The UNIX and Linux Forums  

Go Back   The UNIX and Linux Forums > Special Forums > News, Links, Events and Announcements > Software Releases - RSS News
Google UNIX.COM


Software Releases - RSS News Software Releases Via RSS (Freshmeat and Others)

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
fwknop 1.9.4 (Default branch) iBot Software Releases - RSS News 0 06-02-2008 07:30 AM
grub-choose-default 0.3 (Default branch) iBot Software Releases - RSS News 0 05-30-2008 07:10 AM
Fwknop and single packet authorization iBot UNIX and Linux RSS News 0 05-20-2008 01:40 AM
fwknop 1.9.3 (Default branch) iBot Software Releases - RSS News 0 04-06-2008 09:20 AM
fwknop 1.9.1 (Default branch) iBot Software Releases - RSS News 0 01-27-2008 06:20 AM

Reply
 
Submit Tools LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 03-17-2008
iBot's Avatar
RSS Robot Girl
 

Join Date: Sep 2000
Posts: 14,302
fwknop 1.9.2 (Default branch)

fwknop implements an authorization scheme thatrequires only a single encrypted packet tocommunicate various pieces of information,including desired access through a Netfilterpolicy and/or specific commands to execute on thetarget system. The main application of thisprogram is to protect services such as SSH with anadditional layer of security in order to make theexploitation of vulnerabilities much moredifficult. The authorization server works bypassively monitoring authorization packets vialibpcap.License: GNU General Public License (GPL)Changes:
The "Salted__" prefix was removed from Crypt::CBCencrypted SPA messages. More granular source IPand allowed IP tests were added so that access toparticular internal IP addresses can be excludedin --Forward-access mode. A new keyword,INTERNAL_NET_ACCESS, is now parsed from theaccess.conf file in order to implement theserestrictions. BLACKLIST functionality was added toallow source IP addresses to be excluded from theauthentication process easily. Firewall ruleaccess timeouts that are defined by the fwknopclient were added. SHA-256 and SHA-1 digestalgorithms were added for replay attack detection.

More...
Reply With Quote
Google The UNIX and Linux Forums
Forum Sponsor
Reply

Thread Tools
Display Modes




All times are GMT -7. The time now is 06:05 PM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited.
The UNIX and Linux Forums Content Copyright ©1993-2008. All Rights Reserved.Ad Management by RedTyger Visit The Global Fact Book

Content Relevant URLs by vBSEO 3.2.0