8 ms·
CorkScrew: A tool for tunneling SSH through HTTP proxies
- 55555 7y ago> Corkscrew is a tool for tunneling SSH through HTTP proxies, but... you might find another use for it. What are some of the other uses for this?
- xmichael999 7y agoI think they are implying that the code of wrapping binary data up and going through an HTTP proxy might prove useful for another project.
- commandersaki 7y agoSome companies force everything through a proxy. This is common with big telcos and banks. So even if you want to SSH into a machine from your workstation/desktop you probably want something like this. We used it for so much more though - because it's not just a proxy between your workstation - but there's many different bastion proxies situated all over the place isolating and guarding networks. So at the end of the day it's really just a productivity tool like your calendar or email program, except this is used because corporate security is egregiously bad.
- 1996 7y agoPlayers tunnel SSH through DNS. iodine is one of the many tools to do that. The best are not distributed, to avoid creation of DPI rules. cloudflare is doing something similar on 1.1.1.1 with wireguard.
- jtchang 7y agoStuffing TXT messages in DNS queries inside DNS queries tends to be quite slow.
- pastage 7y agoYes but at times you can actually receive data normally it just that sending it will be blocked. So download bandwidth is MB/S and upload is relly slow. Some times port 53 to anywhere is available so you don't evwn need to tunnel over dns.
- 1996 7y agoIf your firewall doesn't let SSH go through, step1) different port like 81, step2) udp tunnel like openvpn (pick your port, SIP sometimes work), step3) tcp inside ssl tunnel on port 443, step4) http tunnel on port 80, step5) dns on port 53 Don't go to step5 if anything else work because yes, it's slow. I don't use ICMP but some people do.
- djsumdog 7y agoiodine is great for getting free Wi-Fi too. Most captive portals don't block DNS, but just do HTTP redirects. You can pump all your traffic over DNS to an iodine server you have setup on a VM (it's not encrypted, so for the very paranoid, run OpenVPN or Wireguard through your iodine tunnel). Note: this is most likely illegal .. in every jurisdiction. So .. don't actually do this.
- QualityReboot 7y ago> Note: this is most likely illegal .. in every jurisdiction. So .. don't actually do this. Sad if true. If a service is providing public DNS access without any service agreement, I don't see how making DNS queries with it could be illegal, especially on a public radio channel. You might be right, but how? It's certainly within their right to ban you by filtering out certain queries though.
- AdamJacobMuller 7y agoIt's theft of service. Remember as abstract as the law can be, the legal system is not going to be amused by contrivances like "they were offering DNS service free and clear, so tunneling youtube over DNS is fine" The legal system is going to understand that you were trying to circumvent paying for services and treat it appropriately.
- QualityReboot 7y agoHow can it be theft of service when they can deny you service at any time automatically by identifying abnormally heavy users and removing them? This isn't like bypassing the electrical grid by running your own line from somebody else's service. This is like saying it's theft of service to read a chapter in the bookstore. If you hang out there all day, you might get kicked out, but that's not a crime. The courts might agree with you, but only because "computers are hard". There's a world of difference between tunneling over DNS and compromising servers. Or at least, there should be.
- 7y ago
- porjo 7y ago> cloudflare is doing something similar on 1.1.1.1 with wireguard. The primary maintainer of Wireguard had some misgivings about that: https://lists.zx2c4.com/pipermail/wireguard/2019-March/004048.html https://lists.zx2c4.com/pipermail/wireguard/2019-March/00404...
- 1996 7y agocloudflare is not our friend, but another google/facebook in the making
- LinuxBender 7y agoA former coworker and I used to do friendly red-team/blue-team challenges with each other. He tunneled traffic through a test DNS server and my goal was to limit the usefulness or block it. Blocking it was very difficult. I had to limit window sizes. Unbound can do this native. With bind I had to use iptables. Both Unbound and Bind could limit the packet rate. Unbound had the most granular controls around limits per domain/tld/ip. Tampering with window sizes would most certainly break some things, like DNSSEC and zone transfers.
- geggam 7y agoBeen using this for years to get around silly corporate proxies
- yjftsjthsd-h 7y agoI'm not going to tell you how to live your life, but isn't that intentionally violating security policy and likely to end poorly? I suppose if we ignore ethical questions it might come down to hoping that IT departments that block stuff are also incapable of catching you, but that seems... riskier than I'd like.
