Background:
I was reading through Black Hat Go where the author presents a simple port scanner that uses go routines1:
package main
import (
"fmt"
"net"
)
func main() {
for i := 1; i <= 9000; i++ {
go func(j int) {
address := fmt.Sprintf("127.0.0.1:%d", j)
conn, err := net.Dial("tcp", address)
if err != nil {
return
}
conn.Close()
fmt.Printf("%d open\n", j)
}(i)
}
}
And then he mentions the following:
Scanning an excessive number of hosts or ports simultaneously may cause network or system limitations to skew your results.
To test it, I started 2 php servers2 on ports 8000 and 8500 and ran the above code to scan my local ports.
Each time it gave me inconsistent results. Sometimes it'd detect both the open ports, sometimes it would not.
Question:
Are the inconsistent results due to some limitations in TCP?
Is there a way to calculate the optimal number of ports that can be scanned in parallel so that the results remain correct?
Edit:
I seem to have missed out waitgroups in the above code.
Besides that, is there anything else (OS limitation or protocol limitation) that prevents concurrent port scans over a large range?