Re: Access SSH server via HTTP proxy



Mark <markbpan@xxxxxxxxxxxxxx> wrote:
On Mon, 23 Oct 2006 14:59:19 -0700, Doug wrote:
Apparently setting up sshd listening on 443 or 8080 would be fine.

I have always set my home ssh server on port 443 for this reason and it
has worked for me. Does anybody know whether this will always work in
all environments? Or are there "deep inspection" corporate firewalls
that can discern the ssh content (the setup at least) and block it (but
still pass normal https)?

I don't know about 'discern the ssh content', but you could use a web
proxy instead of a normal firewall. Such a device could participate in
the HTTPS connection, which the ssh client would not conduct. That
would prevent basic use of the port. You could still tunnel traffic,
but it would have to be done within an HTTPS transport rather than
directly via TCP/443.

The first hit for me on google turned up this page:
http://dag.wieers.com/howto/ssh-http-tunneling/

--
Darren Dunham ddunham@xxxxxxxx
Senior Technical Consultant TAOS http://www.taos.com/
Got some Dr Pepper? San Francisco, CA bay area
< This line left intentionally blank to confuse you. >
.



Relevant Pages

  • [Full-Disclosure] RE: By passing surf control
    ... That is very easy if you can have a machine in the net with ssh server... ... With a standard proxy that support CONNECT METHOD (Typically HTTPS ...
    (Full-Disclosure)
  • RE: https
    ... You can add VNC over ssh to provide a GUI interface. ... So, what about https? ... > is to run an ftp server. ... LAUNCH - Your Yahoo! ...
    (Security-Basics)
  • Re: Wie beurteilt Ihr IPCop
    ... Welche Proxy brauche ichfür die SOHO denn noch? ... muss will man die Kiste fernwarten. ... Fernwartung per https und/oder ssh von außen zu ermöglichen!? ...
    (de.comp.security.firewall)
  • Re: Primer on SSH through https proxy tunnel needed
    ... Our firewall closed off the ssh port that I used to get ... >of running a ssh tunnel through a web proxy, but, I can't find enough ... >Our proxy accepts http and https request all on port 80. ...
    (comp.security.ssh)
  • Re: https, ssh - remote control
    ... > workstation still attempted to make the connection from the wks behind ... > becuase i will need to ssh to it before being able to ssh to the remote ... > i am basically trying to get the web server to place a connection on ... so no more https on that address. ...
    (alt.os.linux)