Robert Graham: Counting the Internet With masscan
In September 2013, Robert Graham announced that he could knock on every door on the internet in just under three minutes.
The tool was masscan, and for more than a decade it's been how researchers, and plenty of attackers, take a census of the whole internet: how many machines still answer on a vulnerable port, how many are still bleeding after Heartbleed, how many nobody has patched.
By then Graham had already built the first intrusion prevention system most people ever installed, sold his company to the biggest name in the business and given the world the word "sidejacking." He's also, by his own account, still angry that nobody gave him credit for stopping a worm in 2003.
Robert Graham at a Glance
- Graham says he learned hacking "as a toddler from his grandfather, a WW-II codebreaker," and wrote his first intrusion detection system in the mid-1990s to catch copycats of the Morris worm.
- He co-founded Network ICE as CTO and chief architect. Its BlackICE product ran as a desktop defender and as a network appliance, and Internet Security Systems bought the company in 2001.
- At ISS he was chief scientist. When the Slammer worm hit on January 25, 2003, he says BlackICE caught it while Snort-style tools failed.
- By 2007 he'd co-founded Errata Security with David Maynor. That August he released Hamster and Ferret and demonstrated "sidejacking," stealing web logins over open Wi-Fi.
- In July 2013 he started masscan. On September 14, 2013, he reported scanning the entire internet in under three minutes at 25 million packets per second from a desktop PC.
- The day after Heartbleed was disclosed in April 2014, he scanned the internet and counted 615,268 vulnerable servers.
- He went on to scan for Shellshock, cracked the password on Lenovo's Superfish certificate, and still maintains masscan, whose code was updated this month.
The Life of Robert Graham
Graham's Early Years
Robert Graham's conference biographies have always opened with the same line: he learned hacking as a toddler from his grandfather, a codebreaker in the Second World War.
His first intrusion detection system, written in the mid-1990s, was built to catch copycats of the 1988 Morris worm. He'd spend the next decade arguing that the way everyone else detected intrusions was wrong.
Network ICE and BlackICE
Graham went on to co-found Network ICE, serving as its CTO and chief architect, and wrote BlackICE, an intrusion detection and prevention system that ran both as a desktop program and as a network appliance. The desktop version gave small offices and home users what ISS later called "enterprise-strength security," and for many of them it was the first firewall they ever installed.
Internet Security Systems bought Network ICE in 2001 and sold BlackICE PC Protection under its own name. Graham became ISS's chief scientist.
Still Bitter About Slammer
On January 25, 2003, the Slammer worm tore through the internet's SQL servers. Twenty years later, to the day, Graham was still fuming about it.
"When Slammer hit, Snort and Snort-like products failed. Mine succeeded extremely well," he wrote on the anniversary. "Yet, I didn't get the credit for this."
Most detectors had no signature for the worm and reported a "UDP flood," so many people thought they were watching a denial-of-service attack; BlackICE, he wrote, "correctly identified the vulnerability being exploited" as a SQL buffer overflow. His technology was "radically different," built on a custom poll-mode driver instead of interrupts, and "the thing that makes me angry is that I couldn't explain the differences to the community because they weren't technical enough."
He called the post "me venting my bitterness and get off my lawn!!" It's also one of the clearest explanations of how BlackICE actually worked that anyone has written.
Sidejacking
By 2007 Graham had struck out on his own, co-founding Errata Security with David Maynor as CTO. The firm did consulting and product testing, but it became famous for a demo.
On August 5, 2007, Graham released Hamster and Ferret, a pair of tools that sniffed session cookies out of the air on an open Wi-Fi network and dropped them into the attacker's browser, so he was simply logged in as the victim. He called it sidejacking. "This isn't really 'new' in theory," he admitted, but watching Gmail accounts fall over at Black Hat made the point in a way no paper had.
The fix was as obvious as it was slow to arrive: encrypt the whole session, not just the login page. Errata kept the pressure on, and in August 2008 Graham and Maynor were back at DEF CON with new penetration techniques and updated tools.
The Entire Internet in Three Minutes
Graham created the masscan repository on July 28, 2013. On September 13 he posted "We scanned the Internet for port 22." The next day came the headline: "Masscan: the entire Internet in 3 minutes."
The numbers were absurd for the time. A "typical quad-core desktop processor" with a dual-port 10-gigabit Ethernet card could "transmit 25 million packets/second, which is fast enough to scan the entire Internet in just under 3 minutes."
The trick was to stop asking the operating system for help. Masscan uses "asynchronous transmission" and, as the documentation warns, "its own ad hoc TCP/IP stack," firing probes without waiting for replies and sorting out the answers as they trickle back.
The README still describes it as "an Internet-scale port scanner" that "can scan the entire Internet in under 5 minutes, transmitting 10 million packets per second, from a single machine," with usage "similar to nmap, the most famous port scanner." Anyone who knew Nmap could run it in a minute. Many did.
Heartbleed by the Numbers
When the Heartbleed bug in OpenSSL became public on April 7, 2014, the first question was how bad it was. Graham answered it with masscan.
On April 8 he published a how-to, "Using masscan to scan for heartbleed vulnerability," and ran the scan that night. The results came the next morning: of 28,581,134 machines answering with a valid SSL connection, 615,268 were vulnerable, and another 330,531 supported the heartbeat feature without being exploitable. "600,000 servers vulnerable to heartbleed" became the number every news story used.
He followed up with "What the heartbleed bug looks like on the wire" and an essay arguing that the real culprit was pointer arithmetic. That August he and two collaborators presented "Mass Scanning the Internet: Tips, Tricks, Results" at DEF CON 22, a how-to for a generation of researchers who now had the same power he did.
The pattern repeated with every big bug. When Shellshock hit in September 2014 he scanned the internet for it and then picked apart the offending bash source line by line.
In February 2015, when Lenovo laptops were found shipping with Superfish adware, it took him "about 3 hours to reverse engineer the Lenovo/Superfish certificate and crack the password." The password was "komodia," and he published a demonstration of how it could be used against victims.
Graham Today
Graham still writes, less often: on memory-safe C in 2023 and 2024, on the myths of RISC processors, on building a tiny home server. His most-read post is still the one titled "You are committing a crime right now," an argument that the Computer Fraud and Abuse Act is written so broadly that reading his blog could qualify. He posts as @ErrataRob, and his GitHub profile sums up the career in six words: "I created BlackICE, sidejacking, masscan."
Masscan, meanwhile, has more than 26,000 stars on GitHub and had its latest commit on October 5, 2026. The man who first counted the whole internet in three minutes is still keeping the counter running.
Robert Graham: The Man Who Counts the Internet
Most security researchers find one thing. Graham built tools that find everything, all at once, and then told you what the numbers meant.
He's never been shy about it, and the record shows he was usually right, from worms in 2003 to heartbeats in 2014.
There are about four billion IPv4 addresses. He's knocked on all of them, more than once.
QUOTE:
"Amateurs hack systems, professionals hack people."