 17

🔐 MFA Durumu

89%
17 aktif | 0 eksik

🛡 Admin MFA

16/16
Tüm adminler MFA'lı ✓

📈 Secure Score

44%
543/1211 — Düşük

⚙ Conditional Access

4
policy — MFA: ✓, Legacy block: ✓

📋 Tenant Özet

Doğrulanmış Domainler

tarzaksesuar.com.tr, afnteknoloji.com, afnteknoloji.onmicrosoft.com, shamashai.com.tr

Diğer Bilgiler

Ülke: TR | Audit Log: —

Dis Yuzey Guvenligi

Domain, DNS, web yuzeyi ve internete acik servisler bu bolumde gruplanir. Ayni IP altindaki tum subdomain ve bulgular birlikte sunulur.

Dis Yuzey Ozeti

Host: 3
DNS Kaydi: 26
Bulgu: 11

Skor

82/100 - Yonetilebilir

Alan Adi

afnteknoloji.com

Domain Seviyesi Bulgular

Medium
HTTP → HTTPS Yönlendirmesi Eksik
Port 80 üzerinden gelen HTTP istekleri HTTPS'e yönlendirilmiyor.
💰 İŞ ETKİSİ
Şifrelenmemiş HTTP bağlantısı ağ dinleme (MITM) saldırılarında oturum cookie'leri ve form verilerini açığa çıkarır.
✓ AKSİYON
Sunucunuzu HTTP (80) isteklerini HTTPS (443)'e kalıcı yönlendirecek şekilde yapılandırın (301 redirect).
Kanıt: http://afnteknoloji.com — HTTPS yönlendirmesi yok
Seviye: Observed | Güven: High
Low
DNSSEC Devre Dışı
Domain için DS veya DNSKEY kaydı yok — DNSSEC aktif değil.
💰 İŞ ETKİSİ
DNSSEC olmadan DNS cache poisoning ve DNS spoofing saldırılarına karşı kriptografik koruma yok. Hedefli saldırılarda kullanıcı yanlış IP'lere yönlendirilebilir.
✓ AKSİYON
Domain registrar'ınız DNSSEC destekliyorsa aktif edin. Cloudflare, Route 53, Google DNS gibi sağlayıcılar tek tıkla DNSSEC açabilir.
Kanıt: DNS DS/DNSKEY sorgusu boş döndü.
Seviye: Observed | Güven: High
Low
Sunucu Sürümü Açığa Çıkıyor (Server: Vercel)
HTTP Server başlığı sunucu yazılımını ve sürümünü açıklıyor: Vercel
💰 İŞ ETKİSİ
Saldırganlar sürüm bilgisiyle bilinen CVE açıklarını hedefler. Gereksiz bilgi ifşası saldırı yüzeyini artırır.
✓ AKSİYON
Web sunucusu konfigürasyonunda Server başlığını gizleyin veya generik yapın (nginx için: server_tokens off).
Kanıt: Server: Vercel
Seviye: Banner | Güven: High
Info
Mail Altyapısı: Microsoft 365 / Hosted Exchange
MX kayıtları Microsoft'un hosted altyapısına yönlendiriyor: afnteknoloji-com.mail.protection.outlook.com. Firma on-prem Exchange çalıştırmıyor.
💰 İŞ ETKİSİ
Bu durumda mail güvenliği büyük oranda Microsoft'un sorumluluğunda; siz config (MFA, conditional access, ATP vb.) tarafına odaklanmalısınız. On-prem Exchange CVE'leri (ProxyLogon, ProxyShell vb.) sizi etkilemez.
✓ AKSİYON
Microsoft 365 admin portalında MFA, conditional access, Defender for O365 ve audit log ayarlarını gözden geçirin. Exchange Online için phishing/spam koruması aktif edin.
Kanıt: MX: afnteknoloji-com.mail.protection.outlook.com (öncelik 0)
Seviye: Observed | Güven: High

IP Bazli Dis Yuzey Varliklari

216.150.1.1
Subdomain: afnteknoloji.com, www.afnteknoloji.com
Orta

Web ve Port Ozetleri

afnteknoloji.com
80 443
Final URL: https://afnteknoloji.com/
www.afnteknoloji.com
80 443
Final URL: https://afnteknoloji.com/

Bulgular

Medium
HTTP → HTTPS Yönlendirmesi Eksik
Port 80 üzerinden gelen HTTP istekleri HTTPS'e yönlendirilmiyor.
💰 İŞ ETKİSİ
Şifrelenmemiş HTTP bağlantısı ağ dinleme (MITM) saldırılarında oturum cookie'leri ve form verilerini açığa çıkarır.
✓ AKSİYON
Sunucunuzu HTTP (80) isteklerini HTTPS (443)'e kalıcı yönlendirecek şekilde yapılandırın (301 redirect).
Kanıt: http://afnteknoloji.com — HTTPS yönlendirmesi yok
Seviye: Observed | Güven: High
Medium
HTTP → HTTPS Yönlendirmesi Eksik
Port 80 üzerinden gelen HTTP istekleri HTTPS'e yönlendirilmiyor.
💰 İŞ ETKİSİ
Şifrelenmemiş HTTP bağlantısı ağ dinleme (MITM) saldırılarında oturum cookie'leri ve form verilerini açığa çıkarır.
✓ AKSİYON
Sunucunuzu HTTP (80) isteklerini HTTPS (443)'e kalıcı yönlendirecek şekilde yapılandırın (301 redirect).
Kanıt: http://www.afnteknoloji.com — HTTPS yönlendirmesi yok
Seviye: Observed | Güven: High
Low
DNSSEC Devre Dışı
Domain için DS veya DNSKEY kaydı yok — DNSSEC aktif değil.
💰 İŞ ETKİSİ
DNSSEC olmadan DNS cache poisoning ve DNS spoofing saldırılarına karşı kriptografik koruma yok. Hedefli saldırılarda kullanıcı yanlış IP'lere yönlendirilebilir.
✓ AKSİYON
Domain registrar'ınız DNSSEC destekliyorsa aktif edin. Cloudflare, Route 53, Google DNS gibi sağlayıcılar tek tıkla DNSSEC açabilir.
Kanıt: DNS DS/DNSKEY sorgusu boş döndü.
Seviye: Observed | Güven: High
Low
Sunucu Sürümü Açığa Çıkıyor (Server: Vercel)
HTTP Server başlığı sunucu yazılımını ve sürümünü açıklıyor: Vercel
💰 İŞ ETKİSİ
Saldırganlar sürüm bilgisiyle bilinen CVE açıklarını hedefler. Gereksiz bilgi ifşası saldırı yüzeyini artırır.
✓ AKSİYON
Web sunucusu konfigürasyonunda Server başlığını gizleyin veya generik yapın (nginx için: server_tokens off).
Kanıt: Server: Vercel
Seviye: Banner | Güven: High
Low
Sunucu Sürümü Açığa Çıkıyor (Server: Vercel)
HTTP Server başlığı sunucu yazılımını ve sürümünü açıklıyor: Vercel
💰 İŞ ETKİSİ
Saldırganlar sürüm bilgisiyle bilinen CVE açıklarını hedefler. Gereksiz bilgi ifşası saldırı yüzeyini artırır.
✓ AKSİYON
Web sunucusu konfigürasyonunda Server başlığını gizleyin veya generik yapın (nginx için: server_tokens off).
Kanıt: Server: Vercel
Seviye: Banner | Güven: High
Info
Mail Altyapısı: Microsoft 365 / Hosted Exchange
MX kayıtları Microsoft'un hosted altyapısına yönlendiriyor: afnteknoloji-com.mail.protection.outlook.com. Firma on-prem Exchange çalıştırmıyor.
💰 İŞ ETKİSİ
Bu durumda mail güvenliği büyük oranda Microsoft'un sorumluluğunda; siz config (MFA, conditional access, ATP vb.) tarafına odaklanmalısınız. On-prem Exchange CVE'leri (ProxyLogon, ProxyShell vb.) sizi etkilemez.
✓ AKSİYON
Microsoft 365 admin portalında MFA, conditional access, Defender for O365 ve audit log ayarlarını gözden geçirin. Exchange Online için phishing/spam koruması aktif edin.
Kanıt: MX: afnteknoloji-com.mail.protection.outlook.com (öncelik 0)
Seviye: Observed | Güven: High
52.98.179.88
Subdomain: autodiscover.afnteknoloji.com
Orta

Web ve Port Ozetleri

autodiscover.afnteknoloji.com
80
Final URL: https://outlook.office365.com/mail/?realm=afnteknoloji.com&vd=autodiscover

Bulgular

Medium
Clickjacking Koruması Eksik (X-Frame-Options)
X-Frame-Options HTTP başlığı tanımlanmamış. Site iframe içine alınabilir.
💰 İŞ ETKİSİ
Clickjacking saldırılarında kullanıcı görünmez bir çerçeve içine gizlenmiş sayfaya tıklatılarak kimlik bilgileri çalınabilir.
✓ AKSİYON
'X-Frame-Options: DENY' veya 'SAMEORIGIN' başlığı ekleyin. Alternatif: CSP frame-ancestors direktifi kullanın.
Kanıt: GET https://outlook.office365.com/mail/?realm=afnteknoloji.com&vd=autodiscover — X-Frame-Options başlığı yok
Seviye: Observed | Güven: High
Medium
Content Security Policy (CSP) Eksik
Content-Security-Policy HTTP başlığı tanımlanmamış.
💰 İŞ ETKİSİ
CSP olmadan XSS saldırılarında saldırgan kötü amaçlı script çalıştırabilir, kullanıcı oturumlarını çalabilir.
✓ AKSİYON
Uygulamanıza uygun bir CSP politikası tanımlayın. Başlangıç için 'default-src self' kullanın.
Kanıt: GET https://outlook.office365.com/mail/?realm=afnteknoloji.com&vd=autodiscover — Content-Security-Policy başlığı yok
Seviye: Observed | Güven: High
Low
Sunucu Sürümü Açığa Çıkıyor (Server: Microsoft-HTTPAPI/2.0)
HTTP Server başlığı sunucu yazılımını ve sürümünü açıklıyor: Microsoft-HTTPAPI/2.0
💰 İŞ ETKİSİ
Saldırganlar sürüm bilgisiyle bilinen CVE açıklarını hedefler. Gereksiz bilgi ifşası saldırı yüzeyini artırır.
✓ AKSİYON
Web sunucusu konfigürasyonunda Server başlığını gizleyin veya generik yapın (nginx için: server_tokens off).
Kanıt: Server: Microsoft-HTTPAPI/2.0
Seviye: Banner | Güven: High

Ic Ag Guvenligi

Her IP kendi altinda ele alinir; ilgili roller, portlar, kimlikli denetim sonucu ve bulgular ayni blokta toplanir.

Ic Ag Ozeti

Cihaz: 14
Bulgu: 123
Kritik: 12

Skor

20/100 - Kritik

Hedef Aralik

10.10.10.0/24, 10.255.1.0/24, 192.169.1.0/24, 85.105.152.31

Kritik Cihazlar

192.169.1.117
15/100
Domain Controller
Sorun: SMBv1 protocol active — MS17-010 risk
Etkisi: MS17-010 (EternalBlue) CVSS 9.8 — the vulnerability used by WannaCry and NotPetya. Allows unauthenticated remote code execution.
Duzelt: URGENT: Disable SMBv1: 'Set-SmbServerConfiguration -EnableSMB1Protocol $false' | Apply the MS17-010 patch (KB4012212).
192.169.1.110
15/100
Switch
Sorun: SMB service open — version verification required
Etkisi: An open SMB service creates surface for null-session, brute-force and various SMB vulnerabilities.
Duzelt: Restrict SMB access to the management network only. If unnecessary, filter port 445.
192.169.1.17
15/100
SQL Server
Sorun: Microsoft SQL Server (port 1433) Ağa Açık
Etkisi: Veritabanı varsayılan kimlik bilgileri ('sa' / (boş veya 'sa')) ile çalışıyor olabilir. MongoDB ve Redis VARSAYILAN olarak kimlik doğrulaması yapmaz — internete açık olduğunda 1 dakikada ele geçirilir. MSSQL 'sa' boş/zayıf parola çok yaygın. Veri ihlali, ransomware (özellikle MongoDB/Elastic'te) en hızlı saldırı vektörü.
Duzelt: 1) Default kimlik bilgilerini DERHAL değiştirin (kompleks parola). 2) Veritabanını sadece uygulama sunucusundan erişilebilir kılın (firewall ACL). 3) MongoDB/Redis için authentication zorunlu yapın. 4) MSSQL sa hesabını DISABLE edin, Windows Auth + service account kullanın. 5) İnternete kesinlikle expose etmeyin — VPN/jump host arkasına alın.
192.169.1.99
15/100
Firewall
Sorun: FortiGate Policy #1 (LAN_TO_SD_WAN) — AnyAny
Etkisi: An ANY-ANY:Accept rule allows every traffic type from anywhere to anywhere. It is the opposite of least privilege — effectively equivalent to having no firewall.
Duzelt: DELETE this rule, or narrow source/destination/service fields to specific objects. Example: src=LAN_users, dst=Server_subnet, service=445/SMB,3389/RDP
192.169.1.111
21/100
IPCamera
Sorun: Hikvision Backdoor Authentication Bypass (CVE-2017-7921)
Etkisi: IP kameralar genellikle yıllarca güncellenmeden çalışır, eski firmware'lerde bilinen kritik CVE'ler vardır. Bu CVE'ler kimlik doğrulamasız admin yetki kazanmaya izin verir; saldırgan canlı görüntüye, ses kaydına, hatta ağa pivot yapma imkanına ulaşır.
Duzelt: Firmware'i 5.4.5 veya üzerine güncelleyin. Tüm Hikvision kameraları kontrol edin.
192.169.1.113
28/100
NAS / File Server
Sorun: CVE-2006-5051 — banner match (CVSS 9.3)
Etkisi: Banner analysis detected a service version matching this CVE. CVSS 9.3/10 — Critical risk.
Duzelt: OpenSSH 9.x sürümüne acilen güncelleyin. Bu sürüm son derece tehlikelidir.
192.169.1.110
Hostname: NAS.local | Segment: 192.169.1.0/24 | Tur: NAS
Yuksek

IT Ozeti

15/100
Rol: Switch
Sorun: SMB service open — version verification required
Etkisi: An open SMB service creates surface for null-session, brute-force and various SMB vulnerabilities.
Duzelt: Restrict SMB access to the management network only. If unnecessary, filter port 445.

