Security groups open to 0.0.0.0/0 on admin or database ports
What does ZopNight detect here?
ZopNight flags an EC2 security group with an inbound rule from `0.0.0.0/0` or `::/0` to a sensitive port (22, 3389, 3306, 5432, 1433, 27017, 6379 or 9200) or to every port. Port ranges are checked for any sensitive port inside them, so a wide range cannot hide SSH. Public 443 alone is not flagged. The finding carries a $0 saving.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-084 |
| Category | compliance |
| Severity | critical |
| Metric | none — pure configuration read |
| Threshold | 0.0.0.0/0 to a sensitive port |
| Source | ZopNight |
| Permissions used | ec2:DescribeSecurityGroups · ec2:DescribeSecurityGroupRules |
Where it applies
Why these ports should never face the whole internet
A security group rule with source 0.0.0.0/0 accepts traffic from every IPv4 address. That is the
intended setting for a load balancer on 80 or 443, as the
security group rules guide
shows. It is a serious exposure for anything else. Automated scanners sweep the public IPv4 space
continuously, and the ports below expose admin and data services.
| Port | Usual service |
|---|---|
| 22 | SSH |
| 3389 | Remote Desktop |
| 3306 | MySQL and MariaDB |
| 5432 | PostgreSQL |
| 1433 | SQL Server |
| 27017 | MongoDB |
| 6379 | Redis |
| 9200 | Elasticsearch and OpenSearch |
Listing world-open rules
Find groups with any rule from 0.0.0.0/0, then list the individual inbound rules of one group:
aws ec2 describe-security-groups \ --filters Name=ip-permission.cidr,Values=0.0.0.0/0 \ --query 'SecurityGroups[].[GroupId,GroupName]' --output table
aws ec2 describe-security-group-rules \ --filters Name=group-id,Values=sg-0123456789abcdef0 \ --query 'SecurityGroupRules[?!IsEgress && CidrIpv4==`0.0.0.0/0`].[SecurityGroupRuleId,IpProtocol,FromPort,ToPort]'An IpProtocol of -1 means all protocols and ports.
Rules that trigger a finding
ZopNight reads every inbound rule of each security group and records which ports are open to
0.0.0.0/0 or ::/0. A finding is raised when either is true:
- A public rule covers all ports, written as 0 to 65535 or as protocol
-1. - A public rule reaches one of the eight sensitive ports, including a sensitive port that sits inside a wider range such as 1 to 10000.
What does not trigger it
Public rules that only open other ports, such as 443 for HTTPS, are not flagged. Rules whose source is a specific CIDR or another security group are not flagged either. If ZopNight could not read the group’s rules, it records no ports and raises nothing. For databases, the related RDS Instance Publicly Accessible check looks at the instance side.
The cost of leaving it open
The finding saves nothing. Its severity is critical because an open admin or database port turns a weak password or an unpatched service into a direct compromise.
Closing the rule safely
- Work out who needs the port. Replace
0.0.0.0/0with your office or VPN CIDR, or with the security group of the calling tier. - For SSH and RDP, use Session Manager, which works without open inbound ports, bastion hosts or SSH keys.
- Remove the public rule:
aws ec2 revoke-security-group-ingress --group-id sg-0123456789abcdef0 \ --security-group-rule-ids sgr-0123456789abcdef0- Remove any matching rule with an IPv6 source of
::/0too; ZopNight treats it the same way. - Move databases and caches into private subnets so a future rule change cannot expose them.