  EGeezer Go Bobcats Premium join:2002-08-04 Country!
·Callcentric
·RoadRunner Cable
·AT&T CallVantage
1 edit | reply to Daniel Re: Is Portknocking "Real" Security?
this is an interesting discussion, since I'm not familiar with the technical aspects of common portknocking implementations.
The point Daniel made in the second link is an intriguing one -
You are some bad guy with a brand-spankin'-new zero-day SSH exploit. You need victims. You proceed to scan a juicy class B and come back with 5,000 open SSH ports.
Out of the remaining 60,000 plus hosts that didn't have SSH open, how do you attack the portknocked ones?
If portknocking does significantly mitigate or raise the effort bar for such an attack, it would provide value as an added layer. Some thoughts on this? -- 03:14:07 UTC Tuesday, Jan. 19, 2038 - a date that will live in infamy... |