Masscan: The entire internet in 3 minutes
blog.erratasec.com
blog.erratasec.com
[1] http://blog.erratasec.com/2013/09/we-scanned-internet-for-po...
Second of all, we response personally to each abuse report and offer to include them in our "exclude" file so that we won't scan them ever again. Though, of course, I prefer they add us to a "whitelist" file: not opening their firewall, but adding us a file that ignore logging.
Only one thing bugs me: "but I replace 'xor' with a mathematically equivalent 'modulus' operation."
Unless you scan 256,512,768,etc. number of ports there will be bias, and sequence only looks random. I suggest the author to take a look at this:
I'm using the "Feistal network" construction that is at the heart of the data encryption standard, replacing binary operations like 'xor' with the "addition plus modulus" operation.
My found function sucks, and I only do 3 rounds, so there's probably some issues there. But, if I were to fix those issues, then there should be no more detectable bias than in the original DES cipher.
Pretty terrifying if you subvert it to hit just one network instead of randomly scanning the internet.