3 ms·
If you do not have the ability to eavesdrop on the network between my client and my server, then port knocking is essentially unhackable. Port knocking only fai
by developer2 10y ago
If you do not have the ability to eavesdrop on the network between my client and my server, then port knocking is essentially unhackable. Port knocking only fails when the malicious party can monitor the network traffic. This is a valid concern, and I would never say that port knocking by itself is all the security one needs. It does however completely block all regular "outsiders" from ever being able to even open a connection to sshd.
If I require 5 ports to be hit in sequence, and blacklist IPs that hit unknown ports, it is extremely unlikely you will ever connect. Now if someone on my local network, at my ISP, or at my hosting provider sniffs my traffic to determine a static knocking sequence... good for them. They're the one unauthorized person who can connect to sshd, without a valid ssh key to authenticate with.
It's a reality that most businesses are not going to invest in setting up a network that cannot be accessed from the internet at large. For such setups, a little bit of obscurity via something like port knocking to prevent every single port scanner in existence from discovering your sshd server must be better than nothing at all.
- munin 10y ago> blacklist IPs that hit unknown ports so what happens when someone hits an unknown port on your system from every IP on the internet?
- developer2 10y agoYou reject all packets from "bad IPs" for a period of time. 5 minutes, 30 minutes, whatever. If you're in a position to spoof IPs and you manage to spoof one I need to connect from (or I make a mistake and get myself blacklisted), it's a temporary inconvenience. That, and having out-of-band access to the server always helps. ;)