The Qlyne scanner
QlyneScanner/1.0 in your logs is the Qlyne scanner. It checks a site from the outside, seeing only what any visitor sees, and writes a report for the owner of the site.
Who starts it
Section titled “Who starts it”Only the owner of a Qlyne account, for a domain they proved is theirs with a TXT record at _qlyne.<domain>. The scanner never picks a domain on its own and doesn’t follow links to other domains.
What it asks for
Section titled “What it asks for”A scan makes at most 30 requests to the site, and the next one can start only 10 minutes later:
- the home page, over HTTPS and over plain HTTP, to check the redirect to HTTPS;
- one TLS connection to read the certificate, and one attempt each with TLS 1.0 and TLS 1.1, which a well-configured server refuses;
/.env,/.env.local,/.env.productionand/.git/HEAD;- up to 5 scripts of the home page, from the same domain, and the source map of each.
It also reads public DNS records, through a public resolver, and the public certificate logs (crt.sh). Every request is a GET, without cookies.
What it never does
Section titled “What it never does”It doesn’t log in, submit forms, try passwords, send attack payloads or query databases. It doesn’t keep what it reads: the report shows the names of the variables in a public .env, never their values, and secret keys appear masked.
On sites protected by Qlyne
Section titled “On sites protected by Qlyne”The requests carry the Qlyne-Scanner header, signed with the connector secret of the site, so the scanner trap of the site doesn’t block the scan. Every other rule applies to it as to any visitor.
Stopping it
Section titled “Stopping it”If the scanner runs on a domain you own and you didn’t ask for it, write to [contact e-mail] with the domain. If you are the account owner, removing the TXT record stops new scans.