Tunnelmole, an ngrok alternative (open source)
softwareengineeringstandard.com
softwareengineeringstandard.com
https://github.com/anderspitman/awesome-tunneling
I'm not sure there's a single class of software that's been implemented more times than ngrok-style tunneling. I keep finding more and more.
Honestly it's a really fun exercise. Fairly challenging, but well within the reach of a single developer. I believe I'm currently working on my 5th incarnation.
Cloudflare tunnels are good, but Cloudflare terminates TLS certificates, and scans the traffic. People host on premise for privacy, which is moot if using Cloudflare.
FRP is simple and works, but it takes inbound traffic from open Internet. A vulnerability in it could compromise your environment. The transport encryption is customized (probably using TLS). It’s not a VPN quality software, going through audits. It may need a reverse proxy in front of it.
The ones that make outbound connections seem better. Ngrok pricing is not good, particularly when using custom domains. Tailscale funnel seems to be for short lived lightweight connections, has bandwidth and speed limitations due use of relay servers, kills my CPU, and requires a tailnet.
SSH reverse tunnels require some scripting with autossh or similar to ensure persistent connections.
There are several options on the list that do e2ee, including commercial services that likely have better pricing than ngrok. That said, I'm not aware of any that are marketed for high bandwidth usage such as video streaming. FWIW my 5th incarnation mentioned above will be such a service.
This is similar to running your own VPN server, vs using what’s called zero trust network access with services provided by companies such as Cloudflare.
Cloudflare tunnels are simple, robust and include a range of features: various authentication options, a secure internet-facing webpage in Cloudflare Access, DDoS mitigation, IP hiding, DNS and domain setup, etc . If they don’t decrypt and scan the traffic, that’s how an ideal solution would look like.
I think self hosting internet facing servers is not a good idea for most people. That component should be outsourced to specialists, in a product that includes a range of features (see my comment on Cloudflare Access below).
I'm a fan of their approach[0] though. No termination of TLS, SNI proxying(I presume) to backend machines, etc.
AFAIK ngrok was the first widespread implementation of it, and there was such a sheer lack of it before that everyone started working on their own implementations at once and now we have an abundance.
(At least that's my personal theory.)
Webhooks created the need for local tunneling software. Before ngrok, webhooks themselves were just starting to become more common. The need for local tunneling is much much greater than it was 15 years ago.
(Also consider that ngrok today is far more then a local tunnel proxy. They noticed the abundance of open source options years ago and have moved on from the basic concept.)
No, widespread means widespread. As in tons of people started to use it, ngrok started pivoting into enterprise, moved from ngrok.io to ngrok.com, etc. I was there for all of it.
The landscape of software other than ngrok was a total wasteland. Maybe there was localtunnel or SSH, I guess. But both of them kind of sucked and were fragile. ngrok was a static Go binary you could run anywhere to open a tunnel and it was total magic, worked perfectly, and was exactly what the world needed. It was the original. It taught people how this stuff ought to work and once people learned the formula, just like the iPhone, everyone else started copying it and now there are tons of implementations.
I would only use the self-hosted version.
You shouldn't assume that a server which is ostensibly running code you can see is actually running that code without modifications.
That said, there is a difference between someone claiming (explicitly or implicitly) that they're not doing something, versus not making a claim, versus admitting they are doing it.
Its amazing how far we've fallen from the internet of the 90s when you could get this done on most ISPs with all of a phone call.
I also ended up with several worms infecting the Windows version I was running, part of why I switched to Linux and haven't looked back since.
Do you know of any resources that cover how to do the security necessary for hosting at home?
I haven’t look at the code for the link above, but I think I am going to build a self hosted solution in Go and WireGuard with a simple GUI.
edit: one other cool thing to note was not only was this service behind a firewall, it was also behind my mullvad desktop client on Linux. Will probably run WireGuard connection to the VPS in a container to avoid conflicts with commercial VPN.
EDIT: And, actually, I don't think this is really an ngrok alternative. Unless I'm mistaken it looks like it only supports HTTP, whereas ngrok is a generic TCP proxy. (Albeit that ngrok does not support TCP half-close because it treats it like a full close).
