Difference between revisions of "Fwknop"
Jump to navigation
Jump to search
↑ https://serverfault.com/a/608976
Line 18: | Line 18: | ||
[[Category:Linux]] | [[Category:Linux]] | ||
− | [[Category:Security]] | + | [[Category:IT Security]] |
Revision as of 17:17, 25 December 2019
"FireWall KNock OPerator" implements an authorization scheme called Single Packet Authorization (SPA) (encrypted, non-replayed, with an HMAC SHA-256)
- macOS installation:
brew install fwknop
- Config files:
/etc/fwknop/access.conf
Quick Start
fwknop --key-gen
Ref: https://www.cipherdyne.org/fwknop/docs/fwknop-tutorial.html#quick-start- Send SPA packet:
fwknop -n DESTINATION_SERVER_OR_IP --verbose -R
See also
- Port knocking,
fail2ban
[1]fwknop
, DenyHosts - OpenSSH (changelog):
/etc/ssh/sshd_config
|/etc/ssh/ssh_config
|~/.ssh/
|openSSL | sshd logs
|sftp
|scp
|authorized_keys
|ssh-keygen
|ssh-keyscan
|ssh-add
|ssh-agent
|ssh
|Ssh -O stop
|ssh-copy-id
|CheckHostIP
|UseKeychain
, OpenSSF iptables
ufw
firewalld
nftables
firewall-cmd
ipfw (FreeBSD)
PF (OpenBSD)
, netsh advfirewall- Security tools: Vulnerability scanner, port scan, Host sweep,
nmap
,nping
,ncat, nc
,psad
, Gordon Lyon - Port Knocking
Advertising: