4 ms·
I'm somewhat surprised there is no reference to scanrand[1][2], a fast stateless syn scanner by Dan Kaminsky in 2002. It wasn't directly geared towards scannin
by colonelxc 13y ago
I'm somewhat surprised there is no reference to scanrand[1][2], a fast stateless syn scanner by Dan Kaminsky in 2002. It wasn't directly geared towards scanning the entire Internet, but instead scanning large subnets (like for a pen test of a /16 network... takes a long time to scan).
It is a bit obscure, but it did do tricks like encoding encrypted data in extra mutable fields (just the sequence number for scanrand) for validation purposes. Actually, scanrand 2.0 can apparently measure latency (without state!) by encoding timing information in the source port field, which zmap doesn't currently do.
I think this research is great, but I just hate to see interesting old projects get forgotten.
[1] http://dankaminsky.com/2002/11/18/77/ http://dankaminsky.com/2002/11/18/77/
[2] http://www.sans.org/security-resources/idfaq/scanrand.php http://www.sans.org/security-resources/idfaq/scanrand.php
[3] http://s3.amazonaws.com/dmk/SBO_Hiver.ppt http://s3.amazonaws.com/dmk/SBO_Hiver.ppt
- dsl 13y agoI currently scan the entire internet once a week using a re-implementation of scanrand I did myself. (and will be switching to Zmap shortly) There aren't as many people using it as you'd think because 1) finding a working download link is quite an exercise and 2) compiling paketto is near impossible except on Dan's machine. :)
- jnazario 13y agocheck out dscan from dugsong, which was built around 2003 or so to address that problem, that dan doesn't often write portable code. https://github.com/dugsong/dscan https://github.com/dugsong/dscan