Rol ve Port Ozetleri

Musteri Tanimi: Switch NetworkSwitch (Observed) FileServer (Observed) ManagementSurface (Observed) NAS
MAC / Vendor: 00:08:9B:CD:3A:EE / ICP Electronics Inc.
21/FTP 22/SSH 80/HTTP 139/NetBIOS 443/HTTPS 445/SMB 8080/HTTP-Alt
Urunler: Customer Declared Switch, Web Service 1.3, SMB File Sharing, SSH Remote Access, NAS / Storage 1.3, Managed Switch
Maruziyet: FTP Exposure, SMB Exposure, SSH Management Exposure, Web Service Exposure, General File Share Surface, Credential Attack Surface

Kimlikli Denetim

[Authenticated] Windows/WMI audit could not be completed
The RPC server is unavailable.
Kanit: Authenticated audit attempt ended with an error.
[Authenticated] Switch SSH login failed
Username or password is incorrect.
Kanit: SSH 22/tcp → 192.169.1.110
[Authenticated] SMB Paylasim audit could not be completed
The RPC server is unavailable.
Kanit: Authenticated audit attempt ended with an error.
[ConfigurationConfirmed] NAS management interface confirmed
Management page is accessible
Kanit: URL: http://192.169.1.110:80/ | HTTP: 200 | Title:

Bulgular

High
P47
SMB service open — version verification required
The SMB service is open on port 445 and responded to the negotiate request.
💰 İŞ ETKİSİ
An open SMB service creates surface for null-session, brute-force and various SMB vulnerabilities.
⏱ Tahmini Kesinti
2-8 saat
💸 Olası Kayıp
30.000 – 150.000 TL
📉 Veri Riski
🟠 Orta-Yüksek
✓ AKSİYON
Restrict SMB access to the management network only. If unnecessary, filter port 445.
Kanıt: Port 445: SMB Negotiate response received (41 bytes) | Dialect index=-1
Seviye: Passive | Güven: Medium
High
P47
FTP Open
The FTP service allows credentials to be transmitted unencrypted.
💰 İŞ ETKİSİ
Creates risk of data leakage and credential capture during file transfer.
⏱ Tahmini Kesinti
1-6 saat
💸 Olası Kayıp
20.000 – 100.000 TL
📉 Veri Riski
🟠 Veri sızıntısı
✓ AKSİYON
Disable FTP; use SFTP or FTPS instead.
Kanıt: Port 21 open (FTP)
Seviye: Observed | Güven: High
📋 Uygulama Rehberi: Remove FTP and Move to SFTP/FTPS
FTP is unencrypted. Username, password and file contents traverse the network in clear text.
1. Stop the FTP service in IIS [Windows IIS]
Stop-Service ftpsvc
Set-Service ftpsvc -StartupType Disabled
💡 Server Manager → Roles and Features → remove FTP Server.
2. Remove vsftpd or force SSL [Linux (vsftpd)]
sudo systemctl stop vsftpd
sudo systemctl disable vsftpd
# Veya SSL zorunlu kılmak için /etc/vsftpd.conf'a:
# ssl_enable=YES
# force_local_data_ssl=YES
# force_local_logins_ssl=YES
💡 If OpenSSH is already installed, SFTP can be used automatically.
3. SFTP ships with OpenSSH [Alternative: SFTP]
# SSH kurulu ise SFTP de kullanılabilir:
sftp user@host
💡 Tools like FileZilla and WinSCP support SFTP.
✓ Doğrulama:
nmap -p 21 <host>  →  closed/filtered
High
P47
NAS Management Interface Confirmed via Authenticated Audit
The management panel of the NAS device or NAS-like file storage interface was confirmed.
💰 İŞ ETKİSİ
NAS devices typically hold shares, backups, or archive data; exposure of the management interface amplifies data and backup risk.
⏱ Tahmini Kesinti
2-8 saat
💸 Olası Kayıp
30.000 – 150.000 TL
📉 Veri Riski
🟠 Orta-Yüksek
✓ AKSİYON
Separate the NAS management panel from the user network, block unnecessary internet access, and enforce strong authentication.
Kanıt: URL: http://192.169.1.110:80/ | Behavior: Management page is accessible | Product:
Seviye: ConfigurationConfirmed | Güven: High
Medium
P35
CVE-2018-15473 — banner match (CVSS 5.3)
OpenSSH 7.x: Kullanıcı adı enumeration açığı — geçerli kullanıcılar tespit edilebilir.
💰 İŞ ETKİSİ
Banner analysis detected a service version matching this CVE. CVSS 5.3/10 — Medium risk.
✓ AKSİYON
OpenSSH 8.0+ sürümüne güncelleyin.
Kanıt: Port 22/TCP (SSH): "SSH-2.0-OpenSSH_7.6"
Seviye: Passive | Güven: Medium
Medium
P35
Eksik HTTP Security Headers (4 adet) — port 80
Bu web servisinde 4 kritik güvenlik header'ı eksik: Content-Security-Policy, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
💰 İŞ ETKİSİ
Modern web saldırılarının (XSS, clickjacking, MIME confusion) çoğu HTTP security header'ları ile engellenir. Eksik header = exploit yüzeyi açık. Mozilla Observatory ve OWASP benchmark'larda 'F' notu alır.
✓ AKSİYON
Web sunucu/reverse proxy seviyesinde header'ları ekleyin: HSTS ('max-age=31536000; includeSubDomains'), X-Frame-Options 'DENY', CSP 'default-src self', X-Content-Type-Options 'nosniff', Referrer-Policy 'strict-origin-when-cross-origin', Permissions-Policy 'geolocation=()'.
Kanıt: GET http://192.169.1.110:80/ → eksik: Content-Security-Policy, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
Seviye: Observed | Güven: High
Medium
P35
SSH Management Exposure
SSH yonetim yuzeyi erisilebilir durumda.
💰 İŞ ETKİSİ
This surface raises risk when unnecessarily or broadly exposed.
✓ AKSİYON
SSH erisimini yalnizca yonetim aglarindan acin.
Kanıt: Port 22 acik
Seviye: Observed | Güven: Medium
Medium
P35
General File Share Surface
Bu host dosya paylasim yuzeyi sunuyor. Genel/anonim erisim durumu ayrica dogrulanmali.
💰 İŞ ETKİSİ
Share surfaces are a typical source of data leakage and broad-permission errors.
✓ AKSİYON
Public/anonymous share dogrulamasi icin kimlikli veya kontrollu null-session audit yapin; gereksiz paylasimlari kapatin.
Kanıt: Acik paylasim portlari: 139, 445
Seviye: Observed | Güven: Medium
Medium
P35
Credential Attack Surface
Kimlik dogrulama bekleyen servisler erisilebilir durumda. Bu yuzeyler cevrim ici parola denemesi veya hesap hedefleme icin cazip olabilir.
💰 İŞ ETKİSİ
Unnecessary exposure of authentication-requiring services increases account-targeting risk.
✓ AKSİYON
Yonetim erisimlerini ayri VLAN, MFA ve hesap kilitleme politikalariyla koruyun.
Kanıt: Kimlik dogrulama yuzeyleri: 21, 22, 443
Seviye: Observed | Güven: Medium
Medium
P35
NAS / Storage Detected
NAS / Storage product detected. Version trace: 1.3. The management and access surface of this system should be reviewed.
💰 İŞ ETKİSİ
File-sharing services are prone to data leakage and broad-access errors.
✓ AKSİYON
Audit access lists, anonymous access, and write permissions on file-sharing services.
Kanıt: NAS / depolama cihazi izi tespit edildi
Seviye: Fingerprint | Güven: Medium
Medium
P35
Likely File Server / Share Surface
This host behaves like a file server because SMB or NFS share ports are open.
💰 İŞ ETKİSİ
Shares open to broad access or with permissive ACLs amplify data leakage and lateral movement risk.
✓ AKSİYON
Verify public/anonymous share status, close unnecessary shares, and tighten ACLs.
Kanıt: Share ports: 139, 445
Seviye: Fingerprint | Güven: Medium
Low
P25
Sunucu Banner Sürüm İfşası (443/TCP)
HTTP yanıt header'ında sürüm bilgisi açık: 'Server: http server 1.0'
💰 İŞ ETKİSİ
Saldırgan sürüm bilgisini kullanarak hedefe özel exploit aramaktan vakit kazanır. nginx 1.18.0 gibi tam sürüm bilgisi = CVE eşleştirmesi tek tık.
✓ AKSİYON
Web server config'inde sürüm gizleyin. nginx: 'server_tokens off;'. Apache: 'ServerTokens Prod, ServerSignature Off'. IIS: 'X-Powered-By' header'ı kaldır.
Kanıt: Server header: http server 1.0
Seviye: Observed | Güven: High
Low
P25
Web Service Exposure
Web arayuzu erisilebilir durumda.
💰 İŞ ETKİSİ
This surface raises risk when unnecessarily or broadly exposed.
✓ AKSİYON
Web arayuzlerini segment bazli erisim kontroluyle koruyun.
Kanıt: Acik portlar: 80, 443, 8080
Seviye: Observed | Güven: Medium
Low
P25
Customer Declared Switch Detected
Customer Declared Switch product detected. The management and access surface of this system should be reviewed.
💰 İŞ ETKİSİ
Exposure of this product can create operational and security risk.
✓ AKSİYON
Verify the service exposure and access controls.
Kanıt: Customer infrastructure profile
Seviye: Fingerprint | Güven: High
Low
P25
Managed Switch Detected
Managed Switch product detected. The management and access surface of this system should be reviewed.
💰 İŞ ETKİSİ
Exposure of this product can create operational and security risk.
✓ AKSİYON
Verify the service exposure and access controls.
Kanıt: Switch / ag altyapi cihazi izi tespit edildi
Seviye: Fingerprint | Güven: Medium
192.169.1.113
Hostname: 192.169.1.113 | Segment: 192.169.1.0/24 | Tur: Switch
Kritik

IT Ozeti

28/100
Rol: NAS / File Server
Sorun: CVE-2006-5051 — banner match (CVSS 9.3)
Etkisi: Banner analysis detected a service version matching this CVE. CVSS 9.3/10 — Critical risk.
Duzelt: OpenSSH 9.x sürümüne acilen güncelleyin. Bu sürüm son derece tehlikelidir.

Rol ve Port Ozetleri

Musteri Tanimi: NAS / File Server NetworkSwitch (Observed) AccessPoint (Observed) ManagementSurface (Observed)
MAC / Vendor: D8:EC:E5:7D:E2:A9 / Zyxel Communications Corporation
21/FTP 22/SSH 443/HTTPS
Urunler: Customer Declared NAS, Web Service 1.0, SSH Remote Access, Managed Switch, Wireless Access Point
Maruziyet: FTP Exposure, SSH Management Exposure, Web Service Exposure, Credential Attack Surface

Kimlikli Denetim

[Authenticated] Switch SSH login failed
Username or password is incorrect.
Kanit: SSH 22/tcp → 192.169.1.113

Bulgular

Critical
P47
CVE-2006-5051 — banner match (CVSS 9.3)
OpenSSH 3.x (EOL): SIGCHLD race condition — uzaktan komut yürütme. 2004 yılından kalma sürüm, onlarca bilinen CVE içeriyor.
💰 İŞ ETKİSİ
Banner analysis detected a service version matching this CVE. CVSS 9.3/10 — Critical risk.
⏱ Tahmini Kesinti
4-24 saat
💸 Olası Kayıp
100.000 – 500.000 TL
📉 Veri Riski
🔴 Yüksek
✓ AKSİYON
OpenSSH 9.x sürümüne acilen güncelleyin. Bu sürüm son derece tehlikelidir.
Kanıt: Port 22/TCP (SSH): "SSH-2.0-OpenSSH_3.9p1"
Seviye: Passive | Güven: Medium
High
P37
FTP Open
The FTP service allows credentials to be transmitted unencrypted.
💰 İŞ ETKİSİ
Creates risk of data leakage and credential capture during file transfer.
⏱ Tahmini Kesinti
1-6 saat
💸 Olası Kayıp
20.000 – 100.000 TL
📉 Veri Riski
🟠 Veri sızıntısı
✓ AKSİYON
Disable FTP; use SFTP or FTPS instead.
Kanıt: Port 21 open (FTP)
Seviye: Observed | Güven: High
📋 Uygulama Rehberi: Remove FTP and Move to SFTP/FTPS
FTP is unencrypted. Username, password and file contents traverse the network in clear text.
1. Stop the FTP service in IIS [Windows IIS]
Stop-Service ftpsvc
Set-Service ftpsvc -StartupType Disabled
💡 Server Manager → Roles and Features → remove FTP Server.
2. Remove vsftpd or force SSL [Linux (vsftpd)]
sudo systemctl stop vsftpd
sudo systemctl disable vsftpd
# Veya SSL zorunlu kılmak için /etc/vsftpd.conf'a:
# ssl_enable=YES
# force_local_data_ssl=YES
# force_local_logins_ssl=YES
💡 If OpenSSH is already installed, SFTP can be used automatically.
3. SFTP ships with OpenSSH [Alternative: SFTP]
# SSH kurulu ise SFTP de kullanılabilir:
sftp user@host
💡 Tools like FileZilla and WinSCP support SFTP.
✓ Doğrulama:
nmap -p 21 <host>  →  closed/filtered
Medium
P25
Eksik HTTP Security Headers (4 adet) — port 443
Bu web servisinde 4 kritik güvenlik header'ı eksik: HSTS, Content-Security-Policy, Referrer-Policy, Permissions-Policy
💰 İŞ ETKİSİ
Modern web saldırılarının (XSS, clickjacking, MIME confusion) çoğu HTTP security header'ları ile engellenir. Eksik header = exploit yüzeyi açık. Mozilla Observatory ve OWASP benchmark'larda 'F' notu alır.
✓ AKSİYON
Web sunucu/reverse proxy seviyesinde header'ları ekleyin: HSTS ('max-age=31536000; includeSubDomains'), X-Frame-Options 'DENY', CSP 'default-src self', X-Content-Type-Options 'nosniff', Referrer-Policy 'strict-origin-when-cross-origin', Permissions-Policy 'geolocation=()'.
Kanıt: GET https://192.169.1.113:443/ → eksik: HSTS, Content-Security-Policy, Referrer-Policy, Permissions-Policy
Seviye: Observed | Güven: High
Medium
P25
SSH Management Exposure
SSH yonetim yuzeyi erisilebilir durumda.
💰 İŞ ETKİSİ
This surface raises risk when unnecessarily or broadly exposed.
✓ AKSİYON
SSH erisimini yalnizca yonetim aglarindan acin.
Kanıt: Port 22 acik
Seviye: Observed | Güven: Medium
Medium
P25
Credential Attack Surface
Kimlik dogrulama bekleyen servisler erisilebilir durumda. Bu yuzeyler cevrim ici parola denemesi veya hesap hedefleme icin cazip olabilir.
💰 İŞ ETKİSİ
Unnecessary exposure of authentication-requiring services increases account-targeting risk.
✓ AKSİYON
Yonetim erisimlerini ayri VLAN, MFA ve hesap kilitleme politikalariyla koruyun.
Kanıt: Kimlik dogrulama yuzeyleri: 21, 22, 443
Seviye: Observed | Güven: Medium
Medium
P25
Customer Declared NAS Detected
Customer Declared NAS product detected. The management and access surface of this system should be reviewed.
💰 İŞ ETKİSİ
File-sharing services are prone to data leakage and broad-access errors.
✓ AKSİYON
Audit access lists, anonymous access, and write permissions on file-sharing services.
Kanıt: Customer infrastructure profile
Seviye: Fingerprint | Güven: High
Low
P15
Web Service Exposure
Web arayuzu erisilebilir durumda.
💰 İŞ ETKİSİ
This surface raises risk when unnecessarily or broadly exposed.
✓ AKSİYON
Web arayuzlerini segment bazli erisim kontroluyle koruyun.
Kanıt: Acik portlar: 443
Seviye: Observed | Güven: Medium
Low
P15
Managed Switch Detected
Managed Switch product detected. The management and access surface of this system should be reviewed.
💰 İŞ ETKİSİ
Exposure of this product can create operational and security risk.
✓ AKSİYON
Verify the service exposure and access controls.
Kanıt: Switch / ag altyapi cihazi izi tespit edildi
Seviye: Fingerprint | Güven: Medium
Low
P15
Wireless Access Point Detected
Wireless Access Point product detected. The management and access surface of this system should be reviewed.
💰 İŞ ETKİSİ
Exposure of this product can create operational and security risk.
✓ AKSİYON
Verify the service exposure and access controls.
Kanıt: Kablosuz erisim cihazi izi tespit edildi
Seviye: Fingerprint | Güven: Medium
192.169.1.117
Hostname: dc | Segment: 192.169.1.0/24 | Tur: WindowsServer | OS: Microsoft Windows Server 2012 R2 Standard
Kritik

IT Ozeti

15/100
Rol: Domain Controller
Sorun: SMBv1 protocol active — MS17-010 risk
Etkisi: MS17-010 (EternalBlue) CVSS 9.8 — the vulnerability used by WannaCry and NotPetya. Allows unauthenticated remote code execution.
Duzelt: URGENT: Disable SMBv1: 'Set-SmbServerConfiguration -EnableSMB1Protocol $false' | Apply the MS17-010 patch (KB4012212).

Rol ve Port Ozetleri

Musteri Tanimi: Domain Controller DomainController (Observed) FileServer (Observed) DatabaseServer (Observed) ManagementSurface (Observed) File Server
MAC / Vendor: 1C:98:EC:52:1A:5C / Hewlett Packard Enterprise
53/DNS 80/HTTP 135/MSRPC 139/NetBIOS 443/HTTPS 445/SMB 1433/MSSQL 3389/RDP
Urunler: Web Service 1.1, SMB File Sharing, Microsoft SQL Server 1.1, RDP Remote Access
Maruziyet: SMB Exposure, RDP Management Exposure, Database Service Exposure, Web Service Exposure, Domain Controller Surface, General File Share Surface, Credential Attack Surface

Kimlikli Denetim

[Authenticated] Windows/WMI audit could not be completed
Not found
Kanit: Authenticated audit attempt ended with an error.
[Authenticated] Active Directory LDAP audit could not be performed
The supplied credential is invalid.
Kanit: LDAP error code: 49
[Authenticated] Yerel Administrators Üyeleri
Toplam: 9 | Standart-dışı: 6
Kanit: ERKANLI\Administrator | ERKANLI\Enterprise Admins | ERKANLI\Domain Admins | ERKANLI\code5 | ERKANLI\bkuyumcu | ERKANLI\mustafa | ERKANLI\macmaz | ERKANLI\erkanli1 | ERKANLI\erkanli2
[Authenticated] Failed Logon Analizi Tamamlandı
Son 7 gün: 82 failed logon | 0 spam'lenen hesap | 0 spam kaynağı IP
Kanit: WMI Win32_NTLogEvent Security log
[Authenticated] Windows Hardening Gaps Taraması
WDigest:-1 | PSModule:-1 | PSScriptBlock:-1 | CmdLine:-1 | LSAPPL:-1 | CredGuard:-1
Kanit: Registry: WDigest, PowerShell policies, Audit policies, LSA, DeviceGuard
[Authenticated] Scheduled Task Analizi
Privileged task: 0
Kanit: MSFT_ScheduledTask WMI
[ConfigurationConfirmed] SMB shares confirmed
Authenticated audit confirmed 6 shares.
Kanit: LOGO, NETLOGON, ORTAK, SMBTest, SYSVOL, Users
[Authenticated] MSSQL audit could not be completed
Login failed for user 'afn_user'.
Kanit: Authenticated audit attempt ended with an error.

Bulgular

Critical
P65
SMBv1 protocol active — MS17-010 risk
The server responded to the SMBv1 protocol. Systems supporting SMBv1 can be vulnerable to EternalBlue (MS17-010).
💰 İŞ ETKİSİ
MS17-010 (EternalBlue) CVSS 9.8 — the vulnerability used by WannaCry and NotPetya. Allows unauthenticated remote code execution.
⏱ Tahmini Kesinti
12-72 saat
💸 Olası Kayıp
200.000 – 2.000.000 TL
📉 Veri Riski
🔴 Çok Yüksek
✓ AKSİYON
URGENT: Disable SMBv1: 'Set-SmbServerConfiguration -EnableSMB1Protocol $false' | Apply the MS17-010 patch (KB4012212).
Kanıt: Port 445: SMB Negotiate response received (209 bytes) | Dialect index=0
Seviye: Passive | Güven: High
📋 Uygulama Rehberi: Disable the SMBv1 Protocol
SMBv1 is a legacy protocol exploited by MS17-010 (EternalBlue) and many ransomware families. Modern Windows already uses SMB2/SMB3, so disabling SMBv1 is safe.
1. Disable the SMBv1 server side [PowerShell (on every server/client)]
Set-SmbServerConfiguration -EnableSMB1Protocol $false -Force
💡 Takes effect immediately; no restart required.
2. Disable the SMBv1 client side (for legacy clients) [PowerShell]
Disable-WindowsOptionalFeature -Online -FeatureName smb1protocol -NoRestart
💡 Fully effective after a restart.
3. Apply across the domain via GPO [GPO (Domain environment)]
Computer Configuration → Policies → Administrative Templates → MS Security Guide → Configure SMBv1 Server = Disabled
💡 The MS Security Baseline ADMX must be installed.
4. Apply the MS17-010 patch [Windows Update]
Windows Update → KB4012212 (Win 7/2008) veya KB4013429 (Win 10/2016+)
💡 The patch may already be installed on modern Windows.
✓ Doğrulama:
Get-SmbServerConfiguration | Select EnableSMB1Protocol  →  False
Critical
P65
Microsoft SQL Server (port 1433) Ağa Açık
Microsoft SQL Server servisi port 1433 üzerinde dinleniyor.
💰 İŞ ETKİSİ
Veritabanı varsayılan kimlik bilgileri ('sa' / (boş veya 'sa')) ile çalışıyor olabilir. MongoDB ve Redis VARSAYILAN olarak kimlik doğrulaması yapmaz — internete açık olduğunda 1 dakikada ele geçirilir. MSSQL 'sa' boş/zayıf parola çok yaygın. Veri ihlali, ransomware (özellikle MongoDB/Elastic'te) en hızlı saldırı vektörü.
⏱ Tahmini Kesinti
4-24 saat
💸 Olası Kayıp
100.000 – 500.000 TL
📉 Veri Riski
🔴 Yüksek
✓ AKSİYON
1) Default kimlik bilgilerini DERHAL değiştirin (kompleks parola). 2) Veritabanını sadece uygulama sunucusundan erişilebilir kılın (firewall ACL). 3) MongoDB/Redis için authentication zorunlu yapın. 4) MSSQL sa hesabını DISABLE edin, Windows Auth + service account kullanın. 5) İnternete kesinlikle expose etmeyin — VPN/jump host arkasına alın.
Kanıt: Port 1433/TCP açık | Default cred: sa:(boş veya 'sa')
Seviye: Observed | Güven: High
Critical
P65
Likely Domain Controller
This host shows multiple AD/DC port signatures and behaves like a Domain Controller.
💰 İŞ ETKİSİ
Domain Controllers are the core of identity, group policy, and authorization chains; exposure impact is broad.
⏱ Tahmini Kesinti
4-24 saat
💸 Olası Kayıp
100.000 – 500.000 TL
📉 Veri Riski
🔴 Yüksek
✓ AKSİYON
Restrict DC access to required servers and management networks only; apply tiering and privileged access policies.
Kanıt: DC port signals: 53, 135, 139, 445
Seviye: Fingerprint | Güven: Medium
Critical
P65
End-of-Life / Near-EOL Windows Version
Operating system: Microsoft Windows Server 2012 R2 Standard. Microsoft support for Windows Server 2012 R2 ended on 2023-10-10. This system no longer receives security patches.
💰 İŞ ETKİSİ
Systems past Microsoft support receive no security patches. Newly discovered vulnerabilities will never be fixed, and attackers can exploit known CVEs on these systems with confidence.
⏱ Tahmini Kesinti
Birikimli risk
💸 Olası Kayıp
100.000 – 800.000 TL
📉 Veri Riski
🟠 Yüksek (yamasız CVE)
✓ AKSİYON
Plan and execute a migration to a supported Windows version (Windows Server 2022 or 2025).
Kanıt: Detected OS: Microsoft Windows Server 2012 R2 Standard
Seviye: Authenticated | Güven: High
📋 Uygulama Rehberi: Migrate Off End-of-Life Windows
EOL Windows does not receive new security patches. Newly discovered CVEs remain exposed forever.
1. List the current OS version and applications [Planning]
Get-WmiObject Win32_OperatingSystem | Select Caption, Version, BuildNumber
Get-WmiObject Win32_Product | Select Name, Version | Out-File C:\sw-list.txt
💡 Check which applications are compatible with the new Windows.
2a. Upgrade the version on the existing server [Migration Strategy — In-Place Upgrade]
💡 Server 2012 R2 → Server 2019/2022 in-place upgrade is supported. Take a backup first.
2b. Install a fresh Windows Server 2022 and move the roles [Migration Strategy — New Server]
💡 AD: ADDS Migration Tools / demote the old DC afterwards. SQL: migrate via AlwaysOn. Files: Robocopy.
3. If an upgrade is not feasible, purchase ESU [Emergency]
Microsoft Extended Security Updates (ESU) — annual subscription, limited patches
💡 ESU is a temporary measure; the ultimate goal must be moving to a new OS.
✓ Doğrulama:
winver  →  should show Windows Server 2019/2022
High
P55
Office Internet-Macro Block Aktif Değil (dc)
Internet'ten indirilen Office dosyalarında macro execution'ı blokleyen ayar yok.
💰 İŞ ETKİSİ
Microsoft 2022'de bu ayarı default aktif yaptı. Eski sürümlerde ve yanlış GPO'larda hala kapalı.
⏱ Tahmini Kesinti
2-8 saat
💸 Olası Kayıp
30.000 – 150.000 TL
📉 Veri Riski
🟠 Orta-Yüksek
✓ AKSİYON
GPO ile 'Block macros from running in Office files from the Internet' enabled yapın.
Kanıt: HKLM\SOFTWARE\Microsoft\Office\16.0\Word\Security\BlockContentExecutionFromInternet != 1
Seviye: Authenticated | Güven: Medium
High
P55
Çok Sayıda Yerel Admin (6 ek hesap)
Bu endpoint'in yerel Administrators grubunda standart hesaplar dışında 6 ek hesap var.
💰 İŞ ETKİSİ
Yerel admin sayısı arttıkça saldırı yüzeyi büyür. Her admin endpoint'i ele geçirilirse saldırgan SYSTEM yetkisi alır → credential dump (Mimikatz) → domain lateral. 'Şüpheli' kabul edilen hesaplar: ayrılan personel, eski vendor, helpdesk, test, manuel eklenen.
⏱ Tahmini Kesinti
2-8 saat
💸 Olası Kayıp
30.000 – 150.000 TL
📉 Veri Riski
🟠 Orta-Yüksek
✓ AKSİYON
Bu hesapları gözden geçirin. Standart workstation'lara: sadece Domain Admins + 1 break-glass local admin. Diğer admin gruplarını LAPS ile yönetin. Helpdesk için ayrı bir tier-2 grup oluşturup sadece gerekli OU'larda yetkilendirin.
Kanıt: Win32_Group.Administrators üyeleri: ERKANLI\code5, ERKANLI\bkuyumcu, ERKANLI\mustafa, ERKANLI\macmaz, ERKANLI\erkanli1, ERKANLI\erkanli2
Seviye: Authenticated | Güven: High
High
P55
PowerShell Logging Aktif Değil
PowerShell logging eksik — Module: ✗, ScriptBlock: ✗, Transcription: ✗
💰 İŞ ETKİSİ
Modern saldırılar PowerShell ile yapılır (Empire, PowerSploit, Mimikatz, BloodHound). Logging kapalıysa saldırgan aktivitesi GÖRÜNMEZ. SIEM'e Event 4103/4104/4688 gönderilmiyor demektir. İhlal sonrası forensic imkansız.
⏱ Tahmini Kesinti
2-8 saat
💸 Olası Kayıp
30.000 – 150.000 TL
📉 Veri Riski
🟠 Orta-Yüksek
✓ AKSİYON
GPO ile etkinleştir: Computer Configuration → Administrative Templates → Windows Components → Windows PowerShell → Turn on Module Logging + Script Block Logging + Transcription. Module names = '*' (tümü).
Kanıt: HKLM\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ — EnableModuleLogging=-1, EnableScriptBlockLogging=-1
Seviye: Authenticated | Güven: High
High
P55
Process Creation Command-Line Logging Kapalı
Event 4688 (Process Creation) için command-line argümanları loglanmıyor.
💰 İŞ ETKİSİ
Saldırı sonrası forensic için Event 4688 KRİTİK. Command-line olmadan 'cmd.exe' veya 'powershell.exe' görürsünüz ama saldırganın hangi komutu çalıştırdığını bilemezsiniz. Modern ihlal soruşturmasının en önemli log kaynağı.
⏱ Tahmini Kesinti
2-8 saat
💸 Olası Kayıp
30.000 – 150.000 TL
📉 Veri Riski
🟠 Orta-Yüksek
✓ AKSİYON
GPO: Administrative Templates → System → Audit Process Creation → 'Include command line in process creation events' = Enabled. Ayrıca 'Audit Process Creation' Success+Failure açık olmalı.
Kanıt: ProcessCreationIncludeCmdLine_Enabled = -1
Seviye: Authenticated | Güven: High
High
P55
LSA Protection (RunAsPPL) Aktif Değil
LSASS process protected light (PPL) modda çalışmıyor.
💰 İŞ ETKİSİ
LSA Protection açık olduğunda Mimikatz LSASS belleğine erişemez (driver gerekir, EDR alarm verir). Modern Windows için güçlü koruma. Çoğu kurumda 'eski uygulamalar bozulur' diye açılmaz, ama bu güvenlik açısından KRİTİK.
⏱ Tahmini Kesinti
2-8 saat
💸 Olası Kayıp
30.000 – 150.000 TL
📉 Veri Riski
🟠 Orta-Yüksek
✓ AKSİYON
Registry: RunAsPPL = 1 (Windows 11 24H2+ default). Önce test ortamında uygulamaların etkilenmediğini doğrulayın.
Kanıt: HKLM\SYSTEM\CurrentControlSet\Control\Lsa\RunAsPPL = -1
Seviye: Authenticated | Güven: High
High
P55
Share Folders Enumerated via Authenticated Audit
Share folders with visible names were found on this host. If the permission model is broad, data leakage or lateral movement impact may grow.
💰 İŞ ETKİSİ
Seeing actual share names is a stronger evidence level than the mere fact that port 445 is open.
⏱ Tahmini Kesinti
2-8 saat
💸 Olası Kayıp
30.000 – 150.000 TL
📉 Veri Riski
🟠 Orta-Yüksek
✓ AKSİYON
Review per-share ACLs, anonymous enumeration, write permissions, and whether sensitive data is stored.
Kanıt: Shares: LOGO, NETLOGON, ORTAK, SMBTest, SYSVOL, Users
Seviye: ConfigurationConfirmed | Güven: High
High
P55
Local Administrators Group Too Broad
More members than expected were observed in the local Administrators group on this host.
💰 İŞ ETKİSİ
A broad local admin group amplifies impact in credential theft or lateral movement scenarios.
⏱ Tahmini Kesinti
2-8 saat
💸 Olası Kayıp
30.000 – 150.000 TL
📉 Veri Riski
🟠 Orta-Yüksek
✓ AKSİYON
Tighten local admin membership using role-based and least-privilege principles.
Kanıt: Members: ERKANLI\Administrator, ERKANLI\Enterprise Admins, ERKANLI\Domain Admins, ERKANLI\code5, ERKANLI\bkuyumcu, ERKANLI\mustafa, ERKANLI\macmaz, ERKANLI\erkanli1, ERKANLI\erkanli2
Seviye: ConfigurationConfirmed | Güven: High
Medium
P43
Credential Guard Etkin Değil
Virtualization-Based Security (VBS) ve Credential Guard kapalı.
💰 İŞ ETKİSİ
Credential Guard ile NTLM hash'leri ve Kerberos ticket'lar hipervizör tarafından izole edilmiş bellekte tutulur — Mimikatz ve LSASS dump koruması.
✓ AKSİYON
GPO: Administrative Templates → System → Device Guard → 'Turn On Virtualization Based Security' + Credential Guard. UEFI Secure Boot + TPM 2.0 gerekli.
Kanıt: EnableVirtualizationBasedSecurity = -1
Seviye: Authenticated | Güven: Medium
Medium
P43
Eksik HTTP Security Headers (5 adet) — port 80
Bu web servisinde 5 kritik güvenlik header'ı eksik: X-Frame-Options, Content-Security-Policy, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
💰 İŞ ETKİSİ
Modern web saldırılarının (XSS, clickjacking, MIME confusion) çoğu HTTP security header'ları ile engellenir. Eksik header = exploit yüzeyi açık. Mozilla Observatory ve OWASP benchmark'larda 'F' notu alır.
✓ AKSİYON
Web sunucu/reverse proxy seviyesinde header'ları ekleyin: HSTS ('max-age=31536000; includeSubDomains'), X-Frame-Options 'DENY', CSP 'default-src self', X-Content-Type-Options 'nosniff', Referrer-Policy 'strict-origin-when-cross-origin', Permissions-Policy 'geolocation=()'.
Kanıt: GET http://192.169.1.117:80/ → eksik: X-Frame-Options, Content-Security-Policy, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
Seviye: Observed | Güven: High
Medium
P43
RDP Management Exposure
RDP yonetim yuzeyi erisilebilir durumda.
💰 İŞ ETKİSİ
This surface raises risk when unnecessarily or broadly exposed.
✓ AKSİYON
RDP erisimini yalnizca yonetim VLAN'lariyla sinirlandirin.
Kanıt: Port 3389 acik
Seviye: Observed | Güven: Medium
Medium
P43
Database Service Exposure
Veritabani servisi ag uzerinden erisilebilir durumda.
💰 İŞ ETKİSİ
This surface raises risk when unnecessarily or broadly exposed.
✓ AKSİYON
Veritabani erisimini yalnizca uygulama sunuculari ve yonetim aglariyla sinirlandirin.
Kanıt: Acik portlar: 1433
Seviye: Observed | Güven: Medium
Medium
P43
Domain Controller Surface
Bu host muhtemel Domain Controller gibi davraniyor ve kimlik/rehber servisleri tasiyor.
💰 İŞ ETKİSİ
This surface raises risk when unnecessarily or broadly exposed.
✓ AKSİYON
Domain Controller erisimini yalnizca yonetim aglari ve gerekli sunucularla sinirlandirin; ayricalikli hesaplari ayri yonetin.
Kanıt: Rol sinyalleri: DomainController, FileServer, DatabaseServer, ManagementSurface
Seviye: Observed | Güven: Medium
Medium
P43
General File Share Surface
Bu host dosya paylasim yuzeyi sunuyor. Genel/anonim erisim durumu ayrica dogrulanmali.
💰 İŞ ETKİSİ
Share surfaces are a typical source of data leakage and broad-permission errors.
✓ AKSİYON
Public/anonymous share dogrulamasi icin kimlikli veya kontrollu null-session audit yapin; gereksiz paylasimlari kapatin.
Kanıt: Acik paylasim portlari: 139, 445
Seviye: Observed | Güven: Medium
Medium
P43
Credential Attack Surface
Kimlik dogrulama bekleyen servisler erisilebilir durumda. Bu yuzeyler cevrim ici parola denemesi veya hesap hedefleme icin cazip olabilir.
💰 İŞ ETKİSİ
Unnecessary exposure of authentication-requiring services increases account-targeting risk.
✓ AKSİYON
Yonetim erisimlerini ayri VLAN, MFA ve hesap kilitleme politikalariyla koruyun.
Kanıt: Kimlik dogrulama yuzeyleri: 443, 3389
Seviye: Observed | Güven: Medium
Medium
P43
Likely File Server / Share Surface
This host behaves like a file server because SMB or NFS share ports are open.
💰 İŞ ETKİSİ
Shares open to broad access or with permissive ACLs amplify data leakage and lateral movement risk.
✓ AKSİYON
Verify public/anonymous share status, close unnecessary shares, and tighten ACLs.
Kanıt: Share ports: 139, 445
Seviye: Fingerprint | Güven: Medium
Low
P33
Sunucu Banner Sürüm İfşası (80/TCP)
HTTP yanıt header'ında sürüm bilgisi açık: 'Server: Microsoft-IIS/8.5'
💰 İŞ ETKİSİ
Saldırgan sürüm bilgisini kullanarak hedefe özel exploit aramaktan vakit kazanır. nginx 1.18.0 gibi tam sürüm bilgisi = CVE eşleştirmesi tek tık.
✓ AKSİYON
Web server config'inde sürüm gizleyin. nginx: 'server_tokens off;'. Apache: 'ServerTokens Prod, ServerSignature Off'. IIS: 'X-Powered-By' header'ı kaldır.
Kanıt: Server header: Microsoft-IIS/8.5
Seviye: Observed | Güven: High
Low
P33
X-Powered-By Header İfşası (80/TCP)
HTTP yanıtta 'X-Powered-By: ASP.NET' tespit edildi.
💰 İŞ ETKİSİ
Backend technology stack ifşası (PHP/X.X, ASP.NET vb.) saldırı yüzeyini netleştirir.
✓ AKSİYON
Header'ı kaldırın. IIS: web.config'de <customHeaders><remove name="X-Powered-By" />.
Kanıt: X-Powered-By: ASP.NET
Seviye: Observed | Güven: High
Low
P33
X-Powered-By Header İfşası (443/TCP)
HTTP yanıtta 'X-Powered-By: ASP.NET' tespit edildi.
💰 İŞ ETKİSİ
Backend technology stack ifşası (PHP/X.X, ASP.NET vb.) saldırı yüzeyini netleştirir.
✓ AKSİYON
Header'ı kaldırın. IIS: web.config'de <customHeaders><remove name="X-Powered-By" />.
Kanıt: X-Powered-By: ASP.NET
Seviye: Observed | Güven: High
Low
P33
Web Service Exposure
Web arayuzu erisilebilir durumda.
💰 İŞ ETKİSİ
This surface raises risk when unnecessarily or broadly exposed.
✓ AKSİYON
Web arayuzlerini segment bazli erisim kontroluyle koruyun.
Kanıt: Acik portlar: 80, 443
Seviye: Observed | Güven: Medium
192.169.1.17
Hostname: ANFNERSUR | Segment: 192.169.1.0/24 | Tur: WindowsServer
Kritik

IT Ozeti

15/100
Rol: SQL Server
Sorun: Microsoft SQL Server (port 1433) Ağa Açık
Etkisi: Veritabanı varsayılan kimlik bilgileri ('sa' / (boş veya 'sa')) ile çalışıyor olabilir. MongoDB ve Redis VARSAYILAN olarak kimlik doğrulaması yapmaz — internete açık olduğunda 1 dakikada ele geçirilir. MSSQL 'sa' boş/zayıf parola çok yaygın. Veri ihlali, ransomware (özellikle MongoDB/Elastic'te) en hızlı saldırı vektörü.
Duzelt: 1) Default kimlik bilgilerini DERHAL değiştirin (kompleks parola). 2) Veritabanını sadece uygulama sunucusundan erişilebilir kılın (firewall ACL). 3) MongoDB/Redis için authentication zorunlu yapın. 4) MSSQL sa hesabını DISABLE edin, Windows Auth + service account kullanın. 5) İnternete kesinlikle expose etmeyin — VPN/jump host arkasına alın.

Rol ve Port Ozetleri

Musteri Tanimi: SQL Server DatabaseServer (Observed) FileServer (Observed) ManagementSurface (Observed) Database Server
MAC / Vendor: BC:F1:05:68:6B:3B / Intel Corporate
80/HTTP 135/MSRPC 139/NetBIOS 445/SMB 1433/MSSQL 3389/RDP
Urunler: Customer Declared SQL 16.0.1000.6, Web Service 1.1, SMB File Sharing, Microsoft SQL Server 1.1, RDP Remote Access
Maruziyet: SMB Exposure, RDP Management Exposure, Database Service Exposure, Web Service Exposure, General File Share Surface, Credential Attack Surface

Kimlikli Denetim

[Authenticated] Windows/WMI audit could not be completed
Insufficient memory to continue the execution of the program.
Kanit: Authenticated audit attempt ended with an error.
[Authenticated] SMB Paylasim audit could not be completed
Insufficient memory to continue the execution of the program.
Kanit: Authenticated audit attempt ended with an error.
[ConfigurationConfirmed] MSSQL authenticated connection succeeded
Edition=Enterprise Edition (64-bit); Version=16.0.1000.6; Level=RTM; Mixed Mode active; TLS not required; sa active; PolicyExceptions=2; Sysadmin=1
Kanit: Server=ANFNERSUR; Databases=afn_mail, afn_teklifler, AfnTeknolojiDB, Debt, ITCompanyDB
[ConfigurationConfirmed] SQL login password-policy exceptions observed
2 logins: afn_user, sa
Kanit: sys.sql_logins: is_policy_checked / is_expiration_checked
[ConfigurationConfirmed] SQL sysadmin members enumerated
1 sysadmin members observed.
Kanit: sa

Bulgular

Critical
P60
Microsoft SQL Server (port 1433) Ağa Açık
Microsoft SQL Server servisi port 1433 üzerinde dinleniyor.
💰 İŞ ETKİSİ
Veritabanı varsayılan kimlik bilgileri ('sa' / (boş veya 'sa')) ile çalışıyor olabilir. MongoDB ve Redis VARSAYILAN olarak kimlik doğrulaması yapmaz — internete açık olduğunda 1 dakikada ele geçirilir. MSSQL 'sa' boş/zayıf parola çok yaygın. Veri ihlali, ransomware (özellikle MongoDB/Elastic'te) en hızlı saldırı vektörü.
⏱ Tahmini Kesinti
4-24 saat
💸 Olası Kayıp
100.000 – 500.000 TL
📉 Veri Riski
🔴 Yüksek
✓ AKSİYON
1) Default kimlik bilgilerini DERHAL değiştirin (kompleks parola). 2) Veritabanını sadece uygulama sunucusundan erişilebilir kılın (firewall ACL). 3) MongoDB/Redis için authentication zorunlu yapın. 4) MSSQL sa hesabını DISABLE edin, Windows Auth + service account kullanın. 5) İnternete kesinlikle expose etmeyin — VPN/jump host arkasına alın.
Kanıt: Port 1433/TCP açık | Default cred: sa:(boş veya 'sa')
Seviye: Observed | Güven: High
Critical
P60
Lateral Movement Risk (SMB + RDP)
Both SMB and RDP are reachable. An attacker who breaches this host can move within the network more easily.
💰 İŞ ETKİSİ
The impact of compromise grows when file sharing and interactive management access coexist on the same host.
⏱ Tahmini Kesinti
2-12 saat
💸 Olası Kayıp
50.000 – 300.000 TL
📉 Veri Riski
🟠 Yetkisiz erişim
✓ AKSİYON
Restrict both services using segment-based access controls.
Kanıt: Ports 445 and 3389 open
Seviye: Observed | Güven: High
High
P50
SQL 'sa' Account Enabled
During the authenticated audit, the 'sa' account did not appear to be disabled.
💰 İŞ ETKİSİ
The well-known built-in 'sa' account is one of the first targets in credential-guessing and targeted identity attacks.
⏱ Tahmini Kesinti
2-8 saat
💸 Olası Kayıp
30.000 – 150.000 TL
📉 Veri Riski
🟠 Orta-Yüksek
✓ AKSİYON
Disable the sa account or restrict it to controlled break-glass scenarios only.
Kanıt: Server: ANFNERSUR | sa disabled: false
Seviye: ConfigurationConfirmed | Güven: High
High
P50
SQL Login Password Policy Exceptions Found
One or more SQL logins have password policy or expiration checks disabled.
💰 İŞ ETKİSİ
SQL logins without policy enforcement are more vulnerable to credential-guessing and weak-password scenarios.
⏱ Tahmini Kesinti
2-8 saat
💸 Olası Kayıp
30.000 – 150.000 TL
📉 Veri Riski
🟠 Orta-Yüksek
✓ AKSİYON
Enable CHECK_POLICY and CHECK_EXPIRATION for SQL logins; disable unnecessary SQL logins.
Kanıt: Exception logins: afn_user, sa
Seviye: ConfigurationConfirmed | Güven: High
High
P50
MSSQL Mixed Mode Enabled
SQL Server has mixed-mode authentication (SQL logins) enabled.
💰 İŞ ETKİSİ
SQL logins introduce additional risk through password management overhead and a targetable identity surface.
⏱ Tahmini Kesinti
4-24 saat
💸 Olası Kayıp
100.000 – 800.000 TL
📉 Veri Riski
🟠 DB ele geçirme
✓ AKSİYON
Move to Windows/Entra-only authentication if possible; for any remaining SQL logins, enforce strong passwords and rotation.
Kanıt: Edition: Enterprise Edition (64-bit) | Version: 16.0.1000.6 | MixedMode: true
Seviye: ConfigurationConfirmed | Güven: High
High
P50
SQL 'sa' Account Observed as Sysadmin
The authenticated audit observed that the classic 'sa' account has sysadmin privileges.
💰 İŞ ETKİSİ
Because sa is a targeted, well-known, high-impact account, it increases exposure risk significantly.
⏱ Tahmini Kesinti
4-24 saat
💸 Olası Kayıp
100.000 – 600.000 TL
📉 Veri Riski
🟠 DB yetki
✓ AKSİYON
Disable the sa account or place it under strong controls; log its usage and prefer alternative management accounts.
Kanıt: Sysadmin members: sa
Seviye: ConfigurationConfirmed | Güven: High
High
P50
MSSQL Connection Established Without Encryption
No connection-encryption signal was observed during the authenticated SQL session.
💰 İŞ ETKİSİ
Unencrypted database sessions increase the risk of credentials and query content being observed on the network.
⏱ Tahmini Kesinti
2-8 saat
💸 Olası Kayıp
30.000 – 150.000 TL
📉 Veri Riski
🟠 Orta-Yüksek
✓ AKSİYON
Install a TLS certificate and enforce encrypted connections on the SQL Server side.
Kanıt: Server: ANFNERSUR | EncryptOption: false
Seviye: ConfigurationConfirmed | Güven: High
Medium
P38
Eksik HTTP Security Headers (5 adet) — port 80
Bu web servisinde 5 kritik güvenlik header'ı eksik: X-Frame-Options, Content-Security-Policy, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
💰 İŞ ETKİSİ
Modern web saldırılarının (XSS, clickjacking, MIME confusion) çoğu HTTP security header'ları ile engellenir. Eksik header = exploit yüzeyi açık. Mozilla Observatory ve OWASP benchmark'larda 'F' notu alır.
✓ AKSİYON
Web sunucu/reverse proxy seviyesinde header'ları ekleyin: HSTS ('max-age=31536000; includeSubDomains'), X-Frame-Options 'DENY', CSP 'default-src self', X-Content-Type-Options 'nosniff', Referrer-Policy 'strict-origin-when-cross-origin', Permissions-Policy 'geolocation=()'.
Kanıt: GET http://192.169.1.17:80/ → eksik: X-Frame-Options, Content-Security-Policy, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
Seviye: Observed | Güven: High
Medium
P38
No HTTPS
The web service is running only over HTTP. Communications may be unencrypted.
💰 İŞ ETKİSİ
Session data or management traffic may be intercepted.
✓ AKSİYON
Configure an SSL/TLS certificate and redirect traffic to HTTPS.
Kanıt: Port 80 open, Port 443 closed
Seviye: Observed | Güven: High
Medium
P38
RDP Management Exposure
RDP yonetim yuzeyi erisilebilir durumda.
💰 İŞ ETKİSİ
This surface raises risk when unnecessarily or broadly exposed.
✓ AKSİYON
RDP erisimini yalnizca yonetim VLAN'lariyla sinirlandirin.
Kanıt: Port 3389 acik
Seviye: Observed | Güven: Medium
Medium
P38
Database Service Exposure
Veritabani servisi ag uzerinden erisilebilir durumda.
💰 İŞ ETKİSİ
This surface raises risk when unnecessarily or broadly exposed.
✓ AKSİYON
Veritabani erisimini yalnizca uygulama sunuculari ve yonetim aglariyla sinirlandirin.
Kanıt: Acik portlar: 1433
Seviye: Observed | Güven: Medium
Medium
P38
General File Share Surface
Bu host dosya paylasim yuzeyi sunuyor. Genel/anonim erisim durumu ayrica dogrulanmali.
💰 İŞ ETKİSİ
Share surfaces are a typical source of data leakage and broad-permission errors.
✓ AKSİYON
Public/anonymous share dogrulamasi icin kimlikli veya kontrollu null-session audit yapin; gereksiz paylasimlari kapatin.
Kanıt: Acik paylasim portlari: 139, 445
Seviye: Observed | Güven: Medium
Medium
P38
Credential Attack Surface
Kimlik dogrulama bekleyen servisler erisilebilir durumda. Bu yuzeyler cevrim ici parola denemesi veya hesap hedefleme icin cazip olabilir.
💰 İŞ ETKİSİ
Unnecessary exposure of authentication-requiring services increases account-targeting risk.
✓ AKSİYON
Yonetim erisimlerini ayri VLAN, MFA ve hesap kilitleme politikalariyla koruyun.
Kanıt: Kimlik dogrulama yuzeyleri: 3389
Seviye: Observed | Güven: Medium
Medium
P38
Customer Declared SQL Detected
Customer Declared SQL product detected. Version trace: 16.0.1000.6. The management and access surface of this system should be reviewed.
💰 İŞ ETKİSİ
Database services are critical surfaces that hold sensitive data and authorization information.
✓ AKSİYON
Restrict database access to application servers and management networks only.
Kanıt: SQL login succeeded and server properties were confirmed
Seviye: Fingerprint | Güven: High
Medium
P38
Likely File Server / Share Surface
This host behaves like a file server because SMB or NFS share ports are open.
💰 İŞ ETKİSİ
Shares open to broad access or with permissive ACLs amplify data leakage and lateral movement risk.
✓ AKSİYON
Verify public/anonymous share status, close unnecessary shares, and tighten ACLs.
Kanıt: Share ports: 139, 445
Seviye: Fingerprint | Güven: Medium
Low
P28
Sunucu Banner Sürüm İfşası (80/TCP)
HTTP yanıt header'ında sürüm bilgisi açık: 'Server: Microsoft-IIS/10.0'
💰 İŞ ETKİSİ
Saldırgan sürüm bilgisini kullanarak hedefe özel exploit aramaktan vakit kazanır. nginx 1.18.0 gibi tam sürüm bilgisi = CVE eşleştirmesi tek tık.
✓ AKSİYON
Web server config'inde sürüm gizleyin. nginx: 'server_tokens off;'. Apache: 'ServerTokens Prod, ServerSignature Off'. IIS: 'X-Powered-By' header'ı kaldır.
Kanıt: Server header: Microsoft-IIS/10.0
Seviye: Observed | Güven: High
Low
P28
Web Service Exposure
Web arayuzu erisilebilir durumda.
💰 İŞ ETKİSİ
This surface raises risk when unnecessarily or broadly exposed.
✓ AKSİYON
Web arayuzlerini segment bazli erisim kontroluyle koruyun.
Kanıt: Acik portlar: 80
Seviye: Observed | Güven: Medium
192.169.1.99
Hostname: 192.169.1.99 | Segment: 192.169.1.0/24 | Tur: Firewall
Kritik

IT Ozeti

15/100
Rol: Firewall
Sorun: FortiGate Policy #1 (LAN_TO_SD_WAN) — AnyAny
Etkisi: An ANY-ANY:Accept rule allows every traffic type from anywhere to anywhere. It is the opposite of least privilege — effectively equivalent to having no firewall.
Duzelt: DELETE this rule, or narrow source/destination/service fields to specific objects. Example: src=LAN_users, dst=Server_subnet, service=445/SMB,3389/RDP

Rol ve Port Ozetleri

Musteri Tanimi: Firewall FirewallGateway (Observed) ManagementSurface (Observed) FortiGate Firewall
MAC / Vendor: 04:D5:90:DE:14:1F / Fortinet, Inc.
22/SSH 443/HTTPS
Urunler: Customer Declared Firewall, Web Service 2.0, SSH Remote Access, Fortinet Firewall 2.0
Maruziyet: SSH Management Exposure, Web Service Exposure, Firewall Management Exposure, Credential Attack Surface

Kimlikli Denetim

[Authenticated] Switch SSH login failed
Username or password is incorrect.
Kanit: SSH 22/tcp → 192.169.1.99
[ConfigurationConfirmed] Firewall management interface confirmed
Management page is accessible
Kanit: URL: https://192.169.1.99:443/ | HTTP: 200 | Title:
[Authenticated] FortiGate system information retrieved
Firmware: v7.0.17 | Model: | S/N: FGT60ETK20009386
Kanit: Hostname:
[Authenticated] FortiGate administrator accounts enumerated
1 administrator account(s) present.
Kanit: admin
[Authenticated] FortiGate policy deep analysis: 4 rules / 3 risks
Total 4 rules | ANY-ANY:Accept = 1 | Risks detected = 3.
Kanit: API: /api/v2/cmdb/firewall/policy — 4 records reviewed
[Authenticated] FortiGate VLAN trust map: 3 edges
Total 3 inter-VLAN trust paths | Unrestricted: 1 | Critical: 0 | High: 1
Kanit: src→dst trust matrix derived from policies
[Authenticated] FortiGate address objects and geo references reviewed
Geo address objects: 1 | USOM reference: not found
Kanit: No explicit USOM references seen in address objects
[Authenticated] FortiGate interface / VLAN inventory
16 interfaces detected — internal subnets: 10.10.10.0/24, 10.255.1.0/24, 192.169.1.0/24 | WAN: 85.105.152.31
Kanit: API: /api/v2/cmdb/system/interface — 16 interfaces, 0 VLANs
[Authenticated] FortiGate DHCP lease inventory
35 DHCP leases detected — IP/MAC/Hostname mapping included in the report.
Kanit: API: /api/v2/monitor/system/dhcp — Active: 0, Total: 35
[Authenticated] FortiOS firmware CVE check: no known critical CVE found
No known critical CVE detected for version v7.0.17. Compared against our current list.
Kanit: Firmware: v7.0.17
[Authenticated] FortiGate REST API audit completed
Model= | FW=v7.0.17 | S/N=FGT60ETK20009386 | Hostname= | Admins=1 | Policy=4 | AnyAny=1 | SSLVPN=On | Syslog=On | IdleTimeout=480 min
Kanit: Login: OK | Firmware: v7.0.17 | Policies: 4 rules | Admins: 1 accounts

