Slashdot Mirror


Knock Safely With portknocking_v1.0

mrdeathgod writes "The Port Knocking project at SourceForge has just released portknocking_v1.0. Based on my undergrad thesis, this client/server package does not use pre-defined knock sequences, but rather utilizes Blowfish in order to encrypt the client data into a sequence of port numbers. This enables a client with the proper password to remotely manipulate firewall rules without fear of replay attacks. While currently designed for FreeBSD+ipfilter, expanded portability is in the works."

78 comments

  1. GNAA Claims Responsibility for Killing 3000 Blogs by Qwaniton · · Score: -1, Troll
    GNAA Claims Responsibility for Killing 3000 Blogs

    GNAUK (the UK branch of the GNAA) consultant rolloffle stood ecstatically in front of the massive GNAUK London office skyscraper. Waving his massive nigger hands for silence, he smiled and announced with glee that the GNAA was the cause of the 3000 blogs outage.

    "Well, aw'right, now aw'right! It's due to our persistent shitflooding and blogbashing efforts that we can claim this spectacular victory over a major epicentre of retardery! Congratulations, morons, for you have been pwned! Remember, regular local backups are your friend!"

    Having concluded with these statements, the crowd burst into an ambivalent mix of outraged and delighted argument. rolloffle then unzipped his trousers and started to beat back the hordes of angry webloggers and journalists with his gigantic nigger cock, fleeing into a side alley. The massive conglomeration of people then enjoyed a spectacular fireworks display, sending the massive office building of glass and steel smashing to the ground and burying the suckers present.

    About GNAA:
    GNAA (GAY NIGGER ASSOCIATION OF AMERICA) is the first organization which
    gathers GAY NIGGERS from all over America and abroad for one common goal - being GAY NIGGERS.

    Are you GAY ?
    Are you a NIGGER ?
    Are you a GAY NIGGER ?

    If you answered "Yes" to all of the above questions, then GNAA (GAY NIGGER ASSOCIATION OF AMERICA) might be exactly what you've been looking for!
    Join GNAA (GAY NIGGER ASSOCIATION OF AMERICA) today, and enjoy all the benefits of being a full-time GNAA member.
    GNAA (GAY NIGGER ASSOCIATION OF AMERICA) is the fastest-growing GAY NIGGER community with THOUSANDS of members all over United States of America. You, too, can be a part of GNAA if you join today!

    Why not? It's quick and easy - only 3 simple steps!

    First, you have to obtain a copy of GAY NIGGERS FROM OUTER SPACE THE MOVIE and watch it. (You can download the movie (~280mb) using BitTorrent, by clicking here.

    Second, you need to succeed in posting a GNAA "first post" on slashdot.org, a popular "news for trolls" website

    Third, you need to join the official GNAA irc channel #GNAA on irc.gnaa.us, and apply for membership.
    Talk to one of the ops or any of the other members in the channel to sign up today!

    If you are having trouble locating #GNAA, the official GAY NIGGER ASSOCIATION OF AMERICA irc channel, you might be on a wrong irc network. The correct network is Niggernet, and you can connect to irc.gnaa.us as our official server. If you do not have an IRC client handy, you are free to use the GNAA Java IRC client by clicking here.


    If you have mod points and would like to support GNAA, please moderate this post up.

    .________________________________________________. fucking
    | ______________________________________._a,____ | CmdrTaco
    | _______a_._______a_______aj#0s_____aWY!400.___ | will
    | __ad#7!!*P____a.d#0a____#!-_#0i___.#!__W#0#___ | he ever learn that
    | _j#'_.00#,___4#dP_"#,__j#,__0#Wi___*00P!_"#L,_ | GNAA is totally
    | _"#ga#9!01___"#01__40,_"4Lj#!_4#g_________"01_ | unstoppable? Teamed
    | ________"#,___*@`__-N#____`___-!^_____________ | up with the other troll groups,
    | _________#1__________?________________________ | GNAA will absolutely own
    | _________j1___________________________________ | the shitty place that i

  2. It would seem to me that the title of this article by Tim_F · · Score: 0, Redundant

    should be knock safely. Not the trollish "kock safely..."

  3. Re:GNAA Claims Responsibility for Killing 3000 Blo by Anonymous Coward · · Score: -1, Troll

    OH FUX BYE BYE KARMA

  4. Re:GNAA Claims Responsibility for Killing 3000 Blo by uberTr011 · · Score: -1

    Trolling while logged in is what it's all about brotha'. If you can get CmDrTaco to revoke your account, you da man!

  5. hrm... by blackcoot · · Score: 4, Funny

    i usually use condoms when i want to kock safely ;-P

    1. Re:hrm... by hitchhacker · · Score: 2, Funny


      blackcoot's Latest 24 of 161 Comments
      Subject Datestamp Replies Score
      hrm... Fri Jun 18, '04 02:30 AM 1 4, Funny
      attached to Kock Safely With portknocking_v1.0

      hehe

      -metric

    2. Re:hrm... by archen · · Score: 2, Funny

      Well theres more to kock safety then that. I know when I knock the wrong port on my girlfriend she gets pretty pissed. Remember, this is about protecting the ports too =P

    3. Re:hrm... by blackcoot · · Score: 2, Funny

      the boyfriend doesn't seem to mind at all ;)

  6. Re:It would seem to me that the title of this arti by manjunaths · · Score: 2, Funny

    Right, I even went and looked up 'Kock' and this is what I got 'No entry found for kock.'

    --
    Slashdot: Tabloid for the nerds. Stuff that doesn't matter.
  7. By god by Anonymous Coward · · Score: 1, Funny

    If your gonna let your port get kocked, do it safely.

  8. Burn the Copy Editor In Effigy by limekiller4 · · Score: -1, Redundant

    "Kock safely?"

    --
    My .02,
    Limekiller
  9. Preview button... by geschild · · Score: 0, Offtopic

    Admonishing us for not using the preview button or a spell checker?! :D

    "Well. I guess I'll have to see your 'dupe on the same day' and I raise you... a glaring spelling mistake in a title."

    At least the editors can edit their entries. :P

    --
    Karma? What's that again?
  10. Reposting the original article for posterity by Anonymous Coward · · Score: -1, Redundant

    _Kock Safely With portknocking_v1.0_

    Posted by timothy on Fri Jun 18, '04 01:57 AM
    from the who-is-it-this-time dept.

    mrdeathgod writes "The Port Knocking project at SourceForge has just released portknocking_v1.0. Based on my undergrad thesis, this client/server package does not use pre-defined knock sequences, but rather utilizes Blowfish in order to encrypt the client data into a sequence of port numbers. This enables a client with the proper password to remotely manipulate firewall rules without fear of replay attacks. While currently designed for FreeBSD+ipfilter, expanded portability is in the works."

  11. I'm still not convinced... by dotz · · Score: 4, Interesting
    Even after reading this one.

    A list of one-time passwords & a simple daemon, that verifies them & enables ssh access (in some high level language) at the user request would do as fine. Give such daemon some IQ, so it would make brute-force attacks very hard, and you have the same thing. Except for the "cool" part.

    1. Re:I'm still not convinced... by sporty · · Score: 1
      So you'll still have a firewall for all other ports, leaving your sshd daemon visible, which may be flawed. And you'll ignore a new technology which will block off ALL ports and only open one to sshd, which may be flawed or not, if you know the right port sequence?


      um...

      --

      -
      ping -f 255.255.255.255 # if only

    2. Re:I'm still not convinced... by dotz · · Score: 1
      No, sire. I'm thinking about a very simple daemon, written in high-level language, that would manipulate my firewall rules using unencrypted OTPs. It could open ssh port for 5 seconds only to IPs, that gave right one-time password. Store only MD5 hashes of those one-time passwords on the server, and voila.

      In Python I could write such daemon in 30 minutes or so. "man ipfw" or "man ipf" would be the part, that would take me most time (not to mention testing, of course) :)

  12. Kock Safely by I(rispee_I(reme · · Score: 0, Offtopic

    Freudian slip, much?

  13. FreeBSD is Dying by Anonymous Coward · · Score: -1, Offtopic
    It is official; Netcraft confirms: *BSD is dying

    One more crippling bombshell hit the already beleaguered *BSD community when IDC confirmed that *BSD market share has dropped yet again, now down to less than a fraction of 1 percent of all servers. Coming on the heels of a recent Netcraft survey which plainly states that *BSD has lost more market share, this news serves to reinforce what we've known all along. *BSD is collapsing in complete disarray, as fittingly exemplified by failing dead last in the recent Sys Admin comprehensive networking test.

    You don't need to be a Kreskin to predict *BSD's future. The hand writing is on the wall: *BSD faces a bleak future. In fact there won't be any future at all for *BSD because *BSD is dying. Things are looking very bad for *BSD. As many of us are already aware, *BSD continues to lose market share. Red ink flows like a river of blood.

    FreeBSD is the most endangered of them all, having lost 93% of its core developers. The sudden and unpleasant departures of long time FreeBSD developers Jordan Hubbard and Mike Smith only serve to underscore the point more clearly. There can no longer be any doubt: FreeBSD is dying.

    Let's keep to the facts and look at the numbers.

    OpenBSD leader Theo states that there are 7000 users of OpenBSD. How many users of NetBSD are there? Let's see. The number of OpenBSD versus NetBSD posts on Usenet is roughly in ratio of 5 to 1. Therefore there are about 7000/5 = 1400 NetBSD users. BSD/OS posts on Usenet are about half of the volume of NetBSD posts. Therefore there are about 700 users of BSD/OS. A recent article put FreeBSD at about 80 percent of the *BSD market. Therefore there are (7000+1400+700)*4 = 36400 FreeBSD users. This is consistent with the number of FreeBSD Usenet posts.

    Due to the troubles of Walnut Creek, abysmal sales and so on, FreeBSD went out of business and was taken over by BSDI who sell another troubled OS. Now BSDI is also dead, its corpse turned over to yet another charnel house.

    All major surveys show that *BSD has steadily declined in market share. *BSD is very sick and its long term survival prospects are very dim. If *BSD is to survive at all it will be among OS dilettante dabblers. *BSD continues to decay. Nothing short of a miracle could save it at this point in time. For all practical purposes, *BSD is dead.

    Fact: *BSD is dying

    1. Re:FreeBSD is Dying by Tezkah · · Score: 0, Offtopic

      If *BSD is dying, why do you feel the need to post this in *every* BSD story? Shouldn't you just ignore it and let it go away?

  14. Offtopic? by hitchhacker · · Score: 1


    (Score:0, Offtopic)
    WTF?

    the topic is:
    "Kock Safely With portknocking_v1.0"

    It's not my fault the topic is offtopic..

