HN2new | past | comments | ask | show | jobs | submitlogin

You can conceal that open port with some form of port knocking. Though this does reinforce your "easy" point.

Also, if it's an UDP port, then using a protocol that expects first client packet to be pre-authenticated and not emitting any response otherwise gets you pretty damn close to having this port closed.





Thanks for the suggestion !

I looked into it but it seems that port knocking and Single Packet AuthZ literally open the firewall and expose the port when used.

Meaning it is great to reveal the SSH port when needed, do your business quickly and close it back when you are done. But my guess is those overlay networks need to port available all the time, so...


Port knocking should open up the port for the IP that sent the knock. Not for everyone.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: