Skip to content

Releases: EvSecDev/SecureKnock

v1.2.1

Choose a tag to compare

@EvSecDev EvSecDev released this 14 Jul 14:12
bcf57eb

🔄 Changed

  • Updated dependency x/crypto

ℹ️ Instructions

  • Please refer to the README.md file for instructions

v1.2.0

Choose a tag to compare

@EvSecDev EvSecDev released this 19 Oct 17:12
f0c6146

✅ Added

  • Support to supply password via stdin (for scripting)

ℹ️ Instructions

  • Please refer to the README.md file for instructions

v1.1.0

Choose a tag to compare

@EvSecDev EvSecDev released this 15 Jul 05:51
f0c6146

✅ Added

  • Feature to force disable use of sudo server-side when not running as root

ℹ️ Instructions

  • Please refer to the README.md file for instructions

v1.0.0

Choose a tag to compare

@EvSecDev EvSecDev released this 08 Jun 05:21
52296e6

🎊 Full Release! 🎊

ℹ️ Instructions

  • Please refer to the README.md file for instructions

v0.6.0

v0.6.0 Pre-release
Pre-release

Choose a tag to compare

@EvSecDev EvSecDev released this 27 May 03:36
4e0b505

✅ Added

  • Statically compiled executable

🔄 Changed

  • Max payload sizes for more reliable delivery of UDP large packets over the internet
  • Daemon installation script moved to built-in function

❌ Removed

  • Regex package

🔨 Fixed

  • Capabilities check would always say there are no caps set (fixed by loading current caps after initializing capability check)

ℹ️ Instructions

  • Please refer to the README.md file for instructions
  • ⚠️ Please be careful with this pre-release, as it may not work as expected.

v0.4.0

v0.4.0 Pre-release
Pre-release

Choose a tag to compare

@EvSecDev EvSecDev released this 09 Mar 17:28
7993e66

Added

  • Dry run to test provided arugment validity
  • Wet runs to test configuration file syntax and packet capture filters
  • Automatic source IP selection if source address argument is omitted for client mode
  • Verbosity levels to logging and stdout

Changed

  • Combined client and server into single code base
  • Encryption algorithm from AESGCM to ChaCha20-Poly1305
  • Required key size from 56 characters to 64 characters

Removed

  • Default encryption key file (path to file must always be manually specified)
  • Deprecated x/crypto/ssh/terminal package

Instructions

  • Please refer to the README.md file for instructions
  • ⚠️ Please be careful with this pre-release, as it may not work as expected.
  • This is only working currently on Debian Stable

v0.2.0

v0.2.0 Pre-release
Pre-release

Choose a tag to compare

@EvSecDev EvSecDev released this 02 Mar 05:10
cd8919b

Added

  • More detailed logging to command execution failures
  • Panic catch to validation and execution functions
  • Generic bpf filter config field to allow for any combination of valid BPF filters
  • Optional server configuration file field to add an exclusion BPF filter
  • Log message in server to show received valid knock packets before executing commands

Fixed

  • Server would ask for more permissions than allowed in sudo apparmor profile (fixed by allowing inet6 and /etc/gai.conf read permissions)
  • Server systemd service repeatedly failed without specific logs (fixed by excluding capabilities from service file, and adding directly to file only)
  • Server install script did not correct owner/permissions of extracted server executable
  • Server install script did not show user missing commands

Instructions

  • Please refer to the README.md file for instructions
  • ⚠️ Please be careful with this pre-release, as it may not work as expected.

v0.1.0

v0.1.0 Pre-release
Pre-release

Choose a tag to compare

@EvSecDev EvSecDev released this 25 Nov 02:13
98cc836

Initial prototype binaries for amd64

These were only tested on Debian 12. Any attempt to run them on other systems may or may not work.

⚠️ Please be careful with this pre-release, as it may not work as expected.