Skip to content

Security scanner

Defensive, non-intrusive checks for exposure and risky configuration.

What it does — and never does

The scanner resolves DNS, opens a plain TCP connection to the ports you declared (public, backend and RCON) and sends one standard Minecraft status request. That is all.

Tickhound never performs DDoS, flooding, stress tests, brute force, exploitation or port-range scans. Run it only against systems you own or are authorised to test.

Backend exposure

Backend servers trust the proxy to authenticate players. If a backend port is reachable from the internet, anyone can bypass the proxy. Firewall backend ports so only the proxy's address can connect.

RCON

RCON gives full console access and is a common brute-force target. Disable it when unused; otherwise firewall the port and use a long random password.

Online mode

online-mode=false without a proxy lets anyone join under any name, including operators. Only run it on backends that are fully hidden behind a correctly configured proxy.

Proxy forwarding

  • Velocity: use modern forwarding with a forwarding secret.
  • BungeeCord/Waterfall: enable ip_forward, add BungeeGuard and firewall the backends.

Query protocol

enable-query=true exposes plugin and player information over UDP. Disable it unless a monitoring tool needs it.

Whitelist

Private or staging servers should not be open to everyone. Enable the whitelist for them.

Firewall posture

Tickhound cannot read your firewall; it infers posture from what an outside connection can reach. Use default-deny: allow only the public Minecraft port and SSH from trusted IPs.

Results

  • Secure — no warnings or worse.
  • Warning — at least one warning or error.
  • Critical — at least one critical exposure.