Apache Guacamole
guacamole.apache.org
guacamole.apache.org
It's also nice if you want to run a GUI application in someone else's sandbox.
https://github.com/jstrieb/ctf-collab/blob/9300c57364f71fe29...
I think Microsoft, for a time, offered VMs for such testing... Or maybe it was a third party... Guacamole world be a very good gatekeeper in this situation so the end users don't need virtualization themselves.
If the network is otherwise set up correctly, you can reasonably safely run windows XP behind Guacamole. Of course, I don't recommend that, but it prices that you can write software and then see how any of OS or setup runs your code/website/software... Without worrying that your VM might be compromised in 60 seconds.
As an aide, the siding of virtualization is also helpful for schools... A Chromebook can access guacamole to get to a VM... But a Chromebook can't run a VM itself.
The only issue we've had is that FreeRDP (that underlies it for connectivity to Window servers) is a bit fussier than the native RDP environment, or at least we've had challenges getting equivalent compatibility across old/odd Windows configurations.
is there some sort of foss "server" implementation of rdp so as to avoid using rdpwrap? i know vnc but i need multiple users connected at the same time...
I really am not a fan of Guacamole. I love the idea and convenience of having everything running in the browser from the client side, but I much prefer a real RDP session (via VPN) than having it in the browser. Why? Keyboard shortcuts! I am soooo much slower because browsers (not guacs fault - but at the same time it is its fault since I would love a native client) can’t catch all keys (e.g. Windows key). ALT-TAB? Yeah you just tabbed away from Guac. Or the new fancy WIN-TAB, no way that gets passed on to Guac. Also the file sharing experience is worse. RDP? Just drag an drop or Ctrl-C, Ctrl-V. That doesn’t always work in Guac…
When I use RDP it is always over SSH (port tunnel)
The benefit is that you can access other things than RDP with this solution.
One of the reasons I hate Wrike is that it hijacks Command-Shift-N (New private window) in Safari.
RDP is still much better user experience, so once when I needed a longer session I used Guacamole to access my router admin interface and temporarily expose RDP directly via a random port and a very strong password. I'm still not convinced that the latter combination is not enough, but it's better to be safe than sorry.
The Wireguard in Docker automatically generates new client configs from ENVS.
https://openzfs.github.io/openzfs-docs/Getting%20Started/Ubu...
I haven't tried it with desktop streaming, but VS Code remote development is a dream, even with little bandwidth.
35Mbps down (steady)
3Mbps up (decays quickly suggesting shown upload is "boost" / "burst" speeds or possibly throttled heavily in some other manner)
Apache Guacamole 1.1.0 - https://news.ycombinator.com/item?id=22190251 - Jan 2020 (50 comments)
Apache Guacamole – Clientless remote desktop gateway - https://news.ycombinator.com/item?id=21660925 - Nov 2019 (40 comments)
Apache Guacamole – A clientless remote desktop gateway - https://news.ycombinator.com/item?id=15778902 - Nov 2017 (41 comments)
Guacamole – A clientless remote desktop gateway - https://news.ycombinator.com/item?id=15389727 - Oct 2017 (216 comments)
Apache Guacamole - https://news.ycombinator.com/item?id=11744430 - May 2016 (57 comments)
Also:
Fixing critical vulnerabilities in Apache's remote desktop - https://news.ycombinator.com/item?id=23715212 - July 2020 (8 comments)
That said:
"We call it clientless because no plugins or client software are required.
Thanks to HTML5, once Guacamole is installed on a server, all you need to access your desktops is a web browser."
So... the web browser is the client software. Why not just come out and say that instead of first calling it fairly misleadingly "clientless"?
vs.
"You don't need a special hammer to bang our nail. Simply use your existing hammer."
The idea being that every computer you own and happen to come across has a browser already. You will not need to install a client so it doesn't matter that you don't have rights to do so or don't want to pollute someone else's computer.
It is pretty straight forward.
What would a clientless (aka no additional client software to install) might work?
But I think I get it now, it's probably a tongue in cheek reference to "serverless" :P
root@localhost:~# uptime
22:21:32 up 3139 days, 19:42, 1 user, load average: 0.00, 0.01, 0.05
root@localhost:~#Yes, that's right, some ISPs rotate IPv6 subnets, negating many things IPv6 was invented for in the first place.
Tailscale, Nebula or any of the automagical VPN solutions you can run yourself (like Innernet, https://github.com/tonarino/innernet) will probably negate the issue as long as you can reach some server with a static IP.
It's still not a great fix, of course, because DDNS still causes outages while intermediate servers wait for their TTLs to expire and caches to clear, which means your record could point to the wrong IP for at least one minute per switch. That's fine for a mail server, but not great for other applications that don't handle servers dropping from the network so we'll.
- Even old routers support at least noip.com and update the IP when it changes
- major DynDNS providers have a custom tool you can install, running in the background sending the current IP every minute or so
- every major registrar has a DNS API, which allows you to send IP updates in a simple CURL command and putting that command into crontab automates this as well.
The server software can run on any address as long as you don't hardcode the listening IP, just like any other web server. You'd need a way to have the URL point to the right server, of course, so DDNS or similar is a necessity if your server doesn't have a static public IP.
The desktop connections to the machines from Guacamole are tuples of { protocol configuration, hostname/IP, credentials}. If you specify the device Guacamole connects to by its IP and then that IP changes, the connection and configuration will break. You can probably work around that with some kind of dynamic DNS setting, or maybe local name resolution (LLMR and friends) if the machines are on a flat network.
TL;DR you don't need it, but it helps.
https://github.com/Ylianst/MeshCentral
https://twitter.com/MeshCentral
https://www.youtube.com/channel/UCJWz607A8EVlkilzcrb-GKg
Disclaimer: we installed meshcentral for enabling student access to regular physical desktops machine during COVID19
Only the other day I wrapped an old version of a mind mapping desktop app so I could open my old files on it without installing it: https://github.com/rcarmo/docker-xmind
Though every so often you need to reinstall the remote access software
https://github.com/linuxserver/docker-calibre
It’s not as smooth as a web application but it works well. Might be useful as a reference if you want to setup your own instance too.
Anybody tried that configuration? If so, how has your experience been?
The landing page and the video using Windows XP makes it look unappealing though
I'd still use 10/10
We give students a Kali Linux box, and a server with dozens of vulnerabilities.. and we don't have to worry about those vulnerable targets being otherwise internet accessible. We've done over 200,000 VMs behind Guacamole over 4 years without incident, despite having machines with the username/password of "student", or being unpatched for 4 years (spinning up old Ubuntu 14 images)
Why, loads too fast?
If someone has consulting chops to help me with this I’d love to chat.
>all you need to access your desktops is a web browser.
So which is it? Not having a client is nonsense.
These days, where basically nobody has a real ip, this is not entirely true. Using tor, you can easily expose a server to the outside world, the other point must support tor connections. Is there a way to freely expose anything to the outside world without needing special software on the client side?
This is a vast exaggeration. Although this is true for many and perhaps a majority, are there any publicly available stats regarding this, there are still a large number of ISPs which provide real ip addresses and allow incoming connections. My ISP serves several million customers across several US sates and provides real up addresses and allows incoming connections.