Nmap Development mailing list archives

Re: Using ncat as a SSH proxycommand to connect trough proxy


From: "Christopher Atanasopulo [John Doe]" <lugsam () gmail com>
Date: Thu, 8 Jul 2010 23:59:29 -0300

2010/7/8 Nuno Gonçalves <nunojpg () gmail com>:
On Tue, Jul 6, 2010 at 19:39, Christopher Atanasopulo [John Doe]
<lugsam () gmail com> wrote:
Why don't just run the ssh server on port 443?...

I'm running on port 443. That is the first step.
But I still need to route SSH trough the company proxy to port 443 of
the server.

On Tue, Jul 6, 2010 at 19:48, DePriest, Jason R. <jrdepriest () gmail com> wrote:
I would advise you to take a thorough look at your employer's
acceptable usage policy or electronic usage policy or whatever you had
to agree to in order to work there.

What you are doing may be implicitly forbidden and you may be risking
termination by doing it.

Be very careful trying to circumvent the various protections put in
place, regardless of how easily they are bypassed.

-Jason

My agreement doesn't talk about IT stuff AND I'm trying to bypass in
the company interest(and only that). The issue is that IT department
is not willing to create the exception on their side.


Ok, I have a solution you may like to try. You can use apache web
server as proxy to let you connect through it to the ssh server.
Apache and ssh server can be on the same host. The thing would be like
this horrible ascii art schematic :p

               /___enterprise proxy___\       /-----------Your remote server---\
YOU -------->----------------------------------------->Apache------->OpenSSh
server
                \--------------------------------/
\-------------------------------------------/

I don't like much to type. So I'l leave you the link to the tutorial I
wrote about this [1]. And will be happy to answer any question.

This thread got way off-topic...

[1] http://labs.j0hnd0e.com.ar/2009/09/04/hells-library-bypassing-transparent-proxy-using-apache/

-- 
Christopher Atanasopulo | J0hn D0e
.o. ..o ooo | www.j0hnd0e.com.ar
If you require my GPG signature, please ask for it, I will send it
back when possible.
_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://seclists.org/nmap-dev/


Current thread: