Penetration Testing mailing list archives

Re: Pushing SSH tunnels over TELNET proxies


From: Blasted <blasted () tech9security com>
Date: Mon, 16 Feb 2004 13:35:59 -0600

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

You should be able to push ssh over the telnet proxy easily.
here is a link to such a script (perl). 

http://www.pdc.kth.se/~jas/tunnel.pl

basically this person
has modified an ssh over http proxy to work with the telnet proxy.

Also it depends what type of proxy is running, ive seen where with ssl 
proxies, you have to use stunnel to get it talking the proper protocol
first. (ie if it didnt see an ssl handshake it would drop the connection).

- -David

On Friday 13 February 2004 21:48, Sekurity Wizard wrote:
Hey all,
  Trying to pen my way into a network we're testing here...and I found
an open TELNET proxy (outbound) from their network.  They believe that
since they can sniff all outbound traffic through this proxy, and log it
all...that it's not possible to "put one past 'em".  I'd like to try and
push an SSH tunnel out to our parent network through their only (besides
HTTP-proxy) way out of the network...can someone throw some advice my
way?
  Essentially, I'd like to tunnel arbitrary traffic out that SSH tunnel
to another endpoint on the 'net, and then use it as sort of a VPN I can
do what-ever I want with.

Thanks,
  Wiz

---------------------------------------------------------------------------
Free trial: Astaro Security Linux -- firewall with Spam/Virus Protection

Protect your network with the comprehensive security solution that
integrates six applications for ease of use and lower TCO.

Firewall - Virus protection - Spam protection - URL blocking - VPN
- Wireless security.

Download 30-day evaluation at:
http://www.astaro.com/php/contact/securityfocus.php
---------------------------------------------------------------------------
-
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2-rc1-SuSE (GNU/Linux)

iD8DBQFAMRufGiw6ooXcmeARAryeAJ0YiaFPMCD+A4a5apZorTdfp/QPKACeOT7J
Gc6Rz6ugmfhnr5rn+JBjQqQ=
=J9sy
-----END PGP SIGNATURE-----

---------------------------------------------------------------------------
Free trial: Astaro Security Linux -- firewall with Spam/Virus Protection

Protect your network with the comprehensive security solution that
integrates six applications for ease of use and lower TCO.

Firewall - Virus protection - Spam protection - URL blocking - VPN
- Wireless security.

Download 30-day evaluation at:
http://www.astaro.com/php/contact/securityfocus.php
----------------------------------------------------------------------------


Current thread: