block ssh tunnels

This is a discussion on block ssh tunnels within the Networking forums, part of the Help category; Hello I've some proxy that is configure to accept only 80 and 443 destination ports. But either that user can find shell account on 80 or 443 port and tunnel ...

Go Back   Unix Linux Forum > Unix > Linux > Help > Networking

FixUnix.com - Unix Linux Forums

Unix Content Register FAQ Calendar Search Today's Posts Mark Forums Read
  #1  
Old 08-24-2008, 08:54 AM
Default block ssh tunnels

Hello

I've some proxy that is configure to accept only 80 and 443 destination
ports. But either that user can find shell account on 80 or 443 port and
tunnel through this proxy to all internet. Is it possible to prevent that
kind of actions that user can work only with http[s] sites without
tunnels?



--
\!/ Kadu: #2940543
( @ @ ) mailto:dimmur-(at)-z-pl
oOO-(_)-OOo Registered Linux user: #277278
D.I.M.M.U.R.: Digital Intelligent Machine Manufactured for Ultimate Repair
Reply With Quote
  #2  
Old 08-24-2008, 10:30 AM
Default Re: block ssh tunnels

On Aug 24, 5:54*am, DimmuR wrote:

> I've some proxy that is configure to accept only 80 and 443 destination
> ports. But either that user can find shell account on 80 or 443 port and
> tunnel through this proxy to all internet. Is it possible to prevent that
> kind of actions that user can work only with http[s] sites without
> tunnels?


This is a human problem, not a technical problem. Review the logs and
appropriately punish those who break the rules.

DS
Reply With Quote
  #3  
Old 08-24-2008, 10:38 AM
Default Re: block ssh tunnels

DimmuR wrote:
> Hello
>
> I've some proxy that is configure to accept only 80 and 443 destination
> ports. But either that user can find shell account on 80 or 443 port and
> tunnel through this proxy to all internet. Is it possible to prevent that
> kind of actions that user can work only with http[s] sites without
> tunnels?


SSH tunneling can be blocked, but there are tunneling
methods using HTTP as the low-level transport. Have a
look at e.g. corkscrew (you can Google for it).

As soon as you open *any* connection to the Internet,
you also open a way to transport clandestine tunneling.

Would you please care to tell why?

--

Tauno Voipio
tauno voipio (at) iki fi

Reply With Quote
  #4  
Old 08-24-2008, 11:15 AM
Default Re: block ssh tunnels

On Sun, 24 Aug 2008 12:54:05 +0000 (UTC), DimmuR wrote:
>Hello


>I've some proxy that is configure to accept only 80 and 443 destination
>ports. But either that user can find shell account on 80 or 443 port and
>tunnel through this proxy to all internet. Is it possible to prevent that
>kind of actions that user can work only with http[s] sites without
>tunnels?


RTFM, specifically sshd.conf



Reply With Quote
  #5  
Old 08-26-2008, 12:49 PM
Default Re: block ssh tunnels

On Sun, 24 Aug 2008 12:54:05 +0000, DimmuR wrote:
> I've some proxy that is configure to accept only 80 and 443 destination
> ports. But either that user can find shell account on 80 or 443 port and
> tunnel through this proxy to all internet. Is it possible to prevent
> that kind of actions that user can work only with http[s] sites without
> tunnels?


Deny all sites and only allow those sites you trust.

Wkr,
Sven Vermeulen
Reply With Quote
Reply

Thread Tools


All times are GMT -5. The time now is 08:49 AM.

In an effort to better serve ads to our visitors, cookies are used on Fixunix.com. For more information, check out our Privacy Policy.

Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0
Ad Management by RedTyger