republican-creole
site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Share Topic
Posting?
Post a:
Post a:
Links: ·Hijack This logs? ·Panda Free Tools ·Vundo Removal
AuthorAll Replies

ghost16825
Use security metrics
Premium
join:2003-08-26

reply to Daniel

Re: Is Portknocking "Real" Security?

said by Daniel:

Ghost,

You mention turning SSH on and off, but the daemon stays running all the time. The only thing that's changing is the firewall configuration between the portknocking client and SSH server.

The key issue here is very simple, and you alluded to it earlier; risk drops dramatically when you remove your daemon's presence from the Internet. It's just that simple, and that's what portknocking does...it effectively closes all Internet access to your daemon.

The concept of SPA is identical to me; only the implementation is different. I think it is a great layer as well. Again, because of the fact that it isolates you from zero-day exploits VERY effectively.
Sorry, I stand corrected on this. I was thinking more along the lines of a port being accessible by everyone whenever a single user entered the correct port sequence for access. Obviously I forgot that iptables can allow access to ports on a per IP address after a port knocking sequence. Hence, my previous questions do not apply. So it's possible to have thousands of users access a service remotely, but no indication to others that a remote service is listening on a certain port.


Daniel
Premium,MVM
join:2000-06-26
San Francisco, CA

said by ghost16825:

So it's possible to have thousands of users access a service remotely, but no indication to others that a remote service is listening on a certain port.
Exactly, yes.
--
dmiessler.com -- grep understanding knowledge

Monday, 04-Jun 20:11:25 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics