![]() |
Hello and Welcome from United States to the UNIX and Linux Forums! Thank You for Visiting and Joining Our Global Community.
|
|
google unix.com
|
|||||||
| Forums | Register | Forum Rules | Links | Albums | FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
| Software Releases - RSS News UNIX and Linux Software Releases Via RSS (Freshmeat and Others) |
More UNIX and Linux Forum Topics You Might Find Helpful
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| fwknop 1.9.4 (Default branch) | iBot | Software Releases - RSS News | 0 | 06-02-2008 11:30 AM |
| grub-choose-default 0.3 (Default branch) | iBot | Software Releases - RSS News | 0 | 05-30-2008 11:10 AM |
| Fwknop and single packet authorization | iBot | UNIX and Linux RSS News | 0 | 05-20-2008 05:40 AM |
| fwknop 1.9.3 (Default branch) | iBot | Software Releases - RSS News | 0 | 04-06-2008 01:20 PM |
| fwknop 1.9.1 (Default branch) | iBot | Software Releases - RSS News | 0 | 01-27-2008 10:20 AM |
|
|
LinkBack | Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
|||||
|
fwknop 1.9.2 (Default branch)
fwknop implements an authorization scheme thatrequires only a single encrypted packet tocommunicate various pieces of information,including desired access through a Netfilterpolicy and/or specific commands to execute on thetarget system. The main application of thisprogram is to protect services such as SSH with anadditional layer of security in order to make theexploitation of vulnerabilities much moredifficult. The authorization server works bypassively monitoring authorization packets vialibpcap.License: GNU General Public License (GPL)Changes:
The "Salted__" prefix was removed from Crypt::CBCencrypted SPA messages. More granular source IPand allowed IP tests were added so that access toparticular internal IP addresses can be excludedin --Forward-access mode. A new keyword,INTERNAL_NET_ACCESS, is now parsed from theaccess.conf file in order to implement theserestrictions. BLACKLIST functionality was added toallow source IP addresses to be excluded from theauthentication process easily. Firewall ruleaccess timeouts that are defined by the fwknopclient were added. SHA-256 and SHA-1 digestalgorithms were added for replay attack detection. More... |
| Bookmarks |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|