MASSCAN
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Interactive tool: Nmap Command Builder
OVERVIEW#
Masscan is the fastest Internet port scanner. It can scan the entire Internet in under 6 minutes, transmitting 10 million packets/sec. Uses asynchronous transmission for extreme speed.
BASIC USAGE#
masscan <target> -p <ports> # Basic scan masscan <target> -p80,443 # Scan specific ports masscan <target> -p1-65535 # Scan all ports
TARGET SPECIFICATION#
masscan 192.168.1.0/24 -p80 # Scan subnet
masscan 10.0.0.0/8 -p80 # Scan /8 network
masscan 192.168.1.1 -p1-1024 # Scan single host
masscan -iL targets.txt -p80 # Read targets from file
masscan 192.168.1.0/24 --excludefile exclude.txt -p80
# Exclude hosts from file
PORT SPECIFICATION#
masscan <target> -p80 # Single port masscan <target> -p80,443 # Multiple ports masscan <target> -p80-100 # Port range masscan <target> -p0-65535 # All ports masscan <target> -pU:53 # UDP port masscan <target> -pU:53,T:80 # Mixed TCP/UDP masscan <target> --top-ports 100 # Top 100 ports
RATE CONTROL#
masscan <target> -p80 --rate 1000
# 1000 packets/sec
masscan <target> -p80 --rate 10000
# 10000 packets/sec
masscan <target> -p80 --rate 100000
# 100000 packets/sec (be careful!)
masscan <target> -p80 --max-rate 1000000
# Max rate limit
BANNER GRABBING#
masscan <target> -p80 --banners # Grab service banners
masscan <target> -p80 --banners --source-port 61000
# Banner grab with source port
OUTPUT OPTIONS#
masscan <target> -p80 -oL out.txt # List format (default) masscan <target> -p80 -oX out.xml # XML format masscan <target> -p80 -oG out.gnmap # Greppable format masscan <target> -p80 -oJ out.json # JSON format masscan <target> -p80 -oB out.bin # Binary format
NETWORK OPTIONS#
masscan <target> -p80 --adapter-ip 192.168.1.100
# Set source IP
masscan <target> -p80 --adapter-port 61000
# Set source port
masscan <target> -p80 --adapter-mac 00:11:22:33:44:55
# Set source MAC
masscan <target> -p80 -e eth0 # Set network interface
masscan <target> -p80 --router-mac 00:11:22:33:44:55
# Set gateway MAC
TIMING & RETRY#
masscan <target> -p80 --retries 2
# Number of retries (default: 0)
masscan <target> -p80 --wait 5 # Seconds to wait for replies
masscan <target> -p80 --ttl 255 # Set TTL value
RESUME & CONFIG#
masscan --resume paused.conf # Resume interrupted scan
masscan -c masscan.conf # Load config file
masscan <target> -p80 --echo > config.conf
# Save current config
EXAMPLES#
# Quick scan of common web ports on a /24 masscan 192.168.1.0/24 -p80,443,8080,8443 --rate 1000 # Full port scan of single host masscan 192.168.1.1 -p0-65535 --rate 1000 # Scan with banner grabbing masscan 10.0.0.0/24 -p21,22,80,443 --banners --rate 500 # Large-scale scan with output masscan 10.0.0.0/8 -p80 --rate 100000 -oJ results.json # Scan top ports with exclude list masscan 192.168.0.0/16 --top-ports 100 --excludefile exclude.txt --rate 10000 # UDP scan for DNS masscan 10.0.0.0/24 -pU:53 --rate 500
NMAP COMPATIBILITY#
# Masscan uses similar syntax to nmap where possible # Key differences: # - No service detection (-sV equivalent uses --banners) # - No OS detection # - No scripting engine # - Uses --rate instead of -T timing # - Default is SYN scan only
NOTES#
- Requires root privileges - Uses custom TCP/IP stack (bypasses OS stack) - Can overwhelm networks - use appropriate --rate - Does NOT use OS network stack (no iptables needed) - Add iptables rule to prevent RST interference: iptables -A INPUT -p tcp --dport 61000 -j DROP - Binary output can be converted: masscan --readscan out.bin -oX out.xml - Pair with nmap for detailed service/version scanning