{"repo":"ivre/masscanned","free":true,"listed":false,"github":"https://github.com/ivre/masscanned","clone":"git clone https://github.com/ivre/masscanned.git","description":"Let's be scanned. A low-interaction honeypot focused on network scanners and bots. It integrates very well with IVRE to build a self-hosted alternative to GreyNoise.","language":"Rust","stars":140,"topics":["networking","udp","ipv6","ipv4","tcp","honeypot","low-interaction-honeypot","low-interaction","hacktoberfest","network-security"],"license":"GPL-3.0","category":"networking-infra","readme_excerpt":"Masscanned Masscanned (name inspired, of course, by masscan) is a network responder. Its purpose is to provide generic answers to as many protocols as possible, and with as few assumptions as possible on the client's intentions. Let them talk first. Just like masscan, masscanned implements its own, userland network stack, similarly to honeyd. It is designed to interact with scanners and opportunistic bots as far as possible, and to support as many protocols as possible. For example, when it receives network packets: masscanned answers to ARP who is-at with ARP is-at (for its IP addresses), masscanned answers to ICMP Echo Request with ICMP Echo Reply , masscanned answers to TCP SYN (any port) with TCP SYN/ACK on any port, masscanned answers to HTTP requests (any verb) over TCP/UDP (any port) with a HTTP 401 web page. Overview Masscanned currently supports most common protocols at layers 2-3-4, and a few application protocols. Network protocols ARP (answers to ARP requests) ICMP (answers to ping) ICMPv6 (answers to ND NS) TCP (answers to SYN and PUSH) Application protocols HTTP (answers to all verbs) SSH (answers to the client banner) STUN (answers to binding requests) SMB DNS (answers to IN/A queries) Try it locally On your host 1. Build masscanned 2. Create a new net namespace 3. Create veth between the two namespaces 4. Set IP on local veth to have a route for outgoing packets 5. Run masscanned in the namespace 6. With another terminal, send packets to masscanned In a Docker","default_branch":null,"files":null,"tree":[],"storefront":"/r/ivre","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/ivre/masscanned/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}