|
From: SourceForge.net <no...@so...> - 2004-07-17 15:49:27
|
Feature Requests item #992900, was opened at 2004-07-17 10:49 Message generated for change (Tracker Item Submitted) made by Item Submitter You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410646&aid=992900&group_id=34096 Category: Packages Group: None Status: Open Priority: 5 Submitted By: Heiko Zuerker (smiley73) Assigned to: Nobody/Anonymous (nobody) Summary: add The Doorman Initial Comment: http://doorman.sourceforge.net/ Summary This project allows a server to run silently, invisibly, with all TCP ports closed... except to those who know... the secret knock! Discussion The doorman is intended to run on systems which have their firewall rules turned down tightly enough as to be effectively invisible to the outside world. The doorman adds and removes extra rules in a carefully controlled manner. Using metaphor 1... The doorman daemon "guards the door" of a host, admitting only recognized parties. It allows a server which is not intended for general public access to run with all of it's TCP ports closed to the outside world. A matching "knocker" is provided, with which to persuade the doorman to open the door a crack, just wide enough for a single TCP connection from a single IP address. And now, switching to metaphor 2... :) A private server thus rigged for silent running has greatly enhanced security. Port scans cannot reveal it's existence. Even if it's existence is known by other means (or the firewall isn't all that tight), possible bugs in server code cannot be exploited; packets from unknown sources simply never get to the bug. The current implementation of the doorman, "doormand", is suitable for protecting only TCP services on Unix-type systems. The door-knocker, "knock", can be run under Unix, GNU/Linux, or Microsoft Windows. ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410646&aid=992900&group_id=34096 |