11 ms·
Some idiot is using your tool to mass scan our network
- junon 6y agoI've been commenting on these issues for years now on this exact repository. People are incredibly, incredibly dense.
- mytailorisrich 6y agoFrom the tool's description: "This is an Internet-scale port scanner. It can scan the entire Internet in under 6 minutes, transmitting 10 million packets per second, from a single machine." Then it seems that it has a link to its github page by default in the User-Agent string it uses while scanning. When you do that you can only get abuse in return, can't you?
- imhoguy 6y agoBTW does anyone know what is a strain on the Internet bones when thousands of script kiddies try to run it?
- jacquesm 6y agoNegligible compared to the existence of Youtube, Spotify, Twitch, Facebook and so on.
- st_goliath 6y agoIf you are running this tool, you are sending packets from a single machine to N remote hosts, so logically the strain and bottleneck should be at your end and I can't see how this should cause much of a burden several hops away. At the destination this should be a small fraction of the usual "Internet background noise" which is usually a negligible fraction of the available bandwidth.
- m463 6y agoI wonder if you can randomize the source address?
- zxcmx 6y agoNot exactly. You can separate transmit and receive IPs, if your tx network does not implement source filtering. So you can tx from one place and receive from one or more other places "sensors" that you use to receive SYN-ACKs. You can use several (an arbitrary number) of spoofed source IPs on tx to hide your "real" rx IPs, at the cost of more egress traffic. There is a technique involving ipids (idle scanning) you can use which does not reveal your IP at all but it is not reliable; read: not usable beyond very tiny scale. You could put a lot of effort into it but it's not worth it. Nobody beyond a few vociferous cranks _really_ cares about IP scanning. The real way to stay off radars (eg dshield) while mass scanning is have a ton of unrelated IPs and scan as slow as you can stand. This assumes good randomization (not obviously striping across networks from the same IP).
- raesene9 6y agoIndividual users running massscan et al, are not going to produce anything like the level of traffic all the major providers (and quite a few sitest that aren't that large) see from DDoS attacks on a pretty regular basis. Given that there are several sites who scan the Internet regularly for more than just open ports (e.g. Shodan, Binary Edge, Censys) it's not a volume of traffic that should cause a concern.
- Jaruzel 6y ago> transmitting 10 million packets per second, from a single machine One wonders if your ISP would detect you running this thing, and kill your connection. I'm pretty sure a lot of ISP T&C forbid mass scanning tools?
- Woansdei 6y agoDoubt my ISP cares, but with 20Mb upload it's not going to send 10 million packets per second (2 bits per packet just isn't valid network traffic).
- nix23 6y ago>One wonders if your ISP would detect you running this thing, and kill your connection. My home ISP just resets the router and let it reboot. Source: Me
- isoprophlex 6y agoI'm very much tempted to try, i wonder what comes of it. If you run any services (ssh, vpn, whatever) from your home connection you're probably making yourself into a target for counter scans
- tleb_ 6y agoMine got disconnected for about 30 minutes. Then I just calculated the rate I needed for the duration I found acceptable (one week for a single country) and let it run at this rate; no issue then.
- zaarn 6y agoYour router is likely to die before you max out 10Mpps. Especially if you have a NAT, that'll probably be more reasonably close to 10-30kpps.
- Dylan16807 6y agoIf someone's scanning the internet at that speed, that means you get less than one packet per five minutes for each IPv4 you have. Hardly something to whine about.
- ivanche 6y agoIf one person in the world is scanning, yes. Ten persons => 1 packet every 30 seconds. 100 000 persons => 1 packet every 3ms. Suddenly doesn't look that innocent, right?
- Dylan16807 6y agoSo in this situation where you have an absolutely ridiculous number of people flooding the internet with scans, all on multi-gigabit connections, it eats up a whole 20 kilobytes per second. 10 000 persons doing this simultaneously is also an insane number, and that's 2 kilobytes per second. It sounds fine.
- BlueTemplar 6y ago"The entire Internet" these days also means IPv6. I suppose that IPv6 scanning is not going to happen any time soon?
- samoa42 6y agoi'd say "the internet" is the biggest "network of networks" and ipv6 is not really a part but a separate network ie. not interoperable with "the internet". maybe it will be more important some day, but not today.
- ingen0s 6y agoThis would have made a great tool for the anonymous FTP days - unless that's still a thing.
