Linux Today: Linux News On Internet Time.
Search Linux Today
Linux News Sections:  Blog -  Developer -  High Performance -  Infrastructure -  IT Management -  Security -  Storage -
Linux Today Navigation
LT Home
Preferences
Contribute
Link to Us
Search
Linux Jobs

Linux Today
Enterprise Linux Today
Apache Today
JustLinux.com
Linux Planet
PHPBuilder
All Linux Devices
Technology Jobs

JustTechJobs.com

LinuxToday Newsletters
Server Daily
IT Management Daily
Subscribe News
Subscribe PR
Subscribe Security

internet.com
Internet News
Small Business

Advertise
Newsletters
Tech Jobs
E-mail Offers

 






Current Newswire:

Tech Comics: "Groundhog Day"

Want a Job? Learn Linux

PC-BSD 9 review – to FreeBSD what Ubuntu is to Debian

Time to dispel open source myths, says Liam Maxwell

SECURITY: Nmap Inside and Out

Eight features Windows 8 'borrowed' from Linux

Malware devs embrace open-source

A tale of two distros: Ubuntu and Linux Mint

Raspberry Pi benchmarked against Beagleboard, low price is long term

20 popular Ubuntu Linux apps you may want to try



Applications Management Engineer Sr (NYC)
Next Step Systems
US-NY-New York

Justtechjobs.com Post A Job | Post A Resume
:NewsForge: A Critique of Port Knocking
NewsForge: A Critique of Port Knocking
Aug 11, 2004, 07 :00 UTC (13 Talkback[s]) (13293 reads)

(Other stories by Arvind Narayanan)

"Suppose you want to be able to retrieve files from your Linux system remotely. The 'standard' method of running the SSH server on port 22 is notoriously inadequate. OpenSSH, which is the SSH server on the majority of Linux installations, suffers from regular exploits of buffer overflow and other vulnerabilities, and you neither have the time to keep up with the patches nor want to make the effort--you'd rather put up with not being able to access your files. This is where port knocking might seem to help--but don't count on it.

"Port knocking is a method of 'message transmission across closed ports.' It works like this: initially a firewall blocks all ports on the server. The client issues a series of connection requests (knocks) to different ports; these are, of course, dropped since the ports are blocked.

Complete Story

Related Story:
Linux Journal: Port Knocking(Jun 18, 2003)


Index Mode   |   Flat Mode   |   Thread Mode   |   Thread Flat  
  Talkback(s) Name  and Date
I don't think this guy has a clue as ...   Oh brother...   
mj
Aug 11, 2004, 07:24:58
 
 Just do not use DEFAULT 22 for ssh. You ...   A much more simple and effective defense...   
Shamar
Aug 11, 2004, 09:58:28
 
>Think of it as a combination lock on a  ...   Re: Oh brother...   
Ross M.
Aug 11, 2004, 14:38:10
 
If I'm not mistaken, nmap checks the ...   Re: A much more simple and effective defense...   
bobzibub
Aug 11, 2004, 15:08:25
 
..... It works like this: initially a fi ...   He's clueless.   
Brandioch Conner
Aug 11, 2004, 16:25:09
 
> If I'm not mistaken, nmap checks t ...   Re: Re: A much more simple and effective defense..   
hey
Aug 11, 2004, 17:06:06
 
How about redirecting external UDP packe ...   maybe use NTP   
Edmund Evans
Aug 11, 2004, 17:07:11
 
> >Think of it as a combination lock on  ...   Re: Re: Oh brother...   
mj
Aug 11, 2004, 23:51:58
 
> How about redirecting external UDP pac ...   Re: maybe use NTP   
mj
Aug 12, 2004, 00:03:31
 
>  Just do not use DEFAULT 22 for ssh. Y ...   Re: A much more simple and effective defense...   
mj
Aug 12, 2004, 00:46:48
 
It occurs to me that, if the knocking se ...   What about key exchange?   
D. Hellman
Aug 12, 2004, 02:46:42
 
> Suppose you want to be able to retriev ...   Opening paragraph full of FUD   
NeoSadist
Aug 12, 2004, 05:13:38
 
mj: Can you explain why you would need t ...   Re: maybe use NTP   
Edmund Evans
Aug 12, 2004, 08:20:03
 
  Home | Search Talkbacks | Customize View    Top of Page  



Enter your comments below:

* Your Name:

* Your Email Address:

* Subject:

CC: [will also send this talkback to an E-Mail address]

* Comments:

Tags allowed:<I>,<B> and <U>. See our talkback-policy for more about talkback content.

Fields marked with * are required!

..............................




All times are recorded in UTC.
Linux is a trademark of Linus Torvalds.
Powered by Linux, Apache and PHP