SSH Tunneling through web filters
s-anand.net
s-anand.net
I just want to point out that this last option does a lot more than what the article does: it actually encapsulates the ssh session in HTTPS requests, so it'll work even if your firewall does layer-7 filtering. The article just runs sshd on port 443 and connects to that.
I'm consulting for one now. For the most part, they filter porn and borderline porn. However, they also filter Facebook (but not LinkedIn!), YouTube, and a few other things mainstream sites.
Circumvention certainly isn't that hard, but it also likely violates some company policy. I connected my Droid to their Exchange servers and got a nastygram from IT security (albeit a few weeks later).
Ironically, the risk isn't just that I would get caught - the first time would be a hand slap unless they wanted a reason to get rid of me. The corporate culture is so focused on conformity and compliance that it would be absolutely shocking to others that I would have even considered such a thing. And, this affects perceptions of trustworthiness. [No, I do not like any of this!]
I know this because the building where my office is has filters setup on the internet (I don't pay the bill, so who am I to complain). Because of the AppEngine proxies, they block all appspot.com domains.
The crappy part is that I have a couple of projects hosted on AppEngine, so in order to access those I have to run a reverse tunnel to get around their filters. (Making this thread circular).
I use this for my proxy (and set a system wide SOCKS proxy on OSX): ssh -CfgN -D 9999 myserver.com
I've seen this proxy method used at a company before, but I'm pretty sure they just passed through the https traffic instead of fucking with the certs. I'll have to check the next time I'm on-site...
There's even some pretty decent desktop clients for OpenVPN, see Viscosity for OSX.
This is assuming you have the ports open (the Great Firewall of China does HTTP inspection but not port blocking).
Anyway, if you can use a SOCKS proxy, it should work for almost every application supporting any kind of proxy (but not using the 443/SSL port).
Step 9 can be skipped completely if no proxy is needed to be configured.
Also don’t forget, doing all of this still sends the DNS requests in the clear to the usual/old dns server and not through EC2. If the DNS server is also meant to filter and redirect, this can be an issue. To go around that, in firefox you can go to about:config and set network.proxy.socks_remote_dns = true
And for linux folks... you don't need any tools or any more special config... just run the ssh command with switch -D <SOCKS_PORT_NUMBER> and configure firefox or your browser to use that.
In exchange for this, though, nobody dictates what technology I use to do my work, I can show up at 2 in the afternoon and nobody cares, and I get a lot of money. (The company I worked at before didn't block any websites, but the work was boring, my manager micro-managed every library decision, and I got almost no money. Trade-offs.)
Financial Services in London filter/block a lot.
They also disable DNS lookups, and so only browser lookups and specially coded wget have resolution capability.
No: Gmail, Yahoo! Mail, Hotmail, Betfair, Twitter, Facebook
People generally assume that it's okay to slack off as long as you get your assigned work completed.
ssh -D <someport> user@slicehost.comCan you schedule EC2 instances for certain times of the day, or is it an all on or nothing thing?
chrome.exe --proxy-server=socks5://127.0.0.1:8008
credits: http://code.google.com/p/chromium/issues/detail?id=29914