Fwknop
Jump to navigation
Jump to search
↑ https://serverfault.com/a/608976
"FireWall KNock OPerator" implements an authorization scheme called Single Packet Authorization (SPA) (encrypted, non-replayed, with an HMAC SHA-256)
- macOS installation:
brew install fwknop
- Config files:
/etc/fwknop/access.conf
Quick Start[edit]
fwknop --key-gen
Ref: https://www.cipherdyne.org/fwknop/docs/fwknop-tutorial.html#quick-start- Send SPA packet:
fwknop -n DESTINATION_SERVER_OR_IP --verbose -R
See also[edit]
- Port knocking,
fail2ban
[1]fwknop
, DenyHosts - OpenSSH (changelog):
/etc/ssh/sshd_config
|/etc/ssh/ssh_config
|~/.ssh/
|openSSL | sshd logs
|sftp
|scp
|authorized_keys
|ssh-keygen
|ssh-keyscan
|ssh-add
|ssh-agent
|ssh
|Ssh -O stop
|ssh-copy-id
|CheckHostIP
|UseKeychain
, OpenSSF, ~/.ssh/authorized_keys iptables
ufw
firewalld
nftables
firewall-cmd
ipfw (FreeBSD)
PF (OpenBSD)
, netsh advfirewall- Security tools: Vulnerability scanner, port scan, Host sweep,
nmap
,nping
,ncat, nc
,psad
, Gordon Lyon
Advertising: