|
|
|
|
|
by penguinduck
3661 days ago
|
|
I don't understand what you mean. How would you prevent the attacker from knowing the port, except by only sending the port knock, and then never actually connecting? Let's say the attacker has no idea you're using port knocking and even somehow missed your port knock packet completely, but after that captures subsequent traffic. He will still see the sequence numbers in the SYN/ACK from the server which is all he needs. Once he has that, he is an equal party to you (the legitimate client) in that connection. |
|
Tell me what percentage of attackers on the net have full access to the network traffic and can do full MITM attack?
If the goal is layered defense and minimizing exposure, worst case scenario is not good counterargument.