Re: port knocking
john s wolter <johnswolter-38kvHzr4fsSEK/[email protected]> Thu, 19 Jun 2014 01:32:43 -0400
| Newsgroups | gmane.comp.security.ipcop.user,gmane.comp.security.ipcop.devel |
|---|---|
| Message-ID | <CANwh-frFsPJGyNSNWxYWO=2+q9vsFUFejJrqGAOS9wxiy4xFnA@mail.gmail.com> |
I'm no expert on "Port Knocking", PtKnk, but I gathered information about it six years ago if I remember correctly. I was interested when I first read about PtKnk. When learning something I try searches and Wikipedia, then I spread out to the Internet with improved searches. Here's the PtKnk article, it's more positive than I am, http://en.wikipedia.org/wiki/Port_knocking ...the article keeps mentioning fwknop. PtKnk was reviewed several times in the 2006-2009 time frame. My take on those reviews was static PtKnk was not a good idea. The static version PtKnk relies on security by obscurity. The phrase "covert channel" comes to mind. Cracking tools, given some creativity, can discover much. Security by obscurity usually does not work. Here's the Wikipedia article, http://en.wikipedia.org/wiki/Covert_channel A dynamic version of PtKnk seems to want to revive the idea. There's a web PtKnk suggesting a secured web page to activate a port. I'm not clear how that is an improvement. Again cracking tools in the mist of an attack will detect the opening of a port. The variety of articles I've read keep returning to the public/private keys or Kerberos with its key management issues. One time passwords are mentioned in the articles as well. IpCop could implement this idea. Based on the information I've seen to date, I don't yet see PtKnk providing an obstacle that is difficult to overcome. Cheers, John S. Wolter ------------------------------------------------------------ Wolter Works EMail: johnswolter-38kvHzr4fsSEK/[email protected] LinkedIn: John S Wolter, johnswolter On Wed, Jun 18, 2014 at 10:30 PM, Andy Yee <[email protected]> wrote: > On 6/18/2014 8:41 PM, Jeffrey S. Russell wrote: > > I had never heard of this prior to your question. It seems to require > some setup prior to use, involving setting up a sequence of ports to > "knock" on in a certain order, then a pre-defined port is opened > dynamically to the host initiating the "knocks". It's an interesting > concept! > > > > ----- Original Message ----- > > From: "Spyros Tsiolis" <stsiol-/[email protected]> > > To: "IpCop List" <[email protected]> > > Sent: Thursday, June 12, 2014 1:26:55 PM > > Subject: [IPCop-user] port knocking > > > > Hello all, > > > > Has anyone played with port-knocking ? > > Is it just a case of port-forwarding the desired tcp ports to > > a node on the inside ? > > > > tia, > > > > s. > > > > > > Is this feature the same thing as the Port Triggering feature that I > know consumer routers like LinkSys have? > > > ------------------------------------------------------------------------------ > HPCC Systems Open Source Big Data Platform from LexisNexis Risk Solutions > Find What Matters Most in Your Big Data with HPCC Systems > Open Source. Fast. Scalable. Simple. Ideal for Dirty Data. > Leverages Graph Analysis for Fast Processing & Easy Data Exploration > http://p.sf.net/sfu/hpccsystems > _______________________________________________ > IPCop-user mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/ipcop-user > ------------------------------------------------------------------------------ HPCC Systems Open Source Big Data Platform from LexisNexis Risk Solutions Find What Matters Most in Your Big Data with HPCC Systems Open Source. Fast. Scalable. Simple. Ideal for Dirty Data. Leverages Graph Analysis for Fast Processing & Easy Data Exploration http://p.sf.net/sfu/hpccsystems