Automic VaultAutomic Vault

brew

knock を Homebrew, apk, dnf, MacPorts, zypper, apt, pacman でインストール

knock のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

インストール

追加のインストールコマンド

macOS

Homebrew確認済み · 100%
brew install knock

local Homebrew formula metadata

MacPorts確認済み · 94%
sudo port install knock

MacPorts ports tree · net/knock/Portfile · ソース: api.github.com

Linux

Alpine Linux apk確認済み · 92%
sudo apk add knock

Alpine Linux edge package indexes · knock · ソース: dl-cdn.alpinelinux.org

Fedora dnf確認済み · 92%
sudo dnf install knock

Fedora Rawhide package metadata · knock · ソース: dl.fedoraproject.org

openSUSE zypper確認済み · 92%
sudo zypper install knock

openSUSE Tumbleweed package metadata · knock · ソース: download.opensuse.org

Debian apt確認済み · 92%
sudo apt install knockd

Debian stable package indexes · knockd · ソース: deb.debian.org

Arch Linux pacman確認済み · 92%
sudo pacman -S knockd

Arch Linux sync databases · knockd · ソース: geo.mirror.pkgbuild.com

概要

パッケージ概要

Port-knock server

コマンドとエイリアス

  • knock
  • knock_helper_ipt.sh
  • knockd

履歴

プロジェクトの歴史と使われ方

knock is Judd Vinet's port-knocking server and client. It watches network traffic with libpcap for a configured sequence of port hits and runs commands, commonly firewall changes, when the sequence matches.

プロジェクトの歴史

The README carries a 2004 copyright notice and describes the core design that still defines the package: closed ports can receive a secret sequence because knockd sniffs link-layer traffic rather than listening on those ports. The bundled ChangeLog lists 0.1 as the initial release and shows later work adding TCP flag handling, reload behavior, timeouts, kernel-space BPF filtering, one-time sequences, interface selection, and IPv6 support.

Version 0.8 was published on 2021-04-24 with multiple fixes and IPv6 support. The GitHub repository retained a small C codebase, an example `knockd.conf`, and manpage documentation rather than growing into a larger access-control framework.

採用の歴史

knock spread through Unix-like distributions because it solved a specific sysadmin problem with a small daemon and client. Package names vary between `knock`, `knockd`, and distribution-specific formula names, but the underlying model stayed close to the original README example: a knock sequence opens SSH, and another sequence closes it.

使われ方

A server runs `knockd` with a configuration file such as `/etc/knockd.conf`; a client runs `knock` to send TCP or UDP packets to the configured sequence. Commands usually add or remove firewall rules, so the tool is operationally simple but security-sensitive: the sequence should be treated like a shared secret and firewall commands must be written carefully.

パッケージ好きにとっての重要性

knock is a memorable package because it embodies a whole security pattern in a tiny Unix daemon. It is also a reminder of the early-2000s sysadmin style: libpcap, iptables commands, config files, and a tiny client were enough to make a practical layer around SSH exposure.

タイムライン

  • 2004: README copyright identifies Judd Vinet's original project era.
  • 0.1: ChangeLog records the initial release.
  • 0.3: ChangeLog added PPP support, command timeout directives, SIGHUP config reloads, and per-port protocols.
  • 0.5: ChangeLog added one-time sequences, interface selection, BPF filtering, and security fixes.
  • 0.7: ChangeLog documented the target directive and consolidated OS-specific networking code.
  • 2021-04-24: v0.8 release published with fixes and IPv6 support.

Related projects

  • knock is related to other port-knocking and single-packet-authorization tools, firewall managers such as iptables, packet crafting tools such as sendip, and SSH hardening workflows.

セキュリティ状態

リスクレベル: blue

broad file, network, media, or database tool signal.

