robertdavidgraham / masscan

TCP port scanner, spews SYN packets asynchronously, scanning entire Internet in under 5 minutes.
GNU Affero General Public License v3.0
23.76k stars 3.08k forks source link

Some idiot is using your tool to mass scan our network #482

Closed vsecades closed 4 years ago

vsecades commented 4 years ago

Not my project. If so inclined close the issue.

JoeMilian commented 4 years ago

@vsecades

Hi,

I ran massscan to find your brain but I haven't been able to find it, I might need to create another issue since the tool isn't working or is it maybe something else?

hachinijuku commented 4 years ago

@vsecades How did you determine that masscan was being used to do the scanning? What were the key indicators?

vsecades commented 4 years ago

@vsecades How did you determine that masscan was being used to do the scanning? What were the key indicators?

We were tracking outages on a Web server, and found your tool on our server logs.

TehVulpes commented 4 years ago

We were tracking outages on a Web server, and found your tool on our server logs.

@vsecades the person you're replying to has no relation to the masscan project, masscan is not "his tool". I would highly recommend closing this issue. At least this tool is polite enough to identify itself in its user-agent string, all the other more malicious scanners that are currently scanning your network aren't.

s0urfruit commented 4 years ago

some idiot closed the issue

vsecades commented 4 years ago

Possibly that should provide visibility into the collateral damage these tools cause other folks.

s0urfruit commented 4 years ago

idk the internet also does a lot of harmful things.

dfault-user commented 4 years ago

Pain.

kaithar commented 4 years ago

A number of attempts have been made to draft code that allows for resolving idiots, however most of them appear to get rejected with a status of "CANTFIX/HUMANRIGHTS" ... I'm sure progress towards implementation will be made just as soon as someone finds a work around for users refusing to run their system security software set to enforcing=pain

SelimEmre commented 4 years ago

I just came to read the comments :+1:

quantumJLBass commented 4 years ago

Ju7l5y9osyymQ I see the issue Karen

0ne-nine9 commented 4 years ago

I can't believe this is an actual thread in 2020.

jimkats1 commented 4 years ago

In a big network security system, masscan was showing up in the logs like every hour, but no one never batched an eye for years. Appointed IT personnel only cared about abnormal traffic, not for scans style of "masscan". So maybe all this fuss is just because you don't want to see masscan-related traffic in your logs (to keep the logs less crowded)?

Enrico204 commented 4 years ago

Possibly that should provide visibility into the collateral damage these tools cause other folks. @vsecades

You don't realize how lucky you are. Seriously. You just found that there are massive scan on internet (they have always been there). And you just found that tools that attackers have, they can be used by you to check your defenses, for free.

I suggest you to collect some of these tools, build up some knowledge (or find someone who has it) and run these tools against your own system to check if there is any vulnerability.

This is the right way to use this tool. And this can save your from the next hacker attack.

oldkingcone commented 4 years ago

Have you tried calling the internet police?

vsecades commented 4 years ago

Wow, never figured this would go viral. Keep at it then.

kurobeats commented 4 years ago

Wow, never figured this would go viral. Keep at it then.

Buddy, the Internet will never forget now that you don't understand how the Internet functions, what goes on or network security in general. Going viral isn't something you should be proud of in this instance.

quantumJLBass commented 4 years ago

Wow, never figured this would go viral. Keep at it then.

Buddy, the Internet will never forget now that you don't understand how the Internet functions, what goes on or network security in general. Going viral isn't something you should be proud of in this instance.

you mean 'forget that you're learning..' I mean damn man why so rough? I have been at this 30 years i don't put random down like that, they could end up your boss. OS is learn and grow together.. that is github

s0urfruit commented 4 years ago

damn this died

vsecades commented 4 years ago

@vsecades you can close this now, thx

I thought I did unfortunately these folks love to keep on trolling.

dfault-user commented 4 years ago

@vsecades you can close this now, thx

I thought I did unfortunately these folks love to keep on trolling.

That's on you for making an unneccessary issue like this in the first place 😳

MartinDevillers commented 3 years ago

Exposed one of my web servers to the internet (gasp) and within an hour I am seeing traffic from this tool appear. So good job on developing this 😉

Zenexer commented 3 years ago

@MartinDevillers Please read the comments at https://news.ycombinator.com/item?id=24728123.

MartinDevillers commented 3 years ago

Thanks @Zenexer my comment was meant as a joke: I am fully expecting random traffic to hit my server the moment I exposed it to the internet. Was fun to see a github url pass by in the access logs. All good

s0urfruit commented 3 years ago

This was really fun lmao

2442919 commented 3 years ago

Is for real? hahahah

On Wed, 12 May 2021 at 16:34, Sourfruit @.***> wrote:

This was really fun lmao

— You are receiving this because you are subscribed to this thread. Reply to this email directly, view it on GitHub https://github.com/robertdavidgraham/masscan/issues/482#issuecomment-839870230, or unsubscribe https://github.com/notifications/unsubscribe-auth/AIBBSNBVV4ZS3U5HQBLG3T3TNKNYLANCNFSM4MCUQYEA .

oldkingcone commented 3 years ago

Is for real? hahahah

nope.

joseph-giron commented 3 years ago

Don't these dullards know the "block list" isn't actually called anywhere in the code / program? I guess placing their IP's in a text file is one way of placating them, or maybe it might make them a target. After all, there's the IP's right there and the people reporting them are whining about it.

ericnyamubbp commented 3 years ago

lol. the thread.the ignorance is overflowing.Port scanning is very essential in protecting the whole internet.It helps in conducting internet Census that helps orgs managing their portion of the internet plan accordingly.It helps cyber security professionals to find vulnerable machines that they can protect by altering owners to patch the machines before they are victimized.Long live Masscan!

dfault-user commented 2 years ago

if i blow my brains out in front of this bot, would it change its ways forever?

Message ID: @.***>

oldkingcone commented 2 years ago

if i blow my brains out in front of this bot, would it change its ways forever?

hm.

no.

egberts commented 2 years ago

Might be a good time to brush up on firewall administration, just sayin’.

thenishantsapkota commented 1 year ago

Came to read comments 😁

Lateralus138 commented 1 year ago

Came to read comments 😁

Lol That's why I follow this thread...

dfault-user commented 1 year ago

Please.. Please Stop... I have had Enough Of This Necro Bumping.....

Lateralus138 commented 1 year ago

Please.. Please Stop... I have had Enough Of This Necro Bumping..... Thanks, Brandan Delafuente @.***

Up at the top of your screen you should have a button labeled [Unsubscribe].

s0urfruit commented 1 year ago

I’m starting to agree with Brandan. Why reply to an old, dead thread just to inform people you’ve read it…?

On Apr 10, 2023 at 7:12 PM, <Ian Pride @.***)> wrote:

Please.. Please Stop... I have had Enough Of This Necro Bumping..... Thanks, Brandan Delafuente @.***

Up at the top of your screen you should have a button labeled [Unsubscribe].

— Reply to this email directly, view it on GitHub (https://github.com/robertdavidgraham/masscan/issues/482#issuecomment-1502454032), or unsubscribe (https://github.com/notifications/unsubscribe-auth/APTZBRWUTJI4Q2OSM27PK2LXASHTXANCNFSM4MCUQYEA). You are receiving this because you commented.Message ID: @.***>

dfault-user commented 1 year ago

Please.. Please Stop... I have had Enough Of This Necro Bumping..... Thanks, Brandan Delafuente @.***

Up at the top of your screen you should have a button labeled [Unsubscribe].

I blindly subscribe to threads and don't expect them to be dredged back into my inbox by someone who read a Hacker News thread from a few years ago

I respect the help but it is not appropriate with the preceding context

Lamby777 commented 1 year ago

Please.. Please Stop... I have had Enough Of This Necro Bumping..... Thanks, Brandan Delafuente @.***

Up at the top of your screen you should have a button labeled [Unsubscribe].

I blindly subscribe to threads and don't expect them to be dredged back into my inbox by someone who read a Hacker News thread from a few years ago

I respect the help but it is not appropriate with the preceding context

ok.

Asday commented 8 months ago

@dfault-user is the weather getting warmer where you are yet? We've just had our first few sunny days! I'm enjoying it.

dfault-user commented 8 months ago

@dfault-user is the weather getting warmer where you are yet? We've just had our first few sunny days! I'm enjoying it.

it isn't too bad

dfault-user commented 8 months ago

i also additionally apologize for my previous conduct. not sure where that came from other than a place of disgruntlement

alexyavo commented 1 month ago

why u mad tho

odiferousmint commented 1 month ago

I am so glad comments are not disabled, makes me chuckle.