    -metric

    1. Re:Offtopic? by blackcoot · · Score: 0, Offtopic

      we are not all one with the typo detection ;-)

  15. You forget by hummassa · · Score: 5, Insightful

    That a portscan reveals nothing in the case of port knocking.
    And it shows a listening port in the case of the deamon, well, listening, conventionally.

    --
    It's better to be the foot on the boot than the face on the pavement. ~~ tkx Kadin2048
    1. Re:You forget by dotz · · Score: 1

      Yes, of course. Hiding such things means exactly, that you use "security by obscurity" approach, which "portknocking" is told not to use. Really only good thing is, when compared portknocking to one-time passwords in my proposed approach, that in passwords each "digit" can be one from about 63 characters possible (upper case, lower case, 10 digits) - and in portknocking each knock could be around 655350 - which makes a short port knock sequence harder to bruteforce, than a long one-time password.

    2. Re:You forget by NicolaiBSD · · Score: 1
      "And it shows a listening port in the case of the deamon, well, listening, conventionally."

      Not if you firewall it. I cannot see the point of this (except for academic exercise ofcourse).

    3. Re:You forget by Curien · · Score: 4, Interesting

      Huh? Without portknocking, you have to have at least /one/ listening service.

      The advantage with portknocking is that if someone was scanning IP ranges for computers running exposed services, you won't show up as a valid target. You'll look like an unused IP or a computer that's off (or one that's simply firewalled every port).

      --
      It's always a long day... 86400 doesn't fit into a short.
    4. Re:You forget by dotz · · Score: 1

      Unused IP? Yes, with TCP_BLACKHOLE, why not. But... if portknocking is active, it is also a kind of listening service - even if it won't show up on nmap, it also does listen for network events. At a given level of abstraction, this will be the same as network daemon listening on open port ;)

    5. Re:You forget by claudius0425 · · Score: 2, Informative

      He has a good point. Consider, for example, a student at a university that forbids you to run any servers (say, UF with ICARUS). With portknocking, you could keep all ports closed yet, with minimal effort, open a transient hole in your firewall, allowing you to, say, access an ssh server, but only from the machine originating the portknock. This is particularly useful in a DHCP based environment, where a static firewall rule would be utterly ineffectual.

      DISCLAIMER: No, I do not attend UF, don't send in the goons. It is just an example.

      --
      Phus. Sysiphus.
    6. Re:You forget by Anonymous Coward · · Score: 1, Interesting

      That explains it for me. I couldn't think of a reason this is useful. It's only advantage over ssh is stealth. Stealth is of little advantage to white hats (please no, security through obscurity arguments). Black hats love stealth. This will be a great techology for open proxies, etc.

    7. Re:You forget by kace · · Score: 1

      DHCP environments are a good example of when this method can give you more benefits than just having no open ports to scan -- which is a pretty darn big plus too start off with.

      I'd suggest that you incorpaorate something like a RSA-SecureID system -- so that you'd have a [nearly] unlimited supply of one time passwords -- and this method becomes even stronger.

      Remember the onion -- layered security.

      K.C.

    8. Re:You forget by Khazunga · · Score: 2, Interesting
      Just use a datagram service, like UDP instead of TCP. Have your protocol not reply to requests until the authentication is done. Presto! It works, has all the benefits of port knocking, and uses no clever trick.

      This is a solution in search of a problem....

      --
      If at first you don't succeed, skydiving is not for you
    9. Re:You forget by evilviper · · Score: 1
      if someone was scanning IP ranges for computers running exposed services, you won't show up as a valid target.

      Same is true if you run SSH on some obscure port, especially if you remove the version number, etc.

      Port knocking is obscurity, and obscurity is not security. People forget that a lot.
      --
      Slashdot gets worse every day... Pipedot: News for nerds, without the corporate slant
    10. Re:You forget by lewp · · Score: 1

      Obscurity is, however, a valid part of security. Even if I'm patched, up to date, and configured properly, I'd still prefer to give away as little info as possible.

      --
      Game... blouses.
    11. Re:You forget by pboulang · · Score: 1
      Nope. You are wrong. Consider it as another key. Normal ssh would require you to have a username and a password. Paranoid firewall rules might say that you need to ssh from a specific IP. Even more paranoid rules would require that specific IP to portknock.

      Besides that point, what you say about ssh on an obscure port is much worse that you think. The very moment someone does a portscan, finds a responsive host (remember that a portknock protected computer wouldn't even show up) and then has open ports on some obscure port, then it becomes INTERESTING. I hold that that description is the LAST thing you want to have for your site... like having a .gov URL. Plus, it would take all of about 2 seconds to guess what the protocol running on that port would be:

      Telnet to that port... hmmm, no version number, no service description.. therefore not http, not smtp, etc

      ssh to that port.. hey, a login prompt. Joy. Let's run known scripts against it now.

      --

      This comment is guaranteed*

      *not guaranteed

    12. Re:You forget by evilviper · · Score: 1
      someone does a portscan, finds a responsive host (remember that a portknock protected computer wouldn't even show up)

      Now this is wrong... A machine trying to be stealthy is far worse than a machine that admits it exists, but has no open ports.

      I say that because anybody can tell if an IP address is in use. If they find that they don't get any reply from pinging that host, they know they're dealing with a host trying to be stealthy, and will spend much more time working on it.

      If a machine just returns the normal messages, like a TCP rst on all common ports, then the scanner will just figure it's a normal machine with no open ports.

      This is a case where trying to hide your machine actually gives people more information about it, and makes you the subject of more interest.

      then has open ports on some obscure port, then it becomes INTERESTING.

      No, there are 65535 ports on every machine. Do you expect anybody to scan all ports on millions of machines, then investigate every single open port to find if one happens to be an SSH daemon? No, in reality they just scan port 22 and move on. It takes a long time to scan all the possible ports on a machine, and it leaves them open to easy detection by a port-scan monitor, which could then refuse to accept connections on the SSH port from their IP address, and from anyone else for a few minutes time. Then even a full port-scan wouldn't detect your single open port.

      it would take all of about 2 seconds to guess what the protocol running on that port would be:

      The idea was just to hide the version, so they'd have to run hundreds of exploits, since they don't have any idea what brand of SSH daemon is running, and no idea vhat version. It would be easy to catch them in the process. But that's besides the point, the odds of them discovering the SSH daemon on an obsecure port in the first place is practically 0.

      --
      Slashdot gets worse every day... Pipedot: News for nerds, without the corporate slant
    13. Re:You forget by pboulang · · Score: 1
      I guess the part I really had a problem with is the "security through obscurity" flippancy. I totally agree that simply hiding and hoping is worthless. But let's take the "scan port 22 and move on" example and delve. You say change ports and hide the version, I say basically the same thing, except do a better job of hiding.

      Let's change the example into a lock on a door. With a normal door lock, you can look at it and determine the make and model, maybe check if there is a master key floating around. That would be vanilla SSH, sitting on port 22 with version 2.exploitable branded on the connect string. You say, leave the lock where it is, but rub out the make and model, make someone try and use a bunch of different keys to figure out what's going on. You watch when someone does that. I say, hide the lock, make them push my secret squares on the door before they can even tell that there IS a lock on the door. I don't think our solutions are at all mutually exclusive.

      Put this way, I feel that more bits to decode means I have more time to realize I am being attacked. (My answer to that 2 years ago was to implement IDS and bond with IPFW and disable all connections from whatever IP was bothering me for 24 hours.. hugely entertaining in my head to think of someone saying.. umm, where did it go!?!?) And maybe we both will end up with scripts that say, hmm, nothing here no port 22, next machine. I still better not exposing a possibly critical/vulnerable service at all until someone has messed with my machine and given my IDS a chance to trigger "IPFW 10 DENY IP $Bad-person to $EXT_NIC"

      --

      This comment is guaranteed*

      *not guaranteed

    14. Re:You forget by Tassach · · Score: 1
      Huh? Without portknocking, you have to have at least /one/ listening service.
      Again, what's the point? I can not see any legitimate purpose for this. The only reason I could see where you'd want to completely obscure the fact that a box has open ports is if you are up to no good -- eg, hiding a back door on a subverted box or running an unauthorized service on your employer's network. It may be an interesting hack, but it has zero practical value.

      --
      Why is it that the proponents of "one nation under God" are so eager to get rid of "liberty and justice for all"?
  16. Michael Kocks Safely by Anonymous Coward · · Score: -1, Offtopic
    Hello. My name is Michael. You might know me as the censor at a Geek news site where we pretend to offer news that matters. Or perhaps you remember me as the guy who hijacked an anti-censorship website. Whatever.

    Now is your chance to really know me. I'm going to let you in on my personal life, and the secret of how Timothy, Rob, Jeff, and I all "came" together.

    I remember that autumn day so well. It was in our dorm room at Hope College, in Holland, Michigan. Timothy stood there by the bathroom sink, totally naked and shaving his face. He didn't recoil when I went into the bathroom which we also shared with Rob and Jeff--the guys next door.

    Timothy and I had been roommates for almost three months now and gotten used to seeing each other strip down, dress, and even "hard".

    "Hey, Michael" he said.

    I had gotten the chance to look Timothy over a few times. But for some reason that evening I just stood there looking at his scraggly unkempt hair, his bare back, his flabby back muscles flowing down into the lumpy mounds of cellulite which composed his saggy buttocks and thick thighs.

    Despite his flab, the sexy swastika tattoo on Timothy's right butt cheek gave him an air of hunky manliness.

    "Oh I'm sorry, Timothy" I said without him saying anything despite the fact I had been standing there looking at him.

    "I was just ..." he turned and smiled through the shaving cream. "it's OK ... I look at you too, Michael" he said.

    I didn't know what to say then. I just moved next to him at the sink and stripped off my shirt to wash.

    "Got a hot night tonight, Michael?" he asked.

    "Naw just thought I'd go for a swim and pizza later. How 'bout you, Timothy?"

    "You keep swimming, Michael, and that hot ass of yours will be the talk of the dorm" he said as he patted my butt. He left his hand there and stroked one ass-cheek a bit.

    "You keep doing that and you won't be going anywhere, Timothy" I said half joking. My cock had already began to turn my boxer shorts into a small tent.

    He didn't move his hand at all. In fact his fingers moved under the boxers and he stroked bare skin.

    Timothy said, "Shit, Michael, I'm getting you hard".

    "Yea you get it too hard and you'll have to find a way to get it down again" I said spreading the shaving cream on my face.

    His fingers moved between my ass-cheeks and stroked. It felt good ... and then he suddenly stopped.

    "Can't now ... maybe when I get back. Will you still be up then, Mikey?"

    His hand had moved to my tented crotch and he gently felt my boner when he asked.

    "Not if you keep doing that, Timothy"

    We joked around like that often of course. But that evening his attention was more then the usual goosing or ass grabbing.

    I swam hard laps so my effort and the water would make my cock shrink. But my head was full of the memories of his petting as well as his naked body.

    I knew that after my pizza and maybe a beer, I'd be in my bed jacking off as many times as I could before he got back to the room.

    I was mid-way through my second go round when the door opened. He looked at me and smiled.

    "I hoped you'd be waiting, Michael" he said as he stripped off his shirt and jeans. We didn't speak. Timothy moved to my bed and pulled my covers off.

    Timothy pushed my hands over my head and to the bed pipe. I held them as he lifted my legs and curled my body over so his fingers, lips and tongue could take total control of my body.

    I closed my eyes and swooned as the sensations I had only fantasized about made me shiver and shake. Timothy's fingers stroked the lips of my ass then moved inside to find my prostate and stroked that bringing me to the point of orgasm. The sperm splattered on my face, chest, and stomach.

    But he wasn't through and his cock moved into my ass before it could recover and close tight after the orgasm. It hurt and made me beg him to stop. "Shut up Michael. Y

  17. Trolls that write themselves by Anonymous Coward · · Score: -1, Troll

    KOCK safely!!! Bwahahaha, I=funny. Because KOCK looks like COCK and that's funny! You get it, right? Get it????!!! They wrote KOCK when they meant KNOCK, and KOCK looks like COCK, as in a FLAMING PENIS OF DOOM, so it's really funny and we should all be giggling like little boys.

    KOCK=funny.

    1. Re:Trolls that write themselves by Anonymous Coward · · Score: 0

      you forgot the part about BLOWfish encryption.

    2. Re:Trolls that write themselves by Anonymous Coward · · Score: -1, Troll

      Typical slashdot crowd, very childish - mostly Linux people that's why.

  18. knock knock by kwoff · · Score: 2, Funny
    Knock, knock.
    Who's there?
    Kock.
    Kock who?
    Kock you!
    Well, my nephew would get a kick out of it, at least.
  19. Important message from Alan Kocks by Anonymous Coward · · Score: -1, Troll
    So why now? Why did *BSD fail? Once you get past the fact that *BSD is fragmented between a myriad of incompatible kernels, there is the historical record of failure and of failed operating systems. *BSD experienced moderate success about 15 years ago in academic circles. Since then it has been in steady decline. We all know *BSD keeps losing market share but why? Is it the problematic personalities of many of the key players? Or is it larger than their troubled personae?

    The record is clear on one thing: no operating system has ever come back from the grave. Efforts to resuscitate *BSD are one step away from spiritualists wishing to communicate with the dead. As the situation grows more desperate for the adherents of this doomed OS, the sorrow takes hold. An unremitting gloom hangs like a death shroud over a once hopeful *BSD community. The hope is gone; a mournful nostalgia has settled in. Now is the end time for *BSD.

  20. Re:GNAA Claims Responsibility for Killing 3000 Blo by Anonymous Coward · · Score: -1, Offtopic

    i had fun modding down the rest of your comments. thanks troll.

  21. Missing the point (see other posts below) by hummassa · · Score: 5, Insightful

    If you enable portknocking, your computer does not show up in a IP range portscan as a target. To a portscanner, your computer looks like all ports are closed, no way to reach it. It's turned off for all the port scanner knows. So the 5kr1p7 k1dd1ez will not bother you.

    I would be stupid, though, if *after* the port knock open some door, you get to open a telnet port for instance, instead of a more secure ssh port.

    What the topic *is* about is that now you can have OTPs and other types of non-fixed port knocks. Additionally to the security of not being "seen" by port scans, the port knock sequence changes and is more difficult to brute force.

    --
    It's better to be the foot on the boot than the face on the pavement. ~~ tkx Kadin2048
    1. Re:Missing the point (see other posts below) by dotz · · Score: 4, Insightful
      What's the point of having the machine look like invisible/unused, if you still can watch packets with data (heck, even encrypted) come to it?

      portknocking won't help you keeping your IP hidden. Having a tunnel from your IP to a trusted machine will (so you will appear as another IP and noone administrating that machine will give your "secret" IP to public).

      pr0n kiddiez? Man, just change SSH port from 22 to 2222 and you have pr0n kiddiez off your back. In the times of scanner automation (scan IP range, find vulnerable hosts, launch all known exploits, install rootkits) people won't bother trying to hack your sshd if it's not standard anyway - just because in the time they are trying to find, where is your sshd at, they can find & hack all those 5 windows 98 machines, which NEVER saw Windows Update, on the same network.

  22. Re:It would seem to me that the title of this arti by MullerMn · · Score: 1

    *bing* *bong* Captain Obvious to aisle 5 ..... Paging Captain Obvious...

  23. I'm confused by epine · · Score: 2, Insightful

    This does nothing more than redefine an existing problem. It's still a communication channel between two participants, whether the bits are conveyed inside the IP packets, or as attributes of the IP header.

    The "genius" of this approach seems to lie in the fact that the closed machine makes no response whatsoever until a valid doorknock sequence is received, which renders the system more clandistine from a very narrow point of view.

    One of the reasons why ssh security negotiation is two sided is to eliminate replay attacks. The doorknock concept is going to have a problem with this.

