3 ms·
I’ve written a few toy port knocking implementations, and doing it right is hard. If your connections crap and there’s packet loss, some of the sequence may be
by fullspectrumdev 2y ago
I’ve written a few toy port knocking implementations, and doing it right is hard.
If your connections crap and there’s packet loss, some of the sequence may be lost.
Avoiding replay attacks is another whole problem - you want the sequence to change based on a shared secret and time or something similar (eg: TOTP to agree the sequence).
Then you have to consider things like NAT…
- dspillett 2y agoAlso, if you are trying to connect to a resource from a restrictive network your knocking sequence might be blocked by filters at the client end. I've been on networks that allow nothing except the standard TCP & UDP ports for HTTP(S), SSH and DNS (and even then DNS was restricted to their local name server).