Re: Securing ssh tunnels.

From: Darren Reed (avalon_at_caligula.anu.edu.au)
Date: 06/26/03

  • Next message: Ben Lindstrom: "Re: Securing ssh tunnels."
    To: newhouse@rockhead.com (Paul Newhouse)
    Date: Thu, 26 Jun 2003 14:06:06 +1000 (Australia/ACT)
    
    

    In some mail from Paul Newhouse, sie said:
    >
    >
    > I'd guess they don't want (or can't) sshd running on their firewall and can't
    > figure out how to route through a secure incoming ssh connection, through
    > the firewall.

    I was thinking why would you do this and then I thought, shouldn't
    there be an ssh proxy ? (You can all stone me for suggesting this
    after you've read it ;)

    The idea would be to use either an unencrypted ssh connection to a
    proxy and then the proxy makes an outbound connection to the host.
    The problem with this is most obviously that it interferes with the
    manner in which host authentication is decided unless the proxy was
    transparent (a la transparent web proxy) in nature so the client
    was unaware of the MITM. Then there's got to be a problem of the
    authentication being in clear text ?

    Well I suppose others must have given some consideration to an ssh
    proxy in the past and shot the idea down in flames already ?

    Cheers,
    Darren


  • Next message: Ben Lindstrom: "Re: Securing ssh tunnels."

    Relevant Pages

    • Re: Securing ssh tunnels.
      ... >> figure out how to route through a secure incoming ssh connection, ... > proxy and then the proxy makes an outbound connection to the host. ... > manner in which host authentication is decided unless the proxy was ... > transparent (a la transparent web proxy) in nature so the client ...
      (SSH)
    • Re: [fw-wiz] dirty packet tricks?
      ... solve via promiscuously sucking up packets. ... restriction that your 'sideways' proxy box is it will have to be on a hub ... The firewall will have to suppress all ICMP errors to the internal network ...
      (Firewall-Wizards)
    • Re: [fw-wiz] httport 3snf
      ... >> wouldn't have gotten SSH out of my firewall. ... > Postfix SMTP server with a wildcard MX that handed the mail that wasn't ... > destined to me off to the downstream MS stuff, and an HTTP proxy server ... All it needs is a written policx "Internet access is ...
      (Firewall-Wizards)
    • Re: Kids bypassing firewall via web proxy sites
      ... We use a Sonicwall firewall, 3060, I subscribe to content fltering, ... I checked "Access to HTTP Proxy Servers" But I am still able to get to ... CyBlock, which does network proxy and filtering ...
      (comp.security.firewalls)
    • Re: Tool to find hidden web proxy server
      ... No reason the proxy has to be INSIDE your firewall. ... Cell Phones to just bypass your firewall completely. ... On Thu, 2 Sep 2004, vinay mangal wrote: ... policy for Internet access says it is through IP ...
      (Pen-Test)