ZMap: Internet scanner maps all of IPv4 in 45 minutes
zmap.io
zmap.io
You want to generate a permutation of the entire IPv4 address space, but you don't simply want to shuffle every possible IP address because that would require you to keep an insane amount of state. So instead, work in the multiplicative group modulo p for prime p > 2^32, find an appropriate generator, and iterate by multiplying with the generator mod p. Remember the prime, the generator, the starting address, and your current address and you can detect a complete traversal of the space when the starting address recurs.
There are a number of simpler ways to do this (after sheepishly conceding that this is pretty fundamental stuff, I played with using PRFs and card shuffling to do it; DrHoney suggested Gray codes), but I liked how immediately obvious the multiplicative group solution was, and that I could code it from a simple description.
http://www.cs.ucdavis.edu/~rogaway/papers/subset.pdf
(Marsh Ray tweeted this yesterday; it's an easy read)
I have to admit that I'm slightly chagrined by the disparity of approach between a lame-ass pentester and an associate professor and two PHD candidates. Reverse elitism, it lives.
I still find the decision to release to be an interesting choice; I didn't because I felt that it would lead to an increase in Internet background radiation, and that basically it's an obvious approach and anyone working in this area will come to exactly the same conclusions. Beer soaked napkin calculations will lead everyone to exactly the same scanner. From my POV there was little benefit in giving this crap to people who wouldn't make the same calculations and write the same code.
What amused me for a while was how long we could get away with being the top "malicious" source on DShield [hint, this requires a ridiculously high packet rate - but it was less than 50k PPS :]. But if you use zmq and distribute your targets that way between a bunch of scan agents, you can get off the top 10 list. Also you can do a scanner like this with a lot less SLOC. The correct architecture is "ip distributor", "scan agent", "listener". They're sort of conflating.
Is that the same as a PRNG with period 2^32-1? I thought I read that idea in the Warhol Worm paper, but looking again it uses a block cipher so I was probably thinking of the Witty worm.
The Sapphire worm used a similar approach, and got the math so distinctively wrong that Vern Paxson was able to fingerprint it, reverse the generator, and take a stab at "patient zero" (I think I'm remembering this correctly).
I agree with you about the formal impact of the "math" here. The irony is that I'm not impressed by the scanner stuff, and easily impressed by simple math!
Can't I just be left to be impressed by a direct use of the math behind a crappy textbook random number generator in peace?
-.-
What they are doing modulo 2^32 + 15 is IMO the simplest way to achieve that goal. Yes, you could do it without overflowing 2^32 using a binary field; you could also cook your own mini block-cipher. But that increases the complexity of the code and is not really faster everywhere.
Ah thanks, now it makes more sense, I knew I was missing something. What about choosing different prime polys for a galois lfsr? I believe you will get the same result.
I've noticed recently I'm coming unstuck on particular CS problems (notably crypto as well), and have realised I need to further my math knowledge greatly.
2^32 (IP addresses) * 1 (port per IP) * 80 (bytes per packet) * 8 (bits per byte) / 1e9 (throughput in bit/sec) / 60 (sec per min) = 46 minutes (note: excluding multicast space, RFC 1918 space, etc, scanning time would be reduced down to ~35 min)
That's equivalent to "scanning all 65,535 ports of a /16 subnet in 45 min" which does sound less impressive...
scanning all 65,535 ports of a /16 subnet in 45 min
...or in other words: scanning all ports in the reserved Class C range,
from 192.168.0.0 to 192.168.255.255, in 45 minI realize lots of people are simply in the habit of saying "Class C" when what they really mean is a /24, "Class B" for a /16, etc. but classless routing[0] has been around for 20 years now and these terms need to go away.
[0]: http://en.wikipedia.org/wiki/Classless_Inter-Domain_Routing
"Note that (in pre-CIDR notation) the first block is nothing but a single class A network number, while the second block is a set of 16 contiguous class B network numbers, and third block is a set of 256 contiguous class C network numbers."
So it is common for crusty old network engineers and sysadmins to refer to 192.168/16 as "the class C" private block, even when they understand that you can subnet it however you'd like.
Right, I realized that when s/he said "reserved Class C range". It was more of a general observation. I always forget I have to be extremely specific here on HN.
Case in point: 11.5.0.0/16 is not a Class B network and never was. (11.0.0.0/8, however, was/"is" a Class A network).
/16 != Class B network.
It's not a class B network under the old system. Because under the old system 11.5.0.0/16 didn't exist.
But you can make such a network now, and if you were to classify its size the appropriate letter is 'B'.
Also, for these scans is quite common to just send a SYN packet and wait for the SYN/ACK to decide if the port is "open" or not.
Actually, the above is a much harder problem. Scanning a limited subnet requires congestion control in a way that scanning the whole Internet does not.
It is a bit obscure, but it did do tricks like encoding encrypted data in extra mutable fields (just the sequence number for scanrand) for validation purposes. Actually, scanrand 2.0 can apparently measure latency (without state!) by encoding timing information in the source port field, which zmap doesn't currently do.
I think this research is great, but I just hate to see interesting old projects get forgotten.
[1] http://dankaminsky.com/2002/11/18/77/ [2] http://www.sans.org/security-resources/idfaq/scanrand.php [3] http://s3.amazonaws.com/dmk/SBO_Hiver.ppt
There aren't as many people using it as you'd think because 1) finding a working download link is quite an exercise and 2) compiling paketto is near impossible except on Dan's machine. :)
I would also scrub all the sinkholes and captured botnet C&C ip addresses as hitting those will lower the reputation your netblock. List we use at meanpath is: http://mirror1.malwaredomains.com/files/domains.txt https://zeustracker.abuse.ch/blocklist.php?download=domainbl... https://zeustracker.abuse.ch/blocklist.php?download=ipblockl... http://malc0de.com/bl/IP_Blacklist.txt http://hosts-file.net/download/hosts.txt http://www.joewein.net/dl/bl/dom-bl-base.txt http://www.dshield.org/feeds/suspiciousdomains_High.txt http://www.malware.com.br/cgi/submit?action=list https://spyeyetracker.abuse.ch/blocklist.php?download=domain... https://spyeyetracker.abuse.ch/blocklist.php?download=ipbloc...
If you have the list of the whole internet servers which answers on http port 80. Then you can reverse map government censorship dns list. Ie you can find out what the government wants to censor by doing lookups in the censored dns and for example opendns on the servers ip that answers on port 80, then you diff the results from the dns servers and if you get different answers you find out the government black list.
There has been a very positive trend recently in the quality of documentation, a move away from dry, man-style listing of options to more operational descriptions, tutorial, examples, a bit of hand-holding. Here's a Docker tutorial[1], still on the front page.
In the ideal case, you might have a quality man page that provides usage information and links to more detailed documentation (that would include tutorials, implementation info, etc.) on the web somewhere.
It's great that we have blogs and such nowadays where anyone and everyone can contribute their own documentation, guides, tutorials, etc., but there was something awesome about having a single, centralized, authoritative HOWTO covering a particular topic.
For the technically inclined, a good white paper describing the advantages of IPv4-wide scanning for security reconaissance and the advantages of ZMap vs other tools like NMap can be found here:
https://www.usenix.org/system/files/conference/usenixsecurit...
User-land Distributed Portscanner released in 2005: http://unicornscan.com
Defcon Presentation Introducing Unicornscan from 2005: http://www.youtube.com/watch?v=ZdCEo6yoEWA
What an absolutely stupid default setting. Thanks for giving a bunch of noobs a simple IPMC DOS application. If this thing gets popular it will soon be the bane of network admins everywhere.
2) There are at least 2 obvious omissions from their default blacklist file. There might be more but these are the obvious ones that come to mind. class-E 240.0.0.0/4 CGN 100.64.0.0/10
3) Can someone explain to me why I wouldn't just want to use nmap to do this same thing? Why do we need a new tool for this?
If you work for an ISP?
If you ask the University nicely?
As soon as you expose someone downstream to stuff like this you're asking for being disconnected. If you ask your University nicely they'll likely refuse unless you state a goal you wish to achieve.
If using a script to download documents qualifies as hacking then hitting all of the internet with a portscanner is likely going to get you network administrator attention of the entirely wrong kind. And that's because they in turn will get some flak from the outside world.
Since I was already accessing my dorm computer via Samba in the labs (I know, dumb idea in hindsight, even with a password, but this was 2004), I decided to figure out a way to print directly from my room and then just grab it on the way to class. Long story short I ran a port scan on the computer lab to find the printer IPs and had my network port turned off within minutes (I had the IPs though!). Ended up having to go to some office and explain what I was doing. Got turned back on a few days later.
The upside was that I eventually was able to print from my room as long as I converted whatever it was to postscript first. The downside was that I didn't need to know the printer IPs after all (the university's unix server already had the printers setup... just piped it through ssh to it).
The old NCP networking protocol required that connect and listen sockets must have different parity gender (one even, the other odd -- I can't remember which was which, or if it mattered -- they just had to be different). The act of trying to connect an even socket to another even socket, or an odd socket to another odd socket, was called "homosocketuality", and it was strictly forbidden by internet protocols, and was called the "Anita Bryant feature".
http://www.saildart.org/IMPSER.DOC[SS,SYS][1]
Illegal gender in RFC, host hhh/iii, link 0
The host is trying to engage us in homosocketuality. Since this is against the laws of God and ARPA, we naturally refuse to consent to it.
http://www.saildart.org/FTP.OLD[S,NET]1[2]
; Try to initiate connection
loginj:
init log,17
sixbit /IMP/
0
jrst noinit
setzm conecb
setom conecb+lsloc
move ac3,hostno
movem ac3,conecb+hloc
setom conecb+wfloc
movei ac3,40
movem ac3,conecb+bsloc
move ac3,consck
trnn ac3,1
jrst gayskt ; only heterosocketuals can win!
movem ac3,conecb+fsloc
mtape log,[
=15
byte (6) 2,24,0,7,7
] ; Time out CLS, RFNM, RFC, and INPut
[...]
gayskt: outstr [asciz/Homosocketuality is prohibited (the Anita Bryant feature)
/]
ife rsexec,<jrst rstart;>exit 1,
(The code above adds the connect and listen socket numbers together, which results in bit 0 being 0 if they are the same gender, then TRNN is "test bits right, no change, skip if non zero", which skips the next instruction (jrst gayskt) if they different sex.)https://zmap.io/documentation.html#extending
Very good, very extensible.