Re: [Full-Disclosure] SSH vs. TLS

From: Gerhard den Hollander (gerhard_at_fugro-jason.com)
Date: 06/29/04

  • Next message: David T Hollis: "Re: [Full-Disclosure] PIX vs CheckPoint"
    To: "Ng, Kenneth (US)" <kenng@kpmg.com>
    Date: Tue, 29 Jun 2004 21:29:23 +0200
    
    

    * Ng, Kenneth (US) <kenng@kpmg.com> (Tue, Jun 29, 2004 at 12:30:12PM -0500)
    > Today this is a straw man arguement. You can tunnel practically anything
    > over any protocol. I've seen NFS tunneled over EMAIL. Yes, when you type
    > "ls" the NFS request packet gets UUENCODED into an email, sent over
    > sendmail, fed into a decoder and routed back into NFS, and then back. A few
    > seconds later and you get a directory listing. And frankly, I'm not sure
    > you want to know what besides http really goes over port 80.

    In fact, it's quite easy to tunnel ssh through your http(s) proxy
    (do a google on proxytunnel) and it's most liekly that you can tunnel ssh
    over a TLS telnet session, thiogh someone might have to be convinced that
    writign such a thing is necesary ;) )

    > : original poster:
    >> - SSH allows tunneling other protocols, circumventing firewall policies.

            Gerhard, (faliquid@xs4all.nl) == The Acoustic Motorbiker ==

    -- 
       __0	Oh my God, the bomb has just dropped
     =`\<,	And everybody climbed right on top
    (=)/(=)	Singing,"What a beautifull country
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    

  • Next message: David T Hollis: "Re: [Full-Disclosure] PIX vs CheckPoint"

    Relevant Pages

    • ssh tunnel to non standard port .... connection refused
      ... Using intermediate server to tunnel SSH: ... and the -v flag reports: local connections to LOCALHOST:4444 forwarded ... Local forwarding listening on 127.0.0.1 port ...
      (comp.security.ssh)
    • Re: NAT is not a mechanism for securing a network.. but.. HELP!
      ... each packet is modified to change the IP addresses ... and ports but uses the same protocol. ... build a "tunnel", where UDP packets are actually sent using the ... Notice that each layer can have multiple /different/ protocols. ...
      (comp.security.firewalls)
    • RE: Tunnel any protocol over any protocol?
      ... service requests retransmission of any lost or corrupted packets. ... Tunnel any protocol over any protocol? ... InfoSec Institute ...
      (Security-Basics)
    • Re: Tunnel any protocol over any protocol?
      ... Is it possible to Tunnel any Protocol over any other ... http tunnel, https tunnel, ftp tunnel, ssh tunnel etc. ... Totally hands-on course with evening Capture The Flag exercises, Certified Ethical Hacker and Certified Penetration Tester exams, taught by an expert with years of real pen testing experience. ...
      (Security-Basics)
    • Re: Tunnel any protocol over any protocol?
      ... Tunnel any protocol over any protocol? ... +1000, Chip Panarchy wrote: ... materials and an expert instructor means you pass the exam. ...
      (Security-Basics)