[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

RFS: doorman -- Port knocking daemon for SSH and other servers.



Name: doorman
Version: 0.81
ITP number: 305584
Section: admin
License: GPL-2

Doorman allows a server which is not intended for general public access to
run with most (or even all) of it's TCP ports closed to the outside world.
It admits only recognized parties, that properly introduce themselves by
"knocking" to a specific closed port on the server.
The door-knocker, "knock",  can be run under Unix, GNU/Linux, or  Microsoft 
Windows.

This particular implementation deviates a bit from his original proposal 
(described by Martin Krzywinski in Sysadmin magazine and linuxjournal.com), 
in that the doorman watches for only a single UDP packet. To get the doorman 
to open up, the packet must contain an MD5 hash which correctly hashes a 
shared secret, salted with a 32-bit random number, the identifying user or 
group-name, and the requested service port-number. 

Currently doorman can only protect TCP services.

The project's home page is at: http://doorman.sourceforge.net/


You can get the source and i386 binary packages from:
http://poczta.prezu.one.pl/doorman/

-- 
Regards,
Patryk Cisek

Attachment: pgpu1mLydYhx0.pgp
Description: PGP signature


Reply to: