A customer stuck due to a hurricane who needed SSH
rachelbythebay.com
rachelbythebay.com
For the price they charge for support I'd expect more quality.
Internally big tech would need to prioritise customer satisfaction as some OKR to incentivise engineers - but this doesn’t happen for some reason. As a result you’re at the whim of whether the engineer cares enough to spend time on your case.
Note in my experience AWS has great support - so their internal incentives seem to be aligned with customers.
We managed it by assigning someone to support on a rotating weekly basis. During that week, project hours missed due to support tasks were acceptable. If you had a critical task due and it was your support week, you could swap support with someone, or we'd reassign the task. But with Software being the "last line of defense" after Field Service and Product Technical Support, we couldn't just ignore it.
There are solutions. You just have to act like you want it solved.
But there's nothing like an engineer seeing the struggles people have for themselves and choosing to fix it so they don't have to field that damned question anymore (I'm saying this tongue-in-cheek).
Plus, you know as well as I do, the more people between your customers and your engineers, the more agenda's get injected into the mix.
The problem actually comes from the fact that big tech is becoming increasingly cheap on creating good support organizations. Experienced support engineers are fired and replaced with outsourced low-cost inexperienced personnel. In most cases, issues can be resolved or worked around with the help of a support engineer with access to some extra knobs. When those engineers are removed and are replaced with people who act like a pipe for cat to send the customer's stdout to product engineers, you get what you describe.
The list of companies providing support for GCP can be found in their subprocessors list.
I thought that was above and beyond, but honestly I don’t know the support contract my company had with GCP
Port 22
Port 80
Much cleaner than iptables magic; though I have done similar iptables redirects before it is almost always a bad idea. :)You could also do it in the load balancer/router.
setcap 'cap_net_bind_service=+ep' /path/to/executable
Now, the process doesn't need to start as root and drop privs.The reason privileged ports require root is so that they cannot be easily intercepted by userland processes.
The entire reason for the root requirement is this; it's expected that after your port assignment you drop your privileges to a lesser user. But requiring root to bind is a feature, not a bug.
If you do not have this then intentionally crashing the process for a user and rebinding the port as a standard user (even `nobody`) is possible.
This means if you break into someones mail server and run as the mail user, you would be able to bind ssh ports (if they are not privileged ports <1024).
Of course your mail server should be running as the `mail` user or some equivelent, because only the binding of the ports should be done on startup as root and then it should drop into the mail user.
Security is an onion.
None of this was new stuff back then. It just wasn’t well blogged (in fact it was so poorly written about that my very first blog post was on exactly this topic. Blog is long gone now though). However if anyone took the time to read the man pages, you’d see all the functionality is already backed into openssh
https://serverfault.com/questions/284566/configuration-for-m...
just idle speculation.
I'm pretty sure "Port" worked with older ssh servers, maybe. openssh was only 4 years old 20 years ago.
EDIT: hmmm what about needing privileges or an selinux config change?
Hell even in current year I occasionally come across guides that suggest disabling it... great way to get ctrl-w'd smh
… I’ll see myself out.
Tornado Cloud Protocol.
# Redirect port 8080 to local port 22
iptables -A PREROUTING -t nat -i eth0 -p tcp --dport 8080 -j REDIRECT --to-port 22
iptables -t nat -I PREROUTING -p tcp --dport NNNN -j REDIRECT --to-ports 22
Worked great until the hotel where such connections also had a maximum duration!
Never had many login attempts that weren't me through it, but had fail2ban installed just in case.
at bigger chains, there is some dpi security solution involved which will easily spot the difference between https and ssh.
Listen on port 8080 and route to some local 22?
socat TCP-LISTEN:8080,fork,reuseaddr TCP:[somelocalip]:22
This lets you be very explicit in watching this run and killing when done.
Socat also lets you route networks through old serial ports, log all data going over a connection to a file, and even join completely different protocols.
Fun past projects based on socat; a serial port->socat to tcp out->socat on another computer to listen->a serial port out. Basically this created a serial port that worked over a satellite for a customer doing some remote monitoring so they could set an alarm if something failed (a lot of equipment only has serial connectivity for status).
iptables with a dnat redirect addresses that.
There is a lot of tooling to filter out bad behavior by HTTP. When it comes to other protocols, not so much. Much easier to block other ports then end up with your IP range on a block list.
Blocks useful access for worms, Trojans, etc but still lets you get out once.
it uses high ports that shouldn't be blocked. usually it is already running when i open the laptop. saves a lot of time. as an added benefit, it sometimes even works when the actual wifi connection is not yet authorized at the portal because that often only blocks tcp and not udp.
It allows you to listen for https and ssh traffic on a single port.
Basically your services listen on localhost:port, sslhd listens on hostname:port, inspects the packets and forwards them (transparently) to localhost:port.
If you put everything on port 443 it's very unlikely they will ever be blocked.
Can someone explain this reference to me, I didn't get it?
meshcentral has a web shell too.
Maybe eventually they will be less suspectable to social engineering but I don't have that confidence yet
Is it still social engineering if you're talking to an AI?