1. Get a cheap server (ex: DigitalOcean $5/month) in the city/country you want to connect through.
2. Add these 2 lines to /etc/ssh/sshd_config:
AllowTcpForwarding yes
GatewayPorts yes
3. Restart sshd (service ssh restart), or restart the server.
4. Connect to the server setting a dynamic port forward. On linux or Mac, this is just "ssh -D 8000 user@domain.com". On Windows, putty lets you set a dynamic port forward.
5. Personally I use Chrome for my real browsing, and then use Firefox for the proxy since it allows configuring a proxy for the browser only rather than the entire operating system. You just set the SOCKS proxy under advanced networking settings (host 127.0.0.1, port 8000).
6. If you want all internet traffic to go over the proxy rather than just Firefox, this is easy on Mac through the Network Preferences panel. I'm not able to comment on linux/Windows in this regard.
1) If you want everything, UDP data, non-SOCKS supporting apps, etc to go through, you're better off configuring an OpenVPN server. It takes some extra effort, but this allows it to work easily on mobile platforms and stuff too.
2) If you want to use this from a restricted network, use port 443 (for OpenVPN or SSH).
3) If your network is extremely strict, use stunnel to make it look exactly like standard SSL web traffic. I've written a helper app for people who need this on Android, https://github.com/ultramancool/Stunneler
They have an interesting model: you buy a token that expires after a certain length of time (1 week, 1 month, 1 year, etc). The clock doesn't start ticking until the first time you log in. Instead of registering a username/password, you're sent the token via email and your login ends up being a sha512 hash of the token for the username. There is no password associated, just the hash of the token is all you need.
I like this because you're able to buy 'disposable' accounts basically. They take bitcoin and some alt coins too, which is nice. Dns protection and access to .onion and .bit domains. It all seems pretty solid. NordVPN tends to be a little bit faster for me, though it may depend on which servers you use.
As a former privacy VPN operator I can tell you its extremely hard to operate one securely.
or
even better just run socks5 thru ssh http://straightedgelinux.com/blog/howto/socks.html
Tho I recommend using autossh to maintain the ssh tunnel which could be flaky at times
http://www.debianadmin.com/autossh-automatically-restart-ssh...
One port (443) to rule them all!
I did the trial for 1 day and tried them out. Have no pressing reason to continue for now but have filed them in the mental rolodex.
It doesn't work if you want to anonymize yourself.
https://security.stackexchange.com/questions/47518/is-pptp-v...