Skip to main content

Alternative Network Scans

Generate Target List

Linux

ip="10.9.9.0"; cidr=24; IFS=. read -r i1 i2 i3 i4 <<< "$ip"; raw=$(( (1 << (32 - cidr)) - 2 )); base_ip=$(( (i1<<24) + (i2<<16) + (i3<<8) + i4 )); network=$(( base_ip & (0xFFFFFFFF << (32 - cidr)) )); for i in $(seq 1 $raw); do ip_calc=$((network + i)); printf "%d.%d.%d.%d\n" $(( (ip_calc >> 24) & 255 )) $(( (ip_calc >> 16) & 255 )) $(( (ip_calc >> 8) & 255 )) $(( ip_calc & 255 )); done | awk '{ print $1 }' > targets.txt &

Given an IP address and CIDR bitmask, calculate a full set of IP addresses in the network

Ping Scan

Linux

Partially developed with the assistance of Bing CoPilot. It's not perfect, but it'll do the job.

ip="10.9.9.0"; cidr=24; IFS=. read -r i1 i2 i3 i4 <<< "$ip"; raw=$(( (1 << (32 - cidr)) - 2 )); base_ip=$(( (i1<<24) + (i2<<16) + (i3<<8) + i4 )); network=$(( base_ip & (0xFFFFFFFF << (32 - cidr)) )); for i in $(seq 1 $raw); do ip_calc=$((network + i)); printf "%d.%d.%d.%d\n" $(( (ip_calc >> 24) & 255 )) $(( (ip_calc >> 16) & 255 )) $(( (ip_calc >> 8) & 255 )) $(( ip_calc & 255 )); done | awk '{ system("bash -c '"'"'ping -c 1 -w 1 " $1 " | grep \"bytes from\" &'"'"' ; sleep 0.1"); }'

One-liner to ping loop through IP addresses and ping given a CIDR block

Port Scan

Linux

Single Target

awk is super fast thanks to multi-threaded support

( target="10.9.9.11" && output_file="awk_scan_${target}.txt" && ([ -f "$output_file" ] && : > "$output_file" || touch "$output_file") && cpu_count=$(grep -c ^processor /proc/cpuinfo 2>/dev/null || echo 2) && echo "Scan Started: $(date +%FT%T%z)" > "$output_file" && seq 1 65535 | shuf | xargs -P $((cpu_count * 10)) -I {} /bin/sh -c 'timeout 0.5 nc -nz "$target" {} >/dev/null 2>&1 && echo "$(date +%FT%T%z) -- tcp/{} is open on ${target}" >> ${output_file}' ; echo "Scan Finished: $(date +%FT%T%z)" >> "$output_file" ) &

nc

( target="10.9.9.11" && output_file="awk_scan_${target}.txt" && ([ -f "$output_file" ] && : > "$output_file" || touch "$output_file") && cpu_count=$(grep -c ^processor /proc/cpuinfo 2>/dev/null || echo 2) && echo "Scan Started: $(date +%FT%T%z)" > "$output_file" && seq 1 65535 | shuf | xargs -P $((cpu_count * 10)) -I {} /bin/bash -c "/bin/bash -c \"(timeout 0.3 echo 1 > /dev/tcp/$target/{}) >/dev/null 2>&1\" && echo \"\$(date +%FT%T%z) -- tcp/{} is open on ${target}\" >> ${output_file}" ; echo "Scan Finished: $(date +%FT%T%z)" >> "$output_file" ) &

bash builtin - /dev/tcp

Multi Target

These one-liners have a long list of ports instead using seq 1 65535. I used the list_nmap_top_ports function to output the top 500 ports like so: list_nmap_top_ports tcp 500 | paste -s -d ' ' - | shuf and pasted them into the command line. I opted to top 500 since I'm scanning a list of targets.

( input_file="targets.txt" ; export output_file="awk_scan_batch.txt" ; : > "$output_file" ; cpu_count=$(grep -c ^processor /proc/cpuinfo 2>/dev/null || echo 2) ; echo "Scan Started: $(date +%FT%T%z)" > "$output_file" ; xargs -P "$((cpu_count * 2))" -a "$input_file" -I {} /bin/sh -c 'echo "1 3 4 6 7 9 13 17 19 20 21 22 23 24 25 26 30 33 37 42 49 53 79 80 81 82 83 85 88 90 100 106 110 111 113 119 135 139 143 144 146 161 163 179 199 211 222 254 255 264 280 306 311 340 366 389 407 427 443 444 445 464 465 497 500 512 513 514 515 541 543 544 548 554 563 587 593 625 631 636 646 648 705 711 787 800 808 873 880 888 900 901 902 912 987 990 992 993 995 999 1000 1002 1022 1023 1024 1025 1026 1027 1028 1029 1030 1031 1032 1033 1034 1035 1036 1037 1038 1039 1040 1041 1042 1043 1044 1045 1046 1047 1048 1049 1050 1051 1052 1053 1054 1055 1056 1057 1058 1059 1060 1061 1062 1063 1064 1065 1066 1067 1068 1069 1070 1071 1072 1073 1074 1075 1077 1078 1079 1080 1081 1082 1083 1085 1086 1088 1093 1094 1096 1097 1098 1099 1100 1104 1106 1107 1108 1110 1111 1148 1169 1218 1234 1248 1272 1310 1311 1352 1433 1494 1500 1501 1503 1521 1666 1687 1700 1717 1718 1720 1723 1755 1761 1783 1801 1840 1863 1864 1900 1935 1947 1998 2000 2001 2002 2003 2004 2005 2006 2007 2008 2009 2010 2030 2049 2065 2100 2103 2105 2107 2119 2121 2135 2144 2160 2161 2190 2222 2260 2301 2381 2383 2399 2401 2492 2500 2525 2601 2602 2604 2605 2607 2701 2702 2717 2718 2809 2811 2869 2875 2967 3000 3001 3005 3017 3031 3052 3071 3128 3211 3260 3268 3269 3283 3300 3301 3306 3323 3325 3333 3351 3367 3389 3404 3476 3551 3580 3659 3689 3690 3703 3766 3784 3801 3827 3986 3998 4000 4001 4002 4003 4045 4126 4129 4242 4443 4444 4449 4662 4899 5000 5001 5002 5003 5004 5009 5030 5050 5051 5060 5100 5101 5102 5120 5190 5214 5222 5225 5226 5269 5357 5414 5431 5432 5500 5550 5555 5566 5631 5633 5666 5679 5718 5800 5801 5810 5825 5877 5900 5901 5902 5910 5911 5925 5959 5960 5961 5962 5985 5986 5987 5988 5989 6000 6001 6002 6004 6005 6059 6101 6112 6123 6129 6156 6389 6543 6580 6646 6666 6667 6788 6789 6881 6901 6969 7000 7001 7019 7070 7100 7106 7200 7625 7627 7741 7777 7778 7911 7937 7938 8000 8001 8002 8007 8008 8009 8010 8021 8031 8080 8081 8082 8083 8084 8085 8086 8087 8088 8089 8181 8192 8193 8194 8222 8291 8333 8400 8402 8443 8600 8649 8651 8652 8701 8873 8888 8899 9000 9001 9009 9050 9071 9090 9100 9101 9102 9207 9415 9535 9593 9594 9595 9876 9999 10000 10001 10010 10243 12000 12345 13782 13783 14238 15000 16992 16993 20005 20828 23502 27000 32768 32769 32770 32771 32772 32773 32774 32775 33354 35500 42510 45100 49152 49153 49154 49155 49156 49157 49999 50000 50001 51103 52822 52869 55555 55600 64623 64680 65000 65389" | tr " " "\n" | shuf | xargs -P $((cpu_count * 4)) -I @ /bin/sh -c '"'"'timeout 0.5 nc -nz {} @ >/dev/null 2>&1 && echo "$(date +%FT%T%z) -- tcp/@ is open on {}" >> ${output_file}'"'"'' ; echo "Scan Finished: $(date +%FT%T%z)" >> "$output_file" ) &

