masscan: High-Performance IP Port Scanner
masscan is an asynchronous, stateless, TCP port scanner that can scan the entire internet in under 6 minutes, transmitting 10 million packets per second. It’s often referred to as the “Internet-scale port scanner” due to its incredible speed and ability to discover open ports across vast networks. Unlike traditional scanners like Nmap, which perform a full TCP handshake, masscan’s stateless design allows it to operate much faster, making it ideal for large-scale reconnaissance.
Basic Usage: Full Port Scan with Rate Limit
This command performs a full port scan (0-65535) on a target, limiting the packet transmission rate.
masscan <target> -p0-65535 --rate 10000Command Breakdown:
masscan: Invokes themasscantool.<target>: The IP address, IP range (e.g.,192.168.1.0/24), or hostname to scan.-p0-65535: Specifies the port range to scan.0-65535covers all possible TCP ports.--rate 10000: Limits the packet transmission rate to 10,000 packets per second. This is crucial to avoid overwhelming networks or getting blocked by firewalls. Adjust this value based on network conditions and permissions.
Scanning Specific Ports or Ranges
You can specify individual ports or a list of port ranges.
Example: Scanning Multiple Specific Ports
masscan <target> -p80,443,22Example: Scanning a Discontinuous Range
masscan <target> -p1-1000,8000-9000Scanning an IP Range
masscan excels at scanning entire subnets or larger IP blocks.
# Scan a C-class subnet for common web ports
masscan 192.168.1.0/24 -p80,443Other Useful Options
-oL <filename>: Output scan results in a simple list format.-oJ <filename>: Output scan results in JSON format.-oG <filename>: Output scan results in Greppable format.--banners: Attempts to grab service banners from open ports (can slow down the scan slightly).--source-ip <ip>: Specify the source IP address to use for scanning.--adapter-port <port>: Specify the source port to use for scanning.--adapter-ip <ip>: Specify the IP address of the network interface to bind to.
Disclaimer: masscan is a highly aggressive network scanning tool. Its use can generate significant network traffic and may be detected by intrusion detection systems (IDS/IPS). Always ensure you have explicit, written permission before scanning any network. Unauthorized scanning is illegal and unethical. This documentation is for educational and authorized security testing purposes only.