Re: Mapping Class A network ( any easy trick?)

From: Tim (tim-pentest_at_sentinelchicken.org)
Date: 02/09/05

  • Next message: Moonen, Ralph: "RE: Mapping Class A network ( any easy trick?)"
    Date: Wed, 9 Feb 2005 12:10:24 -0500
    To: "Moonen, Ralph" <Moonen.Ralph@kpmg.nl>
    
    

    > You might also want to manage expectations. Pentesting a full class A,
    > even given low population of the network will take you months. I think

    It can be done faster.

    Once upon a time I built a system with primarily shell/python/perl which
    used nmap and nbtscan to scan all RFC1918 addresses in a large company.
    With a LOT of timing optimization options, and a very focused set of
    ports we were scanning for, we were able to scan this many IPs in 2-3
    days. However, we had to distribute the scan across 8 linux machines,
    each of which ran 4 scanning threads in parallel. We didn't utilize any
    broadcasts, of course.

    It is a pain, and I don't recommend doing it unless you have a good
    reason, but it can be done with enough effort.

    The more recent versions of nmap supposedly has a more efficient
    scanning engine. Definately use the newest stuff.

    tim

    ps- Our scanning network could scan 300+ IPs/sec on average (majority of
    IPs didn't have hosts, of course) and during the scan, a few older
    firewalls tipped over. Be careful.


  • Next message: Moonen, Ralph: "RE: Mapping Class A network ( any easy trick?)"

    Relevant Pages

    • Re: Nmap scanning speed
      ... > I have to scan a large network. ... is it possible to get good port scanning speed of over 700 ports per second from nmap? ...
      (Pen-Test)
    • Question about "guaranteed delivery"
      ... Currently we have a three-layered network, ... messages to the content scanning devices. ... What we need in short is some sort of black box/software solution/method to ... or do some sort of manual delivery. ...
      (Security-Basics)
    • Re: Whats going on here?
      ... >upstream path portscanning, using source port 80 to fool misconfigured ... Three scenarios, both based on the facts that ZoneAlarm is host-based, ... Scenarion #1: Someone port scanning your system: ... Someone external to your network would receive no ...
      (Incidents)
    • RE: Online Scanning Services Vrs. Stand Alone Applications
      ... online scanning might bee seen just as external ... vulnerability scanning outsourcing, ... >> setup a nessus client at various parts of your network ...
      (Pen-Test)
    • RE: Online Scanning Services Vrs. Stand Alone Applications
      ... someone managing your scanning for you or not". ... technical comparison of the scanners. ... network from running the same attacks with a standalone application on the ... > and have those remote agents send back the findings to the ...
      (Pen-Test)