4 ms·
This kind of tools is basically always less safe than straight SSH. This one specifically, by-passed the authenticator of your OS. Yes, you can run `login` ins
by nirui 7y ago
This kind of tools is basically always less safe than straight SSH. This one specifically, by-passed the authenticator of your OS.
Yes, you can run `login` instead of a shell, but doing so require the tool to be executed as root, still sound bad.
I'd recommend to use a proxy that supports converting socket to Websocket(wss) and back, then you can by-pass the blockage from there. And since it's a proxy, it should not decrypt the SSH traffic.
- ttobias 7y agoThat is an interesting idea do you know of any tool that can do the websocket to socket translation in combination with an xterm.js webpage?
- nirui 7y agoNot with a webpage. But there are many two-part proxies supports Websocket or even HTTP as their back-end transport protocol. The idea is basically: Your SSH client <---SSH-Traffic---> Proxy front-end <----Websocket----> Proxy back-end <---SSH-Traffic---> Target SSH server You can deploy the "Proxy front-end" inside the restricted network, and the "Proxy back-end" out side the network. After that, all you need to do it to config your SSH client to go through that proxy front-end. There are many proxy software is capable of doing that, the GitHub keyword I believe is "socks5 websocket".