- imhoguy 6y agoIt is, plus now you also get "big data" with unprotected ElasticSearch instances, MySQLs with silly passwords etc.
- raxxorrax 6y agoIt is used to scan our network too, what a coincidence! Can you move issue reports to integration test results?
- est31 6y agoSoon: Show Hn. logfile-ads.io. Serve job advertisements to disgruntled admins across the internet.
- 0-_-0 6y agoTired of looking at logs of idiots port scanning your network? Come work for us instead!
- viraptor 6y agoThis is already happening. Well, not job ads, but if you're running a popular site you can find various IT services advertised in user-agent.
- ktta 6y agoSomething similar: https://caddy.community/t/caddy-commercial-sponsor-header-clarification/2716 https://caddy.community/t/caddy-commercial-sponsor-header-cl...
- dddddaviddddd 6y agoReferral spam is more common in tools like Google Analytics, but I see it in my server logs as well.
- kreddor 6y agoSo what would be a legitimate use of this tool? I mean, concerning the "scan the whole internet" part.
- twelvechairs 6y agoWhy should it not be legitimate to scan things?
- m463 6y agoI think it's kind of like someone who goes down the hallways in a building, checking to see if all the doors are locked. There are basically two types of people who do that. The security guards and... cat burglars.
- kchr 6y agoWhat's wrong with checking all doors? It's what you decide to do with the knowledge that really matters...
- nix23 6y ago>So what would be a legitimate use of this tool? Scanning for open ports sounds like a legitimate use, but being a Network admin and not capable to block a robot called "masscan/1.0" is NOT legitimate.
- ryanjshaw 6y agoThis is entertaining: https://github.com/robertdavidgraham/masscan/blob/master/data/exclude.conf https://github.com/robertdavidgraham/masscan/blob/master/dat...
- st_goliath 6y agoSee also: People finding the curl copyright notice in an application and blaming Daniel Stenberg for hacking them: https://daniel.haxx.se/blog/2016/01/19/subject-urgent-warning/ https://daniel.haxx.se/blog/2016/01/19/subject-urgent-warnin... Or the reason sqlite no longer uses "sqlite" as a file extension for temporary files: https://github.com/endlesssoftware/sqlite3/blob/master/os.h#L133 https://github.com/endlesssoftware/sqlite3/blob/master/os.h#...
- 3np 6y ago> Also, Spotify is a major partner of Spotify Can't argue with that
- bballer 6y agoThis is great, thanks for posting.
- danmur 6y agoHa ha ha, surely not, it's too hilarious. Must be a top tier troll :)
- andai 6y ago> How about simply renaming curl to zurl so that you end up at the very bottom of the list and hand over the case to the next dependency in alphabetical order?
- andai 6y agoFound this gem in the comments of the first one: A city in Oklahoma threatened to call the FBI over an Apache error message... and sent the threat to CentOS. https://www.theregister.com/2006/03/24/tuttle_centos/ https://www.theregister.com/2006/03/24/tuttle_centos/
- bjeds 6y agoAs a security professional I'm very disappointed when I read the (often angry) messages people have written to the maintainer/author of this software. You can read them here, in the ip range blacklist: https://github.com/robertdavidgraham/masscan/blob/master/data/exclude.conf https://github.com/robertdavidgraham/masscan/blob/master/dat... If you don't want people on the internet to connect to your server, then you shouldn't allow network connections to your server. A few connections per minute hardly classify as abuse in any reasonable sense of the word. The owner of the source network, on the other hand, (compared to the destination server), I think have a more legitimate reason to raise flags. Most cloud providers for example do not allow port scanning from their network (for various reasons). If you're gonna send out millions of packages all over the place I think it's good practice to inform your network provider first.
- m463 6y ago> If you're gonna send out millions of packages all over the place I think it's good practice to inform your network provider first. So amazon should notify AWS? :)
- bjornedstrom 6y ago:) This reminds me of my favorite typo: https://slashdot.org/comments.pl?sid=406154&cid=21914102 https://slashdot.org/comments.pl?sid=406154&cid=21914102
- nix23 6y agoYes this! I'm not a security professional but System Administrator, and i need tools like that, especially DoS and metasploit-kind tools to harden my own systems/services. We need tools like that, if we don't try to break our own Systems, someone else will do it (and this time with consequences). BTW: Massscan is excellent at braking routers, over-flood them and they will often crash.
