6 ms·
So what would be a legitimate use of this tool? I mean, concerning the "scan the whole internet" part.
by kreddor 6y ago
So what would be a legitimate use of this tool? I mean, concerning the "scan the whole internet" part.
- twelvechairs 6y agoWhy should it not be legitimate to scan things?
- m463 6y agoI think it's kind of like someone who goes down the hallways in a building, checking to see if all the doors are locked. There are basically two types of people who do that. The security guards and... cat burglars.
- kchr 6y agoWhat's wrong with checking all doors? It's what you decide to do with the knowledge that really matters...
- nix23 6y ago>So what would be a legitimate use of this tool? Scanning for open ports sounds like a legitimate use, but being a Network admin and not capable to block a robot called "masscan/1.0" is NOT legitimate.
- grumple 6y agoScanning for open ports on other peoples networks? How is that different from casing a house for entrances? It’s behavior only two types of people would have: criminals and security professionals.
- nsomaru 6y agoSecurity professionals are born that way?
- nix23 6y agoHehe, and the experience comes from books...no need to do it with your own hands. Same with pilots just read a book and that's it...maybe some Microsoft flight-simulator hours too.
- superkuh 6y agoOr just curious people who interact with the internet directly for fun. Not everyone is confined to a web browser and facebook. No one is hurt, no one is defrauded, and no one's privacy is impacted by using the internet as it is meant to be used.
- enriquto 6y ago> Scanning for open ports on other peoples networks? How is that different from casing a house for entrances? It's more like looking through other people's windows as you walk by the street. May be creepy if you always stare at the same window, but formally there's nothing wrong with that. If you do not want people to see through your public-facing windows in your home, it's your responsibility to install blinds or shades.
- grumple 6y agoIf you walk around town looking in every window, you’re probably not gonna have a good time when you get detained or shot. Let’s not pretend like there are legitimate use cases for scanning ports of networks you don’t control.
- enriquto 6y ago> If you walk around town looking in every window, you’re probably not gonna have a good time when you get detained or shot. Dude, what kind of town do you live in? It sounds scary! Here in Europe many towns have narrow streets with houses directly by the street (with no front yard). It is essentially impossible to not look through the windows of people unless you make a robotic effort to avoid it.
- projektfu 6y agoTIL there are hackers living in high-crime areas. Seems like a good idea to move to a neighborhood where you won’t get shot for having your eyes up, which is almost all of my city.
- nix23 6y agoHint...it's probably NOT Europe :)
- NeutronStar 6y agoBut are you looking through every single windows?
- 6y ago
- CraneWorm 6y ago> How is that different from casing a house for entrances? If you don't see a difference then I hope we don't share neighborhood. > It’s behavior only two types of people would have: criminals and security professionals. consider also curious people seeking knowledge; the Internet is a massive space and an interesting phenomenon in itself, scanning is one of many ways to learn about it.
- superjan 6y agoHe did not suggest casing a house is OK.
- nix23 6y ago>How is that different from casing a house for entrances? Your House is not a Server, compare it to a Butler, i yell into your house and if a Butler answers i ask him whats on the table.
- jbarberu 6y agoIf you don't want anyone connecting to you network, don't connect it to the internet. If you only want certain people to access your network, whitelist their IPs. If you don't want people to look at you, don't go out in public.
- antoinealb 6y agoWell scanning has some useful security research applications. The part about scanning the whole internet is useful if you want to do larger scale research (like how many % of the internet run telnet). In addition massscan is really interesting from a software engineering persepective. They do kernel bypass to talk to network drivers directly, have a custom TCP stack, custom mutexes, etc. All of that to be able to reach ~1.5M packets per second (from the README), allowing someone to scan the whole IPv4 range in 6 minutes. Really impressive work.
- Netcob 6y agoI wonder how many "counter-scans" would start arriving immediately afterwards.
- stoolpigeon 6y agoresulting in the much loved venn diascan.
- wang_li 6y agoScanning other people's networks without their permission has no valid research purpose.
- deleted 6y ago[deleted]
- shawnz 6y agoThe person you are replying to just gave an example of a research application. What's not valid about it?
- wang_li 6y agoBecause it's always invalid to research on someone else's property without their permission. Also what is the hypothesis that is being researched or investigated by knowing how many systems on the internet respond to TCP SYNs on port 23?
- m463 6y agoI think it might be useful to scan a large corporate address space from within without waiting days. You could also scan your own internal 10 net in a finite amount of time. 1/255th of the internet is for all practical purposes, the internet.
- halflife 6y agoI’m working at a cyber security company, we have an agent running on customer machines that helps identifying security breaches. One tool we use is to scan the customer’s network and find out which machines don’t have our agent running.
- herman_toothrot 6y agoIs the word "cyber" making a comeback?
- uzakov 6y agoYes, companies find it easier to sell solutions, when there is the word cyber present
- soylentcola 6y agoI feel like most of us who rolled our eyes at all of the "cyber" stuff have generally thrown in the towel. I see it mostly used when talking about security-related issues as opposed to just "on the internet" stuff nowadays. Cyber-warfare, cyber-security, cyber-espionage, etc. I do still chuckle a little bit, but language and popular terminology is just funny like that.
- NeutronStar 6y agoScanning your own network is not the same as scanning the whole internet.
- tgv 6y agoThat you probe your customer's networks, I can understand, but, but why would you scan other people's networks? I encountered a bunch, always trying the same, lame URLs for a PHP framework bug or a Wordpress config error, sometimes a hundred variations in a few seconds. What's the point? Same goes for all these ssh connections, but they seem to be real hacking attemps.
- rblatz 6y agoOdds on this agent taking commands from the network running as root? Just one buffer overflow away from the whole networked being owned.
- Lendal 6y agoThis tool is like a flashlight for the Internet. It reveals the location of all the cobwebs. At the same time, there are admins out there that don't like you shining lights in their windows and they will ban you for it. Everyone knows flashlights are used by bank robbers. But if you can think of a legitimate use of a flashlight, then you can think of a legitimate use for this tool.
- mellosouls 6y agoSurely you can provide examples then? I am wondering the same thing myself; it's not obvious to those of us not looking for vulnerabilities in other people's systems what the use of it is at internet scale. Flashlights are used by normal people for strictly local, very closely defined location illumination. We don't turn them on and light up the whole world.
- PeterisP 6y agoScan any large network instead of the whole internet. If you want to scan many ports in a large network quickly then you need an "internet-scale" portscanner like masscan.