3 ms·
> Well, tcpdump is explicitely not what you want to do in this case as Moxie points out Why's that? E: oh, if you aren't familiar with OpenBSD I might get the
by thrwaway1985882 2y ago
> Well, tcpdump is explicitely not what you want to do in this case as Moxie points out
Why's that?
E: oh, if you aren't familiar with OpenBSD I might get the confusion – pflogd/the kernel (not me!) watches the actual network device and dumps to a file. So the actual "knocking" daemon I bodged together is one part running as a privsep user watching a log file and giving IPs to the other part which just adds to the pf table allowing access.
My threat model didn't include people who can fuck with pflog(4) to attack tcpdump(8) - I'm sure they're out there, and if they wanted to be they'd already be in my network (or already are).
- mr_mitm 2y agoAh, that makes sense. I actually didn't know that about openbsd.