RE: Scanning - anyone got ball park timings?

From: Conan the Librarian (conan_the_librarian_at_adelphia.net)
Date: 05/29/03

  • Next message: Pete Herzog: "RE: Scanning - anyone got ball park timings?"
    To: "Mark Phillips" <mark@probably.co.uk>, <pen-test@securityfocus.com>
    Date: Thu, 29 May 2003 12:57:52 -0600
    
    

    I've done one or two scans in my time with a host of vendor's and open
    source tools. It seems that if you are doing a SANS Top Ten for 1700 hosts,
    your 16 hour time frame is a bit long. Let's assume that the scanner machine
    is not cpu max'ed and causing the delays.

    Your comment about "1700 hosts found" implies that you have set the scanner
    to look for hosts, instead of specifying a list or tight range. Searching
    for hosts usually involves some species of ICMP query or a connect attempt
    via TCP. Doing this is going to add time as you have a limited number of
    threads you can support at any one time and you must allow timeouts to occur
    on absent/down machines before you can add another. Try being more specific
    on your host list to avoid this. Also check out the default "host alive?"
    settings on the scanner- you may be trying to connect to multiple protocols
    or ports and not be aware of it.

    Another thing that can add lots of time to a simple scan is name resolution
    for each host found. Each resolution query is brief, but it does add up with
    large segments involved in the scan. Disable name resolution to avoid this
    problem.

    Finally, sniff a scan session and look for network problems, esp with
    congestion, time-outs, slow host responses and resolutions. Scanners are
    relatively noisy and the increased load may burden the host(s) scanned or
    some portion of the network. Any device causing issues should show up
    clearly in the trace file.

    If all else fails, a reliable standby is to break the scan into smaller
    segments and run them via cron or AT.

    Dr. Michael J Staggs

     -----Original Message-----
    From: Mark Phillips [mailto:mark@probably.co.uk]
    Sent: Thursday, May 29, 2003 7:27 AM
    To: pen-test@securityfocus.com
    Subject: Scanning - anyone got ball park timings?

    Hi,

    What are peoples experiences of time scales when scanning ranges of hosts?
    OK, so I know that's a "how long is a piece of string", but if people can
    say what sort of times they're getting for a given size of IP range and
    given type of scan, that would be helpful.

    I've been running a "SANS 20" policy scan from ISS Internet Scanner 7,
    across the Internet, and am seeing timings like 16 hours for 1700
    addresses found. Is this realistic? Is this quick or slow? If it's slow,
    do people have any hints and tips about how to speed up the whole process?

    Any pointers muchos appreciated.

    Cheers,

    --Mark

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: Pete Herzog: "RE: Scanning - anyone got ball park timings?"

    Relevant Pages

    • Re: Mandriva: Cant connect to ANY NTP server - Why?
      ... > I'm too bothered by the host 1.0.0.0. ... except to debug the name resolution using ... is name resolution failing only for ntpdate? ... ping or telnet, the question is if we get a response that shows the right ...
      (comp.os.linux.setup)
    • Re: Domain controller not found
      ... This takes name resolution out of the picture. ... You should also verify that F&P sharing is enabled and that a personal ... Just query the host that has the shares from a host ... >> username and password for the domain admin account. ...
      (microsoft.public.win2000.active_directory)
    • RE: DNS
      ... Troubleshooting TCP/IP - Verifying NetBIOS Name Resolution ... Host Name Resolution ... Microsoft Global Technical Support Center ... I can ping it and even connect to ...
      (microsoft.public.windowsxp.general)
    • Re: 127.0.1.1 in /etc/hosts, why?
      ... Is which a bug? ... If domain name resolution is really slowed, ... host name was split off to 127.0.1.1, ... applications happy and running smoothly you simple need to add the host ...
      (Ubuntu)
    • Re: W2K PC much slower after joining domain and applying SP4
      ... But if my SBS03 domain is natively using host name resolution, ... Implementing NetBIOS name resolution as your ... >> obtained via DHCP from the server. ...
      (microsoft.public.windows.server.sbs)