- somehnguy 7y agoAs with most small 'crimes' you'll more than likely get away with it as long as you're not stupid about it.
- ryanlol 7y ago>and likely to end poorly? I would guess that in most organizations it would be rather unlikely for this to end poorly. Most IT departments simply don’t give a shit about this stuff. But hey, presumably you know your employer better than random internet people.
- BLKNSLVR 7y agoIf the IT Department has time to trawl through internet access logs, the likelihood is that they're due for a headcount / productivity review. In my experience. Further anecdotal evidence towards the previously mentioned 'corporate security is egregiously bad'.
- brodo 7y agoI think that's a matter of attitude. You are more risk averse then OP. My hypothesis is that programmers tend to be rule followers because programming is "making up rules for computers".
- move-on-by 7y agoyeah, purposefully bypassing corporate security policies is certainly a fire-able offense. It doesn't mean OP's company would take that action, but if they did, then no one could fault the company for enforcing their security policy. The question is, is that proxy worth putting your job in jeopardy?
- paulddraper 7y agoRecently on a cruise ship I found my SSH access blocked. And HTTP proxies were blocked too. So I used a WebSocket proxy and that worked great. I highly recommend wstunnel. https://github.com/erebe/wstunnel https://github.com/erebe/wstunnel
- yjftsjthsd-h 7y ago> P.S: Please do not pay attention to Main.hs because as I hate to write command line code this file is crappy Well thank you for directing me to the most entertaining readme I've seen in a while... Though of course we should appreciate a developer willing to admit to their weak spots; good show.
- saagarjha 7y agoYou may enjoy this README, written by a friend: https://github.com/tbodt/ish#a-note-on-the-jit https://github.com/tbodt/ish#a-note-on-the-jit
- yjftsjthsd-h 7y ago> So a warning: Long-term exposure to this code may cause loss of sanity, nightmares about GAS macros and linker errors, or any number of other debilitating side effects. This code is known to the State of California to cause cancer, birth defects, and reproductive harm. Beautiful; thanks for sharing:)
- jraph 7y agoDon't get fooled, this is a maintainer's trick to make you read the code (and Main.hs is the entry point!). :-)
- ohazi 7y agoWait, so how did you start the other end of the tunnel if you were already on the cruise ship with restricted access? Did you already have it running ahead of time?
- elktea 7y agoI used this the other day - works very well.
- commandlinefan 7y agoI can’t quite tell from the readme (but I suspect the answer is probably yes) - does corkscrew need to be installed on both the client and the server for it to work?
- elktea 7y agono, just the client!
- tbrock 7y agoAlways great to have more tools that can do this sort of thing. I used to use desproxy for this almost 20 years ago back in my windows days: http://desproxy.sourceforge.net/ http://desproxy.sourceforge.net/
- deniska 7y agoOpenVPN can connect through http proxies as well in case if you want to tunnel all kinds of traffic https://openvpn.net/community-resources/connecting-to-an-openvpn-server-via-an-http-proxy/ https://openvpn.net/community-resources/connecting-to-an-ope...
- sigsergv 7y agoIt requires CONNECT method to be enabled in the proxy, am I right?
- brodo 7y agoYes you are.
- rossmohax 7y agoBash only version: Host github.com User git ProxyCommand /bin/bash -c 'exec 3<>/dev/tcp/$PROXY_IP/$PROXY_PORT; printf "CONNECT %h:%p HTTP/1.1\n\n" >&3; cat <&3 & : ; exec cat >&3'
- JoshTriplett 7y agoSome distributions don't have /dev/tcp enabled in bash, though.
- leni536 7y agosocat can help in that case, if it's available. But I wonder if socat is available on the same distributions by default.
- vertex-four 7y agosome variant of netcat (nc) is generally available on most distros.
- commandersaki 7y agoThis is part of the standard toolkit at Telstra - otherwise nothing would get done.
- de_watcher 7y agoThere is also htc/hts HTTPTunnel.
- johnchristopher 7y agoWhat's the difference with `ProxyCommand nc -X connect -x proxy_ip:port %h %p` ?
- derpherpsson 7y agoProxychains and especially socat är really handy tools for borrowing through filtering firewalls. Socat is somewhat difficult to use though. But IMHO the best one.
- larodi 7y agowhats the 'new' about corkscrew? maintainer changed? i see no recent commits with new stuff?