    I find it interesting to imagine that the doorknock sequence is defined as a function of the IP address of the requesting system. This would eliminate a replay attack by an adversary who can snoop traffic, originate traffic under its own identity, but not actively impersonate.

    1. Re:I'm confused by CamMac · · Score: 4, Insightful

      This isn't an attempt to redefine a problem, this is an attempt to provide a diffrent solution to a known problem. Two sided ssh security negotiation might work great for your application, but it might not be so hot for mine. Diffrent solutions have diffrent strenghts and weaknesses, and the more solutions we have, the better able we are to select one which matches our security needs. Options are a /good/ thing.

      And honestly, its a damn good idea with a simple implementation. Because its so simple to implement, there will be more than one portknock server. How would an external attacker know if a broken version of portknock was being used, or if there wasn't even a computer there?

      Pay attention to portknock, because you will see it again.

      --Cam

      --
      All jocks think about is sports. All nerds think about is sex.
    2. Re:I'm confused by Anonymous Coward · · Score: 0

      You're right; the implementation is simple. And by simple I mean simple in a bad way. First of all, it's easily vulnerable to DoS. Look at the code. The way it handles determining if a sequence from an ip address is correct is easily made by an attack to allocate arbitrary amounts of memory that is never freed. It also doesn't bother to check to see if its allocation succeeds, and will write into unallocated memory when an attack takes place, causing the daemon to segfault; leaving the firewall rules in an indeterminate state and removing legitimate usage of the service. Each packet processed involves searching through a linked list of the entire collection of addresses, so on its way to running out of memory and segfaulting, it will happily suck all of the CPU time of one processor.
      You'll also notice that even if it wasn't designed like some 19-year old that just learned C and has absolutely no understanding of algorithmic complexity wrote it, that the approach taken is easily DoSed period. IP blocks can be easily poisoned.

      Yes, pay attention to this retarded concept and its terrible implementation. You can learn a lot about how little people on Slashdot know about anything by how they either praise something that they know nothing about, or skirt the issue entirely and ramble about philisophical issues. Not one person bothered to look at this program and realize that it's a piece of shit. It's a wonderful learning device really. Q: Just how ignorant is Slashdot? A: Very.

    3. Re:I'm confused by CamMac · · Score: 3, Insightful

      Sigh... I can't believe I'm actually responding to this troll. Anyways

      The code looks like it was designed by some one who just learned C because, well, it was. The code is something called a proof of concept. A proof of concept, for those that are unfamiliar with the idea, is when something is quickly done just to prove that it might work and is feasible. Its usually the first step that leads to larger projects that address concerns like segfaulting.

      And NO security measures, short of pulling the plug, is immune to DoS. So ignoring a security messure that is succeptable to an attack that almost all security measures are not immune to is idiotic. Perhaps I should stop using my firewall because my poor 56k modem can get DoSed.

      --Cam

      --
      All jocks think about is sports. All nerds think about is sex.
    4. Re:I'm confused by Anonymous Coward · · Score: -1, Flamebait

      The code is something called a "piece of shit." If you don't know anything about writing secure software, then providing some sort of security service is not something you do. You're not capable.

      The entire concept is flawed because it can be DoSed by your shitty 56k modem. If a service can be rendered useless for legitimate purpose with a 56k modem then it is functionally deficient. No matter what is done, IP blocks can be poisoned with a miniscule amount of bandwidth. THE END.
      IT SERVES NO PURPOSE AT ALL YOU CLUELESS SHIT

      None.

      This won't be seen anywhere, because it's a piece of garbage. You're an idiot. I pointed out how this is useless and all you can comment about is that it's a proof of concept. Wahh your 56k modem. This has no utility. It will never have any utility.

      Maybe you should think about going back into the military, because you have no future in computer science.

  24. Re: Headline typo by mhesseltine · · Score: 3, Funny

    It's nothing major. It's just that Michael's "N" key is worn out from "approving" stories:

    Approve this one? N

    Approve this one? N

    Approve this one? N

    Approve this one? N

    Approve this one? N

    Approve this one? N

    Approve this one? N

    Approve this one? N

    Approve this one? N

    Approve this one? N

    Approve this one? N

    Approve a story on port knocking? Y

    Broken keyboard? Y

    That explains why it's so hard to get your stories posted. (wink, wink, nudge, nudge)

    --
    Overrated / Underrated : Moderation :: Anonymous Coward : Posting
  25. K is funny. by Ayanami+Rei · · Score: 0, Offtopic

    Cake is funny. Muffin? Not funny.

    --
    THIS THING CAN TURN ON A DIME, MACROSSZERO STYLE ALSO FUCK BETA, ~NYORON
  26. three things by Hubert_Shrump · · Score: 3, Interesting
    1. you have a single point of vulnerability in your daemon
    2. for the moderately paranoid, you can just shove all your stuff up into the ephemeral port range - most portscanners don't scan past 6000 unless you tell them to
    3. anyone that didn't think this thread would be mainly about 'kock' hasn't had their coffee. such as myself
    4. there is no item the fourth
    --
    Keep your packets off my GNU/Girlfriend!
  27. +1 Funny by dotz · · Score: 1

    ... only if I had mod points :)

  28. Kock by dotz · · Score: 3, Funny
    Kock is a real place. You don't belive me? Just click here

    Anyway, dear /. editors, it's a great way to ruin a story. 90% of posts in this discussion are offtopic, just because you did a typo (for those who plan to mod me down - I did posted a serious comment already, have mercy!).

