I see things that look alarmingly like industrial control. Who leaves wide open unpassworded VNC?

I can only guess it's people who think of their IP as a password. Like, who's going to guess the IP, right.

I have to ask, how does one come across such open servers? Do you just try common ports on random IP addresses until you find one that works?

another, newer alternative is https://github.com/robertdavidgraham/masscan

note that doing this is a very good way to get angry letters from your ISP