masscan: High-Performance IP Port Scanner

masscan is an asynchronous, stateless, TCP port scanner that can scan the entire internet in under 6 minutes, transmitting 10 million packets per second. It’s often referred to as the “Internet-scale port scanner” due to its incredible speed and ability to discover open ports across vast networks. Unlike traditional scanners like Nmap, which perform a full TCP handshake, masscan’s stateless design allows it to operate much faster, making it ideal for large-scale reconnaissance.

Basic Usage: Full Port Scan with Rate Limit

This command performs a full port scan (0-65535) on a target, limiting the packet transmission rate.

masscan <target> -p0-65535 --rate 10000

Command Breakdown:

  • masscan: Invokes the masscan tool.
  • <target>: The IP address, IP range (e.g., 192.168.1.0/24), or hostname to scan.
  • -p0-65535: Specifies the port range to scan. 0-65535 covers all possible TCP ports.
  • --rate 10000: Limits the packet transmission rate to 10,000 packets per second. This is crucial to avoid overwhelming networks or getting blocked by firewalls. Adjust this value based on network conditions and permissions.

Scanning Specific Ports or Ranges

You can specify individual ports or a list of port ranges.

Example: Scanning Multiple Specific Ports

masscan <target> -p80,443,22

Example: Scanning a Discontinuous Range

masscan <target> -p1-1000,8000-9000

Scanning an IP Range

masscan excels at scanning entire subnets or larger IP blocks.

# Scan a C-class subnet for common web ports
masscan 192.168.1.0/24 -p80,443

Other Useful Options

  • -oL <filename>: Output scan results in a simple list format.
  • -oJ <filename>: Output scan results in JSON format.
  • -oG <filename>: Output scan results in Greppable format.
  • --banners: Attempts to grab service banners from open ports (can slow down the scan slightly).
  • --source-ip <ip>: Specify the source IP address to use for scanning.
  • --adapter-port <port>: Specify the source port to use for scanning.
  • --adapter-ip <ip>: Specify the IP address of the network interface to bind to.

Disclaimer: masscan is a highly aggressive network scanning tool. Its use can generate significant network traffic and may be detected by intrusion detection systems (IDS/IPS). Always ensure you have explicit, written permission before scanning any network. Unauthorized scanning is illegal and unethical. This documentation is for educational and authorized security testing purposes only.