Single packet port knocking with Fwknop

    I read this article in a linux mag that described the use of this tool. What it does is close all you ports(i'm guessing using iptables), you have a serivce running like ssh, it will stop you connecting to ssh until you send a crafted packet, which will open up port you selectd with the client and only the IP the client sent the packet from will be aloud in.

    A quick setup tut.
    Download fwknop-1.9.1tar.gz

    Flush iptables input chain
    >iptables -A INPUT -d -m state --state RELATED ESTABILSHED -j ACCEPT
    >iptables -A INPUT -i lo -j ACCEPT
    >iptables -P INPUT DROP
    change to you server

    open up/etc/fwknop/access.conf and change the KEY value to your password

    now start fwknop /etc/init.d/fwknop start
    try and ssh into you server

    on the client do
    >fwknop -A tcp/22 -a -D

    It looks to a be promising alternative to port knocking. I watched the HOPE video presentation of this tool, and am a bit anxious to see it rewritten in C.