- luckylion 6y ago> A few connections per minute hardly classify as abuse in any reasonable sense of the word. That's for one individual who's scanning something. On the receiving end, you're not dealing with one individual, you're dealing with many individuals who are probing for vulnerabilities. If one guy intentionally steps on your foot, that's mildly annoying. If a thousand people intentionally step on your foot, that's a very different issue. > Most cloud providers for example do not allow port scanning from their network (for various reasons). They don't? They are often the source I see. Is that a policy thing where they say "yeah well please don't" or will they actively shut you down if you're doing it from their infrastructure?
- rejschaap 6y agoProbably not a great idea to make it so easy to scan the entire internet. Even providing the command in the readme before explaining why it is a bad idea.
- ricardo81 6y agoThere are numerous public domain tools that do this, so the cat is already out of the bag. Last I read about it, you can scan the entire IPv4 space for a port in about 40 minutes providing you have the bandwidth and a forgiving ISP. I see another comment claiming a tool can do it in 6 minutes. Easy at "apt get install" and a single command.
- Qub3d 6y agoThe tool that can do it in 6 minutes is massscan, the original repo of which is the link of the post: https://github.com/robertdavidgraham/masscan https://github.com/robertdavidgraham/masscan Note that "scan the internet in 6 minutes" only means this tool is capable of generating packets fast enough on the host machine to theoretically do a 6 minute scan. In practice, the NIC, home network, and local ISP connection will bottleneck and the scan will be orders of magnitude slower.
- krageon 6y agoIt's been trivial to do for ages even before masscan existed. Even then, you exist as an entity on the internet to have things connect to you. If there are ways in which you don't want to be connected to, you have a firewall to enforce that.
- croes 6y agoSecurity by "Stop doing that"
- afwe 6y agoI love masscan, I guess the author won't read this, but thanks for this tool, it's very useful. If you hadn't made it, someone else would've written it in Python so it would get stuck on CPU all the time, heh.
- nix23 6y agoHe even wrote his own IP-Stack! It's a great tools for sure.
- m463 6y agoReading the description it's kind of amazing what kind of throughput you can get with it. And I will say that identifying the tool in a way that it would show up in logs was responsible.
- bob33212 6y agoRob is active on Twitter. https://mobile.twitter.com/erratarob?lang=en https://mobile.twitter.com/erratarob?lang=en
- Lev1a 6y agoRelevant DEFCON talk from the creator and friends: https://www.youtube.com/watch?v=nX9JXI4l3-E https://www.youtube.com/watch?v=nX9JXI4l3-E
- ChrisMarshallNY 6y agoI must say that the software code quality of that project seems quite good.
- rootsudo 6y agoI enjoy how the exemption list is now a target of places you want to scan.
- kchr 6y agotargets.conf
- smoyer 6y agoThat's weird ... I've got hundreds of thousands of idiots scanning mine! (but they don't seem to be getting results).
- nix23 6y agoWhats your IP if i may ask?
- smoyer 6y agoIt's a Comcast IP address but really I think it comes down to the fact that I own my own CM and I don't trust it as my router/firewall. You can ask but posting the actual IP address here would be like wearing a cell phone in a belt clip at BlackHat/DefCon.
- nix23 6y agoBTW Did someone send this to github-dramas allready? That guy makes: >E-commerce, IoT and mobile engineering services, with a software boutique approach Man i really don't want a IoT device from them...also not a shop if they don't know how to block Robots.
- nemetroid 6y agoReminds me of etilqs. https://github.com/endlesssoftware/sqlite3/blob/master/os.h#L133 https://github.com/endlesssoftware/sqlite3/blob/master/os.h#...
- gavreh 6y agohttps://github.com/sqlite/sqlite/blob/master/src/os.h#L52 https://github.com/sqlite/sqlite/blob/master/src/os.h#L52
- deleted 6y ago[deleted]
- mawalu 6y agoAfter reading this I checked my own logs. I seem to get hit by masscan every few days and at least once per week: "2020-08-31T05:55:15.314510181Z" "2020-09-07T04:31:10.32778784Z" "2020-09-12T07:37:23.354113494Z" "2020-09-14T04:48:22.862297069Z" "2020-09-14T10:31:45.331617062Z" "2020-09-21T01:03:47.198615685Z" "2020-09-21T04:04:12.142308436Z" "2020-09-28T04:40:15.616859176Z" "2020-09-30T14:21:35.844867635Z" "2020-10-02T23:05:58.837039985Z" "2020-10-03T03:18:33.945424629Z" "2020-10-03T14:02:51.344484887Z" "2020-10-03T16:47:59.941939178Z" "2020-10-03T16:54:16.67585357Z" "2020-10-04T03:40:37.740594379Z" "2020-10-04T09:12:23.443293148Z" "2020-10-04T23:07:21.37800867Z" "2020-10-05T06:06:11.452526929Z"
- oefrha 6y agoI wonder how often the reverse happens, i.e. admins sending angry emails to their own users who appear to be scanning other people's networks. Anecdote: when I was a grad student at AS88, I once got an email asking me to stop port scanning. I was confused because I wasn't port scanning anyone. I asked for details and an admin sent me a report generated by some seemingly off-the-shelf network admin software (forgot the brand), with a bar chart of all IP addresses I was frequenting -- rather creepy, honestly. Turns out I was renting ~20 servers around the world as PoPs for a personal project at that time, and regularly deploying code to all of them at once over SSH (all configured at port 22). Apparently regularly accessing ~20 servers at once over a single port was enough to be flagged as "port scanning". I wonder if people doing actual security research over at the CS department were exempt from nonsense like this.
- taxcoder 6y agoHas anyone made available the exclude lists they have compiled?
- deleted 6y ago[deleted]
- VLM 6y agoThe same logic of "blame the vendor" is very popular and accepted for gun control reasons.
- eli 6y agoMasscan hasn’t killed anyone
- thedanbob 6y agoIf you own a building with many doors and you catch someone spying on the doors trying to find one left open, it’s not much use to complain to the manufacturer of the binoculars.
- ivanche 6y agoTIL that masscan is actually a legitimate tool! It's one of the first user-agent strings I block on every new nginx installation.
- mike_d 6y agoPeople who don't change the default user agent are legitimate security researchers. People with actual malicious intent change it to whatever the current Chrome UA is.
- johndbritton 6y agoFrom the exclude.conf file: #Received: from elbmasnwh002.us-ct-eb01.gdeb.com ([153.11.13.41] # helo=ebsmtp.gdeb.com) by mx1.gd-ms.com with esmtp (Exim 4.76) (envelope-from # <bmandes@gdeb.com>) id 1VS55c-0004qL-0F for support@erratasec.com; Fri, 04 # Oct 2013 09:06:40 -0400 #To: <support@erratasec.com> #CC: <ebsoc@gdeb.com> #Subject: Scanning and Probing our network #From: Robert Mandes <bmandes@gdeb.com> #Date: Fri, 4 Oct 2013 09:06:36 -0400 # #Stop scanning and probing our network, 153.11.0.0/16. We are a defense #contractor and report to Federal law enforcement authorities when scans #and probes are directed at our network. I assume you don't want to be #part of that report. Please permanently remove our network range from #your current and future research. # #Thank you # #Robert Mandes #Information Security Officer #General Dynamics #Electric Boat # #C 860-625-0605 #P 860-433-1553 https://github.com/robertdavidgraham/masscan/blob/master/data/exclude.conf#L41-L65 https://github.com/robertdavidgraham/masscan/blob/master/dat...
- parliament32 6y agoI'm more upset about this org managing a /16 than anything.
- ihattendorf 6y agoCool, now I know to focus my scans on 153.11.0.0/16 if I want anything juicy.
- fsociety 6y agoYou would hope a defense contractor was smarter than this but of course they tend not to be... threatening to put a maintainer in a report to Federal law enforcement is weak sauce.
- protomyth 6y agoAnother classic case is the fun had by thttpd: the classic "Attack of the Repo Men" http://www.acme.com/software/thttpd/repo.html http://www.acme.com/software/thttpd/repo.html
- ericol 6y agoWell, this is interesting (as long as something this stupid can be interesting). Somebody stated what we all already know: That there are a lot of stupid people using available tools for stupid purposes. But the person that stated this doesn't seem to be any less stupid than any other stupid involved.
- Pick-A-Hill2019 6y agoMy favorite comment from the GitHub bug report comments section "This tool is coded in C, which was unfortunately created without any regard for its misuse. OP should open the bug upstream."