<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/css" href="/stylesheets/rss.css"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">
  <channel>
    <title>ClearNet Security: Trying out unicornscan</title>
    <link>http://blog.clearnetsec.com/articles/2007/10/14/trying-out-unicornscan</link>
    <language>en-us</language>
    <ttl>40</ttl>
    <description></description>
    <item>
      <title>Trying out unicornscan</title>
      <description>&lt;p&gt;We&#8217;ve hit a new high.  We&#8217;ve soaked ourselves in a bandwidth bath on behalf of a client whom would like us to discover active services across a range of six public /16 blocks plus some scattered /17s, /24s, etc.  The range is close to a total of 400,000 IPs.  
&lt;/p&gt;
&lt;p&gt;
We started out with five dual Xeon systems running 20 to 40 instances of nmap, each tuned, and each instance targeting 64 IPs.  This client wants the job completed in weeks, so we decided it was a good time to get more experience with unicornscan.
&lt;/p&gt;
&lt;p&gt;
By luck, we tapped into a Danish provider that is allowing us to push 55Mbits/s.  I have no idea how much that amount of bandwidth would normally cost, especially if sustaining it 24x7 for a few weeks, but I&#8217;m guessing it is way over $10,000.  Our client would allow us to go up to 100Mbits/s, alas, our luck doesn&#8217;t go that far.  
&lt;/p&gt;
&lt;p&gt;
Anyway, we now have faster dual-core systems each pushing ~25 Mbits/s via &lt;a href="http://www.unicornscan.org/"&gt;unicornscan&lt;/a&gt; like so:
&lt;/p&gt;
&lt;p&gt;
&lt;blockquote&gt;
sudo nohup /usr/local/bin/unicornscan -mT -p &#8211;r25000 -vv xxx.zz.0.0/16:a -w unicorn.output.for.xxx.zz..0.0.fullTCP &gt; unicorn.output.fullTCP &amp;
&lt;/blockquote&gt;
&lt;/p&gt;
&lt;p&gt;
We have lots of results from nmap; so far unicornscan is matching the nmap results.  Having the ability to specify packets per second with unicornscan is super nice.
&lt;/p&gt;
&lt;p&gt;
We&#8217;ll create a follow up post on how all our scanning worked out on this gig when we&#8217;re finished (sometime in late November).


</description>
      <pubDate>Sun, 14 Oct 2007 22:10:00 -0600</pubDate>
      <guid isPermaLink="false">urn:uuid:41de7625-dc6f-4304-bd0f-07fd9f49eca1</guid>
      <author>tate@ClearNetSec.com (Tate Hansen)</author>
      <link>http://blog.clearnetsec.com/articles/2007/10/14/trying-out-unicornscan</link>
      <category>nmap</category>
      <category>port  scanning</category>
      <category>ClearNet</category>
      <category>ClearNet Security</category>
      <category>Tate Hansen</category>
      <category>unicornscan</category>
    </item>
  </channel>
</rss>
