Q: ssh tunneling (port forwarding)

From: G. Ralph Kuntz, MD (grk@usa.net)
Date: 04/19/02


From: grk@usa.net (G. Ralph Kuntz, MD)
Date: 19 Apr 2002 12:14:12 -0700

I have a few questions about port forwarding in ssh and hope that
someone out there can answer them. My side runs linux with OpenSSH.

My company is entering a relationship with another company where they
would like to use ssh port forwarding to have their server application
communicate with our server application. I am not a security expert
and have some trepidations about using this technology.

As I understand it, I will write a program on my system that will
listen to a specific port (say 1234). SSH will be used from their
machine to tunnel through port 22 to port 1234.

Can an intruder run my listener program on port 1234 (am I opening
this port to outsiders) or can I specify that only connections from
127.0.0.1 will be accepted?

Can the other company run any arbitrary program on my machine since
they can run ssh on my machine? Can I restrict the set of programs the
other company can run on my machine?

Will my listener program be able to "authenticate" the other company's
software or do we still need digital signatures (PGP maybe)? Can I set
it up so that if they get through to my listener I am sure they came
through port 22 (ssh) and not directly to port 1234?

Thanks for any help you can give on these questions.
-Ralph



Relevant Pages

  • Re: ssh gives "Permission denied, please try again"
    ... port 22 on your internal machine, so you will need to keep ssh up to ... I configure the router to forward a different external port to 22 on my ... For good measure pick usernames that are none obvious, ... root/password: 163 times ...
    (uk.comp.os.linux)
  • [NEWS] SSH service at Dell DRAC4 Denial of Service (Mocana)
    ... SSH service at Dell DRAC4 Denial of Service ... Dell Remote Access Card 4 allows customers to effectively manage ... After the use of such a port scanner, ...
    (Securiteam)
  • Re: Remote Desktop directly to another computer on the network
    ... default port... ... And there is no reason for me to believe that ssh ... When I have a multibillion company I will use the key pair, ... WinSCP for that to access my home SSH server. ...
    (microsoft.public.windowsxp.work_remotely)
  • Re: SSH safety
    ... SSH safety (J.L. ... FC3 missing KDE menu items ... I was wondering how safe it is to open the ssh port up to the internet. ...
    (Fedora)
  • Re: Mac `owned in hacking competition
    ... the router's port forwarding rules. ... The firewall or a NAT router only stops connections initiated from ... ssh will let you set up forwarded ports in both ... You start an ssh session from the target machine (this is ...
    (uk.comp.sys.mac)