Automic VaultAutomic Vault

brew

knock mit Homebrew, apk, dnf, MacPorts, zypper, apt, pacman installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für knock in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install knock

local Homebrew formula metadata

MacPortsverifiziert · 94%
sudo port install knock

MacPorts ports tree · net/knock/Portfile · Quelle: api.github.com

Linux

Alpine Linux apkverifiziert · 92%
sudo apk add knock

Alpine Linux edge package indexes · knock · Quelle: dl-cdn.alpinelinux.org

Fedora dnfverifiziert · 92%
sudo dnf install knock

Fedora Rawhide package metadata · knock · Quelle: dl.fedoraproject.org

openSUSE zypperverifiziert · 92%
sudo zypper install knock

openSUSE Tumbleweed package metadata · knock · Quelle: download.opensuse.org

Debian aptverifiziert · 92%
sudo apt install knockd

Debian stable package indexes · knockd · Quelle: deb.debian.org

Arch Linux pacmanverifiziert · 92%
sudo pacman -S knockd

Arch Linux sync databases · knockd · Quelle: geo.mirror.pkgbuild.com

Überblick

Paketzusammenfassung

Port-knock server

Befehle und Aliase

  • knock
  • knock_helper_ipt.sh
  • knockd

Verlauf

Projektgeschichte und Nutzung

knock is Judd Vinet's port-knocking server and client. It watches network traffic with libpcap for a configured sequence of port hits and runs commands, commonly firewall changes, when the sequence matches.

Projektgeschichte

The README carries a 2004 copyright notice and describes the core design that still defines the package: closed ports can receive a secret sequence because knockd sniffs link-layer traffic rather than listening on those ports. The bundled ChangeLog lists 0.1 as the initial release and shows later work adding TCP flag handling, reload behavior, timeouts, kernel-space BPF filtering, one-time sequences, interface selection, and IPv6 support.

Version 0.8 was published on 2021-04-24 with multiple fixes and IPv6 support. The GitHub repository retained a small C codebase, an example `knockd.conf`, and manpage documentation rather than growing into a larger access-control framework.

Adoptionsgeschichte

knock spread through Unix-like distributions because it solved a specific sysadmin problem with a small daemon and client. Package names vary between `knock`, `knockd`, and distribution-specific formula names, but the underlying model stayed close to the original README example: a knock sequence opens SSH, and another sequence closes it.

Wie es verwendet wird

A server runs `knockd` with a configuration file such as `/etc/knockd.conf`; a client runs `knock` to send TCP or UDP packets to the configured sequence. Commands usually add or remove firewall rules, so the tool is operationally simple but security-sensitive: the sequence should be treated like a shared secret and firewall commands must be written carefully.

Warum Paket-Nerds sich dafür interessieren

knock is a memorable package because it embodies a whole security pattern in a tiny Unix daemon. It is also a reminder of the early-2000s sysadmin style: libpcap, iptables commands, config files, and a tiny client were enough to make a practical layer around SSH exposure.

Zeitleiste

  • 2004: README copyright identifies Judd Vinet's original project era.
  • 0.1: ChangeLog records the initial release.
  • 0.3: ChangeLog added PPP support, command timeout directives, SIGHUP config reloads, and per-port protocols.
  • 0.5: ChangeLog added one-time sequences, interface selection, BPF filtering, and security fixes.
  • 0.7: ChangeLog documented the target directive and consolidated OS-specific networking code.
  • 2021-04-24: v0.8 release published with fixes and IPv6 support.

Related projects

  • knock is related to other port-knocking and single-packet-authorization tools, firewall managers such as iptables, packet crafting tools such as sendip, and SSH hardening workflows.

Sicherheitslage

Risikostufe: blue

broad file, network, media, or database tool signal.

Risikoklassifikator

blue Risiko · mittel Konfidenz · tool

Warum

  • broad file, network, media, or database tool signal

Signale

  • text:server

Installationsverhalten

  • In den Formelmetadaten ist kein Homebrew-Post-install-Hook erfasst.
  • Homebrew-Bottle-Metadaten sind für 13 Plattformziele verfügbar.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
/etc/knockd.conf

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
knockcliglobales Executable
knock_helper_ipt.shcliglobales Executable
knockdcliglobales Executable

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-07-25
Manager-Version0.8
Manager aktualisiert
lokale DatenOK
Upstreamnot checked
neueste erkannte Versionnicht erkannt

https://github.com/jvinet/knock

  • InfoNo package-manager update timestamp was available.niedrig Konfidenz
  • InfoNo cached GitHub release or tag data was available.https://github.com/jvinet/knocknone Konfidenz

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:knock
Version0.8
PaketmanagerHomebrew
Paketmanager-Seitehttps://formulae.brew.sh/formula/knock
Homepagehttps://github.com/jvinet/knock
Repositoryhttps://github.com/jvinet/knock
Upstream-Dokumentationhttps://github.com/jvinet/knock#readme
LizenzGPL-2.0-or-later
Quellarchivhttps://github.com/jvinet/knock/releases/download/v0.8/knock-0.8.tar.gz
Von macOS bereitgestellte Bibliothekenlibpcap
Bottleverfügbar (auf arm64_big_sur, arm64_linux, arm64_monterey, arm64_sequoia, arm64_sonoma, arm64_tahoe, arm64_ventura, big_sur, catalina, monterey, sonoma, ventura, x86_64_linux)
Homebrew post-installnicht definiert
Dienstkeiner deklariert

Registry-Fakten

Details aus der Quelldatenbank

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Nameknock
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

Source-Datenbank-Treffer

Andere Paketmanager-Einträge

Treffer stammen aus externen Paketmanager-Indizes und bleiben von lokalen Automic-Vault-Paketlinks getrennt.

apk95%

knock 0.8.2-r2

A simple port-knocking daemon

https://github.com/TDFKAOlli/knock

sudo apk add knock
  • License: GPL-2.0-or-later
  • Architecture: x86_64
  • Source Package: knock
  • 1 Abhängigkeiten
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Knock
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: knock from https://dl-cdn.alpinelinux.org/alpine/edge/main/x86_64/APKINDEX.tar.gz
apk95%

knock-doc 0.8.2-r2

A simple port-knocking daemon (documentation)

https://github.com/TDFKAOlli/knock

sudo apk add knock-doc
  • License: GPL-2.0-or-later
  • Architecture: x86_64
  • Source Package: knock
  • normalized package name match
  • Abgeglichen nach: Knock
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: knock-doc from https://dl-cdn.alpinelinux.org/alpine/edge/main/x86_64/APKINDEX.tar.gz
apk95%

knock-openrc 0.8.2-r2

A simple port-knocking daemon (OpenRC init scripts)

https://github.com/TDFKAOlli/knock

sudo apk add knock-openrc
  • License: GPL-2.0-or-later
  • Architecture: x86_64
  • Source Package: knock
  • normalized package name match
  • Abgeglichen nach: Knock
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: knock-openrc from https://dl-cdn.alpinelinux.org/alpine/edge/main/x86_64/APKINDEX.tar.gz
dnf95%

knock 0.8-13.fc44

A port-knocking server/client

http://www.zeroflux.org/projects/knock

sudo dnf install knock
  • License: GPL-2.0-or-later
  • Category: Unspecified
  • Architecture: x86_64
  • Source Package: knock
  • 3 Abhängigkeiten
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Knock
Fedora Rawhide package metadata · dl.fedoraproject.org · Fedora Rawhide package metadata: knock from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/e5ca8ce900cd68f5419e1c39ae517343100b306336cbaeb70a3c153121d95094-primary.xml.zst
dnf95%

knock-server 0.8-13.fc44

A port-knocking server/client

http://www.zeroflux.org/projects/knock

sudo dnf install knock-server
  • License: GPL-2.0-or-later
  • Category: Unspecified
  • Architecture: x86_64
  • Source Package: knock
  • 6 Abhängigkeiten
  • 2 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Knock
Fedora Rawhide package metadata · dl.fedoraproject.org · Fedora Rawhide package metadata: knock-server from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/e5ca8ce900cd68f5419e1c39ae517343100b306336cbaeb70a3c153121d95094-primary.xml.zst
zypper95%

knock 0.8-4.4

A Port-Knocking Client

http://www.zeroflux.org/knock/

sudo zypper install knock
  • License: GPL-2.0-or-later
  • Category: Productivity/Networking/Security
  • Architecture: x86_64
  • Source Package: knock
  • 2 Abhängigkeiten
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Knock
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: knock from https://download.opensuse.org/tumbleweed/repo/oss/repodata/be8d3611d25469107f32075a1697e69ec57a2b850b42348a658cc671ad5ec2b50760d02c3e59524d50da9a11d5be799bdaffba2e166e8ca8858512e3c0bd665d-primary.xml.zst
zypper95%

knockd 0.8-4.4

A port-knocking server

http://www.zeroflux.org/knock/

sudo zypper install knockd
  • License: GPL-2.0-or-later
  • Category: Productivity/Networking/Security
  • Architecture: x86_64
  • Source Package: knock
  • 4 Abhängigkeiten
  • 2 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Knock
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: knockd from https://download.opensuse.org/tumbleweed/repo/oss/repodata/be8d3611d25469107f32075a1697e69ec57a2b850b42348a658cc671ad5ec2b50760d02c3e59524d50da9a11d5be799bdaffba2e166e8ca8858512e3c0bd665d-primary.xml.zst
MacPorts95%

knock

sudo port install knock
  • normalized package name match
  • Abgeglichen nach: Knock
MacPorts ports tree · api.github.com · MacPorts ports tree: net/knock/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1
Debian apt92%

knockd 0.8-2+b6

small port-knock daemon

http://www.zeroflux.org/projects/knock

sudo apt install knockd
  • Section: net
  • Architecture: amd64
  • Source Package: knockd
  • 4 Abhängigkeiten
  • installed executable or alias match
  • Abgeglichen nach: Knockd
Debian stable package indexes · deb.debian.org · Debian stable package indexes: knockd from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz
Ubuntu apt92%

knockd 0.8-2build2

small port-knock daemon

http://www.zeroflux.org/projects/knock

sudo apt install knockd
  • Section: universe/net
  • Architecture: amd64
  • 4 Abhängigkeiten
  • installed executable or alias match
  • Abgeglichen nach: Knockd
Ubuntu 24.04 LTS package indexes · archive.ubuntu.com · Ubuntu 24.04 LTS package indexes: knockd from https://archive.ubuntu.com/ubuntu/dists/noble/universe/binary-amd64/Packages.gz
pacman92%

knockd 0.8-2

A simple port-knocking daemon

https://github.com/jvinet/knock

sudo pacman -S knockd
  • License: GPL-2.0-or-later
  • Architecture: x86_64
  • 1 Abhängigkeiten
  • installed executable or alias match
  • Abgeglichen nach: Knockd
Arch Linux sync databases · geo.mirror.pkgbuild.com · Arch Linux sync databases: knockd from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment