fwknop 1.8.1
Sponsored Links
fwknop 1.8.1 Ranking & Summary
File size:
0.44 MB
Platform:
Any Platform
License:
GPL (GNU General Public License)
Price:
Downloads:
866
Date added:
2007-06-12
Publisher:
Michael Rash
fwknop 1.8.1 description
fwknop stands for the "FireWall KNock OPerator", and implements an authorization scheme based around Netfilter and libpcap that requires only a single encrypted packet in order to communicate various pieces of information including desired access through a Netfilter policy and/or complete commands to execute on the target system.
By using Netfilter to maintain a "default drop" stance, the main application of this program is to protect services such as OpenSSH with an additional layer of security in order to make the exploitation of vulnerabilities (both 0-day and unpatched code) much more difficult.
The authorization server passively monitors authorization packets via libcap and hence there is no "server" to which to connect in the traditional sense. Access to a protected service is only granted after a valid encrypted and non-replayed packet is monitored.
This method is similar to the Single Packet Authorization scheme proposed by Simple Nomad and the folks at NMRC
fwknop project was also the first tool to combine traditional encrypted port knocking with passive OS fingerprinting. This makes it possible to do things like only allow, say, Linux-2.4/2.6 systems to connect to your SSH daemon.
Enhancements:
- A bugfix to ensure that the "keep-state" directive is added to firewall rules on systems running the ipfw firewall.
- The --Save-packet and --Save-packet-file command line arguments have been added to the fwknop client.
- These options instruct fwknop to save a copy of an encrypted SPA packet before it is sent across the network.
- A bugfix to find the minimal unused ipfw rule number for ipfw firewalls.
- This fixes an issue where ipfw rules added by fwknopd could be inserted at the same position as rules from an existing ipfw policy.
By using Netfilter to maintain a "default drop" stance, the main application of this program is to protect services such as OpenSSH with an additional layer of security in order to make the exploitation of vulnerabilities (both 0-day and unpatched code) much more difficult.
The authorization server passively monitors authorization packets via libcap and hence there is no "server" to which to connect in the traditional sense. Access to a protected service is only granted after a valid encrypted and non-replayed packet is monitored.
This method is similar to the Single Packet Authorization scheme proposed by Simple Nomad and the folks at NMRC
fwknop project was also the first tool to combine traditional encrypted port knocking with passive OS fingerprinting. This makes it possible to do things like only allow, say, Linux-2.4/2.6 systems to connect to your SSH daemon.
Enhancements:
- A bugfix to ensure that the "keep-state" directive is added to firewall rules on systems running the ipfw firewall.
- The --Save-packet and --Save-packet-file command line arguments have been added to the fwknop client.
- These options instruct fwknop to save a copy of an encrypted SPA packet before it is sent across the network.
- A bugfix to find the minimal unused ipfw rule number for ipfw firewalls.
- This fixes an issue where ipfw rules added by fwknopd could be inserted at the same position as rules from an existing ipfw policy.
fwknop 1.8.1 Screenshot
fwknop 1.8.1 Keywords
authorization scheme
to communicate
fwknop
authorization
encrypted
packet
single
scheme
fwknop 1.8.1
Networking
System
Bookmark fwknop 1.8.1
fwknop 1.8.1 Copyright
WareSeeker periodically updates pricing and software information of fwknop 1.8.1 full version from the publisher, so some information may be slightly out-of-date. You should confirm all information before relying on it. Software piracy is theft, Using crack, password, serial numbers, registration codes, key generators is illegal and prevent future development of fwknop 1.8.1 Edition. Download links are directly from our publisher sites, torrent files or links from rapidshare.com, yousendit.com or megaupload.com are not allowed
Featured Software
Want to place your software product here?
Please contact us for consideration.
Contact WareSeeker.com
Related Information
no matching authorization scheme
authorization schemes
fwknop ubuntu
encrypted dvd
packet and times
authorization required
authorization scheme definition
copy encrypted dvd
packet 8
sample authorization letter
authorization to release medical information
encrypted mail
packet loss
authorization scheme apex
authorization letter
encrypted email
packet8
application express authorization scheme
Related Software
Nagios is a daemon written in C that is designed to monitor networked hosts and services. Free Download
Oyez is a portable, standalone streaming audio server written in Python. Free Download
MozPlugger is a modification of Plugger, a very small multimedia plugin for the Unix versions of Netscape, Mozilla, and Opera. Free Download
absence is a calendar tool written in Perl for keeping track of people on a daily basis. Free Download
SQL Uniform is a database client with a graphical user interface (GUI). Free Download
fl0p provides a passive OS fingerprinting tool. Free Download
Simplebackup is a cross-platform backup program. Free Download
Guile is a GNU extension language, an embeddable library implementation of Scheme. Free Download
Latest Software
Popular Software
Favourite Software