Some idiot is using your tool to mass scan our network
github.com
github.com
If you don't want people on the internet to connect to your server, then you shouldn't allow network connections to your server. A few connections per minute hardly classify as abuse in any reasonable sense of the word.
The owner of the source network, on the other hand, (compared to the destination server), I think have a more legitimate reason to raise flags. Most cloud providers for example do not allow port scanning from their network (for various reasons). If you're gonna send out millions of packages all over the place I think it's good practice to inform your network provider first.
So amazon should notify AWS? :)
This reminds me of my favorite typo: https://slashdot.org/comments.pl?sid=406154&cid=21914102
BTW: Massscan is excellent at braking routers, over-flood them and they will often crash.
That's for one individual who's scanning something. On the receiving end, you're not dealing with one individual, you're dealing with many individuals who are probing for vulnerabilities.
If one guy intentionally steps on your foot, that's mildly annoying. If a thousand people intentionally step on your foot, that's a very different issue.
> Most cloud providers for example do not allow port scanning from their network (for various reasons).
They don't? They are often the source I see. Is that a policy thing where they say "yeah well please don't" or will they actively shut you down if you're doing it from their infrastructure?
The tools is precisely advertised to be able to send 10M packets per second, to scan all internet or all ports quickly.
As a security professional, I wouldn't be surprised if someone runs this at home with gigabit fiber and DDoS the machines/networks they are testing.
Also, minor nit, if it's just one machine doing the scanning, that's a DoS, not a DDoS :)
What is the difference between this tool and the drive by DDoS "testing" tools you can pay to use online. They seem identical to this tool except Masscan stops after the first try.
Where would the line between abuse and curiosity be? If you were the target of an overzealous company how can you make the distinction?
It would be expensive to just use raw network power to overwhelm a web service(u would need more bandwidth than the host)
Meanwhile with amplification u only need a 10th or less
Here an example https://www.imperva.com/learn/ddos/dns-amplification/
https://github.com/robertdavidgraham/masscan/blob/master/dat...
I'll amend my earlier comment a bit. Apple as a corporation doesn't care, neither I imagine would Apple's corporate IT security as an entity, but individual people in Apple might decide port scanning is the bain of their existence and send something, but that's a fluke.
For one very quick stat "The average size of DDoS attacks was at the mindblowing 26.37 GBps in Q2 2018"
Yes i do that and i test my own routers with it.
https://github.com/robertdavidgraham/masscan#how-to-scan-the...
>While useful for smaller, internal networks, the program is really designed with the entire Internet in mind. It might look something like this: [...]
>Scanning the entire Internet is bad. For one thing, parts of the Internet react badly to being scanned. For another thing, some sites track scans and add you to a ban list, which will get you firewalled from useful parts of the Internet. Therefore, you want to exclude a lot of ranges. To blacklist or exclude ranges, you want to use the following syntax: [...]
That 2nd bit is where that "exclude.txt" file comes in, it's not even used by default as far as I can tell.
So basically the author acknowledge that the software's intended purpose is bad, they also decided that it was their responsibility to maintain an exclude list. That's a bit odd IMO. I'd think that in these situations you can either say "I'm not responsible for people misusing my software" and in this case maintaining an exclude file with random addresses as people complain to you doesn't make sense, or you think that you share some of the responsibility if your software is used to do bad things and then it seems like it would make more sense to take the project down or take steps to make it harder for users to do these things.
By also supplying an exclude file (and showing how to use it), the author goes a long way to help I'd you ask me.
The rest is up to to whomever decides to use/abuse it, as always.
The tech world is in for a rude awakening as technology becomes less a field of nothing but specialists, and actually gets infiltrated by a greater and greater number of tech-savvy, yet industry independent stakeholders.
We've had a social blank check to work from for the better part of half a century. You now have people writing children's intros to k8's. If you don't think that at some points technical problems don't start getting solved via social/legislative/legal means, you're in for a bit of a rough time.
The people who look to project github for help are ones that already selected themselves. I bet for every one that posted on github there are dozens or more that went to the actual entity that tried to scan them or, better yet, blocked the scan or otherwise ensured it is harmless.
> yes, configuration files are specified on the command-line and not hard-coded, so only those performing legitimate surveys of the Internet (possibly wanting to be responsible or respectful of those NOCs who still live in the world of generating abuse complaints when snort tells them to) would be likely to use them. Maybe there are a few script kids out there who are intelligent enough to avoid hitting the small collection of networks on this list to avoid their scans generating abuse complaints that may get their boxes killed, but I guess it's probably a near-zero population
If somehow it were hard-coded into the tool, well, the source is available, as is the ability to port scan any one of a number of other ways.
Anecdote: when I was a grad student at AS88, I once got an email asking me to stop port scanning. I was confused because I wasn't port scanning anyone. I asked for details and an admin sent me a report generated by some seemingly off-the-shelf network admin software (forgot the brand), with a bar chart of all IP addresses I was frequenting -- rather creepy, honestly. Turns out I was renting ~20 servers around the world as PoPs for a personal project at that time, and regularly deploying code to all of them at once over SSH (all configured at port 22). Apparently regularly accessing ~20 servers at once over a single port was enough to be flagged as "port scanning". I wonder if people doing actual security research over at the CS department were exempt from nonsense like this.
People finding the curl copyright notice in an application and blaming Daniel Stenberg for hacking them:
https://daniel.haxx.se/blog/2016/01/19/subject-urgent-warnin...
Or the reason sqlite no longer uses "sqlite" as a file extension for temporary files:
https://github.com/endlesssoftware/sqlite3/blob/master/os.h#...
Can't argue with that
A city in Oklahoma threatened to call the FBI over an Apache error message... and sent the threat to CentOS.
But I suspect if someone is the kind of person to email a tool author because of what an unrelated tool user is doing, they're probably going to be quite chuffed there's a tangible outcome they can point at and say "see, I fixed the issue"
#contractor and report to Federal law enforcement authorities when scans
#and probes are directed at our network. I assume you don't want to be
#part of that report. Please permanently remove our network range from
#your current and future research.
#NOTICE: This e-mail and any attachments is intended only for use by the add= #ressee(s) named herein and may contain legally privileged, proprietary or c= #onfidential information. If you are not the intended recipient of this e-ma= #il, you are hereby notified that any dissemination, distribution or copying= # of this email, and any attachments thereto, is strictly prohibited. If you= # receive this email in error please immediately notify me via reply email o= #r at (800) 927-9800 and permanently delete the original copy and any copy o= #f any e-mail, and any printout.
Maybe we should call them, to say we "averted our eyes, m'lord"?
#Received: from elbmasnwh002.us-ct-eb01.gdeb.com ([153.11.13.41]
# helo=ebsmtp.gdeb.com) by mx1.gd-ms.com with esmtp (Exim 4.76) (envelope-from
# <bmandes@gdeb.com>) id 1VS55c-0004qL-0F for support@erratasec.com; Fri, 04
# Oct 2013 09:06:40 -0400
#To: <support@erratasec.com>
#CC: <ebsoc@gdeb.com>
#Subject: Scanning and Probing our network
#From: Robert Mandes <bmandes@gdeb.com>
#Date: Fri, 4 Oct 2013 09:06:36 -0400
#
#Stop scanning and probing our network, 153.11.0.0/16. We are a defense
#contractor and report to Federal law enforcement authorities when scans
#and probes are directed at our network. I assume you don't want to be
#part of that report. Please permanently remove our network range from
#your current and future research.
#
#Thank you
#
#Robert Mandes
#Information Security Officer
#General Dynamics
#Electric Boat
#
#C 860-625-0605
#P 860-433-1553
https://github.com/robertdavidgraham/masscan/blob/master/dat... "2020-08-31T05:55:15.314510181Z"
"2020-09-07T04:31:10.32778784Z"
"2020-09-12T07:37:23.354113494Z"
"2020-09-14T04:48:22.862297069Z"
"2020-09-14T10:31:45.331617062Z"
"2020-09-21T01:03:47.198615685Z"
"2020-09-21T04:04:12.142308436Z"
"2020-09-28T04:40:15.616859176Z"
"2020-09-30T14:21:35.844867635Z"
"2020-10-02T23:05:58.837039985Z"
"2020-10-03T03:18:33.945424629Z"
"2020-10-03T14:02:51.344484887Z"
"2020-10-03T16:47:59.941939178Z"
"2020-10-03T16:54:16.67585357Z"
"2020-10-04T03:40:37.740594379Z"
"2020-10-04T09:12:23.443293148Z"
"2020-10-04T23:07:21.37800867Z"
"2020-10-05T06:06:11.452526929Z"Can you move issue reports to integration test results?
There are basically two types of people who do that. The security guards and... cat burglars.
Scanning for open ports sounds like a legitimate use, but being a Network admin and not capable to block a robot called "masscan/1.0" is NOT legitimate.
Yeah rlly hard ;)
It's more like looking through other people's windows as you walk by the street. May be creepy if you always stare at the same window, but formally there's nothing wrong with that. If you do not want people to see through your public-facing windows in your home, it's your responsibility to install blinds or shades.
Dude, what kind of town do you live in? It sounds scary!
Here in Europe many towns have narrow streets with houses directly by the street (with no front yard). It is essentially impossible to not look through the windows of people unless you make a robotic effort to avoid it.
I do that..even in a big city. It's cool when you do it to yourself, but makes much more fun with a another person, you should try it out someday.
You can ask Ebay about that.
If you don't see a difference then I hope we don't share neighborhood.
> It’s behavior only two types of people would have: criminals and security professionals.
consider also curious people seeking knowledge; the Internet is a massive space and an interesting phenomenon in itself, scanning is one of many ways to learn about it.
Your House is not a Server, compare it to a Butler, i yell into your house and if a Butler answers i ask him whats on the table.
If you don't want people to look at you, don't go out in public.
In addition massscan is really interesting from a software engineering persepective. They do kernel bypass to talk to network drivers directly, have a custom TCP stack, custom mutexes, etc. All of that to be able to reach ~1.5M packets per second (from the README), allowing someone to scan the whole IPv4 range in 6 minutes. Really impressive work.
Also what is the hypothesis that is being researched or investigated by knowing how many systems on the internet respond to TCP SYNs on port 23?
Alternately, you could ask me "If a computer is broadcasting packets to my computer which is connected to a network port that I'm allowed to connect to, is it ok for me to note that?" In which case I'd say yes.
I also think that moves the analogy too far in the other direction. While it may not be the case that servers are actively "broadcasting" their port open status to all internet users, that's only because it would not be feasible to do so. It is not because port open status is supposed to be private or secret information, like the inside of my bedroom for example.
In fact TCP/IP is designed with the intention that anyone can check the port open status without authentication. It is part of the intended usage of the protocol, so presumably it is safe to assume that anyone using it is probably using it with that intention.
If it's valid to shine a laser pulse from space/the sky onto the entire surface of the Earth (private property included) to determine the elevation of everything, it's valid to send TCP SYNs out to the entire surface of the internet.
If they didn't want to accept any connections, they should've closed the port.
If they only wanted authorised users to connect, they should put an authorisation requirement on the connection.
As for your statement that there's no valid research purpose, that's your assertion, a lot of people will disagree.
Is it valid to research untreated syphilis in black men? Yes. Is it valid to research untreated syphilis in black men without their permission and informed consent? No.
The Tuskegee Syphilis Study was inappropriate because they purposely withheld information about the diagnosis and lied about the efficacy of the treatments they were giving.
The problem wasn't that they conducted the research without telling the patients. Obviously the patients were aware that they were part of a research effort, since they directly interacted with the clinicians conducting it.
How do you know? Lots of people misconfigure their systems and leave them open to access unintentionally.
Huge numbers of people have done this, I've certainly done it in the past when I knew less. Discovering that the webserver logfiles were rather larger than I expected, or that HTTP Traffic was through the roof... oh, right, I left something open, better close that and remember it for next time.
However I don't think it's a reasonable assumption that the open status of TCP ports is supposed to be private information.
We're not discussing the morals of human research, we're discussing IT security, and specifically in scenarios that are unlikely in the extreme to lead to any physical harm to people.
We're also not talking about trying to sabotage or attack a system.
Standard, well-formed web requests on standard HTTP sockets, made infrequently are very unlikely to cause problems on any system that's not outright deliberately misconfigured.
You could also scan your own internal 10 net in a finite amount of time.
1/255th of the internet is for all practical purposes, the internet.
I encountered a bunch, always trying the same, lame URLs for a PHP framework bug or a Wordpress config error, sometimes a hundred variations in a few seconds. What's the point? Same goes for all these ssh connections, but they seem to be real hacking attemps.
Everyone knows flashlights are used by bank robbers. But if you can think of a legitimate use of a flashlight, then you can think of a legitimate use for this tool.
I am wondering the same thing myself; it's not obvious to those of us not looking for vulnerabilities in other people's systems what the use of it is at internet scale.
Flashlights are used by normal people for strictly local, very closely defined location illumination. We don't turn them on and light up the whole world.
https://github.com/endlesssoftware/sqlite3/blob/master/os.h#...
That guy makes:
>E-commerce, IoT and mobile engineering services, with a software boutique approach
Man i really don't want a IoT device from them...also not a shop if they don't know how to block Robots.
"This is an Internet-scale port scanner. It can scan the entire Internet in under 6 minutes, transmitting 10 million packets per second, from a single machine."
Then it seems that it has a link to its github page by default in the User-Agent string it uses while scanning.
When you do that you can only get abuse in return, can't you?
At the destination this should be a small fraction of the usual "Internet background noise" which is usually a negligible fraction of the available bandwidth.
You can separate transmit and receive IPs, if your tx network does not implement source filtering.
So you can tx from one place and receive from one or more other places "sensors" that you use to receive SYN-ACKs.
You can use several (an arbitrary number) of spoofed source IPs on tx to hide your "real" rx IPs, at the cost of more egress traffic.
There is a technique involving ipids (idle scanning) you can use which does not reveal your IP at all but it is not reliable; read: not usable beyond very tiny scale. You could put a lot of effort into it but it's not worth it. Nobody beyond a few vociferous cranks _really_ cares about IP scanning.
The real way to stay off radars (eg dshield) while mass scanning is have a ton of unrelated IPs and scan as slow as you can stand. This assumes good randomization (not obviously striping across networks from the same IP).
Given that there are several sites who scan the Internet regularly for more than just open ports (e.g. Shodan, Binary Edge, Censys) it's not a volume of traffic that should cause a concern.
One wonders if your ISP would detect you running this thing, and kill your connection. I'm pretty sure a lot of ISP T&C forbid mass scanning tools?
My home ISP just resets the router and let it reboot.
Source: Me
If you run any services (ssh, vpn, whatever) from your home connection you're probably making yourself into a target for counter scans
10 000 persons doing this simultaneously is also an insane number, and that's 2 kilobytes per second.
It sounds fine.
"This tool is coded in C, which was unfortunately created without any regard for its misuse. OP should open the bug upstream."
Somebody stated what we all already know: That there are a lot of stupid people using available tools for stupid purposes.
But the person that stated this doesn't seem to be any less stupid than any other stupid involved.
You can ask but posting the actual IP address here would be like wearing a cell phone in a belt clip at BlackHat/DefCon.
If you hadn't made it, someone else would've written it in Python so it would get stuck on CPU all the time, heh.
And I will say that identifying the tool in a way that it would show up in logs was responsible.
Last I read about it, you can scan the entire IPv4 space for a port in about 40 minutes providing you have the bandwidth and a forgiving ISP. I see another comment claiming a tool can do it in 6 minutes. Easy at "apt get install" and a single command.
https://github.com/robertdavidgraham/masscan
Note that "scan the internet in 6 minutes" only means this tool is capable of generating packets fast enough on the host machine to theoretically do a 6 minute scan. In practice, the NIC, home network, and local ISP connection will bottleneck and the scan will be orders of magnitude slower.
Even then, you exist as an entity on the internet to have things connect to you. If there are ways in which you don't want to be connected to, you have a firewall to enforce that.