[TOOL] KnockD - Port Knocking Daemon

From: SecuriTeam (support_at_securiteam.com)
Date: 04/15/04

  • Next message: SecuriTeam: "[TOOL] Hatchet - PF Firewall Log Parser"
    To: list@securiteam.com
    Date: 15 Apr 2004 16:21:15 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

      KnockD - Port Knocking Daemon
    ------------------------------------------------------------------------

    SUMMARY

    DETAILS

     <http://www.zeroflux.org/knock/> knockd is a port-knock server. It
    listens to all traffic on an Ethernet interface, looking for special
    "knock" sequences of port-hits. A client makes these port-hits by sending
    a TCP (or UDP) packet to a port on the server. This port need not be open
    -- since knockd listens at the link-layer level, it sees all traffic even
    if it's destined for a closed port. When the server detects a specific
    sequence of port-hits, it runs a command defined in its configuration
    file. This can be used to open up holes in a firewall for quick access.

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:jvinet@zeroflux.org> Judd
    Vinet.

    The tool can be downloaded from: <http://www.zeroflux.org/knock/>
    http://www.zeroflux.org/knock/

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[TOOL] Hatchet - PF Firewall Log Parser"

    Relevant Pages

    • [NT] Multiple vulnerabilities in Hired Team: Trial
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Hired Team is a nice FPS game developed by New Media ... allows an attacker to join a server (that doesn't have password support, ... Each time a new player joins, the server assigns an UDP port to him ...
      (Securiteam)
    • [EXPL] Quake 3 Buffer Overflow (Exploit)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... port and exit cleanly with an unsuspicious error message. ... unsigned char ipx; ... int hooklen; // for both sendservercommand and directconnect ...
      (Securiteam)
    • [UNIX] Solaris Socket Hijack Vulnerability
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... By binding a socket with an already binded port number of specific IP ... attackers can hijack an already binded sockets in Solaris. ... A bug with Solaris Kernel flag of SO_REUSEADDR cause the Kernel to accept ...
      (Securiteam)
    • [TOOL] IRC DCC Connect() Blind Port Scanner
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... IRC DCC ConnectBlind Port Scanner ... After waiting a short while for the mIRC client ...
      (Securiteam)
    • [NT] SLMail Pro Multiple Denial of Service
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... The SLMail Pro Web Service running on port 801 is ... int main{ ...
      (Securiteam)