Combining Port Knocking With OS Fingerprinting 154
Posted
by
timothy
from the belt-and-suspenders-and-tape-and-elastic dept.
from the belt-and-suspenders-and-tape-and-elastic dept.
michaelrash writes "Port knocking implementations are on the rise. I have just released fwknop; (the Firewall Knock Operator) at DEF CON 12. Fwknop implements both shared and encrypted knock sequences, but with a twist; it combines knock sequences with passive operating system fingerprints derived from p0f. This makes it possible to allow, say, only Linux systems to connect to your SSH daemon. Fwknop is based entirely around iptables log messages and so does not require a separate packet capture library. Also, at the Black Hat Briefings, David Worth has released a cryptographic port knock implementation based around one-time pads."
Combining Port Knocking With OS Fingerprinting More Login
Combining Port Knocking With OS Fingerprinting