lolwut. It would never ever ever take 2 to 3 years for a port scan. On a 56k modem it only takes a couple min. A DDoS attack isn't even in the same realm as actually owning a system. If you knew what I know about the heartland attack lol you wouldn't even be saying what you're saying. It was a REALLY REALLY simple exploit and you'd be loling all over if you knew what it was.
Hmm. Obviously you can do it within minutes/seconds. But if you port scan a well secured system IDS will detect it very simply and alert the admins. So, in order to attack well secured systems port scans are done for months to years in order to avoid detection. I don't mean the straight forward port scanning (port scanning google.com, etc) because such servers get a lot of port scans daily and it's not going to be an issue. But, when you port scan a system that's secured behind some layers you have to do it without their knowledge(Lets say that you've managed to find access to an internal server of google then you have to do it secretly). Usually this is how hackers break, they penetrate the perimeter first and carefully find the next level vulnerabilities.
Last edited: