{"id":713,"date":"2011-03-30T16:36:30","date_gmt":"2011-03-30T15:36:30","guid":{"rendered":"http:\/\/www.dotmana.com\/index.php\/?p=713"},"modified":"2011-03-30T16:36:30","modified_gmt":"2011-03-30T15:36:30","slug":"tunnel-ssh-through-proxy-web-with-dns","status":"publish","type":"post","link":"http:\/\/www.dotmana.com\/weblog\/2011\/03\/tunnel-ssh-through-proxy-web-with-dns\/","title":{"rendered":"Tunnel SSH through proxy web (with DNS !)"},"content":{"rendered":"<p><strong>This is a little cookquide to setup a ssh tunnel through a proxy web. Your DNS queries will also be tunneled.<\/strong><\/p>\n<p>First step, you need a ssh server on a remote server.<br \/>\nConfigure it to listen to port 443 :<\/p>\n<blockquote><p>file : \/etc\/ssh\/sshd_config<br \/>\nPort 22<br \/>\nPort 443<\/p><\/blockquote>\n<p>Then you need to install corkscrew (on your local machine) :<\/p>\n<blockquote><p>sudo apt-get install corkscrew<\/p><\/blockquote>\n<p>Then create (or edit) your local ssh config file (~\/.ssh\/config) :<\/p>\n<blockquote><p>Host ssh-proxy<br \/>\nHostName your-remote-ssh-server<br \/>\n# Local SSH Server port<br \/>\nPort 443<br \/>\n# Keep-Alive<br \/>\nKeepAlive yes<br \/>\nProtocolKeepAlives 60<br \/>\n# Use proxy with login\/passwd<br \/>\n# ProxyCommand \/usr\/bin\/corkscrew address-of-proxy 3128 %h %p \/home\/user\/.ssh\/proxy_auth<br \/>\n# Use proxy without authentication<br \/>\nProxyCommand \/usr\/bin\/corkscrew address-of-proxy 3128 %h %p<\/p><\/blockquote>\n<p>If your proxy need authentication, enable first ProxyCommand line and add in ~\/.ssh\/proxy_auth credentials for proxy :<\/p>\n<blockquote><p>user:password<\/p><\/blockquote>\n<p>Then launch your ssh tunnel through the proxy<\/p>\n<blockquote><p>ssh -D 9999\u00a0 user@ssh-proxy<\/p><\/blockquote>\n<p>From this point, you can use your application with proxy socks enabled to localhost:9999 and you can reach the web.<\/p>\n<p>if you just need to browse, you can directly forward your DNS queries through proxy socks with (in Firefox) :<\/p>\n<blockquote>\n<li>about:config<\/li>\n<li>search string &#8220;dns&#8221;<\/li>\n<li>enable to &#8220;true&#8221; key &#8220;network.proxy.socks_remote_dns&#8221;<\/li>\n<\/blockquote>\n<p><strong>And now, how to send your DNS queries also through your ssh tunnel.<\/strong><\/p>\n<p>Install socat tool on your remote server AND on your local machine :<\/p>\n<blockquote><p>sudo apt-get install socat<\/p><\/blockquote>\n<p>On your remote server, launch socat to transform TCP request from 5353 to DNS UPD queries 53 (in this command, we use Google DNS) :<\/p>\n<blockquote><p>socat tcp4-listen:5353,reuseaddr,fork UDP:8.8.8.8:53<\/p><\/blockquote>\n<p>On your local machine, launch socat to transform local DNS queries to TCP port 5353 (need to be launched as root, since we listen on port 53) :<\/p>\n<blockquote><p>sudo socat -T15 udp4-recvfrom:53,reuseaddr,fork tcp:localhost:5353<\/p><\/blockquote>\n<p>Edit your \/etc\/resolv.conf file to add a &#8220;local DNS server&#8221; :<\/p>\n<blockquote><p>nameserver localhost<\/p><\/blockquote>\n<p>And eventually, launch a a specific DNS tunnel over SSH :<\/p>\n<blockquote><p>ssh -N -L 5353:localhost:5353 user@your-remote-server<\/p><\/blockquote>\n<p>You can ping real world \ud83d\ude09<\/p>\n<p><strong>To resume, once tools are installed, you need to launch (in this order) : <\/strong><\/p>\n<p>First terminal :<\/p>\n<ul>\n<li>edit your \/etc\/resolv.conf file and add localhost as local dns server)<\/li>\n<li>ssh -N -L 5353:localhost:5353 user@ssh-proxy<\/li>\n<\/ul>\n<p>Second terminal :<\/p>\n<ul>\n<li>sudo socat -T15 udp4-recvfrom:53,reuseaddr,fork tcp:localhost:5353<\/li>\n<\/ul>\n<p>Third terminal :<\/p>\n<ul>\n<li>ssh -D 9999\u00a0 user@ssh-proxy<\/li>\n<li>on this same remote terminal :<\/li>\n<li>socat tcp4-listen:5353,reuseaddr,fork UDP:8.8.8.8:53<\/li>\n<\/ul>\n<p>Thanks to : <a href=\"http:\/\/zarb.org\/~gc\/html\/udp-in-ssh-tunneling.html\" target=\"_blank\">http:\/\/zarb.org\/~gc\/html\/udp-in-ssh-tunneling.html<\/a> \/ <a href=\"http:\/\/tcweb.org\/wiki\/Traverser_un_proxy\" target=\"_blank\">http:\/\/tcweb.org\/wiki\/Traverser_un_proxy<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This is a little cookquide to setup a ssh tunnel through a proxy web. Your DNS queries will also be tunneled. First step, you need a ssh server on a remote server. Configure it to listen to port 443 : &hellip; <a href=\"http:\/\/www.dotmana.com\/weblog\/2011\/03\/tunnel-ssh-through-proxy-web-with-dns\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-713","post","type-post","status-publish","format-standard","hentry","category-ubuntu"],"_links":{"self":[{"href":"http:\/\/www.dotmana.com\/weblog\/wp-json\/wp\/v2\/posts\/713","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.dotmana.com\/weblog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.dotmana.com\/weblog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.dotmana.com\/weblog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.dotmana.com\/weblog\/wp-json\/wp\/v2\/comments?post=713"}],"version-history":[{"count":2,"href":"http:\/\/www.dotmana.com\/weblog\/wp-json\/wp\/v2\/posts\/713\/revisions"}],"predecessor-version":[{"id":715,"href":"http:\/\/www.dotmana.com\/weblog\/wp-json\/wp\/v2\/posts\/713\/revisions\/715"}],"wp:attachment":[{"href":"http:\/\/www.dotmana.com\/weblog\/wp-json\/wp\/v2\/media?parent=713"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.dotmana.com\/weblog\/wp-json\/wp\/v2\/categories?post=713"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.dotmana.com\/weblog\/wp-json\/wp\/v2\/tags?post=713"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}