CorkScrew: A tool for tunneling SSH through HTTP proxies
github.com
github.com
And HTTP proxies were blocked too.
So I used a WebSocket proxy and that worked great. I highly recommend wstunnel.
Well thank you for directing me to the most entertaining readme I've seen in a while... Though of course we should appreciate a developer willing to admit to their weak spots; good show.
Beautiful; thanks for sharing:)
Otherwise, I could have done it with my web browser, using EC2 user data scripts, but that would have taken longer to get right.
[1] https://github.com/tsl0922/ttyd [2] https://github.com/shellinabox/shellinabox [3] https://github.com/novnc/noVNC
...
"And HTTP proxies were blocked too."
What would the possible rationale for this be ? I can understand these being blocked in, say, a non-western hotel inside mainland China ... or in a .gov lobby ... or ... ?
But on a cruise ship - the maintainers of that network must know that guests on the ship might have remote work to do - or just workflows that involve something beyond "the web".
Further, the bandwidth generated by web usage typically dwarfs bandwidth usage over VPNs or actual SSH ...
What are they thinking ?
> that network must know that guests on the ship might have remote work to do - or just workflows that involve something beyond "the web"
You'd think so.
This particular cruise line (Holland America) is known for its older travelers.
Host github.com
User git
ProxyCommand /bin/bash -c 'exec 3<>/dev/tcp/$PROXY_IP/$PROXY_PORT; printf "CONNECT %h:%p HTTP/1.1\n\n" >&3; cat <&3 & : ; exec cat >&3'https://openvpn.net/community-resources/connecting-to-an-ope...
iodine is one of the many tools to do that. The best are not distributed, to avoid creation of DPI rules.
cloudflare is doing something similar on 1.1.1.1 with wireguard.
Don't go to step5 if anything else work because yes, it's slow.
I don't use ICMP but some people do.
Note: this is most likely illegal .. in every jurisdiction. So .. don't actually do this.
Sad if true. If a service is providing public DNS access without any service agreement, I don't see how making DNS queries with it could be illegal, especially on a public radio channel.
You might be right, but how?
It's certainly within their right to ban you by filtering out certain queries though.
Remember as abstract as the law can be, the legal system is not going to be amused by contrivances like "they were offering DNS service free and clear, so tunneling youtube over DNS is fine"
The legal system is going to understand that you were trying to circumvent paying for services and treat it appropriately.
This isn't like bypassing the electrical grid by running your own line from somebody else's service.
This is like saying it's theft of service to read a chapter in the bookstore. If you hang out there all day, you might get kicked out, but that's not a crime.
The courts might agree with you, but only because "computers are hard".
There's a world of difference between tunneling over DNS and compromising servers. Or at least, there should be.
DNS tunnelling is not fast or convenient. Places deploying captive portals have probably looked at the risk to their business from it and have decided not to worry about it.
I can't believe that using a slow DNS connection, intentionally made public, to tunnel traffic would be considered theft or criminal.
How many free samples do I have to eat before I'm a theif? I don't believe I'm a thief until the offer for free samples is rescinded.
It’s like having a “free” street light and, instead of just enjoying the light, you pull its cables and plug your AC in.
The free service is just for the light.
> tunneling youtube over DNS is fine
probably wasn't going to work very well anyway. (Happy to be corrected if I'm wrong, though!)
There is no circumventing of any access control here. If a service is giving a public access point, on public spectrum, and they let you connect, and they allow you to use DNS, you should be able to use DNS however their access control systems allow you to use it.
Now if you find an exploit in their captive portal that allows you access to their service, then sure, that's illegal, because you're breaking into something.
You can't circumvent access controls if the access control list is wide open.
As I often say, self-proclaimed nerds who can't imagine life without a big brother taking care of things love to complain and complain and complain.
The ages of relying on oneself and technology seems gone. Cover-your-ass for 'nerds'
I'll be happy to sell these self proclaimed 'nerds' lessons about how to secure a captive portal with iptables, so that no DNS or HTTP/S or ICMP can go through until the login is entered and the TOS validated.
Quite the opposite -- there is complete openness in this thread about the technical aspects of the circumvention or use of the technique, plus open and timely reminders regarding the potential legal ramifications of executing this technique in certain jurisdictions.
How about if I run sshd on tcp 22 and it's not blocked?
Is it illegal if I just want to see if a dns change I made has propagated and I query an A record?
It seems obvious (to me) that a judge would say "It's not theft if you're giving it away. If you have a problem with how people are using your free service, add restrictions. Case dismissed."
I would hope that the court uses their human brain to make a judgment of my intent and the intent of the service provider. My intent is to have free DNS access to communicate with my server. The service provider intended to provide a public access point with free DNS and no restrictions on its use. The conclusion should be obvious.
It makes me wonder if using 1.1.1.1 on my network is a crime. Sure my ISP is letting my DNS queries through, but think of all the analytics that they're missing about me.
And the CFAA is a peculiarly poor bit of legislation, even by US standards, nothing like it applies in the EU.
There is no basis to say these actions, or using a different DNS, is criminal. At worst a contract dispute.
The primary maintainer of Wireguard had some misgivings about that: https://lists.zx2c4.com/pipermail/wireguard/2019-March/00404...
Tampering with window sizes would most certainly break some things, like DNSSEC and zone transfers.
I would guess that in most organizations it would be rather unlikely for this to end poorly.
Most IT departments simply don’t give a shit about this stuff.
But hey, presumably you know your employer better than random internet people.
In my experience. Further anecdotal evidence towards the previously mentioned 'corporate security is egregiously bad'.
The question is, is that proxy worth putting your job in jeopardy?
I was not privy to all of the network setup but suffice to say the security team ok'd removing the proxy but doing so broke the application. They left everything in place and told everyone who was an admin and needed outside to use corkscrew.
As a note you can prevent corkscrew from getting out a proxy if you desire.
Socat is somewhat difficult to use though. But IMHO the best one.
What are some of the other uses for this?
So at the end of the day it's really just a productivity tool like your calendar or email program, except this is used because corporate security is egregiously bad.