5 ms·
> Access your device's terminal from anywhere via the web Nah, nice try, but I'm good with ssh, key based authentication and few white-listed IPs.
by mad182 7y ago
> Access your device's terminal from anywhere via the web
Nah, nice try, but I'm good with ssh, key based authentication and few white-listed IPs.
- mr_toad 7y agoIt’d be nice if you could just outbound ssh from anywhere that has a browser, but sadly this isn’t the case.
- ktm5j 7y agoYou would have to really trust whatever service is providing this ssh client. For a browser based ssh client either it's code running on your local computer (in which case, just download an ssh client) or your ssh connection is coming from some third party server that you may or may not trust. This is something I've thought about time and again, but the security issues always seem to outweigh any potential benefit from something like the OP or similar (in my opinion).
- mikorym 7y agoWhat do you mean by that?
- fifnir 7y agoAs an an example, at my work you cannot make any outbound ssh connection. The only way to get one is to apply for a specific connection , where you have to explain why you need an outbound connection, in which case they open a port for you and the remote machine you specified.
- contravariant 7y agoUsing tools like this to get around that restriction is quite possibly the worst idea I've seen today.
- kraftomatic 7y agocorkscrew?
- W4ldi 7y agoif it's just filtering of certain ports, you can just set your ssh port to 80 or 443
- 72deluxe 7y agoYep, using 443 as your SSH port seems a good way of doing this. I do.
- shandor 7y agoIn its simplest form, yes. Anything more sophisticated will inspect the traffic and drop SSH connections no matter the port.
- kryptiskt 7y agoAt my last job we used corkscrew (https://github.com/bryanpkc/corkscrew https://github.com/bryanpkc/corkscrew) to tunnel ssh through HTTP proxies without needing the ssh server to use another port. I guess if that work depends on how the proxy is set up.
- loa_in_ 7y agoI suggest learning how those filters work. Also please do respect the policies, they're usually there to protect the intellectual property and you might be unwittingly putting yourself in spotlight despite having no bad intentions.
- fifnir 7y agoOh yeah I wasn't going to try and circumvent, just giving an example to elucidate
- diffeomorphism 7y agoWouldn't you have to apply for permission for the article's solution for the exact same reason? If not, then this seems like an exfiltration risk your security people should fix.
- mikorym 7y agoWhat happens when you log into a VPN and then SSH elsewhere; that should work, right?
- tyingq 7y agoCorporate MITM devices, like those from Forcepoint. Or domain managed client side content filtering / endpoint protection. Basically overzealous IT security stuff. Most won't be fooled by simple stuff like just running sshd on port 443. Edit: Though these MITM vendors will soon have fun with DNS over https and encrypted SNI. Guess they will have to resort to being browser plugins?
- fuzzy2 7y agoWith the help of an additional “proxy”, you can. One such proxy software is Apache Guacamole. It doesn’t only do remote desktop, it also does SSH.
- seized 7y agoIt can also be subject to MITM. If you don't control the certificate store on your device then you don't control the connection to Guacamole (or anywhere else via HTTPS).
- thenewnewguy 7y agoBasically any attacker that is able to control the certificate store on your device could also just install a keylogger.