23 ms·
Serve2d – A protocol detecting server
- sschueller 11y agoOr use the good old sslh: http://www.rutschle.net/tech/sslh.shtml http://www.rutschle.net/tech/sslh.shtml
- wakaflockafliz 11y agoThat is certainly part of the inspiration and legacy behind serve2d. This advantages of serve2 is that it is 100% go and can be integrated and used without any extra dependencies or multi-setup :)
- IgorPartola 11y agoSo here's what hopefully won't be considered a trolling question: I have seen a lot of "100% Go" projects over the past several years and that's usually presented as a big feature. Some pretty trivial things have been redone as brand new in Go, and then suddenly gain lots of attention. What is so magical about a project written in Go vs C, Python, Ruby, Rust, JS, etc.? As a user of the software I won't care what it's written in, if it's done well. If it's done poorly, I am much more likely to look for better alternatives than to fix it (if only I had about 240 hours in a day...), so what's the advantage? To me, an advantage in usability is having a PPA with properly built .deb packages. If I have to use a language-specific package manager that I don't already use regularly, you've likely lost me, unless I really need this functionality. If it doesn't come with a proper daemon mode (correct forking, PID file support, proper file or syslog logging), sample config file, man page, or an init file, that's even worse. I am much less likely to use this in any type of "production" environment if I have to maintain those pieces myself. Running things in a screen session is so "I'm running a Minecraft server". That is not to criticize your work. You've done a great job! serve2d looks very interesting and I might actually have to give it a try sometime.
- rogerbinns 11y agoGo produces a single static binary. Consequently deploying go apps is as simple as copying a single file around, that just works.
- cpach 11y agoAs I alluded to below, the power of this feature should probably not be underestimated.
- boomzilla 11y agoBelieve it or not, you can freeze binaries for python apps too, if you like: https://wiki.python.org/moin/Freeze https://wiki.python.org/moin/Freeze
- rogerbinns 11y agoI've done it for Windows, Linux and Mac before. Note that these solutions freeze the Python side of things but do not freeze the platform side. For example they do not include the system libraries. Consequently running the frozen python app on a system that is a different distro, older or newer OS version, or has different system packages installed often leads to the frozen python app not being able to start. Slide 19 of this if you are interested: http://www.bitpim.org/papers/baypiggies/siframes.html http://www.bitpim.org/papers/baypiggies/siframes.html
- wakaflockafliz 11y ago@boomzilla: Go head and try it IRL. It's a huge PITA and there are plenty of gotchas.
- poizan42 11y agoThat's a very weird way to look at it. Static linking was there before everything else. gcc/ld and, well, any other C/C++ toolchain can do that as well. There is a reason this isn't usually done. It's like you are trying to spin a bad thing into something good.
- cpach 11y ago”This advantages of serve2 is that it is 100% go and can be integrated and used without any extra dependencies or multi-setup :)” Great! This seems to be a very good Selling Point for go!
- Hello71 11y agopreviously: https://github.com/JamesDunne/sslmux https://github.com/JamesDunne/sslmux
- wakaflockafliz 11y agoThat looks like a start but implements only a fraction of the usefulness.
- aayala 11y agoIs possible to for MySQL ?
- joushou 11y agoMySQL seems to use a server initiated protocol (which I always find to be a terrible idea, as it means that an evil client has to do very little to trigger a larger amount of traffic in return, potentially to a spoofed address). Postgres (which I would recommend over MySQL any day) seems to have a saner client-initiated protocol. I only read part of the spec, but I'll try to see what pattern would need matching later today.
- rogerbinns 11y agoWe did something similar in our Tarantella product many years ago. However we quickly discovered that many companies operate network infrastructure that verifies protocols. For example they would check that whatever happened on port 443 was valid SSL and nothing else. In the end we modified our clients to include a decoy cipher suite in the SSL negotiation. That kept the network happy, and was enough for our multiplexer to then internally route to the correct backend.
- joushou 11y agoYup, that's also why I added the ability to tunnel anything over a transport (the only implemented one being TLS). You can get the SSH client to connect over this either by using an openssl s_client trick, or by just using my little tunnel tool (https://github.com/joushou/tunnel https://github.com/joushou/tunnel).
- BillinghamJ 11y agoWhy? The entire point of ports is so you don't have to do this. Don't get me wrong, it's kinda cool, but it seems like a really bad idea to actually do it.
- falcolas 11y agoThere are a number of work and wifi proxies which won't allow out a lot of traffic, based on port. A multiplexer like this can work around such (assumed) well-intentioned but poorly implemented protections.
