hostcloak.com · defensive only · guides
SSH on a public IP is common. SSH that is louder than you meant — password auth still on, open to the whole world when you only need a few IPs, sitting next to other admin surfaces — is what puts a box on easy radar.
You do not need a red-team report to ask a simple question: from the outside, does this host look like an open SSH target plus whatever else is listening?
Authorized hosts only. Not a pentest. Not a compliance certificate. No root password.
On Contabo (and many other VPS hosts), SSH often lands on the public address by default. That is normal for remote admin — the question is breadth and what else is loud beside it. Scan a Contabo host you own the same way: outside-in presence, not a password guess.
Hetzner Cloud boxes likewise often expose SSH on a floating or primary public IP. Firewall rules in the Hetzner console help, but drift happens. An outside-in HostCloak pass on a Hetzner VPS you own verifies what strangers still see — SSH-class presence plus the wider surface — with a severity-ranked fix order.
HostCloak Surface Guard scans a DNS host or public IP you own. SSH-related presence shows up in the wider public-surface report alongside ports, TLS, headers, and obvious admin exposure — with a severity-ranked fix order.
No root password. No exploit kits. Free: $0 · 1 host · 1 successful scan/day.
Typical defensive follow-ups (yours to apply): prefer key login, disable password auth once keys work, restrict source IPs when you can, keep admin UIs off the public address.
Not always — many operators need remote shell. The issue is breadth (who can reach it, how auth works) and what else is loud on the same IP.
Never. We never ask for keys or root passwords.
If you want history, alerts, PDF, deeper Surface Guard, and Live Deck gauges: Pro is $19/mo. Agency is $49/mo. Free still gives a daily outside-in pass.
Next step: name a DNS name or public IP you own at /scan. Quiet what's loud on a host you own.
Defensive posture only — presence, hygiene, and fix order. Not a pentest. Not a compliance certificate. HostCloak never asks for a root password. Scan only hosts you own or have written authorization to assess.