{"repo":"mrash/fwknop","free":true,"listed":false,"github":"https://github.com/mrash/fwknop","clone":"git clone https://github.com/mrash/fwknop.git","description":"Single Packet Authorization > Port Knocking","language":"Perl","stars":1412,"topics":["port-knocker","authentication","authorization","spa","zero-trust","firewall","hmac"],"license":"GPL-2.0","category":"auth-billing-email","readme_excerpt":"fwknop - Single Packet Authorization Introduction fwknop implements an authorization scheme known as Single Packet Authorization (SPA) for strong service concealment. SPA requires only a single packet which is encrypted, non-replayable, and authenticated via an HMAC in order to communicate desired access to a service that is hidden behind a firewall in a default-drop filtering stance. The main application of SPA is to use a firewall to drop all attempts to connect to services such as SSH in order to make the exploitation of vulnerabilities (both 0-day and unpatched code) more difficult. Because there are no open ports, any service that is concealed by SPA naturally cannot be scanned for with Nmap. The fwknop project supports four different firewalls: iptables, firewalld, PF, and ipfw across Linux, OpenBSD, FreeBSD, and Mac OS X. There is also support for custom scripts so that fwknop can be made to support other infrastructure such as ipset or nftables. SPA is essentially next generation Port Knocking (PK), but solves many of the limitations exhibited by PK while retaining its core benefits. PK limitations include a general difficulty in protecting against replay attacks, asymmetric ciphers and HMAC schemes are not usually possible to reliably support, and it is trivially easy to mount a DoS attack against a PK server just by spoofing an additional packet into a PK sequence as it traverses the network (thereby convincing the PK server that the client doesn't know the proper s","default_branch":null,"files":null,"tree":[],"storefront":"/r/mrash","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/mrash/fwknop/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}