リスク分類器

リスク blue · 信頼度 中 · tool

理由

  • broad file, network, media, or database tool signal

信号

  • text:server

インストール挙動

  • formula メタデータに Homebrew post-install フックは記録されていません。
  • Homebrew bottle メタデータは 13 個のプラットフォームターゲットで利用できます。

推奨レビュー

エージェントに無人実行させる前に、このツールが平文の認証情報を読むか、リモート状態を書き込むか、成果物を公開するか、プラグインを起動するかを確認してください。

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
/etc/knockd.conf

実行可能ファイル

インストールされる実行可能ファイル

コマンド種類公開範囲メモ
knockcliグローバル実行可能ファイル
knock_helper_ipt.shcliグローバル実行可能ファイル
knockdcliグローバル実行可能ファイル

鮮度

バージョンと鮮度

これらの信号は、ページ生成時期、パッケージマネージャの活動、上流リリース比較を分けて示します。バージョン遅れは、証拠 URL と比較可能なバージョンがある場合だけ警告されます。

ページ生成日2026-07-25
マネージャ版0.8
マネージャ更新日
ローカルデータOK
上流not checked
検出された最新未検出

https://github.com/jvinet/knock

  • 情報No package-manager update timestamp was available.信頼度 低
  • 情報No cached GitHub release or tag data was available.https://github.com/jvinet/knock信頼度 none

インストールメタデータ

パッケージメタデータ

パッケージキーbrew:knock
バージョン0.8
パッケージマネージャHomebrew
パッケージマネージャページhttps://formulae.brew.sh/formula/knock
ホームページhttps://github.com/jvinet/knock
リポジトリhttps://github.com/jvinet/knock
上流ドキュメントhttps://github.com/jvinet/knock#readme
ライセンスGPL-2.0-or-later
ソースアーカイブhttps://github.com/jvinet/knock/releases/download/v0.8/knock-0.8.tar.gz
macOS 提供ライブラリlibpcap
Bottle利用可能 (対象 arm64_big_sur, arm64_linux, arm64_monterey, arm64_sequoia, arm64_sonoma, arm64_tahoe, arm64_ventura, big_sur, catalina, monterey, sonoma, ventura, x86_64_linux)
Homebrew post-install未定義
サービス宣言なし

レジストリ情報

ソースデータベース詳細

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Nameknock
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

ソースデータベース一致

他のパッケージマネージャ記録

一致は外部パッケージマネージャインデックスから取得され、ローカルの Automic Vault パッケージリンクとは分けて表示されます。

apk95%

knock 0.8.2-r2

A simple port-knocking daemon

https://github.com/TDFKAOlli/knock

sudo apk add knock
  • License: GPL-2.0-or-later
  • Architecture: x86_64
  • Source Package: knock
  • 1 依存関係
  • 1 提供
  • normalized package name match
  • 一致条件: Knock
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: knock from https://dl-cdn.alpinelinux.org/alpine/edge/main/x86_64/APKINDEX.tar.gz
apk95%

knock-doc 0.8.2-r2

A simple port-knocking daemon (documentation)

https://github.com/TDFKAOlli/knock

sudo apk add knock-doc
  • License: GPL-2.0-or-later
  • Architecture: x86_64
  • Source Package: knock
  • normalized package name match
  • 一致条件: Knock
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: knock-doc from https://dl-cdn.alpinelinux.org/alpine/edge/main/x86_64/APKINDEX.tar.gz
apk95%

knock-openrc 0.8.2-r2

A simple port-knocking daemon (OpenRC init scripts)

https://github.com/TDFKAOlli/knock

sudo apk add knock-openrc
  • License: GPL-2.0-or-later
  • Architecture: x86_64
  • Source Package: knock
  • normalized package name match
  • 一致条件: Knock
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: knock-openrc from https://dl-cdn.alpinelinux.org/alpine/edge/main/x86_64/APKINDEX.tar.gz
dnf95%

knock 0.8-13.fc44

A port-knocking server/client

http://www.zeroflux.org/projects/knock

sudo dnf install knock
  • License: GPL-2.0-or-later
  • Category: Unspecified
  • Architecture: x86_64
  • Source Package: knock
  • 3 依存関係
  • 1 提供
  • normalized package name match
  • 一致条件: Knock
Fedora Rawhide package metadata · dl.fedoraproject.org · Fedora Rawhide package metadata: knock from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/e5ca8ce900cd68f5419e1c39ae517343100b306336cbaeb70a3c153121d95094-primary.xml.zst
dnf95%

