Mailing List Archive
tlug.jp Mailing List tlug archive tlug Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][tlug] Port Knocking . . . . . . . . . . . . . . . . . . . . . (was Re: Blocking bad sshd bruteforce attempt)
- Date: Tue, 11 Jul 2006 22:50:03 -0400
- From: Jim <jep200404@example.com>
- Subject: [tlug] Port Knocking . . . . . . . . . . . . . . . . . . . . . (was Re: Blocking bad sshd bruteforce attempt)
- References: <78d7dd350607102243j32a8b5f1od4f1ff847e096de0@example.com> <44B33B8C.8060902@example.com> <20060711114359.d0d5a0bf.godwin.stewart@example.com> <d8fcc0800607111630q6f11d1e0r8373602905b39520@example.com> <1152697966.18345.17.camel@example.com> <Pine.BSF.4.58.0607112159220.88730@example.com>
Joe Larabell wrote: > I recall ... a daemon on the target machine to watch for SYN > packets to some combination of ports in sequence > and *only then* would it open up a hole in the firewall. Indeed. The name for that technique is called port knocking. > This is still security by obscurity Indeed. > but... it's so incredibly obscure that the probability of NMAP > hitting this combination completely by accident is microscopic. Indeed. Just because it NMAP would not open it by accident, doesn't mean that there aren't other non-accidental ways. > If you combine this with complete firewall blockage for random > port scans on other ports, you would also make it difficult to > find the port combination by trial-and-error. Indeed. Hence replay attacks. > (too lazy to google it right now) Indeed. http://portknocking.org/view/details http://www.shorewall.net/PortKnocking.html http://software.newsforge.com/software/04/08/02/1954253.shtml Port knocking is nice for reducing the amount of junk in your logs. Have fun with port knocking.
- References:
- [tlug] Blocking bad sshd bruteforce attempt
- From: Hung Vu Nguyen
- Re: [tlug] Blocking bad sshd bruteforce attempt
- From: Al Hoang
- Re: [tlug] Blocking bad sshd bruteforce attempt
- From: Godwin Stewart
- Re: [tlug] Blocking bad sshd bruteforce attempt
- From: Josh Glover
- Re: [tlug] Blocking bad sshd bruteforce attempt
- From: scott
- Re: [tlug] Blocking bad sshd bruteforce attempt
- From: Joe Larabell
Home | Main Index | Thread Index
- Prev by Date: Re: [tlug] Blocking bad sshd bruteforce attempt
- Next by Date: Re: [tlug] Hi from new server and a couple of questions
- Previous by thread: Re: [tlug] Blocking bad sshd bruteforce attempt
- Next by thread: Re: [tlug] Blocking bad sshd bruteforce attempt
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links