3 ms·
I was waiting for the article to mention why the author chose not to employ that option. Though the author mentions in passing that one solution is brittle beca
by nulbyte 3y ago
I was waiting for the article to mention why the author chose not to employ that option. Though the author mentions in passing that one solution is brittle because it requires parsing output, I don't see why that's a problem. It's exactly what 'expects was designed to do.
- Joel_Mckay 3y agoexpect/tcl offers many options, but does have some quirks with remote shells. What it does do well: 1. can validate a key signature issue 2. firewall port-knocking (extra http ports interleaved with instant ban ports) 3. ssh over https setup 4. IDS tripwire Morse-code knocking 5. reverse-proxy configuration for trusted zone ingress This approach helps solve several issues: i. distributed firewall probes or nuisance traffic ii. brute force attempts or nuisance traffic iii. obscures security posture identification (what got an IP blacklisted might have occurred several minutes ago) Indeed, I also <3 autoexpect for quickly making monotonous tasks feasible. Good luck =)