Masscan: TCP port scanner, scanning entire Internet in under 5 minutes
github.com
github.com
I once (2016) used it to scan port 22 on the whole ipv4 (had to experiment with rate limits to not trigger alarms and get complaints forwarded by my VPS provider; the clever ip+port randomization technique helps a lot with that). Then took the ~22m (iirc) IPs which responded and ran ssh-keyscan on them to extract and analyze some ~15m ssh banners and public keys (a bunch of them broken, through debianized PRNG etc.) I think most of the scanning + extraction was done overnight, via ~13 VPS rented hourly (whole thing cost < $10, and very few complaints). Fun times :) I should write it up some time, and do it again.
22 meter?
22 millies of something.
I do not follow?
So, we should refrain from using lowercase m for this.
Except that mm is already used by a number of industries and people to mean million.
What you did was quote from the first result of a google search without attribution and then pretend the quote means the opposite of what was written. See: https://corporatefinanceinstitute.com/resources/knowledge/ot...
Your quote left out the first part, which is italicized in the full quote below:
In finance and accounting, MM (or lowercase “mm”) denotes that the units of figures presented are in millions. The Latin numeral M denotes thousands. Thus, MM is the same as writing “M multiplied by M,” which is equal to “1,000 times 1,000”, which equals 1,000,000 (one million).
“People don’t understand”, none of those were at all plausible even without the context of scanning the entire IPv4 address space.
Here is everyone running masscan against the internet: https://www.greynoise.io/viz/query/?gnql=tags%3A%22Masscan%2...
You can look up IPs in GreyNoise to know if they are scanning the internet (if no results are returned, the answer is likely no or not at scale.)
Happy to answer any q's :)
I went back to the page linked by the GP post. I clicked through all 10 items and the actor was "Unknown" on all of them.
I don't really expect you guys to be able to know who is renting AWS servers or something. I don't know how that would be possible, honestly.
It's a cool site, though.
We have also managed to take down the entire corporate network by using it with a too high rate limit. So tread lightly around massscan and its power. Our pentesters did the same 6 months later. The managed service provider is not able to solve the routing table loop which causes the firewall to DOS when a rapid masscan is triggered.
I've got banned pretty hard by both my local home ISP and using Linode servers, when tried such scanners. Mass port scanning is easy to track, and it usually forbidden all ISP ToC.
https://medium.com/@captn3m0/i-scanned-all-of-act-bangalore-...
He often discusses current events in infosec if you're into that.
Some idiot is using your tool to mass scan our network - https://news.ycombinator.com/item?id=24728123 - Oct 2020 (182 comments)
MASSCAN: Mass IP port scanner - https://news.ycombinator.com/item?id=12260809 - Aug 2016 (33 comments)
Masscan: Scan the entire Internet in under 5 minutes - https://news.ycombinator.com/item?id=8803498 - Dec 2014 (29 comments)
Masscan: scan the entire Internet in under 6 minutes, 10 million packets/second - https://news.ycombinator.com/item?id=6391266 - Sept 2013 (30 comments)
Masscan: The entire internet in 3 minutes - https://news.ycombinator.com/item?id=6388222 - Sept 2013 (12 comments)
It's a good one.
I sometimes wonder if it inspired some of the TCP-in-userspace stuff that is done in go (gvisor lib, I think it was).
I'm glad Rob is continuing the development of this idea and continues to scan the whole internet. Scanning the whole internet is cool. It's a shame it's de facto illegal these days (and will get most internet connections in the USA terminated near-instantly).
[1] https://defcon.org/images/defcon-13/dc13-presentations/DC_13...
I know this came a few years later, but it really advanced the state of the art for widescale scanning at that time, particularly once it made its way into Kali.
I've not seen anything that says simply scanning for open ports is illegal, doing vulnerability scans may be though.
Ehhh... I forgot he was the "the late Dan Kaminsky"
:-(
2021 has not been a great year. Too many, too young.
We seem to be a wee bit short of 2^126, yes.
Plus the copy about not hammering other networks won't matter when you're trying to scan entire /64s that are behind one home router or something. That's gonna get noticed. You can't really scan IPv6 like you can scan IPv4, the math I gave is part of why. The code to do it is trivial, but the hardware just isn't there.
For example, someone with access to a backbone internet router could easily log src and destination ipv6 addresses, and sell the complete list sorted and compressed. Malware authors could then use the list to portscan for badly firewalled stuff.
There’s more than enough stuff on IPv4, IPv6 isn’t worth the effort.
FWIW shodan was setting up their own public ntp servers to track down v6 users.
First time to be called shady, though ;)
It is an accident of history that computing spent so much time at binary orders of magnitude that technology could catch up and make the previous limits seem small. At some point, the exponential curve takes off and no amount of physical resources can catch up to it, because our universe taps out at O(n^3). 2^128 is pretty much on the other side of that takeoff point. You can almost catch up to it... at the cost of the resources of an entire galaxy... or more.
(Technically it's even sooner than O(n^3) if you also have to avoid black holes, but since the relevant comparison here is "exponential" the details hardly matter here.)
Still, network address obfuscation really shouldn’t be a security control.
Oh my, that is clever =)
The vast majority of projects seem to take someone months of work, get 50 github stars, and $25 worth of donations... Which is really sad - it basically means the vast majority of opensource authors have to have another job to pay the bills.
All I could find was statements from them that they do not allow port scanning OF their infrastructure.
You can port scan your own infra/vpcs etc -- but YOU MUST tell them you are doing so and why you are doing it, else they will block it.
again, as with anything AWS (and other providers) have a good rapport with your rep, and SEs in AWS and you have a lot more freedom than you expect just from boilerplate ULA TOS stuff.
You may not scan anything other than your own infra. And you can get your external monitors whitelisted as well...
Just talk to your rep.
>"A mutex on the fast path of a program severely limits scalability. Instead, Masscan uses "rings" to synchronize things, such as when the user-mode TCP stack in the receive thread needs to transmit a packet without interfering with the transmit thread."
Is "rings" here referring to PF_RING mentioned in the preceding paragraph or is it referring to a specific synchronization primitive?
But I have told myself to stop spending time optimizing things for no reason..
So 655360 hours, not 5 minutes
For a regular, publicly accessible server, you do want people to be able to connect to it, so it must be scannable.
I don’t know offhand, but with HTTP/3’s udp based protocol, it ought to be possible to at least make scanning a bit trickier. By requiring a valid QUIC client hello packet, with a valid SNI header for that server, the scanner must know the name of the server it’s trying to talk to. I don’t have any experience with HTTP/3 yet so I am probably wrong.