4 ms·
reading the article, it might seem that it's some sort of futuristic technology, but it's been used since 2002 (scanrand) the downside of stateless portscannin
by w_larsen 13y ago
reading the article, it might seem that it's some sort of futuristic technology, but it's been used since 2002 (scanrand)
the downside of stateless portscanning is that you are trading speed for false negatives.
- danielrhodes 13y agoProbably why it's used as a statistical tool rather than a security tool.
- gruseom 13y agothe downside of stateless portscanning is that you are trading speed for false negatives That's interesting. Could you explain this in a bit more detail? Unless I missed it, the thread from yesterday didn't discuss this.
- groby_b 13y agoSince it's stateless, all info is encoded in the outgoing packet. If the outgoing packet (or the reply to it) is lost, it will look exactly the same as if the server didn't respond - after all, the scanning tool has no local state, and thus can't track if an address has been pinged/re-ping it. The port map is entirely drawn based on incoming packets.
- gruseom 13y agoThanks! I get it now. Good explanation.
- perbu 13y agoI don't know how they progress through the IP space, but couldn't they simply solve this by doing it in a deterministic manner? At progress N they should easily be able to tell that A has been scanned. Iterating three times through the IP space all IPs that haven't answered should have gotten the connection attempts.
- hmsimha 13y agoThat might introduce the same overhead that maintaining state does in the first place. It sounds like they're sending out at least a million requests per second.
- sebcat 13y agoThis can't be stressed enough. It's not all about bandwidth, packet loss is very real.