One benefit of doing it on your own server is the static hostname you get with it. A new hostname every time you start up is not fun at all!
Building these types of tunneling systems are great projects. You learn a lot and can master skills in many different areas.
Packetriot has been operating for five years and the first few years was all spent on performance and stability of the core networking services. As the software and network matured, I spent more time on the operations and maintenance, and automating as much of that as possible.
Recently I've begun building tools to detect phishing and potential malicious behaviors. This is a common problem that operators of these tunnel networks have to deal with. It's an interesting and fun technical area and helps make the Internet a safer place :)
The Portals for Mac app is an example of the type of thing you could build using the open source stack of protocols. The README (linked by parent) links out to all of the relevant parts of the protocol documentation to explain how these work together. The NAT Traversal (https://github.com/build-trust/ockam/blob/develop/examples/a...) part of the README is probably the best explanation of why the free relay you get via Ockam Orchestrator is a useful part of this demo.
As for why would anyone trust this: The protocols are designed so you absolutely don't have to trust the relay. Trust is pushed out to the edges that you control and so you're not susceptible to a MITM attack if something like a relay is compromised. The protocol design for all of this is open and documented, and was independently audited by (IMO) some of the best in the business, Trail of Bits: https://docs.ockam.io/reference/protocols.
If you want a nice GUI for remote managing maybe check out one of my tools, boringproxy
[edit] Removed an incorrect assumption. Tailscale does not require CAP_NET_ADMIN in userspace mode.
Tried zrok.io but couldn't figure out what to do, wanted the easiest route.
There seem to be a lot of projects in this space -- including my own tool (https://github.com/gerwim/tunnlr). Still working on it though! ;-)
My apologies - I faced this same issue and completely forgot about it. My use-case was to host a dev server that I can ssh into from anywhere, and host things when needed.
What I eventually ended up doing was:
1. Switched to Cloudflare to manage my DNS.
2. Added a subdomain and pointed my IP address to it.
3. Ran a Cron job that checks my ip address, and if it has changed, I update Cloudflare with the new ip address using the following script: https://gist.github.com/vishaldpatel/fc25ebfc236af43f8453b90...
IMO it's not worth running a free tunneling service.
[0]: https://publicsuffix.org/
EDIT: I see in another thread that you've already gotten hit with phishing. I have some follow up questions I'll ask in that thread.
That being said, as an example `ssh user@host.com -R 8181:localhost:8080` will open port 8181 on the remote machine you’re connecting to, and forward traffic that’s addressed there to port 8181 on the machine you’re connecting from. That is, you’ll be able to open a browser to http://host.com:8181 to test something running on your dev machine at port 8080. Traffic gets forwarded along the ssh tunnel.
Autossh (or a systemd service supervising an `ssh` connection) will keep that tunnel open.
-M sets the control port for autossh which it uses to check if all is working right. The rest is standard SSH syntax; in this example, a loopback socket on port 8080 on host will get opened, and all requests to it are forwarded to localhost's port 80.
If you want it to be a "real" socket instead of just loopback, set "GatewayPorts clientspecified" in sshd_config.
When you think about it, a service that hides your IP under a domain that is not yours means you can do whatever you want without risking your own server or domain being taken down for abuse, instead risking my server.
So I added code to forward an X-Forwarded-For header, which contains the real IP address of the client. Also random URLs have the ip address added to them.
Again, super awesome project and great work!
I haven't had alot of phishing issues since introducing that header and the IP address in random domains.
I'll see if I can get tunnelmole.net added to that public suffix list.
One reason tunnels go through tunnelmole.net instead of tunnelmole.com is to protect the reputation of the main domain.
> One reason tunnels go through tunnelmole.net instead of tunnelmole.com is to protect the reputation of the main domain.
Definitely recommend you keep it that way. There's not saying what various orgs will do. I believe at one point Facebook messenger blocked links to .xyz TLD domains entirely. Maybe they still do.
Why not simply use npx?
npx tunnelmole