Spotlight | Reviews | Current Issue | Newsletter | Subscribe | Contact |
Departments

user friendly

CeBIT 2010 CFP

15 projects have been chosen - they will present their work at CeBIT Open Source 2010 in Hanover, Germany.

Find them in hall 2, March 2-6 or here.

  linuxpromagazine.com » Issues » 2008 » 91 » WHO’S THERE?  

Print this page. Recommend
Slashdot it! Delicious Share on Facebook Tweet! Digg

Remote access security with single-packet port knocking

WHO’S THERE?

Author(s): JULIET KEMP

If you are looking for an extra layer of remote access security, try single-packet port knocking.

Public key cryptography means that the traffic is secured and that if you verify keys correctly, it isn’t vulnerable to man-in-themiddle attacks. Exploits are occasionally found, but they are quickly fixed. However, your system could still be vulnerable to brute-force attacks. If you have only a small number of user accounts, if your usernames are unusual, and if your passwords are carefully crafted, this might not be an issue. But if you have multiple users on a system, it becomes harder to ensure that all passwords really are secure. One solution is to run a passwordguessing system such as John the Ripper, which can discover a poor password before anyone with nefarious intentions has time to exploit it.

Also, you can create firewall rules that establish a maximum number of connection attempts from the same IP address, either indefinitely or for the next few minutes. (The latter option is preferable to avoid problems for real users, who do occasionally mistype their password several times.)


Read full article as PDF »


Comments


Print this page. Recommend
Slashdot it! Delicious Share on Facebook Tweet! Digg
FREE Live Streaming Video from ApacheCon US 2009

Watch our free Video Archive from Apachecon US 2009. Archive provided by The Apache Foundation, COLLABNET, and Linux Pro Magazine

Drawing internationally renowned thought-leaders, contributors, and organizations in the Open Source community, ApacheCon offers insight into the culture and community that develops and shepherds industry-leading Open Source projects, including Apache HTTP Server – the world's most popular Web server software for more than 10 years.

Find out more

 

In the US and Canada, Linux Magazine is known as Linux Pro Magazine.
Entire contents © 2010 [Linux New Media USA, LLC]
Linux New Media web sites:
North America: [Linux Pro Magazine]
UK/Worldwide: [Linux Magazine]
Germany: [Linux-Magazin] [LinuxUser] [EasyLinux] [Linux-Community] [Linux Technical Review]
Eastern Europe: [Linux Magazine Poland] [Linux Community Poland]
International: [Linux Magazine Brazil] [EasyLinux Brazil] [Linux Magazine Spanish]
Corporate: [Linux New Media AG]