3 ms·
I agree with what you say regarding the APT scenario, port knocking is mostly useless there. It wouldn't be an effective camouflage in that case, and one probab
by arde 12y ago
I agree with what you say regarding the APT scenario, port knocking is mostly useless there. It wouldn't be an effective camouflage in that case, and one probably has bigger problems than a hypothetical OpenSSH zero-day then.
I'm not aware of any available plugboard proxy solution, so it would have the added complication of hacking it together. That's what I meant. And there are diminishing returns there: a non-criptographic port knocking scheme with a few packets could be good enough as a camouflage in many cases. But I still find it to be a time saver in the more general case (not APT). I think having cleaner logs is worth using this simple trick then.