nc - using list of IP addresses in targets.txt

( input_file="targets.txt" ; output_file="awk_scan_batch.txt" ; : > "$output_file" ; cpu_count=$(grep -c ^processor /proc/cpuinfo 2>/dev/null || echo 2) ; echo "Scan Started: $(date +%FT%T%z)" > "$output_file" ; xargs -P "$((cpu_count * 2))" -a "$input_file" -I {} /bin/bash -c 't="$1"; o="$2"; p="$3"; echo "1 3 4 6 7 9 13 17 19 20 21 22 23 24 25 26 30 33 37 42 49 53 79 80 81 82 83 85 88 90 100 106 110 111 113 119 135 139 143 144 146 161 163 179 199 211 222 254 255 264 280 306 311 340 366 389 407 427 443 444 445 464 465 497 500 512 513 514 515 541 543 544 548 554 563 587 593 625 631 636 646 648 705 711 787 800 808 873 880 888 900 901 902 912 987 990 992 993 995 999 1000 1002 1022 1023 1024 1025 1026 1027 1028 1029 1030 1031 1032 1033 1034 1035 1036 1037 1038 1039 1040 1041 1042 1043 1044 1045 1046 1047 1048 1049 1050 1051 1052 1053 1054 1055 1056 1057 1058 1059 1060 1061 1062 1063 1064 1065 1066 1067 1068 1069 1070 1071 1072 1073 1074 1075 1077 1078 1079 1080 1081 1082 1083 1085 1086 1088 1093 1094 1096 1097 1098 1099 1100 1104 1106 1107 1108 1110 1111 1148 1169 1218 1234 1248 1272 1310 1311 1352 1433 1494 1500 1501 1503 1521 1666 1687 1700 1717 1718 1720 1723 1755 1761 1783 1801 1840 1863 1864 1900 1935 1947 1998 2000 2001 2002 2003 2004 2005 2006 2007 2008 2009 2010 2030 2049 2065 2100 2103 2105 2107 2119 2121 2135 2144 2160 2161 2190 2222 2260 2301 2381 2383 2399 2401 2492 2500 2525 2601 2602 2604 2605 2607 2701 2702 2717 2718 2809 2811 2869 2875 2967 3000 3001 3005 3017 3031 3052 3071 3128 3211 3260 3268 3269 3283 3300 3301 3306 3323 3325 3333 3351 3367 3389 3404 3476 3551 3580 3659 3689 3690 3703 3766 3784 3801 3827 3986 3998 4000 4001 4002 4003 4045 4126 4129 4242 4443 4444 4449 4662 4899 5000 5001 5002 5003 5004 5009 5030 5050 5051 5060 5100 5101 5102 5120 5190 5214 5222 5225 5226 5269 5357 5414 5431 5432 5500 5550 5555 5566 5631 5633 5666 5679 5718 5800 5801 5810 5825 5877 5900 5901 5902 5910 5911 5925 5959 5960 5961 5962 5985 5986 5987 5988 5989 6000 6001 6002 6004 6005 6059 6101 6112 6123 6129 6156 6389 6543 6580 6646 6666 6667 6788 6789 6881 6901 6969 7000 7001 7019 7070 7100 7106 7200 7625 7627 7741 7777 7778 7911 7937 7938 8000 8001 8002 8007 8008 8009 8010 8021 8031 8080 8081 8082 8083 8084 8085 8086 8087 8088 8089 8181 8192 8193 8194 8222 8291 8333 8400 8402 8443 8600 8649 8651 8652 8701 8873 8888 8899 9000 9001 9009 9050 9071 9090 9100 9101 9102 9207 9415 9535 9593 9594 9595 9876 9999 10000 10001 10010 10243 12000 12345 13782 13783 14238 15000 16992 16993 20005 20828 23502 27000 32768 32769 32770 32771 32772 32773 32774 32775 33354 35500 42510 45100 49152 49153 49154 49155 49156 49157 49999 50000 50001 51103 52822 52869 55555 55600 64623 64680 65000 65389" | tr " " "\n" | shuf | xargs -P "$p" -I @ /bin/bash -c '\''pt="$1"; tg="$2"; out="$3"; (timeout 0.3 /bin/bash -c "echo 1 > /dev/tcp/$tg/$pt") >/dev/null 2>&1 && echo "$(date +%FT%T%z) -- tcp/$pt is open on $tg" >> "$out"'\'' _ @ "$t" "$o"' _ {} "$output_file" "$((cpu_count * 4))" ; echo "Scan Finished: $(date +%FT%T%z)" >> "$output_file" ) &

bash builtin - /dev/tcp - using list of IP addresses in targets.txt

For Loop

for port in {1..65535} ; do nc -w 1 -nz 10.9.9.11 $port && echo "Port ${port} is open" ; done > for_scan.txt &

nc

for port in {1..65535} ; do /bin/bash -c "timeout 0.5 echo 1 > /dev/tcp/10.9.9.11/${port} && echo \"Port ${port} is open\"" 2>/dev/null; done > for_scan.txt &

bash builtin - /dev/tcp

Windows

PowerShell

Custom Script

Compatible with PowerShell v5+

Test-TcpPort: https://github.com/0xBEN/PSToolbox/blob/master/Public/ps1/Test-TcpPort.ps1