  29. kock by pizza_milkshake · · Score: -1, Offtopic

    when the ports are a-kockin....

  30. Why so complicated? by technothrasher · · Score: 3, Insightful

    Why do you need to go to the trouble of hitting a one time sequence of closed ports rather than just knocking with a one time password in a single UDP datagram?

    1. Re:Why so complicated? by tigga · · Score: 1
      Why do you need to go to the trouble of hitting a one time sequence of closed ports rather than just knocking with a one time password in a single UDP datagram?

      Then there is a daemon which listens on that port and you may feed it with UDP stream trying to DOS it.

    2. Re:Why so complicated? by technothrasher · · Score: 3, Insightful
      Then there is a daemon which listens on that port and you may feed it with UDP stream trying to DOS it.


      Yeah, that's a point... but if you know the port to DOS, you must have been snooping. If you're snooping, you can just DOS whatever service the knocking opens up regardless of the knock protocol. Port knocking just keeps port scanners from seeing open services, it doesn't guard against a targetted DOS attack.

    3. Re:Why so complicated? by Krunch · · Score: 4, Insightful

      And what stops you from DOSing the portknock daemon ? If you are concerned about DOS, just change the port it listens to every 30 minutes or so and have it be a function of current time. Something like this: port_number = md5_to_portnum(md5((++time)+secret_salt)). Now if you know the secret_salt and current time you know on which port the daemon is listening for the current 30 minute period. But no DOSer can tell. You can also change the password using the same technique.

      I think this is easier to implement and to use than port knocking.

      --
      No GNU has been Hurd during the making of this comment.
  31. I just realized why portknocking is so good by doc+modulo · · Score: 4, Insightful

    Traditionally, port communications are safeguarded by the application behind the port. This means that if you have 13 network applications, there are 13 possible ways of someone owning your system with a trojan.

    On the other hand, portknocking is handled by a single daemon that is simpler than most applications. Portknocking could even be handled by the OS.

    This means that instead of having to trust several net-connected programs with your system security, whose primary focus will probably not be safety, you only have to trust 1 program which IS focused on security. Added to that, a portknocking program is easier to make safe because it's simpler than most other programs which have to handle both network defence AND some other task (Instant Messaging).

    --
    - -- Truth addict for life.
    1. Re:I just realized why portknocking is so good by ubiquitin · · Score: 4, Insightful

      What you describe here is also a good part of the rationale behind TCP wrappers.

      --
      http://tinyurl.com/4ny52
  32. Bones said it best by Anonymous Coward · · Score: -1, Offtopic

    "It's dead, Jim."

  33. Re: Headline typo by Anonymous Coward · · Score: 0

    Except this one was posted by timothy.

  34. Alka-Seltzer is funny. by Anonymous Coward · · Score: 0

    Nice. Reference. To. The. Film: the Sunshine Boys

  35. done... by Anonymous Coward · · Score: 0

    I have implemented such a system and am presenting on the subject of Cryptographic Port Knocking @ BlackHat this year!
    Check out the abstract @ http://www.hexi-dump.org/bytes.html

  36. BSD insider: Why FreeBSD Died by Anonymous Coward · · Score: -1, Troll
    The End of FreeBSD

    [ed. note: in the following text, former FreeBSD developer Mike Smith gives his reasons for abandoning FreeBSD]

    When I stood for election to the FreeBSD core team nearly two years ago, many of you will recall that it was after a long series of debates during which I maintained that too much organisation, too many rules and too much formality would be a bad thing for the project.

    Today, as I read the latest discussions on the future of the FreeBSD project, I see the same problem; a few new faces and many of the old going over the same tired arguments and suggesting variations on the same worthless schemes. Frankly I'm sick of it.

    FreeBSD used to be fun. It used to be about doing things the right way. It used to be something that you could sink your teeth into when the mundane chores of programming for a living got you down. It was something cool and exciting; a way to spend your spare time on an endeavour you loved that was at the same time wholesome and worthwhile.

    It's not anymore. It's about bylaws and committees and reports and milestones, telling others what to do and doing what you're told. It's about who can rant the longest or shout the loudest or mislead the most people into a bloc in order to legitimise doing what they think is best. Individuals notwithstanding, the project as a whole has lost track of where it's going, and has instead become obsessed with process and mechanics.

    So I'm leaving core. I don't want to feel like I should be "doing something" about a project that has lost interest in having something done for it. I don't have the energy to fight what has clearly become a losing battle; I have a life to live and a job to keep, and I won't achieve any of the goals I personally consider worthwhile if I remain obligated to care for the project.

    Discussion

    I'm sure that I've offended some people already; I'm sure that by the time I'm done here, I'll have offended more. If you feel a need to play to the crowd in your replies rather than make a sincere effort to address the problems I'm discussing here, please do us the courtesy of playing your politics openly.

    From a technical perspective, the project faces a set of challenges that significantly outstrips our ability to deliver. Some of the resources that we need to address these challenges are tied up in the fruitless metadiscussions that have raged since we made the mistake of electing officers. Others have left in disgust, or been driven out by the culture of abuse and distraction that has grown up since then. More may well remain available to recruitment, but while the project is busy infighting our chances for successful outreach are sorely diminished.

    There's no simple solution to this. For the project to move forward, one or the other of the warring philosophies must win out; either the project returns to its laid-back roots and gets on with the work, or it transforms into a super-organised engineering project and executes a brilliant plan to deliver what, ultimately, we all know we want.

    Whatever path is chosen, whatever balance is struck, the choosing and the striking are the important parts. The current indecision and endless conflict are incompatible with any sort of progress.

    Trying to dissect the above is far beyond the scope of any parting shot, no matter how distended. All I can really ask of you all is to let go of the minutiae for a moment and take a look at the big picture. What is the ultimate goal here? How can we get there with as little overhead as possible? How would you like to be treated by your fellow travellers?

    Shouts

    To the Slashdot "BSD is dying" crowd - big deal. Death is part of the cycle; take a look at your soft, pallid bodies and consider that right this very moment, parts of you are dying. See? It's not so bad.

    To the bulk of the FreeBSD committerbase and the developer community at large - keep your eyes on the real goals. It

  37. Re:GNAA Claims Responsibility for Killing 3000 Blo by Anonymous Coward · · Score: -1, Troll

    but as fun as modding you down was, i had far more fun fellating rob maldas penis last night. slurp slurp

  38. Re:GNAA Claims Responsibility for Killing 3000 Blo by Anonymous Coward · · Score: -1, Troll

    What do you mean "rob maldas penis"? I thought Kathleen was the sausage slapper in that household.

  39. has anyone read the thesis? by Anonymous Coward · · Score: 2, Insightful
    I must say I'm quite disappointed in this. Anybody listening in on the "knock" will know the plaintext used in the encryption process. It's then a trivial matter to brute-force the password. This is because 99% of the time, the client will be run from the machine you're connecting from, giving the attacker the source IP and the destination port.

    Also, it seems that an ordinary portscan would add 32 random firewall rules, that would never be cleaned up.

    I'm not even going to mention that an MD5 hash is used to determine if the original file has changed.

  40. Port knocking is bad news. by rice_burners_suck · · Score: -1, Offtopic

    I don't know about all this port knocking. The other day, my valves were knocking, and that concerned me quite a bit, as I just recently finished a head job, and the knocking tells me that I didn't adjust the valves correctly. The last thing I need now is my ports knocking too... that would totally ruin the engine. You can't find Stage-1 455's in this condition anymore.

  41. Broken Implementation by btg · · Score: 4, Interesting

    Not only is the concept stupid, but I looked at the guy's thesis for five seconds and his crypto is totally broken - there is a trivial known plaintext attack to recover the secret password if you can intercept knocks on the wire. The plaintext is [IP addr][port][action] for 4 + 2 + 1 bytes each. The last byte is pad - which is cunningly hardwired to null.

    The IP address makes up 4 bytes of a 7 byte plaintext (which is already small enough to brute force) and the IP address will be that of the knocking host. Wait, it gets worse! The "action" byte is basically "open" or "close" and the port bytes don't quite use the full 2^16 range. In other words I need to brute force a little less than 17 bits. This is only challenging if I want to make like ET and do it with a reprogrammed Speak N Spell.

    Back to sleep for me until version 5.0.

    1. Re:Broken Implementation by Hektor_Troy · · Score: 2, Interesting

      It's proof of concept, not "here, use this in your ultra secretive secure thing-a-ma-jig".

      I knew a guy who had ten locks on his door. You had to turn the key the same way to lock and unlock. He usually only locked two or three locks, when he left, simply because he figured, that by the time he gets home, a possible burglar still haven't unlocked the door (probaby by locking some of the unlocked locks).

      This is (to me anyway) somewhat the same thing.

      It may not be entirely difficult to figure out, what ports are being used to knock, but as I understand port knocking, there's more to it than just the ports; the timing has to be right as well. And using a one time pad, makes sniffing useless. And just how do you brute force a secret knock?

      Just for kicks, let's say we restrict ourselves to knocking on 4 ports, and we have a range of 128 ports.

      Well, if you can knock on a port more than once, you'll end up with 128^4 (268.435.456) (it could be 4^128 which is MUCH worse). Not too shabby, right?

      This is even ignoring any timing restrictions. If you have to say knock on port 1004 first, wait 3 seconds, knock on port 1100, wait 1 second, knock on 1001, wait 5 seconds, knock on port 1027, HOW would you brute that? Remember, knocking on a wrong port in the sequence will reset your attempt.

      I don't even want to speculate on the numbers in that case.

      --
      We do not live in the 21st century. We live in the 20 second century.
  42. Clients? by NickeB · · Score: 1

    Okay, so we have portknocking, but do we have clients that can utilize it?

    Let's say I want to access machine X's ssh daemon, which utilizes portknocking, is there any ssh client today that can access it?

    Anyhow, I'm gonna name my firewall "Heavens door" when this works.

  43. you said portknocker by specialRrider_Joe · · Score: 0, Offtopic

    Butthead: you portknocker! Beavis: he he hehehe Butthead: uhhh huh haha Beavis: he he.... you said knocker Butthead: uhhhh huh ha ha huh Beavis: he hehe he

  44. lolskate by Anonymous Coward · · Score: 0

    no that's hemos

  45. No, it's a reference to Jerk City. by Ayanami+Rei · · Score: 1

    Can't find the strip... "Kafka is twice as funny to neoclassical existentialists. But rape is funny and I don't hear a k. The implication is you can FEEL the k."

    --
    THIS THING CAN TURN ON A DIME, MACROSSZERO STYLE ALSO FUCK BETA, ~NYORON