[tor-relays] Port knocking for SSH on a Tor node

2016-05-03 Thread Cristian Consonni
Hi, I am putting together a blog post with tips and tools for administrating a node and then I have discovered the technique of "port knocking". I decided to experiment with it and I have created a guide that puts it together with the default configuration for iptables by torservers/moba[1a][1b].

Re: [tor-relays] Port knocking for SSH on a Tor node

2016-05-03 Thread Diarmaid McManus
I would no longer recommend port knocking using a static port sequence. Instead, I'd recommend knockknock by moxie, https://github.com/moxie0/knockknock/blob/master/README On 3 May 2016 14:58, "Cristian Consonni" wrote: > Hi, > > I am putting together a blog post with tips and tools for > adminis

Re: [tor-relays] Port knocking for SSH on a Tor node

2016-05-03 Thread Cristian Consonni
2016-05-03 16:25 GMT+02:00 Diarmaid McManus : > I would no longer recommend port knocking using a static port sequence. > Instead, I'd recommend knockknock by moxie, > https://github.com/moxie0/knockknock/blob/master/README I have discovered knockknock project just little before finishing the post

Re: [tor-relays] Port knocking for SSH on a Tor node

2016-05-03 Thread Diarmaid McManus
I agree there have not been any updates, but if you look at the issues list it doesn't seem there are any breaking bugs that would require a patch. Regular port knocking is certainly an improvement over nothing, but it's vulnerable to an attacker in some conditions as mentioned in the readme. So l

Re: [tor-relays] Port knocking for SSH on a Tor node

2016-05-03 Thread goll
On Tue, 3 May 2016 15:58:22 +0200 Cristian Consonni wrote: > Hi, > > I am putting together a blog post with tips and tools for > administrating a node and then I have discovered the technique of > "port knocking". > Have you looked into Single Packet Authorization? http://www.cipherdyne.org/f

Re: [tor-relays] Port knocking for SSH on a Tor node

2016-05-03 Thread Cristian Consonni
Hi, 2016-05-03 17:30 GMT+02:00 goll : > Have you looked into Single Packet Authorization? > > http://www.cipherdyne.org/fwknop/ I saw it mentioned in one of the 2014 threads, but I didn't dig into it. I will take a look. Thanks. C ___ tor-relays mailin