| |
| | Knock, Knock, Knock |
 | | A legitimate port knocking application would often parse firewall logs, waiting for a sequence of logged errors and then spring to life, manipulating firewall rules to open a port. |
 | | Generally, the process or daemon quietly listens for a sequence of pings (such a hitting ports 100, 109, 101, 101 three times in that sequence, a code of 911 that could be used to bring the backdoor to life), or by using packet type, such as sending SYN requests in a similar predetermined sequence. |
 | | Port knocking is a legitimate security concept that has been discussed on Slashdot recently, and some virus writers have started using it "secure" their own backdoors. |
| www.securityfocus.com /columnists/221 (1205 words) |
|