Masscan: Scan the entire Internet in under 5 minutes
github.com
github.com
[https://github.com/robertdavidgraham/masscan#randomization]
"Note that it'll only melt your own network. It randomizes the target IP addresses so that it shouldn't overwhelm any distant network."
Link-local multicast (the replacement for ARP) allows tools like alive6 to very easily enumerate all live v6 addresses on a network. So once a spear phishing attack is sucessful, you can still scan the entire internal network.
Google hacks like "site:ipv6.*" and passive DNS monitoring allow you to easily separate used vs allocated/announced subnets on remote networks. IPv6 breaks in strange ways when you firewall ICMPv6, so ping scanning a subnet has become much easier.
There was also a great talk (i'll try to dig it up) that talked about predictable patterns in DHCPv6 implementations, so you can cut down v6 to a near v4 search space.
The best part of all is that very few security products on the market really support IPv6 correctly, so I suspect we will see more advanced attacks being possible because of IPv6 in the coming years than things being stopped.
Well, this is an IPv4 brute force search, so technically a IPv6 brute force search is still impossible.
You are correct though, no one is going scan something that is 99% empty by brute force.
[1] http://blog.erratasec.com/2014/09/bash-shellshock-scan-of-in...
Can't we just go scan one-after-another IP address? Is this because such scan can easily be detected by ISP?
This is how they can claim: "... it'll only melt your own network. It randomizes the target IP addresses so that it shouldn't overwhelm any distant network."
Note "shouldn't", this was probably added due, in part, through use-case. If I were not scanning the whole Internet, and instead just scan a small section. Masscan has less of a space to randomize through, which means the tree is smaller and the shared paths are more frequent.
Massscan ships with an exclude list which you would do well to utilize:
https://github.com/robertdavidgraham/masscan/blob/master/dat...
If you try to run an internet wide massscan without this list, it will stop you and give you a warning about how to use the list. You then either manually override the warning, or use the list.