6 ms·
Show HN: A simple SSH VPN client
- lima 9y agoHow is it different from sshuttle, which does not need remote root? https://github.com/apenwarr/sshuttle https://github.com/apenwarr/sshuttle Edit: xiringuito uses the SSH tun/tap feature, which does TCP-over-TCP tunneling (which performs badly[1]). sshuttle instead multiplexes the TCP streams over a single connection by capturing them and opening a new TCP session at the remote end. This means it does not need root permissions on the remote side, since it does not need any raw sockets or even create tap devices. The SOCKS proxy and the port forwards (-L, -R etc) work similarly, it's just the tunnel feature which should be avoided since it forwards whole packets. [1]: http://sites.inka.de/bigred/devel/tcp-tcp.html http://sites.inka.de/bigred/devel/tcp-tcp.html
- lathiat 9y agoshuttle is pretty good. I like to use it with tproxy on the client side which lets both tcp/udp work on both v4 & v6
- XorNot 9y agoYeah sshuttle has basically got the "simplest VPN" problem completely closed up IMO.
- ivanilves 9y agoWell, there are some differences between sshuttle and xiringuito: 1) xiringuito is great for UDP. I had issues with RTP streams (UDP, random ports) running over sshuttle , though they run perfectly over SSH tun/tap. 2) I can run low-level non-TCP, non-UDP, IP protocols like OSPF over tunnels I create with tun/tap. 3) xiringuito does not require python. Not everybody loves python. Overally I am a fan of sshuttle, but the way it's made prevented me from using it in a few cases, so I created xiringuito ;)
- benley 9y agoDoes sshuttle still cause occasional kernel panics on MacOS? (This is a real question, not a troll - I haven't used sshuttle for several years and it was a known issue among my colleagues at the time)
- okket 9y agossh has a SOCKS4/5 client/server built in, so why not use it? ssh -D [bind_address:]port <server>
- Daviey 9y agoNot every application supports SOCKS natively. The other options are transparent, with the option of declaring subsets to route over the tunnel.
- deleted 9y ago[deleted]
- sattoshi 9y agoYou can configure most systems to use SOCKS everywhere
- rubatuga 9y agoI know it’s possible macOS
- deleted 9y ago[deleted]
- deathanatos 9y agoWhile most systems have a system-level dialog to enter in SOCKS proxy information, it's still typically up to the application to obey that setting, and most outside of web browsers don't. There are some applications out there (e.g., tsocks) that hook the relevant system calls, but I find them quite annoying to use. (You need still something to trigger them, to say "this connection should be proxied") I've also had issues with proxy applications whose system call hooks fail to implement the system call. (E.g., one would return from connect immediately with success, every time, prior to the connection actually being established. When the connection failed to establish, the send/recv call would fail. The application would immediately loop back to re-establishing the connection. This caused an infinite loop, since the first DNS entry it was encountering was never going to work; it would have skipped it when the connect() call failed, but then, the connect call wasn't failing.)
- deleted 9y ago[deleted]
- contingencies 9y agoAnother approach is to run a localhost-interface only web proxy on the remote system and ssh -L 127.0.0.1:3128:127.0.0.1:3128 remotehost ... which replicates the remote proxy port on your local system.
- ivanilves 9y agoYes... But not all apps are web ;) We should also think about ones using non-HTTP TCP and UDP.
- contingencies 9y agoWell you can use SOCKS or OpenVPN over SSH quite easy too. However, in my experience these are are less reliable, at least in China for GFW.
- riskable 9y agoWhy on Earth would you run OpenVPN through ssh? That makes zero sense. It's like running ssh through ssh. OpenVPN is pretty much the ultimate VPN that can do anything and handle any situation. It is indistinguishable from regular web SSL traffic and can run on any port via TCP or UDP. It can even run in routed (TUN) or promiscuous (TAP) mode! Once you've got OpenVPN setup there's no need to tunnel with ssh since OpenVPN is your tunnel. I used to run an OpenVPN ISP named VPNOut many years ago. I had CTOs from large organizations begging me to tell them all the IPs I used so they could block it because apparently employees were using my service to access things that were normally blocked inside their corporate networks. Even to this day that problem exists: If you configure iptables to forward all ports to an OpenVPN daemon on both TCP and UDP you can get around basically any form of blocking that isn't IP-based. You can even do some tricks to make it look like regular web traffic for the initial SSL preamble to get around "intelligent" firewalls! OpenVPN is the best!
- contingencies 9y agoI like OpenVPN too. However, there are times when one size doesn't fit all. For example, opening another service to the public is not always a good idea. GFW is programmed to profile and periodically kill OpenVPN traffic flows. OpenVPN under many configurations is MITMable, SSH much less so. The list goes on.
- sharjeelsayed 9y agoThis creates an Auto closing SSH Tunnel (Tunnel will close if Chrome exits) to a remote ssh server and redirect to localhost on port 7070 and launch Chrome Portable using local port 7070 as socks 5 proxy The following command is for cygwin on Windows.Can be customised for Mac OS or Linux ssh -o StrictHostKeyChecking=no -C -f -q -D 7070 username@servername sleep 10 ; "/cygdrive/c/PortableApps/GoogleChromePortable/GoogleChromePortable.exe" --proxy-server="socks5://localhost:7070" &
- zenlikethat 9y agoProbably shouldn't turn off StrictHostKeyChecking. SSH will prompt to confirm the fingerprint if needed.
- deleted 9y ago[deleted]
- jsnathan 9y agoYou might also want to pass --host-resolver-rules="MAP * 0.0.0.0 , EXCLUDE localhost" to Chrome to avoid leaking DNS queries [1]. Edit: typo [1]: https://www.chromium.org/developers/design-documents/network-stack/socks-proxy https://www.chromium.org/developers/design-documents/network...
- ivanilves 9y agohttps://github.com/ivanilves/xiringuito/issues/42 https://github.com/ivanilves/xiringuito/issues/42 `sshuttle` & `xiringuito` differences well explained (I hope).