Releases: EvSecDev/SecureKnock
Releases · EvSecDev/SecureKnock
Release list
v1.2.1
v1.2.0
v1.1.0
v1.0.0
v0.6.0
✅ Added
- Statically compiled executable
🔄 Changed
- Max payload sizes for more reliable delivery of UDP large packets over the internet
- Daemon installation script moved to built-in function
❌ Removed
- Regex package
🔨 Fixed
- Capabilities check would always say there are no caps set (fixed by loading current caps after initializing capability check)
ℹ️ Instructions
- Please refer to the README.md file for instructions
⚠️ Please be careful with this pre-release, as it may not work as expected.
v0.4.0
Added
- Dry run to test provided arugment validity
- Wet runs to test configuration file syntax and packet capture filters
- Automatic source IP selection if source address argument is omitted for client mode
- Verbosity levels to logging and stdout
Changed
- Combined client and server into single code base
- Encryption algorithm from AESGCM to ChaCha20-Poly1305
- Required key size from 56 characters to 64 characters
Removed
- Default encryption key file (path to file must always be manually specified)
- Deprecated x/crypto/ssh/terminal package
Instructions
- Please refer to the README.md file for instructions
⚠️ Please be careful with this pre-release, as it may not work as expected.- This is only working currently on Debian Stable
v0.2.0
Added
- More detailed logging to command execution failures
- Panic catch to validation and execution functions
- Generic bpf filter config field to allow for any combination of valid BPF filters
- Optional server configuration file field to add an exclusion BPF filter
- Log message in server to show received valid knock packets before executing commands
Fixed
- Server would ask for more permissions than allowed in sudo apparmor profile (fixed by allowing inet6 and /etc/gai.conf read permissions)
- Server systemd service repeatedly failed without specific logs (fixed by excluding capabilities from service file, and adding directly to file only)
- Server install script did not correct owner/permissions of extracted server executable
- Server install script did not show user missing commands
Instructions
- Please refer to the README.md file for instructions
⚠️ Please be careful with this pre-release, as it may not work as expected.