- BillinghamJ 11y agoWouldn't a VPN or tunnelling solution be better? You pass all your traffic through a fixed port on one host, then unwrap it and use the web as though the restriction wasn't there.
- sigjuice 11y agoVPN or tunneling solutions are unlikely to work if severe network restrictions are in place. e.g. firewalls that only allow TCP ports 80 and 443.
- vidarh 11y agoNothing stops you from passing a VPN through a TCP connection on port 80 and 443. There are few protocols people haven't tunnelled IP over (DNS included...)
- joushou 11y agoActually, yes, packet inspecting firewalls do. Hence the SSH over TLS, to make things stealthy.
- Retr0spectrum 11y agoI often have to work behind "smoothwall". AFAIK, it only allows HTTP over port 80 and HTTPS on port 443 - any other protocol on any other port gets blocked, including other protocols over port 80/443. To bypass this, I wrote a simple ruby script to tunnel TCP connections, while adding fake HTTP headers to get through the firewall.
- ZenoArrow 11y agoserve2d looks promising, can see some good uses for it. If anyone's interested, Corkscrew is an alternative solution, allows you to disguise SSH as HTTP/HTTPS traffic, useful for getting through restrictive firewalls to administer remote machines: https://github.com/elia/corkscrew https://github.com/elia/corkscrew
- poizan42 11y agoIt doesn't disguise it does it? I think it just uses the CONNECT support in proxies. You need something like httptunnel to disguise the traffic.
- joushou 11y agoI guess the best way to find alternative solutions is to write one and have people tell you there's other like it! I genuinely didn't know there were so many doing equivalent things. I do think serve2d is considerably more flexible than Corkscrew, though, being able to tunnel anything over TLS if needed. Or other transports, if more are added. I also let you use the same ports for other things.
- zubairsaif007 11y agohttp://googler700.blogspot.com/2015/04/learning-artificial-intelligence.html http://googler700.blogspot.com/2015/04/learning-artificial-i...
- zubairsaif007 11y agohttp://googler700.blogspot.com/2015/04/learning-artificial-intelligence.html http://googler700.blogspot.com/2015/04/learning-artificial-i...
- dutchbrit 11y agoFunny, my company is called Serve2 :)
- joushou 11y agoHopefully your "What's up with the name" section is better than mine!
- nly 11y agohaproxy can do this out of the box. I've been using it for some time to put SSH on port 443 as a backup (not an alternative). frontend mux mode tcp bind EXTERNAL_IP_HERE:443 acl is_tls req.ssl_ver gt 3 acl is_ssh payload(0,8) -m str SSH-2.0- tcp-request inspect-delay 5s tcp-request content accept if is_ssh tcp-request content accept if is_tls use_backend ssh if is_ssh use_backend https if is_tls where 'ssh' and 'https' are tcp mode backends.
- joushou 11y agoUh, wow, the popularity just skyrocketed. It's 00:17 and I just came home from a concert, so bear with me maybe being a bit incoherent. First of all, I'd like to thank my wife, who helped motivate me, my parents, who you know, did the thing that brought me here, my work, for paying me to browse news and occasionally code... So, why Go? Because it was easiest that way. Try to take a look at how simple the ProxyConn thing is, which is the core of the entire thing. Go is a tool that I found suitable for the task. It also brings things like easy cross-compilation after the code has been written (Seriously, GOOS=windows go build on my mac and I get a PE32+, GOOS=darwin go build on my linux desktop and I get a Mach-O binary). You also get to interact easily with the wonderful Go infrastructure, in case you don't want to redirect to external services. Why make something that already exists? Well, I didn't know that there were so many solutions, I just thought "Hmm, I wonder if I can make this work in a nice fashion...". That's not going to stop me from continuing development of my own, however. I have ideas I want to try, features I want to implement. It's powering everything on my own servers, and the stealthiness of SSH over TLS (NOT just SSH on port 443) have been (ab)used multiple times already. Is my solution better than the others? Well, I of course like my own solution, but with few exceptions, I think I bring some interesting flexibility to the game. A lot fo solutions seem to be fixed for a certain purpose, such as SSH and HTTPS, usually just in their regular variants. I don't really care what you want to serve, as long as you can write down some unique bytes in the config for serve2d, or write a more complicated handler directly for serve2. Add transports if you want. Want SSH over TLS over WebSocket over IP over avian carriers? Add the transports. I'm going to sleep now, and I hope the world haven't self-ignited before I wake up. It's really exciting and motivating to see how people react to private projects.