Bulgular

Critical
P60
FortiGate Policy #1 (LAN_TO_SD_WAN) — AnyAny
src=all, dst=all, service=ALL, action=accept — rule that ACCEPTS ALL TRAFFIC
💰 İŞ ETKİSİ
An ANY-ANY:Accept rule allows every traffic type from anywhere to anywhere. It is the opposite of least privilege — effectively equivalent to having no firewall.
⏱ Tahmini Kesinti
6-24 saat
💸 Olası Kayıp
100.000 – 500.000 TL
📉 Veri Riski
🟠 Lateral movement
✓ AKSİYON
DELETE this rule, or narrow source/destination/service fields to specific objects. Example: src=LAN_users, dst=Server_subnet, service=445/SMB,3389/RDP
Kanıt: Policy #1 'LAN_TO_SD_WAN' — src=all, dst=all, service=ALL, action=accept — rule that ACCEPTS ALL TRAFFIC
Seviye: Authenticated | Güven: High
📋 Uygulama Rehberi: Narrow the FortiGate ANY-ANY Policy
An ANY-ANY:Accept rule allows all traffic everywhere. It is equivalent to having no firewall.
1. Identify the existing rule [FortiGate GUI]
💡 Policy & Objects → IPv4 Policy → rules with 'all → all' source/destination and 'ALL' service.
2. Analyse which services are actually required [Planning]
💡 Logs & Reports → Forward Traffic → see the most used services (HTTP, HTTPS, DNS, SMB, etc.).
3. Create a new narrow-scope rule [FortiGate CLI]
config firewall policy
edit 0
set name "LAN_to_Server_LimitedServices"
set srcintf "lan"
set dstintf "server_zone"
set srcaddr "LAN_users"
set dstaddr "Server_subnet"
set service "SMB" "RDP" "HTTPS"
set action accept
set logtraffic all
set av-profile "default"
set ips-sensor "protect_client"
next
end
💡 Define the address and service objects ahead of time.
4. DISABLE the old ANY-ANY rule (do not delete yet) [FortiGate]
💡 Status: disable. Observe for a week; if issues arise re-enable. Otherwise delete.
✓ Doğrulama:
Logs & Reports → Forward Traffic → the old 'all → all' rule should not be in use.
Critical
P60
FortiGate Telnet management active
Telnet is enabled for FortiGate CLI access.
💰 İŞ ETKİSİ
Telnet is unencrypted; sniffing the network can expose the admin password.
⏱ Tahmini Kesinti
1-6 saat
💸 Olası Kayıp
20.000 – 150.000 TL
📉 Veri Riski
🟠 Sniffing
✓ AKSİYON
Set admin-telnet to disable; use SSH only for CLI access.
Kanıt: system global → admin-telnet: enable
Seviye: Authenticated | Güven: High
📋 Uygulama Rehberi: Disable Telnet on FortiGate
Telnet traffic is unencrypted; admin passwords can be sniffed on the network. Use SSH instead.
1. Disable Telnet through the admin profile [FortiGate CLI]
config system global
set admin-telnet disable
end
💡 GUI: System → Settings → Administration Settings → uncheck 'Allow Telnet for CLI access'.
2. Remove the telnet port from the management interface [FortiGate CLI]
config system interface
edit <interface_name>
unset allowaccess
set allowaccess https ssh ping
next
end
💡 Repeat the same command on every interface that exposes management access.
✓ Doğrulama:
show system global | grep admin-telnet  →  set admin-telnet disable
Critical
P60
FortiGate Any→Any:Accept rules (1) — firewall bypass
The firewall contains 1 rules with src=any + dst=any + service=ALL action=accept. These rules pass traffic without filtering — the firewall becomes ineffective.
💰 İŞ ETKİSİ
Often overlooked by IT managers: any-any rules added 'for a quick test' or 'urgent work' stay in production for years. Once an attacker is inside, this rule lets them reach anything — segmentation collapses. Audit reports (ISO/PCI/KVKK) flag this as a critical finding.
⏱ Tahmini Kesinti
4-24 saat
💸 Olası Kayıp
100.000 – 500.000 TL
📉 Veri Riski
🔴 Yüksek
✓ AKSİYON
1) Review each any-any rule INDIVIDUALLY — why was it added, who owns it? 2) DELETE rules with no owner or stale rules IMMEDIATELY. 3) Narrow the necessary ones to src=specific_group, dst=specific_subnet, service=specific_port. 4) Add a comment to every policy (owner + date + ticket id).
Kanıt: firewall/policy → 1 Any→Any:Accept | Policy #1 'LAN_TO_SD_WAN'
Seviye: Authenticated | Güven: High
High
P50
VLAN trust violation: internal → virtual-wan-link
'internal' → 'virtual-wan-link' is unrestricted (service=ALL) — segmentation violation.
💰 İŞ ETKİSİ
Unrestricted access from zone 'internal' to zone 'virtual-wan-link'. If a host in internal is compromised, the attacker can move with ANY traffic type to virtual-wan-link — an open highway for ransomware and lateral movement.
⏱ Tahmini Kesinti
2-8 saat
💸 Olası Kayıp
30.000 – 150.000 TL
📉 Veri Riski
🟠 Orta-Yüksek
✓ AKSİYON
NARROW the internal → virtual-wan-link rule. Permit only required ports (e.g. 445 for file server, 3389 for RDP). Add a schedule (business hours). Make the IPS profile mandatory.
Kanıt: Policy ID(s): 1 | Services: ALL | UTM: no
Seviye: Authenticated | Güven: High
High
P50
FortiGate Policy #2 (SSL_TO_LAN) — InternalSegmentation
Internal-to-internal service=ALL — weak VLAN segmentation (ssl.root → internal)
💰 İŞ ETKİSİ
Unrestricted inter-VLAN traffic provides an open highway for lateral movement once a host is compromised. Ransomware uses these gaps to spread.
⏱ Tahmini Kesinti
2-8 saat
💸 Olası Kayıp
30.000 – 150.000 TL
📉 Veri Riski
🟠 Orta-Yüksek
✓ AKSİYON
Make inter-VLAN rules service-based (only the required ports) and schedule-based (business hours). Attach an IPS profile.
Kanıt: Policy #2 'SSL_TO_LAN' — Internal-to-internal service=ALL — weak VLAN segmentation (ssl.root → internal)
Seviye: Authenticated | Güven: High
High
P50
FortiGate Policy #3 (LAN_TO_SSL_VPN) — InternalSegmentation
Internal-to-internal service=ALL — weak VLAN segmentation (internal → ssl.root)
💰 İŞ ETKİSİ
Unrestricted inter-VLAN traffic provides an open highway for lateral movement once a host is compromised. Ransomware uses these gaps to spread.
⏱ Tahmini Kesinti
2-8 saat
💸 Olası Kayıp
30.000 – 150.000 TL
📉 Veri Riski
🟠 Orta-Yüksek
✓ AKSİYON
Make inter-VLAN rules service-based (only the required ports) and schedule-based (business hours). Attach an IPS profile.
Kanıt: Policy #3 'LAN_TO_SSL_VPN' — Internal-to-internal service=ALL — weak VLAN segmentation (internal → ssl.root)
Seviye: Authenticated | Güven: High
High
P50
FortiGate HTTP management active (unencrypted)
The FortiGate management interface is reachable over HTTP.
💰 İŞ ETKİSİ
HTTP management exposes administrator credentials to network sniffing.
⏱ Tahmini Kesinti
2-8 saat
💸 Olası Kayıp
30.000 – 150.000 TL
📉 Veri Riski
🟠 Orta-Yüksek
✓ AKSİYON
Disable HTTP management by setting admin-port to 0; use HTTPS only.
Kanıt: system global → admin-port active
Seviye: Authenticated | Güven: High
High
P50
FortiGate admins without trusted hosts (1)
One or more administrator accounts have no trusted host / source IP restriction.
💰 İŞ ETKİSİ
Admin accounts without source IP restriction expose a broader password-guessing surface.
⏱ Tahmini Kesinti
2-8 saat
💸 Olası Kayıp
30.000 – 150.000 TL
📉 Veri Riski
🟠 Orta-Yüksek
✓ AKSİYON
Define trusted hosts for administrator accounts so access is allowed only from management IP ranges.
Kanıt: Admin accounts: admin
Seviye: Authenticated | Güven: High
High
P50
FortiGate admins without token / MFA (1)
Two-factor authentication is not configured for one or more administrator accounts.
💰 İŞ ETKİSİ
Admin accounts without MFA can be taken over with a single password and lead to full firewall-level compromise.
⏱ Tahmini Kesinti
1-24 saat
💸 Olası Kayıp
100.000 – 1.000.000 TL
📉 Veri Riski
🔴 Tenant ele geçirme
✓ AKSİYON
Require FortiToken or a compatible MFA solution for all administrator accounts.
Kanıt: Admin accounts without MFA: admin
Seviye: Authenticated | Güven: High
📋 Uygulama Rehberi: Enforce MFA on Admin Accounts
Admin accounts without MFA are a single-line failure point under phishing and credential-stuffing attacks.
1. Create an Entra ID Conditional Access policy [Microsoft 365 — Conditional Access]
💡 Entra ID → Security → Conditional Access → New policy: • Users: 'Directory roles' → Global Admin, Privileged Role Admin, etc. • Cloud apps: All cloud apps • Grant: Require MFA • Enable: On
2. Activate FortiToken for the FortiGate admin [FortiGate Admin]
config system admin
edit "<admin_user>"
set two-factor fortitoken
set fortitoken "<token_serial>"
next
end
💡 First activate the token in FortiToken Cloud.
3. MFA backend via RADIUS/TACACS+ [Switch/Network]
💡 Use central auth (RADIUS) instead of device-local accounts; have the RADIUS server invoke MFA.
✓ Doğrulama:
Entra ID → Sign-in logs → an admin login → MFA prompt should appear
High
P50
FortiGate default 'admin' account active
The default 'admin' username has not been changed.
💰 İŞ ETKİSİ
A default username makes brute-force attacks easier; the attacker no longer has to guess the username.
⏱ Tahmini Kesinti
2-8 saat
💸 Olası Kayıp
30.000 – 150.000 TL
📉 Veri Riski
🟠 Orta-Yüksek
✓ AKSİYON
Disable or delete the 'admin' account; create a new administrator account.
Kanıt: system admin → 'admin' account enumerated
Seviye: Authenticated | Güven: High
High
P50
Firewall Management Exposure
Firewall / gateway yonetim yuzeyi erisilebilir durumda.
💰 İŞ ETKİSİ
Firewall/gateway management surfaces are critical points that can affect the entire network.
⏱ Tahmini Kesinti
2-8 saat
💸 Olası Kayıp
30.000 – 150.000 TL
📉 Veri Riski
🟠 Orta-Yüksek
✓ AKSİYON
Firewall yonetimini ayri yonetim segmenti ve MFA ile koruyun.
Kanıt: Firewall veya gateway urunu tespit edildi
Seviye: Observed | Güven: Medium
High
P50
Likely Firewall / Gateway
This host resembles a firewall or gateway appliance and a management surface was detected.
💰 İŞ ETKİSİ
If the firewall management interface is compromised, all segmentation and traffic control may be at risk.
⏱ Tahmini Kesinti
2-8 saat
💸 Olası Kayıp
30.000 – 150.000 TL
📉 Veri Riski
🟠 Orta-Yüksek
✓ AKSİYON
Move the management interface to a dedicated management network, enforce MFA, and block internet access.
Kanıt: Role signals: FirewallGateway, ManagementSurface
Seviye: Fingerprint | Güven: Medium
High
P50
Firewall Management Interface Confirmed via Authenticated Audit
The web management interface of the firewall or gateway appliance was confirmed.
💰 İŞ ETKİSİ
Because this layer is central to network segmentation and traffic control, its compromise can affect the entire environment.
⏱ Tahmini Kesinti
2-8 saat
💸 Olası Kayıp
30.000 – 150.000 TL
📉 Veri Riski
🟠 Orta-Yüksek
✓ AKSİYON
Make the management panel reachable only from management subnets; apply MFA and IP allow-listing.
Kanıt: URL: https://192.169.1.99:443/ | Behavior: Management page is accessible | Product:
Seviye: ConfigurationConfirmed | Güven: High
Medium
P38
FortiGate session timeout too long (480 min)
Administrator sessions stay open even after 480 minutes of inactivity.
💰 İŞ ETKİSİ
A long idle timeout increases the risk of abandoned management sessions being hijacked.
✓ AKSİYON
Reduce admintimeout to 5–10 minutes.
Kanıt: system global → admintimeout: 480
Seviye: Authenticated | Güven: High
Medium
P38
FortiGate password policy disabled
No minimum length / complexity policy is defined for administrator passwords.
💰 İŞ ETKİSİ
A weak password policy weakens defenses against brute-force attacks.
✓ AKSİYON
config system password-policy → status enable; require minimum length 12+, digits, uppercase and special characters.
Kanıt: system global → password-policy: disable
Seviye: Authenticated | Güven: High
Medium
P38
FortiGate SSL VPN active
The SSL VPN service is enabled.
💰 İŞ ETKİSİ
SSL VPN is an attack surface for critical FortiGate vulnerabilities such as CVE-2023-27997 (heap overflow RCE) and CVE-2022-42475.
✓ AKSİYON
Disable SSL VPN if not required. If required, keep firmware current, enforce MFA and restrict access by IP.
Kanıt: vpn.ssl/settings → status: enable
Seviye: Authenticated | Güven: High
Medium
P38
SSH Management Exposure
SSH yonetim yuzeyi erisilebilir durumda.
💰 İŞ ETKİSİ
This surface raises risk when unnecessarily or broadly exposed.
✓ AKSİYON
SSH erisimini yalnizca yonetim aglarindan acin.
Kanıt: Port 22 acik
Seviye: Observed | Güven: Medium
Medium
P38
Credential Attack Surface
Kimlik dogrulama bekleyen servisler erisilebilir durumda. Bu yuzeyler cevrim ici parola denemesi veya hesap hedefleme icin cazip olabilir.
💰 İŞ ETKİSİ
Unnecessary exposure of authentication-requiring services increases account-targeting risk.
✓ AKSİYON
Yonetim erisimlerini ayri VLAN, MFA ve hesap kilitleme politikalariyla koruyun.
Kanıt: Kimlik dogrulama yuzeyleri: 22, 443
Seviye: Observed | Güven: Medium
Medium
P38
Customer Declared Firewall Detected
Customer Declared Firewall product detected. The management and access surface of this system should be reviewed.
💰 İŞ ETKİSİ
Exposure of a network-security device can weaken segmentation and inspection layers.
✓ AKSİYON
Separate firewall management interfaces from user networks, and apply MFA and IP allow-listing.
Kanıt: Customer infrastructure profile
Seviye: Fingerprint | Güven: High
Medium
P38
Fortinet Firewall Detected
Fortinet Firewall product detected. Version trace: 2.0. The management and access surface of this system should be reviewed.
💰 İŞ ETKİSİ
Exposure of a network-security device can weaken segmentation and inspection layers.
✓ AKSİYON
Separate firewall management interfaces from user networks, and apply MFA and IP allow-listing.
Kanıt: Firewall / gateway yonetim arayuzu izi tespit edildi
Seviye: Fingerprint | Güven: Medium
Low
P28
Web Service Exposure
Web arayuzu erisilebilir durumda.
💰 İŞ ETKİSİ
This surface raises risk when unnecessarily or broadly exposed.
✓ AKSİYON
Web arayuzlerini segment bazli erisim kontroluyle koruyun.
Kanıt: Acik portlar: 443
Seviye: Observed | Güven: Medium
Info
P24
FortiGate WAN IPs detected (1) — external surface scan recommended
1 active WAN interfaces detected on FortiGate: 85.105.152.31
💰 İŞ ETKİSİ
These are the customer's Internet-facing IPs. Scanning them from OUTSIDE checks SSL VPN exposure, SSL/TLS configuration, open management ports and externally exploitable issues. An internal scan cannot see this surface.
✓ AKSİYON
Scan these IPs from the 'External Surface' tab — side menu 'External Surface' → Add IP.
Kanıt: FortiGate cmdb/system/interface — WAN role: 85.105.152.31
Seviye: Authenticated | Güven: High
192.169.1.111
Hostname: 192.169.1.111 | Segment: 192.169.1.0/24 | Tur: IPCamera
Kritik

IT Ozeti

21/100
Rol: IPCamera
Sorun: Hikvision Backdoor Authentication Bypass (CVE-2017-7921)
Etkisi: IP kameralar genellikle yıllarca güncellenmeden çalışır, eski firmware'lerde bilinen kritik CVE'ler vardır. Bu CVE'ler kimlik doğrulamasız admin yetki kazanmaya izin verir; saldırgan canlı görüntüye, ses kaydına, hatta ağa pivot yapma imkanına ulaşır.
Duzelt: Firmware'i 5.4.5 veya üzerine güncelleyin. Tüm Hikvision kameraları kontrol edin.

Rol ve Port Ozetleri

MAC / Vendor: B4:A3:82:B2:42:17 / Hangzhou Hikvision Digital Technology Co.,Ltd.
80/HTTP
Urunler: Web Service 1.0
Maruziyet: Web Service Exposure

Kimlikli Denetim

Bu IP icin kimlikli denetim kaydi yok.

Bulgular

Critical
CVE-2017-7921 CVSS 9.8 EPSS 92% 🔥 KEV P94
Hikvision Backdoor Authentication Bypass (CVE-2017-7921)
Hikvision IP kameralarında kimlik doğrulamasız tam admin erişimi sağlayan backdoor. URL'ye '?auth=YWRtaW46MTEK' eklenerek geçilir.
💰 İŞ ETKİSİ
IP kameralar genellikle yıllarca güncellenmeden çalışır, eski firmware'lerde bilinen kritik CVE'ler vardır. Bu CVE'ler kimlik doğrulamasız admin yetki kazanmaya izin verir; saldırgan canlı görüntüye, ses kaydına, hatta ağa pivot yapma imkanına ulaşır.
⏱ Tahmini Kesinti
4-24 saat
💸 Olası Kayıp
100.000 – 500.000 TL
📉 Veri Riski
🔴 Yüksek
✓ AKSİYON
Firmware'i 5.4.5 veya üzerine güncelleyin. Tüm Hikvision kameraları kontrol edin.
Kanıt: MAC vendor: Hangzhou Hikvision Digital Technology Co.,Ltd. | Potansiyel CVE: CVE-2017-7921
Seviye: Fingerprint | Güven: Medium
Critical
CVE-2021-36260 CVSS 9.8 EPSS 95% 🔥 KEV P95
Hikvision Command Injection RCE (CVE-2021-36260)
Hikvision web arayüzünde command injection ile kimlik doğrulamasız RCE — kameraya root shell.
💰 İŞ ETKİSİ
IP kameralar genellikle yıllarca güncellenmeden çalışır, eski firmware'lerde bilinen kritik CVE'ler vardır. Bu CVE'ler kimlik doğrulamasız admin yetki kazanmaya izin verir; saldırgan canlı görüntüye, ses kaydına, hatta ağa pivot yapma imkanına ulaşır.
⏱ Tahmini Kesinti
4-24 saat
💸 Olası Kayıp
100.000 – 500.000 TL
📉 Veri Riski
🔴 Yüksek
✓ AKSİYON
Firmware'i 2021 sonrası en güncel sürüme yükseltin.
Kanıt: MAC vendor: Hangzhou Hikvision Digital Technology Co.,Ltd. | Potansiyel CVE: CVE-2021-36260
Seviye: Fingerprint | Güven: Medium
High
P32
IP Camera Detected — Hangzhou Hikvision Digital Technology Co.,Ltd.
Based on the MAC vendor, this device is an IP camera (Hangzhou Hikvision Digital Technology Co.,Ltd.). Cameras often run outdated firmware and fall outside the IT security scope.
💰 İŞ ETKİSİ
IP cameras are frequently abused by attackers as a foothold due to default credentials, legacy RTSP/HTTP interfaces, and unpatched firmware. Through the camera, attackers can pivot to network traffic or perform lateral movement.
⏱ Tahmini Kesinti
2-8 saat
💸 Olası Kayıp
30.000 – 150.000 TL
📉 Veri Riski
🟠 Orta-Yüksek
✓ AKSİYON
Move cameras to an isolated VLAN (IoT/security segment). Block direct access to the corporate network.
Kanıt: MAC vendor: Hangzhou Hikvision Digital Technology Co.,Ltd. | IP: 192.169.1.111
Seviye: Fingerprint | Güven: High
High
P32
IP Camera HTTP Management Interface Reachable
The HTTP management interface of the Hangzhou Hikvision Digital Technology Co.,Ltd. branded camera is reachable over the network.
💰 İŞ ETKİSİ
An unencrypted HTTP interface creates risk of session hijacking, brute-force, and unauthorized access to the camera feed.
⏱ Tahmini Kesinti
2-8 saat
💸 Olası Kayıp
30.000 – 150.000 TL
📉 Veri Riski
🟠 Orta-Yüksek
✓ AKSİYON
Enable HTTPS; disable HTTP access. Permit management interface access only from the management VLAN.
Kanıt: Open ports: 80
Seviye: Observed | Güven: High
Medium
P20
Eksik HTTP Security Headers (4 adet) — port 80
Bu web servisinde 4 kritik güvenlik header'ı eksik: Content-Security-Policy, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
💰 İŞ ETKİSİ
Modern web saldırılarının (XSS, clickjacking, MIME confusion) çoğu HTTP security header'ları ile engellenir. Eksik header = exploit yüzeyi açık. Mozilla Observatory ve OWASP benchmark'larda 'F' notu alır.
✓ AKSİYON
Web sunucu/reverse proxy seviyesinde header'ları ekleyin: HSTS ('max-age=31536000; includeSubDomains'), X-Frame-Options 'DENY', CSP 'default-src self', X-Content-Type-Options 'nosniff', Referrer-Policy 'strict-origin-when-cross-origin', Permissions-Policy 'geolocation=()'.
Kanıt: GET http://192.169.1.111:80/ → eksik: Content-Security-Policy, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
Seviye: Observed | Güven: High
Medium
P20
No HTTPS
The web service is running only over HTTP. Communications may be unencrypted.
💰 İŞ ETKİSİ
Session data or management traffic may be intercepted.
✓ AKSİYON
Configure an SSL/TLS certificate and redirect traffic to HTTPS.
Kanıt: Port 80 open, Port 443 closed
Seviye: Observed | Güven: High
Low
P10
Web Service Exposure
Web arayuzu erisilebilir durumda.
💰 İŞ ETKİSİ
This surface raises risk when unnecessarily or broadly exposed.
✓ AKSİYON
Web arayuzlerini segment bazli erisim kontroluyle koruyun.
Kanıt: Acik portlar: 80
Seviye: Observed | Güven: Medium
192.169.1.112
Hostname: 192.169.1.112 | Segment: 192.169.1.0/24 | Tur: Unknown
Dusuk

IT Ozeti

100/100
Rol: Unknown
Sorun: Belirgin bir bulgu yok; konfigurasyon teyidi onerilir.
Etkisi: Is etkisini netlestirmek icin daha derin denetim gerekir.
Duzelt: Yama ve konfigurasyon durumu tekrar gozden gecirilmeli.

Rol ve Port Ozetleri

MAC / Vendor: CC:4D:75:8E:35:F9 / Beijing Xiaomi Mobile Software Co., Ltd

Kimlikli Denetim

Bu IP icin kimlikli denetim kaydi yok.

Bulgular

Bu IP icin tespit edilen bulgu yok.
192.169.1.114
Hostname: 192.169.1.114 | Segment: 192.169.1.0/24 | Tur: Switch
Yuksek

IT Ozeti

58/100
Rol: NetworkSwitch, AccessPoint, ManagementSurface
Sorun: FTP Open
Etkisi: Creates risk of data leakage and credential capture during file transfer.
Duzelt: Disable FTP; use SFTP or FTPS instead.

Rol ve Port Ozetleri

NetworkSwitch (Observed) AccessPoint (Observed) ManagementSurface (Observed)
MAC / Vendor: B8:EC:A3:F5:B8:CB / Zyxel Communications Corporation
21/FTP 22/SSH 80/HTTP 443/HTTPS
Urunler: Web Service 2.0, SSH Remote Access, Managed Switch, Wireless Access Point
Maruziyet: FTP Exposure, SSH Management Exposure, Web Service Exposure, Credential Attack Surface

Kimlikli Denetim

[Authenticated] Switch SSH login failed
Username or password is incorrect.
Kanit: SSH 22/tcp → 192.169.1.114

Bulgular

High
P37
FTP Open
The FTP service allows credentials to be transmitted unencrypted.
💰 İŞ ETKİSİ
Creates risk of data leakage and credential capture during file transfer.
⏱ Tahmini Kesinti
1-6 saat
💸 Olası Kayıp
20.000 – 100.000 TL
📉 Veri Riski
🟠 Veri sızıntısı
✓ AKSİYON
Disable FTP; use SFTP or FTPS instead.
Kanıt: Port 21 open (FTP)
Seviye: Observed | Güven: High
📋 Uygulama Rehberi: Remove FTP and Move to SFTP/FTPS
FTP is unencrypted. Username, password and file contents traverse the network in clear text.
1. Stop the FTP service in IIS [Windows IIS]
Stop-Service ftpsvc
Set-Service ftpsvc -StartupType Disabled
💡 Server Manager → Roles and Features → remove FTP Server.
2. Remove vsftpd or force SSL [Linux (vsftpd)]
sudo systemctl stop vsftpd
sudo systemctl disable vsftpd
# Veya SSL zorunlu kılmak için /etc/vsftpd.conf'a:
# ssl_enable=YES
# force_local_data_ssl=YES
# force_local_logins_ssl=YES
💡 If OpenSSH is already installed, SFTP can be used automatically.
3. SFTP ships with OpenSSH [Alternative: SFTP]
# SSH kurulu ise SFTP de kullanılabilir:
sftp user@host
💡 Tools like FileZilla and WinSCP support SFTP.
✓ Doğrulama:
nmap -p 21 <host>  →  closed/filtered
Medium
P25
Eksik HTTP Security Headers (4 adet) — port 443
Bu web servisinde 4 kritik güvenlik header'ı eksik: HSTS, Content-Security-Policy, Referrer-Policy, Permissions-Policy
💰 İŞ ETKİSİ
Modern web saldırılarının (XSS, clickjacking, MIME confusion) çoğu HTTP security header'ları ile engellenir. Eksik header = exploit yüzeyi açık. Mozilla Observatory ve OWASP benchmark'larda 'F' notu alır.
✓ AKSİYON
Web sunucu/reverse proxy seviyesinde header'ları ekleyin: HSTS ('max-age=31536000; includeSubDomains'), X-Frame-Options 'DENY', CSP 'default-src self', X-Content-Type-Options 'nosniff', Referrer-Policy 'strict-origin-when-cross-origin', Permissions-Policy 'geolocation=()'.
Kanıt: GET https://192.169.1.114:443/ → eksik: HSTS, Content-Security-Policy, Referrer-Policy, Permissions-Policy
Seviye: Observed | Güven: High
Medium
P25
SSH Management Exposure
SSH yonetim yuzeyi erisilebilir durumda.
💰 İŞ ETKİSİ
This surface raises risk when unnecessarily or broadly exposed.
✓ AKSİYON
SSH erisimini yalnizca yonetim aglarindan acin.
Kanıt: Port 22 acik
Seviye: Observed | Güven: Medium
Medium
P25
Credential Attack Surface
Kimlik dogrulama bekleyen servisler erisilebilir durumda. Bu yuzeyler cevrim ici parola denemesi veya hesap hedefleme icin cazip olabilir.
💰 İŞ ETKİSİ
Unnecessary exposure of authentication-requiring services increases account-targeting risk.
✓ AKSİYON
Yonetim erisimlerini ayri VLAN, MFA ve hesap kilitleme politikalariyla koruyun.
Kanıt: Kimlik dogrulama yuzeyleri: 21, 22, 443
Seviye: Observed | Güven: Medium
Low
P15
Web Service Exposure
Web arayuzu erisilebilir durumda.
💰 İŞ ETKİSİ
This surface raises risk when unnecessarily or broadly exposed.
✓ AKSİYON
Web arayuzlerini segment bazli erisim kontroluyle koruyun.
Kanıt: Acik portlar: 80, 443
Seviye: Observed | Güven: Medium
Low
P15
Managed Switch Detected
Managed Switch product detected. The management and access surface of this system should be reviewed.
💰 İŞ ETKİSİ
Exposure of this product can create operational and security risk.
✓ AKSİYON
Verify the service exposure and access controls.
Kanıt: Switch / ag altyapi cihazi izi tespit edildi
Seviye: Fingerprint | Güven: Medium
Low
P15
Wireless Access Point Detected
Wireless Access Point product detected. The management and access surface of this system should be reviewed.
💰 İŞ ETKİSİ
Exposure of this product can create operational and security risk.
✓ AKSİYON
Verify the service exposure and access controls.
Kanıt: Kablosuz erisim cihazi izi tespit edildi
Seviye: Fingerprint | Güven: Medium
192.169.1.115
Hostname: 192.169.1.115 | Segment: 192.169.1.0/24 | Tur: Unknown
Dusuk

IT Ozeti

100/100
Rol: Unknown
Sorun: Belirgin bir bulgu yok; konfigurasyon teyidi onerilir.
Etkisi: Is etkisini netlestirmek icin daha derin denetim gerekir.
Duzelt: Yama ve konfigurasyon durumu tekrar gozden gecirilmeli.

Rol ve Port Ozetleri

MAC / Vendor: 24:18:C6:16:B2:1C / HUNAN FN-LINK TECHNOLOGY LIMITED

Kimlikli Denetim

Bu IP icin kimlikli denetim kaydi yok.

Bulgular

Bu IP icin tespit edilen bulgu yok.
192.169.1.120
Hostname: 192.169.1.120 | Segment: 192.169.1.0/24 | Tur: Switch
Yuksek

IT Ozeti

64/100
Rol: NetworkSwitch, AccessPoint, ManagementSurface
Sorun: FTP Open
Etkisi: Creates risk of data leakage and credential capture during file transfer.
Duzelt: Disable FTP; use SFTP or FTPS instead.

Rol ve Port Ozetleri

NetworkSwitch (Observed) AccessPoint (Observed) ManagementSurface (Observed)
MAC / Vendor: D4:1A:D1:59:F0:5D / Zyxel Communications Corporation
21/FTP 22/SSH 80/HTTP 443/HTTPS
Urunler: Web Service 2.0, SSH Remote Access, Managed Switch, Wireless Access Point
Maruziyet: FTP Exposure, SSH Management Exposure, Web Service Exposure, Credential Attack Surface

Kimlikli Denetim

[Authenticated] Switch SSH login failed
Username or password is incorrect.
Kanit: SSH 22/tcp → 192.169.1.120

Bulgular

High
P37
FTP Open
The FTP service allows credentials to be transmitted unencrypted.
💰 İŞ ETKİSİ
Creates risk of data leakage and credential capture during file transfer.
⏱ Tahmini Kesinti
1-6 saat
💸 Olası Kayıp
20.000 – 100.000 TL
📉 Veri Riski
🟠 Veri sızıntısı
✓ AKSİYON
Disable FTP; use SFTP or FTPS instead.
Kanıt: Port 21 open (FTP)
Seviye: Observed | Güven: High
📋 Uygulama Rehberi: Remove FTP and Move to SFTP/FTPS
FTP is unencrypted. Username, password and file contents traverse the network in clear text.
1. Stop the FTP service in IIS [Windows IIS]
Stop-Service ftpsvc
Set-Service ftpsvc -StartupType Disabled
💡 Server Manager → Roles and Features → remove FTP Server.
2. Remove vsftpd or force SSL [Linux (vsftpd)]
sudo systemctl stop vsftpd
sudo systemctl disable vsftpd
# Veya SSL zorunlu kılmak için /etc/vsftpd.conf'a:
# ssl_enable=YES
# force_local_data_ssl=YES
# force_local_logins_ssl=YES
💡 If OpenSSH is already installed, SFTP can be used automatically.
3. SFTP ships with OpenSSH [Alternative: SFTP]
# SSH kurulu ise SFTP de kullanılabilir:
sftp user@host
💡 Tools like FileZilla and WinSCP support SFTP.
✓ Doğrulama:
nmap -p 21 <host>  →  closed/filtered
Medium
P25
SSH Management Exposure
SSH yonetim yuzeyi erisilebilir durumda.
💰 İŞ ETKİSİ
This surface raises risk when unnecessarily or broadly exposed.
✓ AKSİYON
SSH erisimini yalnizca yonetim aglarindan acin.
Kanıt: Port 22 acik
Seviye: Observed | Güven: Medium
Medium
P25
Credential Attack Surface
Kimlik dogrulama bekleyen servisler erisilebilir durumda. Bu yuzeyler cevrim ici parola denemesi veya hesap hedefleme icin cazip olabilir.
💰 İŞ ETKİSİ
Unnecessary exposure of authentication-requiring services increases account-targeting risk.
✓ AKSİYON
Yonetim erisimlerini ayri VLAN, MFA ve hesap kilitleme politikalariyla koruyun.
Kanıt: Kimlik dogrulama yuzeyleri: 21, 22, 443
Seviye: Observed | Güven: Medium
Low
P15
Web Service Exposure
Web arayuzu erisilebilir durumda.
💰 İŞ ETKİSİ
This surface raises risk when unnecessarily or broadly exposed.
✓ AKSİYON
Web arayuzlerini segment bazli erisim kontroluyle koruyun.
Kanıt: Acik portlar: 80, 443
Seviye: Observed | Güven: Medium
Low
P15
Managed Switch Detected
Managed Switch product detected. The management and access surface of this system should be reviewed.
💰 İŞ ETKİSİ
Exposure of this product can create operational and security risk.
✓ AKSİYON
Verify the service exposure and access controls.
Kanıt: Switch / ag altyapi cihazi izi tespit edildi
Seviye: Fingerprint | Güven: Medium
Low
P15
Wireless Access Point Detected
Wireless Access Point product detected. The management and access surface of this system should be reviewed.
💰 İŞ ETKİSİ
Exposure of this product can create operational and security risk.
✓ AKSİYON
Verify the service exposure and access controls.
Kanıt: Kablosuz erisim cihazi izi tespit edildi
Seviye: Fingerprint | Güven: Medium
192.169.1.123
Hostname: 192.169.1.123 | Segment: 192.169.1.0/24 | Tur: Switch
Orta

IT Ozeti

73/100
Rol: ManagementSurface
Sorun: Eksik HTTP Security Headers (4 adet) — port 80
Etkisi: Modern web saldırılarının (XSS, clickjacking, MIME confusion) çoğu HTTP security header'ları ile engellenir. Eksik header = exploit yüzeyi açık. Mozilla Observatory ve OWASP benchmark'larda 'F' notu alır.
Duzelt: Web sunucu/reverse proxy seviyesinde header'ları ekleyin: HSTS ('max-age=31536000; includeSubDomains'), X-Frame-Options 'DENY', CSP 'default-src self', X-Content-Type-Options 'nosniff', Referrer-Policy 'strict-origin-when-cross-origin', Permissions-Policy 'geolocation=()'.

Rol ve Port Ozetleri

ManagementSurface (Observed)
MAC / Vendor: 1C:98:EC:52:1A:5F / Hewlett Packard Enterprise
22/SSH 80/HTTP 443/HTTPS
Urunler: Web Service 2.0, SSH Remote Access, HP iLO Management 2.0
Maruziyet: SSH Management Exposure, Web Service Exposure, Credential Attack Surface

Kimlikli Denetim

[Authenticated] Switch SSH login failed
Username or password is incorrect.
Kanit: SSH 22/tcp → 192.169.1.123

Bulgular

Medium
P25
Eksik HTTP Security Headers (4 adet) — port 80
Bu web servisinde 4 kritik güvenlik header'ı eksik: Content-Security-Policy, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
💰 İŞ ETKİSİ
Modern web saldırılarının (XSS, clickjacking, MIME confusion) çoğu HTTP security header'ları ile engellenir. Eksik header = exploit yüzeyi açık. Mozilla Observatory ve OWASP benchmark'larda 'F' notu alır.
✓ AKSİYON
Web sunucu/reverse proxy seviyesinde header'ları ekleyin: HSTS ('max-age=31536000; includeSubDomains'), X-Frame-Options 'DENY', CSP 'default-src self', X-Content-Type-Options 'nosniff', Referrer-Policy 'strict-origin-when-cross-origin', Permissions-Policy 'geolocation=()'.
Kanıt: GET http://192.169.1.123:80/ → eksik: Content-Security-Policy, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
Seviye: Observed | Güven: High
Medium
P25
SSH Management Exposure
SSH yonetim yuzeyi erisilebilir durumda.
💰 İŞ ETKİSİ
This surface raises risk when unnecessarily or broadly exposed.
✓ AKSİYON
SSH erisimini yalnizca yonetim aglarindan acin.
Kanıt: Port 22 acik
Seviye: Observed | Güven: Medium
Medium
P25
Credential Attack Surface
Kimlik dogrulama bekleyen servisler erisilebilir durumda. Bu yuzeyler cevrim ici parola denemesi veya hesap hedefleme icin cazip olabilir.
💰 İŞ ETKİSİ
Unnecessary exposure of authentication-requiring services increases account-targeting risk.
✓ AKSİYON
Yonetim erisimlerini ayri VLAN, MFA ve hesap kilitleme politikalariyla koruyun.
Kanıt: Kimlik dogrulama yuzeyleri: 22, 443
Seviye: Observed | Güven: Medium
Low
P15
Sunucu Banner Sürüm İfşası (80/TCP)
HTTP yanıt header'ında sürüm bilgisi açık: 'Server: HP-iLO-Server/1.30'
💰 İŞ ETKİSİ
Saldırgan sürüm bilgisini kullanarak hedefe özel exploit aramaktan vakit kazanır. nginx 1.18.0 gibi tam sürüm bilgisi = CVE eşleştirmesi tek tık.
✓ AKSİYON
Web server config'inde sürüm gizleyin. nginx: 'server_tokens off;'. Apache: 'ServerTokens Prod, ServerSignature Off'. IIS: 'X-Powered-By' header'ı kaldır.
Kanıt: Server header: HP-iLO-Server/1.30
Seviye: Observed | Güven: High
Low
P15
Web Service Exposure
Web arayuzu erisilebilir durumda.
💰 İŞ ETKİSİ
This surface raises risk when unnecessarily or broadly exposed.
✓ AKSİYON
Web arayuzlerini segment bazli erisim kontroluyle koruyun.
Kanıt: Acik portlar: 80, 443
Seviye: Observed | Güven: Medium
192.169.1.128
Hostname: 192.169.1.128 | Segment: 192.169.1.0/24 | Tur: Switch
Yuksek

IT Ozeti

64/100
Rol: NetworkSwitch, AccessPoint, ManagementSurface
Sorun: FTP Open
Etkisi: Creates risk of data leakage and credential capture during file transfer.
Duzelt: Disable FTP; use SFTP or FTPS instead.

Rol ve Port Ozetleri

NetworkSwitch (Observed) AccessPoint (Observed) ManagementSurface (Observed)
MAC / Vendor: 5C:E2:8C:6C:4F:38 / Zyxel Communications Corporation
21/FTP 22/SSH 80/HTTP 443/HTTPS
Urunler: Web Service 2.0, SSH Remote Access, Managed Switch, Wireless Access Point
Maruziyet: FTP Exposure, SSH Management Exposure, Web Service Exposure, Credential Attack Surface

Kimlikli Denetim

[Authenticated] Switch SSH login failed
Username or password is incorrect.
Kanit: SSH 22/tcp → 192.169.1.128

Bulgular

High
P37
FTP Open
The FTP service allows credentials to be transmitted unencrypted.
💰 İŞ ETKİSİ
Creates risk of data leakage and credential capture during file transfer.
⏱ Tahmini Kesinti
1-6 saat
💸 Olası Kayıp
20.000 – 100.000 TL
📉 Veri Riski
🟠 Veri sızıntısı
✓ AKSİYON
Disable FTP; use SFTP or FTPS instead.
Kanıt: Port 21 open (FTP)
Seviye: Observed | Güven: High
📋 Uygulama Rehberi: Remove FTP and Move to SFTP/FTPS
FTP is unencrypted. Username, password and file contents traverse the network in clear text.
1. Stop the FTP service in IIS [Windows IIS]
Stop-Service ftpsvc
Set-Service ftpsvc -StartupType Disabled
💡 Server Manager → Roles and Features → remove FTP Server.
2. Remove vsftpd or force SSL [Linux (vsftpd)]
sudo systemctl stop vsftpd
sudo systemctl disable vsftpd
# Veya SSL zorunlu kılmak için /etc/vsftpd.conf'a:
# ssl_enable=YES
# force_local_data_ssl=YES
# force_local_logins_ssl=YES
💡 If OpenSSH is already installed, SFTP can be used automatically.
3. SFTP ships with OpenSSH [Alternative: SFTP]
# SSH kurulu ise SFTP de kullanılabilir:
sftp user@host
💡 Tools like FileZilla and WinSCP support SFTP.
✓ Doğrulama:
nmap -p 21 <host>  →  closed/filtered
Medium
P25
SSH Management Exposure
SSH yonetim yuzeyi erisilebilir durumda.
💰 İŞ ETKİSİ
This surface raises risk when unnecessarily or broadly exposed.
✓ AKSİYON
SSH erisimini yalnizca yonetim aglarindan acin.
Kanıt: Port 22 acik
Seviye: Observed | Güven: Medium
Medium
P25
Credential Attack Surface
Kimlik dogrulama bekleyen servisler erisilebilir durumda. Bu yuzeyler cevrim ici parola denemesi veya hesap hedefleme icin cazip olabilir.
💰 İŞ ETKİSİ
Unnecessary exposure of authentication-requiring services increases account-targeting risk.
✓ AKSİYON
Yonetim erisimlerini ayri VLAN, MFA ve hesap kilitleme politikalariyla koruyun.
Kanıt: Kimlik dogrulama yuzeyleri: 21, 22, 443
Seviye: Observed | Güven: Medium
Low
P15
Web Service Exposure
Web arayuzu erisilebilir durumda.
💰 İŞ ETKİSİ
This surface raises risk when unnecessarily or broadly exposed.
✓ AKSİYON
Web arayuzlerini segment bazli erisim kontroluyle koruyun.
Kanıt: Acik portlar: 80, 443
Seviye: Observed | Güven: Medium
Low
P15
Managed Switch Detected
Managed Switch product detected. The management and access surface of this system should be reviewed.
💰 İŞ ETKİSİ
Exposure of this product can create operational and security risk.
✓ AKSİYON
Verify the service exposure and access controls.
Kanıt: Switch / ag altyapi cihazi izi tespit edildi
Seviye: Fingerprint | Güven: Medium
Low
P15
Wireless Access Point Detected
Wireless Access Point product detected. The management and access surface of this system should be reviewed.
💰 İŞ ETKİSİ
Exposure of this product can create operational and security risk.
✓ AKSİYON
Verify the service exposure and access controls.
Kanıt: Kablosuz erisim cihazi izi tespit edildi
Seviye: Fingerprint | Güven: Medium
192.169.1.148
Hostname: 192.169.1.148 | Segment: 192.169.1.0/24 | Tur: Switch
Yuksek

IT Ozeti

64/100
Rol: NetworkSwitch, AccessPoint, ManagementSurface
Sorun: FTP Open
Etkisi: Creates risk of data leakage and credential capture during file transfer.
Duzelt: Disable FTP; use SFTP or FTPS instead.

Rol ve Port Ozetleri

NetworkSwitch (Observed) AccessPoint (Observed) ManagementSurface (Observed)
MAC / Vendor: 1C:74:0D:F9:BD:07 / Zyxel Communications Corporation
21/FTP 22/SSH 80/HTTP 443/HTTPS
Urunler: Web Service 2.0, SSH Remote Access, Managed Switch, Wireless Access Point
Maruziyet: FTP Exposure, SSH Management Exposure, Web Service Exposure, Credential Attack Surface

Kimlikli Denetim

[Authenticated] Switch SSH login failed
Username or password is incorrect.
Kanit: SSH 22/tcp → 192.169.1.148

Bulgular

High
P37
FTP Open
The FTP service allows credentials to be transmitted unencrypted.
💰 İŞ ETKİSİ
Creates risk of data leakage and credential capture during file transfer.
⏱ Tahmini Kesinti
1-6 saat
💸 Olası Kayıp
20.000 – 100.000 TL
📉 Veri Riski
🟠 Veri sızıntısı
✓ AKSİYON
Disable FTP; use SFTP or FTPS instead.
Kanıt: Port 21 open (FTP)
Seviye: Observed | Güven: High
📋 Uygulama Rehberi: Remove FTP and Move to SFTP/FTPS
FTP is unencrypted. Username, password and file contents traverse the network in clear text.
1. Stop the FTP service in IIS [Windows IIS]
Stop-Service ftpsvc
Set-Service ftpsvc -StartupType Disabled
💡 Server Manager → Roles and Features → remove FTP Server.
2. Remove vsftpd or force SSL [Linux (vsftpd)]
sudo systemctl stop vsftpd
sudo systemctl disable vsftpd
# Veya SSL zorunlu kılmak için /etc/vsftpd.conf'a:
# ssl_enable=YES
# force_local_data_ssl=YES
# force_local_logins_ssl=YES
💡 If OpenSSH is already installed, SFTP can be used automatically.
3. SFTP ships with OpenSSH [Alternative: SFTP]
# SSH kurulu ise SFTP de kullanılabilir:
sftp user@host
💡 Tools like FileZilla and WinSCP support SFTP.
✓ Doğrulama:
nmap -p 21 <host>  →  closed/filtered
Medium
P25
SSH Management Exposure
SSH yonetim yuzeyi erisilebilir durumda.
💰 İŞ ETKİSİ
This surface raises risk when unnecessarily or broadly exposed.
✓ AKSİYON
SSH erisimini yalnizca yonetim aglarindan acin.
Kanıt: Port 22 acik
Seviye: Observed | Güven: Medium
Medium
P25
Credential Attack Surface
Kimlik dogrulama bekleyen servisler erisilebilir durumda. Bu yuzeyler cevrim ici parola denemesi veya hesap hedefleme icin cazip olabilir.
💰 İŞ ETKİSİ
Unnecessary exposure of authentication-requiring services increases account-targeting risk.
✓ AKSİYON
Yonetim erisimlerini ayri VLAN, MFA ve hesap kilitleme politikalariyla koruyun.
Kanıt: Kimlik dogrulama yuzeyleri: 21, 22, 443
Seviye: Observed | Güven: Medium
Low
P15
Web Service Exposure
Web arayuzu erisilebilir durumda.
💰 İŞ ETKİSİ
This surface raises risk when unnecessarily or broadly exposed.
✓ AKSİYON
Web arayuzlerini segment bazli erisim kontroluyle koruyun.
Kanıt: Acik portlar: 80, 443
Seviye: Observed | Güven: Medium
Low
P15
Managed Switch Detected
Managed Switch product detected. The management and access surface of this system should be reviewed.
💰 İŞ ETKİSİ
Exposure of this product can create operational and security risk.
✓ AKSİYON
Verify the service exposure and access controls.
Kanıt: Switch / ag altyapi cihazi izi tespit edildi
Seviye: Fingerprint | Güven: Medium
Low
P15
Wireless Access Point Detected
Wireless Access Point product detected. The management and access surface of this system should be reviewed.
💰 İŞ ETKİSİ
Exposure of this product can create operational and security risk.
✓ AKSİYON
Verify the service exposure and access controls.
Kanıt: Kablosuz erisim cihazi izi tespit edildi
Seviye: Fingerprint | Güven: Medium
85.105.152.31
Hostname: 85.105.152.31.static.ttnet.com.tr | Segment: 85.105.152.31 | Tur: Unknown
Bilgi

IT Ozeti

95/100
Rol: Unknown
Sorun: ✓ WAN IP 85.105.152.31 — External Surface Clean
Etkisi: The FortiGate external-surface lockdown policy is working correctly. There is no direct management/VPN/service access via WAN. This is a healthy state.
Duzelt: Keep the current WAN lockdown policy in place. Run a risk review before opening any new service.

Rol ve Port Ozetleri

MAC / Vendor: - / -

Kimlikli Denetim

Bu IP icin kimlikli denetim kaydi yok.

Bulgular

Info
P6
✓ WAN IP 85.105.152.31 — External Surface Clean
External-surface port scan executed on WAN IP 85.105.152.31. 46 port(s) tested, none open.
💰 İŞ ETKİSİ
The FortiGate external-surface lockdown policy is working correctly. There is no direct management/VPN/service access via WAN. This is a healthy state.
✓ AKSİYON
Keep the current WAN lockdown policy in place. Run a risk review before opening any new service.
Kanıt: Port scan: 46 port(s) tested, 0 open ports
Seviye: Observed | Güven: High

🤝 Neden AFN Teknoloji?

Sadece tarama değil, sürekli güvenlik ortağınız. Bilişim Destek ve Danışmanlık Hizmetleri.

🎯

Gerçek Saldırı Bakışı

Hacker zihniyetiyle taramalarımız: hangi açıkları nereden, nasıl kullanır? Sadece checklist değil, gerçek saldırı yolları.
📊

Sadece Rapor Değil Çözüm

Bulduğumuz her açığa adım-adım uygulama rehberi. Komut, GPO yolu, doğrulama. Müşterimizi yalnız bırakmıyoruz.
🔄

Sürekli İzleme & Yeniden Tarama

Düzeltilen bulguları takip ederiz. Her ay/çeyrek tekrar tarama ile değişimi gösteririz; trend analizi yaparız.
🤖

AI Destekli Yorum

Yapay zeka her ortamı yöneticiye anlaşılır dilde özetler. Cihaz bazlı saldırı senaryoları ve öncelikli aksiyon listesi.
🛡

Hibrit Denetim

İç ağ + Dış yüzey + Microsoft 365 + FortiGate + VMware + Veeam — hepsi tek raporda. Parçalı taramalar yerine bütüncül bakış.

Hızlı Müdahale

Kritik bulgular 24 saat içinde ele alınır. Acil durum hattımız ile saldırı anında destek sağlanır.
💼 Hemen Aksiyon Alın
Bu rapordaki bulguları kapatmak ve ortamınızı sürekli güvende tutmak için
AFN Teknoloji Bilişim Destek ve Danışmanlık Hizmetleri ile çalışın.
📧 Teklif Talep Et 📞 Hemen Ara 🌐 Web Sitesi
www.afnteknoloji.com | info@afnteknoloji.com
AFN RiskScan raporu. HTML cikti tarayicida acilarak PDF olarak yazdirilabilir.