TCP port scanner in a single binary.
go build -o netscan ../netscan -host 192.168.1.1
./netscan -host 192.168.1.0/24 -ports 22,80,443
./netscan -host 192.168.1.1 -ports 1-1024
./netscan -file targets.txt
cat targets.txt | ./netscanTargets can come from any combination of -host, -file, and stdin (when piped/redirected); duplicates are dropped automatically. A CIDR target is expanded into its individual host addresses (network and broadcast addresses are excluded when the range has more than two hosts).
$ ./netscan -help
Usage of ./netscan:
-file string
File with one host/IP/CIDR per line (e.g. targets.txt)
-host string
Host, IP, or CIDR range to scan (e.g. 192.168.1.0/24)
-output string
Save results to this file in real time (e.g. results.txt)
-ports string
Ports: ranges and/or comma-separated (e.g. 22,80,443 | 1-1024 | 22,80,1000-2000) (default "80,23,443,21,22,25,3389,110,445,139,143,53,135,3306,8080,1723,111,995,993,5900,1025,587,8888,199,1720,465,548,113,81,6001,10000,514,5060,179,1026,2000,8443,8000,32768,554,26,1433,49152,2001,515,8008,49154,1027,5666,646,5000,5631,631,49153,8081,2049,88,79,5800,106,2121,1110,49155,6000,513,990,5357,427,49156,543,544,5101,144,7,389,8009,3128,444,9999,5009,7070,5190,3000,5432,1900,3986,13,1029,9,5051,6646,49157,1028,873,1755,2717,4899,9100,119,37")
-timeout duration
Connection timeout per port (default 1s)
-workers int
Number of concurrent TCP workers (default 100)
At least one of -host, -file, or piped stdin must supply a target, or the program exits with an error.
Results are appended to the file in real time as open ports are found, one per line:
192.168.1.1:22
192.168.1.1:80
192.168.1.1:443
# scan default ports on a single host
./netscan -host 192.168.1.1
# scan a subnet on specific ports and save results
./netscan -host 192.168.1.0/24 -ports 22,80,443 -output results.txt
# read targets from a file
./netscan -file targets.txt -ports 1-1024
# full range with more workers and a custom timeout
./netscan -host 10.0.0.5 -ports 1-65535 -workers 500 -timeout 500ms