<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/css" href="/stylesheets/rss.css"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">
  <channel>
    <title>ClearNet Security: Follow-up on using unicornscan for a big scan (400,000+ public IPs)</title>
    <link>http://blog.clearnetsec.com/articles/2007/12/27/follow-up-on-using-unicornscan-for-a-big-scan-400-000-public-ips</link>
    <language>en-us</language>
    <ttl>40</ttl>
    <description></description>
    <item>
      <title>Follow-up on using unicornscan for a big scan (400,000+ public IPs)</title>
      <description>&lt;p&gt;I&#8217;m happy to report our growing experience using unicornscan for large discovery sweeps is a positive one.  Our confidence in using this tool has increased and it is now our preferred weapon of choice for scanning large IP swaths.
&lt;/p&gt;
&lt;p&gt;
&lt;b&gt;To recap:&lt;/b&gt;  We performed a sweep of 400,000+ public IPs across multiple continents by configuring the scans to do a full TCP port scan of each IP, sustained ~55 Mbits/s using between 3 and 5 systems, and completed it in a matter of days.  
&lt;/p&gt;
&lt;p&gt;
This is pretty good considering by sending two SYN probes per port it meant sending ~52.5 billion packets and producing some 3 Terabytes of data. 
&lt;/p&gt;
&lt;p&gt;
Nmap is often our preferred tool, and we used it to spot check our results with unicornscan, but from now on it will come down to the details of the gig to make the choice.
&lt;/p&gt;
&lt;p&gt;
&lt;i&gt;&lt;b&gt;Tech note:&lt;/b&gt;  We avoided problems with table overflows and other like issues by placing the systems directly on the internet and with iptables turned off.&lt;/i&gt;


</description>
      <pubDate>Thu, 27 Dec 2007 12:36:00 -0700</pubDate>
      <guid isPermaLink="false">urn:uuid:bb1d8624-361f-4fca-9777-466bfd9d4124</guid>
      <author>tate@ClearNetSec.com (Tate Hansen)</author>
      <link>http://blog.clearnetsec.com/articles/2007/12/27/follow-up-on-using-unicornscan-for-a-big-scan-400-000-public-ips</link>
      <category>nmap</category>
      <category>scanning</category>
      <category>security</category>
      <category>port  scanning</category>
      <category>ClearNet</category>
      <category>ClearNet Security</category>
      <category>Tate Hansen</category>
      <category>unicornscan</category>
    </item>
  </channel>
</rss>
