Apache Guacamole – Clientless remote desktop gateway
guacamole.apache.org
guacamole.apache.org
Dameware Mini Remote Control from years ago used to have options to set grayscale and dithering and horizontal scanline interleaving(?) and slow refresh frequency and things, but I imagine going beyond that - a line sketch of the visible window borders and their titles, then let me draw a region to update with the mouse, scrape the text out and send that to me.
There's ways to build TUIs inside CLIs, but what about squishing a GUI down towards a CLI-style-basics?
* 2 yrs ago - https://news.ycombinator.com/item?id=15389727
* 2 yrs ago - https://news.ycombinator.com/item?id=15778902
* 4 yrs ago - https://news.ycombinator.com/item?id=11744430
* 5 yrs ago - https://news.ycombinator.com/item?id=8166388
I assume this project doesn't help with that?
For now I'm just sticking to products like TeamViewer.
It’s not really the protocol that people are worried about — it’s attack surface. VPNs have basically zero — everything is opaque and an attacker learns nothing except that you’re on a VPN by observing your traffic. An attacker doesn’t even know that the application you’re connecting to exists and can’t even reach it to break in it without first breaking into your VPN.
You can call this obscurity but I think it’s better to say that you’re not leaking side-channel information about your network.
Having a VPN isn’t an excuse to have poor network security internally but a single portal that’s internet facing is much more defensible than n different home-grown apps.
A cool option that does not have much implementation out there is using port knocking to open ports on demand. If the scheme is dynamic, it could be virtually impenetrable.
Another way to go is to have a web app on your network, behind some decent authentication scheme, that has a menu option to open a remote access session. This app then white lists your IP on your edge firewall for N time for service and presents a quick launcher link -or- send email with link etc. This would be a good option for an SMB with little tolerance for VPN.
Add a NAT in the public subnet so that the target instances can get security updates and install new software.
It's not perfect but it works.
It works amazingly well. I use it to work on my EC2 spot instance and works very well even behind a strict corporate proxy.
If you need the shell, please ping me on my email.
NoVNC: essentially a web page that presents a VNC client that connects to a VNC server over websocket. Part of the noVNC project is a websocket proxy to vnc that you'd run on the machine with the VNC server; or another machine somewhere either within the network or external internet. In either case the proxy has to have access to the VNC server'd machine so not really good for NAT or restrictive firewalls (although you can work around with port forwarding and setting the VNc port to a well known port).
Quacamole: Also presents a browser client for VNC (and RDP) but Guacamole is designed to exist as a standalone service on an external nextwork that proxies into private networks. It proxies the protocol (VNC or RDP) I don't think it tunnels through websocket. Here I mean Guac to private network; Guac to browser is surely tunneled over ws.
So very similar functionality.
In either case the machine to be accessed must have a VNC server (or enable RDP) and access to the open internet on a non standard port (ie likely blocked by company firewalls), to access that machine. Neither work for restrictive company intranets :)
So if you're trying to setup guerilla access to work desktop, and you don't have admin access to install TeamViewer, there aren't any options that I've found.
What both of these enable is accessing your private desktop from anywhere with a browser.
noVnc supports only VNC. Guacamole supports VNC, RDP, SSH.
noVNC can be run on Windows and Linux. I think Guacamole server has be run on Linux. Not sure about that.
That's not apples to oranges.
So when compiling single-file "hello world" app or connecting to a single machine you would prefer a simpler tool (GCC/noVNC), since more complex tools require more complex workflow; but for more complex projects (or when you have tens of machines under your control) you would prefer more complex tools.
Disclaimer: I have never used Guacamole, used Visual Studio very little, and my experience with GCC is rather limited.
Most use it to connect to their ec2-like machines and not for teamviewer-like usecase.
My main problem is that user’s login creds have to go through our server unencrypted as we essentially provide a translation proxy for VNC/RDP to websockets.