knock-server 0.8-13.fc44

A port-knocking server/client

http://www.zeroflux.org/projects/knock

sudo dnf install knock-server
  • License: GPL-2.0-or-later
  • Category: Unspecified
  • Architecture: x86_64
  • Source Package: knock
  • 6 依存関係
  • 2 提供
  • normalized package name match
  • 一致条件: Knock
Fedora Rawhide package metadata · dl.fedoraproject.org · Fedora Rawhide package metadata: knock-server from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/e5ca8ce900cd68f5419e1c39ae517343100b306336cbaeb70a3c153121d95094-primary.xml.zst
zypper95%

knock 0.8-4.4

A Port-Knocking Client

http://www.zeroflux.org/knock/

sudo zypper install knock
  • License: GPL-2.0-or-later
  • Category: Productivity/Networking/Security
  • Architecture: x86_64
  • Source Package: knock
  • 2 依存関係
  • 1 提供
  • normalized package name match
  • 一致条件: Knock
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: knock from https://download.opensuse.org/tumbleweed/repo/oss/repodata/be8d3611d25469107f32075a1697e69ec57a2b850b42348a658cc671ad5ec2b50760d02c3e59524d50da9a11d5be799bdaffba2e166e8ca8858512e3c0bd665d-primary.xml.zst
zypper95%

knockd 0.8-4.4

A port-knocking server

http://www.zeroflux.org/knock/

sudo zypper install knockd
  • License: GPL-2.0-or-later
  • Category: Productivity/Networking/Security
  • Architecture: x86_64
  • Source Package: knock
  • 4 依存関係
  • 2 提供
  • normalized package name match
  • 一致条件: Knock
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: knockd from https://download.opensuse.org/tumbleweed/repo/oss/repodata/be8d3611d25469107f32075a1697e69ec57a2b850b42348a658cc671ad5ec2b50760d02c3e59524d50da9a11d5be799bdaffba2e166e8ca8858512e3c0bd665d-primary.xml.zst
MacPorts95%

knock

sudo port install knock
  • normalized package name match
  • 一致条件: Knock
MacPorts ports tree · api.github.com · MacPorts ports tree: net/knock/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1
Debian apt92%

knockd 0.8-2+b6

small port-knock daemon

http://www.zeroflux.org/projects/knock

sudo apt install knockd
  • Section: net
  • Architecture: amd64
  • Source Package: knockd
  • 4 依存関係
  • installed executable or alias match
  • 一致条件: Knockd
Debian stable package indexes · deb.debian.org · Debian stable package indexes: knockd from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz
Ubuntu apt92%

knockd 0.8-2build2

small port-knock daemon

http://www.zeroflux.org/projects/knock

sudo apt install knockd
  • Section: universe/net
  • Architecture: amd64
  • 4 依存関係
  • installed executable or alias match
  • 一致条件: Knockd
Ubuntu 24.04 LTS package indexes · archive.ubuntu.com · Ubuntu 24.04 LTS package indexes: knockd from https://archive.ubuntu.com/ubuntu/dists/noble/universe/binary-amd64/Packages.gz
pacman92%

knockd 0.8-2

A simple port-knocking daemon

https://github.com/jvinet/knock

sudo pacman -S knockd
  • License: GPL-2.0-or-later
  • Architecture: x86_64
  • 1 依存関係
  • installed executable or alias match
  • 一致条件: Knockd
Arch Linux sync databases · geo.mirror.pkgbuild.com · Arch Linux sync databases: knockd from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz

ソース経路

リポジトリデータから生成

このページは scripts/generate-pkg-sqlite.py が生成した非公開のパッケージ SQLite アーティファクトから av-web によって提供されます。

使用ソース

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment