7 ms·
Chisel – A fast TCP tunnel over HTTP
- daurnimator 10y agoLooks to be TCP over websockets; which isn't really that interesting IMO.
- buserror 10y agoYep, because many firewalls ALSO block websockets; so comparing it to crowbar for speed isn't terribly fair, as crowbar only uses POST/GETs.
- ec109685 10y agoThey can't block websockets over https.
- daurnimator 10y agoMost corp+school firewalls block https or make the user add a MITM cert (well, it's managed via active directory for company machines). Rarely do these firewalls allow websockets.
- dx034 10y agoI don't think that any company can still block https, there are not many pages left you could use. Installing a MITM is probably more common. Although I don't understand the benefit of then blocking ws, if you can read the traffic anyway?
- josephg 10y agoHow common is this, actually? My impression is its fairly rare, but I'd love to see some actual analytics if anyone has some.
- deleted 10y ago[deleted]
- cordite 10y agoK-12 schools definitely block HTTPS at some places, mostly because they can't inspect it.
- notheguyouthink 10y agoWow, so they can only use HTTP? That seems crazy. Would be fun to try and mess with the network though. Yeesh.
- hueving 10y agoNot common anymore. Now it's usually an ssl proxy that uses a cert on all computers to mitm the connection and enforce policies.
- ryao 10y agoHow does this deal with double congestion control?
- partycoder 10y agoI was asking myself the same thing. TCP implements many RFCs for congestion control, flow control, etc. Many of them might be redundant if everything is being sent over HTTP (over TCP). I would use "link conditioner" or a similar tool, simulate packet loss and see how this compares to the other software.
- rpcope1 10y agohttp://sites.inka.de/sites/bigred/devel/tcp-tcp.html http://sites.inka.de/sites/bigred/devel/tcp-tcp.html Even for applications designed to tunnel traffic from the outset (OpenVPN), TCP over TCP is a mess and it's kind of a non-starter for anything that's not a toy (unless you have no other choice, like with certain mobile carriers where path MTU and CGN cause issues).
- noway421 10y agoThat's very interesting, thank you. I think there should be a way to control retransmission times on the client that would alleviate that problem. Probably taking out tcp connection out of kernel space and controlling the protocol in user space will allow to control the lower level tcp to work nicely with upper levels. But still, is there a possibility of a meltdown on the routers further down the line which might be controlling tcp connections? They would be routers which are not simply passing the ip packets, but working with the protocol in a more elaborate way though, either deep packet inspection or some other network mechanisms?
- jpillora 10y agoIt doesn't. I'd like to support UDP at some point, maybe rewrite using https://github.com/xtaci/kcp-go https://github.com/xtaci/kcp-go.
- Matthias247 10y agoWhy TCP over websockets? You can just use the HTTP bodies as a stream in both direction. Which means the proxy just has to strip or add HTTP headers before forwarding. The overhead afterwards is 0 -> you just write to the socket.
- noway421 10y agoHmm, this choice is indeed strange, websockets still are blocked in some restrictive set ups (squid?). But still, what is the way of doing stream in both directions? Do you mean opening multi-part form data for uploading and transfer encoding chunked for download? But that would be 2 tcp connection for 1 tcp tunnel. And I believe there's no other way to do it without the overhead of HTTP request/response headers.
- rusk 10y agoNot necessarily ... you would have to issue a HTTP request per uplink chunk but HTTP can use connection pooling so that does not necessarily translate to a single TCP connection [0] Agreed it's not quite as straightforward as the parent poster suggests. I can see issues with this approach for realtime/streaming applications but for applications relying on a similar request/response flow of traffic it would do the job. [0] https://en.wikipedia.org/wiki/HTTP_persistent_connection https://en.wikipedia.org/wiki/HTTP_persistent_connection
- josephg 10y agoYes, and for various reasons those chunks can be reordered. And a misbehaving proxy might also try to cache them. And to send data back from the server you need long hanging gets, which can also be subject to timeouts and weird chunking by misbehaving proxies. These problems are all solvable, but you need to treat http requests like datagrams and (basically) reimplement TCP on top of HTTP. We've done this several times now. I made one[1] myself a few years ago based on google's browserchannel implementation (that was first written for gchat inside gmail. It supported browsers down to IE5.5). But the best is probably SockJS - https://github.com/sockjs https://github.com/sockjs . IIRC Its written by some (ex?) vmware guys, and its great. But all this stuff is pretty outdated now. Misbehaving corporate proxies are (thankfully) getting much rarer - especially if you tunnel your traffic over HTTPS. These days you should just use websockets directly. [1] https://github.com/josephg/node-browserchannel https://github.com/josephg/node-browserchannel
- partycoder 10y agoMany superlatives, which immediately raise suspicions. If you are trying to solve the problem of NAT traversal and such, I suggest you rather attempt to do this: https://en.wikipedia.org/wiki/TCP_hole_punching https://en.wikipedia.org/wiki/TCP_hole_punching
- noway421 10y agothis surely is great and i can't wait for a moment when someone finally comes up with a TCP Hole Punching as a Service. vpnazure kinda does this, but has the overhead of softether vpn service on top of it... I would rather go with punching myself an ssh port.
- NetStrikeForce 10y agoI do it at Wormhole[1] in a very similar fashion to "vpnazure"; also with SoftEther. Why would you rather "punch yourself and ssh port"? Do you mean that your main problem with vpnazure and the like is the need of an agent/client software installed? I am not sure I understood your concern, but I would be very interested in hearing more about it. Feel free to email me to the address on my profile if you prefer, although a reply here works for me. IMHO the best way to make it transparent for any application is to have a virtual interface. It offers an expected environment for any new or legacy app (instead of proxying stuff explicitly). Thanks! [1] https://wormhole.network https://wormhole.network
- noway421 10y agoThat's seems like an awesome service, thank you for the work! > main problem with vpnazure and the like is the need of an agent/client software installed Yes, and at the same time vpnazure creates a vpn set up (I think it's server/client set up, not bridge), while for my simple usage I only need a single TCP connection through which I'd work with SSH. And from this point, I could spawn a ssh tunnel and forward the needed traffic through it, alleviating the need of vpn. Maybe it is a really basic use case, but for work/home environment I find it to be the thing I actually need, and not the full blown vpn. Another problem with vpnazure I had is that I'd have no way of seeing where the traffic flows inside the vpn interface. Thinking about it now, probably could be seen in traceroute. But at the time, I thought about looking into tcpdump of vpnserver or setting up a firewall. And that was too complicated for my hobby set up. The point of my concern was that I wanted to see whether any traffic is leaking onto third party servers managed by SoftEther or otherwise. Of course I'd want the traffic to flow across the internet, but I'd expect it to take the path it would take if one of the nodes was a natural server. Also, all the traffic is managed by vpnserver (softether's one), which makes it a little opaque in terms of where the packets go out of that process. Of course a client would be inevitable for any hole punching SaaS, but preferebly I'd like if it'd only run during the connection establishment period of time. That's my 2 cents, coming from a personal set up.
- deleted 10y ago[deleted]
- noway421 10y agoIs there any difference with corkscrew? Either way, really keen to test the perfomance of it for getting out of restricted proxies where corkscrew saves me life.
- microcolonel 10y agoAnnoying that this has the same name as https://github.com/ucb-bar/chisel3 https://github.com/ucb-bar/chisel3
- BenoitP 10y agoYup. Same thing with Spark Framework wrt Apache Spark. Seems like a curse targeting game-changing projects written in Scala.
- jpillora 10y agoSorry! Was originally a rewrite of https://github.com/q3k/crowbar https://github.com/q3k/crowbar so I chose a synonym.
- microcolonel 10y agoTireIron. ;- )
- wheaties 10y agoHold on, hold on, hold on. Let me get this straight: you took an application layer protocol (HTTP) that runs on top of TCP and ...reimplemented TCP over it!? (see: https://www.quora.com/What-is-the-difference-between-HTTP-protocol-and-TCP-protocol https://www.quora.com/What-is-the-difference-between-HTTP-pr...)
- yoo1I 10y agoPfft. Amateurs! > Once upon a time at evening I have decided to properly brake the famous browsers communication problem and as a result you have landed in here. I have created implementation of BNC networks model with simple TCP/IP layer, that as transport packet it will use browser's cookie object. http://theprivateland.com/bncconnector/index.htm http://theprivateland.com/bncconnector/index.htm
- jpillora 10y agoNo, TCP has not been reimplemented.
- paulddraper 10y agoAnd no reference to the standard mechanism for HTTP tunnels, which has only existed for 18 years. https://tools.ietf.org/html/rfc2616#section-9.9 https://tools.ietf.org/html/rfc2616#section-9.9